Privacy Policy
Last updated: February 2026
Key Points
- •We collect only what's needed to help you plan DIY projects
- •Your project data belongs to you and is deleted when you delete your account
- •We use Claude AI (by Anthropic) to provide project guidance
- •We earn commission from affiliate links (like Amazon product recommendations)
- •You can delete your account and all data at any time
- •We comply with UK GDPR and store data in the UK/EU
- •International users are subject to UK data protection laws
1. Data We Collect
We collect the following types of information:
Account Information
- Email address (used for authentication and account recovery)
- Name (optional, used to personalise your experience)
- Authentication tokens from third-party login providers (Google, GitHub)
Project Data
- Project titles and descriptions you create
- Chat messages between you and the AI assistant
- Photos you upload of your DIY projects
- Tool and material recommendations generated for your projects
Technical Data
- IP address and approximate location (country level)
- Browser type and device information
- Pages visited and actions taken within the service
2. How We Use Your Data
We use your data for these specific purposes:
- Providing AI guidance: Your project descriptions and photos are sent to Claude AI to generate personalised DIY advice
- Product recommendations: We use your project context to suggest relevant tools and materials from Amazon (affiliate links)
- Account management: We use your email to authenticate you and send important account notifications
- Service improvement: We analyse usage patterns (anonymised) to improve the product experience
We do not sell your personal data. We do not use your data for advertising. We do not share your project details with anyone except our essential service providers listed below.
3. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights regarding your personal data:
- Right to access: You can request a copy of all data we hold about you
- Right to rectification: You can correct any inaccurate personal data
- Right to erasure ("right to be forgotten"): You can request deletion of your data at any time
- Right to restrict processing: You can ask us to temporarily stop using your data
- Right to data portability: You can request your data in a machine-readable format
- Right to object: You can object to certain types of data processing
To exercise any of these rights, contact us at [email protected]. We respond to all requests within 30 days.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
4. Third-Party Data Processors
We share your data with the following service providers who help us operate DIYmaity. Each has appropriate data protection agreements in place:
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Anthropic (Claude AI) | AI project guidance | Project details, conversations | US (SCCs) |
| MongoDB Atlas | Database storage | All user data | EU (London) |
| Cloudflare R2 | Image storage | Uploaded project images | EU |
| Resend | Transactional email | Email address | US (SCCs) |
| Vercel | Hosting | Request logs | Global (EU primary) |
SCCs = Standard Contractual Clauses, the legal mechanism for transferring data outside the UK/EU
5. Data Retention
We retain your data according to these principles:
- Account data: Kept until you delete your account
- Project data: Kept until you delete the project or your account
- Chat history: Kept with your project data
- Uploaded images: Deleted when you delete the associated project or account
- Technical logs: Automatically deleted after 90 days
When you delete your account, we permanently remove all your personal data within 30 days. Some anonymised, aggregated data (like usage statistics) may be retained indefinitely.
6. International Users
DIYmaity is operated from the United Kingdom. If you access our service from outside the UK:
- Your data is processed under UK data protection law (UK GDPR)
- By using DIYmaity, you consent to the transfer of your data to the UK and our third-party processors
- We maintain appropriate safeguards for international data transfers, including Standard Contractual Clauses where required
If you are located in the European Economic Area (EEA), your rights under EU GDPR are substantially similar to UK GDPR rights described above.
7. Contact Us
For privacy-related questions or to exercise your data rights, contact us at:
- Email: [email protected]
- Contact form: diymaity.com/contact
We aim to respond to all privacy requests within 30 days. For urgent matters, please include "URGENT" in your email subject line.