Makerkeep Privacy Policy
Review draft — not yet approved for public release · Version 2026-10-081. Your shop, your information
Makerkeep is provided by NIXA Inc., a corporation incorporated in North Carolina, United States. This policy applies to the Makerkeep app, its account, cloud-storage and shared-workspace services, and Makerkeep support. It does not describe unrelated NIXA products. When a general NIXA policy permits broader processing, this Makerkeep policy governs Makerkeep information.
We collect only information needed for the functions you choose, account security, support you request, and obligations imposed by law. We do not sell or rent personal information or shop records, use them for targeted advertising, or share them for another organization's independent marketing. Makerkeep has no advertisements for trial or paid users. We do not use your records to train AI models or feed another NIXA project.
2. Device storage and optional cloud protection
A Makerkeep account is required to use the app, including a free trial. Account registration does not itself upload your shop records. With cloud storage off, your account-specific store is kept in this app installation or browser, and local calculations do not send business records to NIXA. Turning on private cloud storage uploads the complete saved store to your account so your supported devices can use the same records. No staff or other users can access that private cloud store unless you separately place records in a shared workspace and invite them. Your first sign-in requires internet. The installed app can subsequently open its saved account and store without a connection. A signed access permit, account profile and necessary clock-check metadata are cached on the device to verify offline use; iOS protects the service-key trust and clock checkpoint in Keychain. These records do not contain your readable password.
Saved changes synchronize while Makerkeep is open and online. Offline changes are queued on the device and upload when access and connectivity return. Unsaved form edits are not uploaded. Interrupted uploads or conflicting versions require review, and a change is protected in the cloud only after the app confirms it is synced. A synced store is not a historical archive: an accidental change may synchronize too. Makerkeep also keeps bounded automatic recovery points locally after saved changes and at startup: up to 20 distinct copies within 30 days and 32 MiB per workspace. Older copies are removed when recovery storage is next accessed. These copies are on the same device; they do not protect against device loss. Keep a portable backup for independent recovery.
Local workspaces, unfinished business form drafts, and exports may contain information you enter. Supported business forms save unfinished edits on this device as you work; drafts are not uploaded to NIXA and do not record business transactions until you review and save. Drafts are limited in size, removed on save or discard, and expire after seven days when next accessed. Account credentials and platform tokens are excluded from automatic form drafts. Account deletion removes this account’s local recovery points and drafts on the initiating device. Your device or browser provider may include app data in its own backups. NIXA cannot remotely erase files you downloaded, copies others exported, or backups controlled by you or your device provider. Use your device and backup controls to remove those copies.
3. Account and cloud-service information
An account uses your email address, display name, password verification hash, and an optional profile image. We do not store your password in readable form. Security records include account and session identifiers, session creation and activity times, a browser/device description for the signed-in devices list, hashed session and recovery credentials, and necessary account/workspace access events. Network addresses are used to deliver requests and limit abuse; the app does not use them to infer your location. To administer device limits, we store a platform category and a hash of a random identifier generated for the Makerkeep installation or browser. We do not obtain a hardware serial number, advertising identifier, or device fingerprint. A new installation or cleared browser storage can create a new identifier. The active sign-in limit is one per supported platform category; switching a device invalidates the previous online session in that category. The account creation time determines the 14-day account-service trial. Verified paid access expiry, when billing is integrated, is retained only to administer subscription access. Restoring a shop file does not reset that trial or create a billing entitlement.
A private cloud store or shared workspace stores the business records you choose to upload or enter, workspace and shop identifiers, revisions, member roles, invitation addresses, and optional shop logos. Business records may include sales and costs, cash balances, stock, production activity, product and material descriptions, plans, and notes. Free-text fields can contain personal information if you enter it; avoid buyer details, government identifiers, card numbers, bank credentials, health records, or other unnecessary sensitive information.
Support stores the subject, topic, message, replies, status, account identifier, and timestamps of a request you send. Basic app/browser/viewport diagnostics are attached only if you choose the diagnostic option shown before sending. A saved draft stays on your device until you send it. Closing a support request changes its status; it does not delete it. You may request its deletion.
If you choose an available Apple or Google sign-in method, we receive the provider account identifier, verified email address and any basic display name you authorize. We use them to create or securely connect your Makerkeep account. We do not request your shop, contacts, calendar, advertising activity or payment information from those providers. An Apple private relay address can be used. Existing accounts are connected only after you sign into and confirm the Makerkeep account; a matching email alone does not connect accounts.
