Who is responsible for your data
The data controller for Unwrite Make is Unwrite, based in Australia. That’s the business responsible for everything described on this page.
This policy covers Unwrite Make and the shared Unwrite account data Make uses. You sign in at make.unwrite.co/account/sign-in. Unwrite Voice has its own privacy policy, and the browser-based tools on unwrite.co are covered by the Unwrite website privacy policy.
What we store and why
Under your account and your projects we hold:
- Your account details, held by the one Unwrite account: your name and email address, whether it’s verified, how you signed in, your sign-in sessions with the IP address and browser each was created from, and any linked sign-in accounts. Make verifies your shared account session; it never keeps a copy of your account record.
- Your projects: the name, who owns it, who its members are, and the briefs, requirements and conversation threads you write in it.
- Saved notes: preferences you explicitly save in Make settings for use across your projects. Memory starts off. When you turn it on, Make sends those notes with your next model requests under the provider terms below. You can inspect or delete individual notes in settings; turning memory off keeps them saved but stops their use on the next turn. Your account data export includes them, and deleting your account removes them under the deletion terms below.
- Everything you upload: photographs, drawings, scans and CAD files, with the evidence and measurements taken from them.
- What Make generates: feature graphs, revisions and their parameters, validation runs, the built models and drawings, and the export files, plus review comments and the project activity trail.
- Plan and metering: which plan the owner is on, completed designs used, builds and machine time used, and a record of what each generation spent, so we can bill and meter correctly.
- A short-lived record of a payment you started, so a second attempt cannot charge you twice.
- A copy of the subscriptions Stripe has for you, so we can notice if two are running at once.
- A note of when we last checked your billing with Stripe, so a missed update can be caught up.
- Organisations, keys and integrations, if you use them: members and their roles, governance settings, the audit trail, API keys, and webhook endpoints. Credentials are protected with access controls and encryption.
Each project records a pseudonymous network identifier so build limits apply per person rather than per project. It is an internal abuse-prevention record and is not included in a project export.
We also count requests per address and per credential to stop one machine flooding the service. Those counters hold no name and no email, we store no password because Make has none, and your card details never reach us at all.
Where it runs
The Make site, API and stored project data run on Cloudflare. Pages serves the site, Workers runs the API, D1 stores project records, R2 stores uploaded and generated files, and Cloudflare Containers runs the CAD builder. The containers are restricted to Oceania and Asia Pacific, with placement determined by available capacity. D1 and R2 are encrypted at rest with keys Cloudflare manages.
Cloudflare receives ordinary connection data when it serves a request, including your IP address, the URL and browser details. Our sampled Workers logs are held for up to 7 days. They record operational events and identifiers, not your brief, photographs or model output.
When Make traces an object in a photograph, it uses Meta’s Segment Anything 3.1 model in a container run for Unwrite. The photograph goes to that container and the mask comes back to Make. It is not sent to Meta.
What reaches a model, and what it may do with it
To answer a design request we send the model what it needs: your brief and requirements, the relevant part of the feature graph, and the photographs or drawings a step is reading. Requests are routed through OpenRouter to the provider serving the model.
Every request excludes providers that would use it to train a model. We also require zero data retention where the selected model offers it. The AI providers that serve Make’s models do not train on your requests. They may keep prompts, attached images and replies for up to 90 days to check for abuse, and we cannot shorten that. When Detail Mode is on, the plan at the start of a design is written by a stronger planner from the same set of providers, under the same terms. Make moves to better models as they arrive, and this page states the longest period any provider in use keeps, so a change of model never makes it understate what is kept.
OpenRouter carries the request to the model’s provider and stores request metadata such as the model, provider, token counts, timing and cost. Prompt and response logging is not enabled for Make.
If you supply your own provider key, your runs go to that provider on your key and your agreement with them applies to them. Our own provider keys never leave our servers.
Our own logs hold codes, identifiers and counters. They don’t hold your briefs, your images or the model’s output. We sell your data to nobody, and there is no advertising on Make.
Project history, and improving Make
Project history records what happened in a project. You need it to run the product, because restore, revision provenance, support, export and deletion all read it.
Using a filtered copy of it to improve Make is a separate choice, and it’s off unless you turn it on in the project tools, where you can change it at any time. We remove values that look like secrets or credentials before that improvement copy is stored.