Apple account verification and revocation can require retaining an encrypted Apple token while that sign-in method remains connected. We do not retain Google API access tokens for ongoing access. Disconnecting a provider or deleting an account removes the related Makerkeep identity records and token material. If Apple cannot be reached for revocation, account deletion still removes Makerkeep data and gives you a clear notice about the remaining Apple authorization so you can remove it from your Apple Account.
4. Files, photos, and optional connections
Sales files are parsed on your device. Makerkeep saves the supported financial fields and product/order references needed for reporting and reconciliation, rather than a copy of the entire uploaded file. Supported importers exclude buyer names, buyer email addresses, and delivery addresses. Review free-text product descriptions before importing. Workspace backups contain your entered business data and should be kept private. A .makerkeep store backup contains the saved workspace and integrity metadata, not account passwords, sign-in access, staff memberships, connection credentials, or support threads. Its custom format is not encryption. Anyone who has the file may be able to inspect its contents. Restore validates the file, previews merge or replacement, and does not grant account or subscription access. A local copy made before restoration can be exported for recovery and is cleared with this account’s device data.
A photo or camera choice is used only when you explicitly add a profile picture or shop logo. The app uses the selected image, not a scan of your photo library. File selection, clipboard actions, and export/share actions happen when you invoke them. Makerkeep does not request your contacts, precise location, microphone recordings, or background browsing activity.
Connections to sales platforms are optional and do not make Makerkeep exclusive to any platform. If a supported connection is enabled and you authorize it, the service stores authorization credentials and the minimum financial/product references needed to retrieve and review sales. Provider access tokens are encrypted on the server. Disconnecting removes the saved connection credentials and its unaccepted import inbox; previously accepted shop records remain until you delete them or the workspace. You may also revoke access with the provider. The provider processes information under its own policy when you authorize or use its service.
5. Why information is used
We use account information to authenticate you, recover access, and administer access and the cloud or shared features you request. We use workspace records to synchronize your shop, calculate the estimates and reports you ask for, and apply access rules. We use support information to answer your request and diagnose the reported issue. Necessary security information protects accounts and the service. We may send essential account, support, security, or legal notices; these are not advertisements.
Makerkeep does not contain an advertising SDK, cross-app tracking, session replay, or a third-party behavioral analytics service. Essential session cookies and local storage maintain sign-in, preferences, drafts, and your workspace. We do not use advertising cookies. Business marketing-cost fields describe your own spending; they do not mean Makerkeep serves ads to you.
6. Who can access information
Members you invite can read the shared workspace's business and financial data. Editors can change it; owners can manage membership and deletion. Your display name and optional avatar identify you to members; workspace owners can see member email addresses. Share only with people who should have that access. Members may export records, and removing their access cannot recall copies already exported.
Authorized NIXA personnel access information only when necessary to operate and secure Makerkeep, handle your request, or meet a legal obligation. Hosting, storage, network, and support-delivery providers may process the minimum information necessary on our behalf under confidentiality, security, deletion, and use restrictions. This service processing and your chosen workspace sharing are different from selling information or allowing another company to use it for its own purposes. We require service providers to protect Makerkeep information consistently with this policy. No provider is authorized to use it for advertising or model training.
We disclose information when you direct us to do so, or to the extent disclosure is legally required. We assess legal requests, disclose only what is required, and notify you when legally permitted. We do not treat a possible future dispute, product research, or commercial convenience as a reason to keep your deleted records. A change in company ownership does not authorize a new use of your information inconsistent with this policy.
Apple and Google process their own sign-in and consent flows under their own privacy terms when you choose those methods. Makerkeep sends the minimal sign-in request and public application/return address needed for that choice; it does not send your store records, sales, materials or production plans to the sign-in provider.
7. Retention and deletion
We keep information while it is needed for the active function you have chosen. You can initiate account deletion in Settings → Profile → Sign-in & security → Delete account. Your current password and a clear confirmation protect against accidental deletion. You do not need to contact support to initiate account deletion. Deletion removes the account record, profile, sessions, recovery codes, memberships, your support requests, and associated invitation/security records from the active service. Your private cloud store is removed with account deletion; it does not require transferring ownership.
If you are the only owner of a shared workspace, you may transfer ownership first or expressly include deletion of that workspace when deleting your account. Workspace deletion removes its server business records, memberships, invitations, workspace activity, and connected-provider credentials and inbox. This affects every member and cannot be undone. A workspace with another owner remains that business's workspace; deleting your membership does not instruct us to erase records the other owner continues to manage. Your account/profile and identifying account history are removed. If personal information about you remains in a shop's notes or records, request its removal through the privacy contact; we will assess the request with the responsible business and apply the law, rather than retain it automatically.
Deletion is intended to be irreversible, not account deactivation. We complete deletion of information under NIXA's control, including service-provider copies and restorable backups, within 30 days of a verified request or sooner when law requires. Backups must not be used to restore erased information. If a law or binding order requires retention, we retain only the specific necessary information, restrict access and use to that legal purpose, and erase it when the obligation ends. We explain the information retained, reason, and period unless a law prohibits disclosure. We do not retain deleted data for advertising, analytics, training, or indefinite troubleshooting.
Account deletion also clears this device’s account-specific local store, shared/cloud caches, pending changes, recovery copies, and support drafts. Other offline devices and exported files may keep copies until you remove them; NIXA cannot remotely erase user-controlled exports. Turning cloud storage off requires confirmation and your password, keeps the latest synced copy on this device, and removes your private server store. Other devices stop syncing that private store. Export anything you need before deletion or switching storage. Deleting an account does not cancel an Apple subscription; manage that separately through Apple Settings or the App Store subscriptions page.
8. Security and incident response
Makerkeep uses access controls, password hashing, session protection, protected server database files, and HTTPS for network account/workspace access. Provider tokens are encrypted. We do not claim that all workspace records are end-to-end encrypted or inaccessible to the service operator. Device security and your invited members also affect confidentiality. No system can guarantee absolute security.
If a privacy or security incident affects your information, we investigate, contain it, and provide notices to affected individuals and authorities as required by applicable law. Legally required incident records are limited to their required purpose and retention period. Contact us promptly if you suspect unauthorized access; do not send passwords or recovery codes in a support message.
9. Your choices, access, and privacy rights
An account is required for both trial and paid access. Cloud storage, optional photos, diagnostics, workspace sharing, and sales-platform connections are separate choices. You can correct profile and workspace records, export a complete store file, restore validated files, disconnect providers, remove members where authorized, and delete your account or workspace. Withdrawing a choice may stop the feature that needs it; it does not authorize a new use of your information.
Contact [email protected] with the subject 'Makerkeep privacy' to request access, correction, a portable copy where available, deletion, information about service providers/processing locations, or to raise a privacy complaint. NIXA's privacy contact is responsible for handling these requests. We verify identity using proportionate information and do not require unnecessary identity documents. If you cannot sign in, this contact is available without an account. Do not put sensitive data in an initial email.
We respond to access requests within 30 days and other requests within the applicable legal deadline. If a lawful extension or limited refusal is necessary, we explain the reason and any complaint or appeal route. We do not discriminate or charge a penalty for exercising privacy rights. Rights vary by jurisdiction, and these voluntary controls do not limit rights under applicable US state or Canadian federal/provincial law. Canadians may contact the Office of the Privacy Commissioner of Canada or their applicable provincial regulator, including Québec's Commission d'accès à l'information.
10. United States and Canada
NIXA is based in the United States. Cloud and shared services may involve processing outside your province or country, including in the United States, where authorities may obtain access under local law. NIXA remains accountable for processing on its behalf. Contact the privacy address for the current processing locations and service providers. We assess protection and put appropriate agreements in place before engaging a provider or changing processing locations. We do not promise Canadian-only storage.
Makerkeep's calculations compare your entered business assumptions. They do not automatically make legally significant decisions about you, approve credit, or set your prices. You decide whether and how to act on an estimate. We do not profile users for advertising.
11. Age, changes, and contact
Makerkeep is intended for adults who can enter a binding business-service agreement, and is not directed to children. We do not knowingly collect children's personal information. If a child has provided information, contact us so we can remove it as appropriate.
We update the version and effective date when this policy changes. Material changes are communicated in the app or by an essential account notice before taking effect. A broader use of previously supplied information requires a valid legal basis and any required fresh permission; continuing to use the app does not silently authorize unrelated advertising, sale, or training.
Provider: NIXA Inc., incorporated in North Carolina, United States. Privacy and support contact: [email protected]. Company website: https://nixainc.com. This product policy applies equally to free trials and paid Makerkeep subscriptions.
App Store license: Apple Standard EULA.