Cookies and sign-in
Unwrite uses one shared account cookie to keep you signed in across Make and Voice. It’s Secure and HttpOnly, so scripts can’t read it. Make keeps one non-sensitive preference in browser storage:
- whether you want the interface sounds on, in localStorage.
You only need to sign in to generate: viewing, sharing and downloads stay open, and none of them stores an account credential in browser storage.
Signing in happens against the one Unwrite account, which sends a code to your email address to prove you hold it. The browser receives the shared account cookie after a successful sign-in. Creating a project can be protected by Cloudflare Turnstile. It processes device and network signals to check for automated abuse and may set a strictly necessary cookie.
How long we keep it
Make Free keeps a project for 90 days after it’s created. While its owner has Pro or Max, we keep it for one year after it’s created. If the paid plan ends, the 90-day Free window applies from the project’s original creation date, so export older work before cancelling. An organisation can set its own retention period for the projects it governs, and a legal hold stops any deletion until it’s lifted.
Spend counters are pruned once the window they measure has passed, and the audit entries behind them outlive the counters because a billing question is asked later than the month it is about. Completed-design counters are kept the same way, so the allowance you were sold can be enforced, and they are pruned once their window has passed. An upload that is started and never finished is cleared within an hour.
Export and deletion
Export gives you a JSON file holding every row Make stores for that project, table by table, together with a list of the files kept for it. Where a column is deliberately held back, the file names it and says why, so it tells you what it lacks rather than quietly omitting it. The project history panel downloads its filtered history. A complete project export is available through the API while signed in, and we’ll send it to you if you’d rather ask.
Deleting a project removes its stored files first, then its rows. Delete it from Your projects, ask us, or the retention sweep does it in any case. The intent is kept until the deletion finishes, so an interrupted deletion resumes automatically. API keys and webhook integrations belong to your account rather than to one part, so they stay when a part goes. A key that opened only that part stops opening anything, and one pointed at every part carries on with the parts you still have. The records that hang off you rather than off a part (usage, billing customer reference, organisations you own, notes Make remembers, and the keys and integrations themselves) stay with your account, even with no projects left, and go when you delete your Unwrite account.
Your Unwrite account has its own export and deletion. The export gives you your account record, your sessions, your linked sign-in accounts and your Voice data, with sign-in credentials held back because a file carrying them could be used to sign in as you. Deleting your Unwrite account also deletes your Make projects and their stored files, cancels active Unwrite subscriptions, deletes your Voice data and closes the account. The operation stops if Make can’t confirm its part, so it won’t leave project files without an owner.
What deletion does not reach
Some records expire on a separate timetable:
- Database backups. The platform keeps point in time backups so we can recover from a mistake. Deleted rows can remain in those backups for up to 30 days.
- Model requests. The AI providers serving Make’s models may keep prompts, attached images and replies for up to 90 days to check for abuse.
- Service records. Cloudflare keeps sampled Workers logs for up to 7 days. OpenRouter keeps request metadata, and Resend keeps sign-in messages and delivery records under its published retention policy.
- Stripe. We cancel a subscription, but Stripe keeps its own billing records for as long as its tax and anti-fraud duties require.
Who else sees your data
We use a small number of suppliers to provide Make. Some act on our instructions, while others also process limited data for fraud prevention, security or legal obligations under their own terms.
- Cloudflare hosts everything: the site, the API, the database, your files and the build machines.
- OpenRouter routes model requests, and the model provider serves them under the routing terms described above.
- Stripe takes and stores card details and processes payments. We receive the plan and a customer reference.
- Resend delivers the sign-in code email, so it receives your email address, the message and delivery information when you ask for a code.
These suppliers may process data outside Australia, including in the United States and Asia Pacific. Unwrite is based in Australia, so overseas disclosure is handled under Australian Privacy Principle 8. We take reasonable steps to require recipients to protect the information in line with the Australian Privacy Principles.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, or object to it. Export and deletion in the product cover most of that immediately; for anything else, email us and we’ll act within one month.
If you think we’ve handled your data badly you can complain to us, and you can complain to a data protection regulator. Because Unwrite is based in Australia, that regulator is the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Contact
Questions about this policy or your Make data: support@unwrite.co.