Legal
Privacy Policy
What we collect, why we use it, who we share it with and your rights. We do not use advertising or analytics trackers and we do not sell your data.
Data controller
The controller of your personal data is Eurodmc Dijital Marka Çözümleri Ticaret Limited Şirketi, which operates MakeMyMD. This policy is our privacy notice under the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where it applies, the EU General Data Protection Regulation (GDPR). Contact: [email protected].
Data we collect
- Account details: if you sign up with a username, your username, your name and an irreversible hash of your password; if you sign in with Google, GitHub or X, the name, email address (if the provider shares it), profile photo link and account ID we receive from that service.
- Content in your account: design projects you save, designs you publish to the showcase, your analyses, shares, comments, stars and the members you follow.
- Analyses: the web address you ask us to analyse and the result. During an analysis we measure the public content of that page and take screenshots; this is not your personal data.
- Payment details: Paddle takes the payment and we never see your card details. From Paddle we receive your customer ID, subscription status and plan, billing period dates and payment records (amount, date, invoice number).
- Technical data: IP address and browser details (for security, abuse prevention and rate limits; analysis records only keep an irreversible hash of the IP address) and error logs.
Cookies and browser storage
We only use an essential session cookie that keeps you signed in. Your browser's storage (localStorage and sessionStorage) keeps working data such as your language choice, the template you selected and wizard drafts; this stays on your device. We do not use advertising, analytics or tracking cookies. When you open checkout, Paddle may use its own cookies.
Why we process data
- To provide the service: create your account, store your projects and analyses, and run analyses (performance of a contract).
- Payments and billing: manage your subscription and analysis quota (performance of a contract, legal obligation).
- Community: show analyses you share, your comments, stars and follows (performance of a contract; sharing an analysis also requires your explicit consent).
- Security: prevent abuse, fraud and attacks (legitimate interest).
- Complying with legal obligations and handling legal claims.
Who we share data with
We do not sell your data. To provide the service we share it, only as far as necessary, with these providers:
- Natro: the servers hosting the site and its database (Türkiye).
- Cloudflare: content delivery and security; the browser infrastructure that measures pages during analyses (Workers, Browser Rendering).
- Anthropic: measurements and screenshots of the analysed page are sent to the Claude API to write the analysis; your account details are not sent.
- Paddle: the Merchant of Record for payments; it processes the details you enter at checkout under its own privacy policy.
- Google, GitHub and X: for authentication if you sign in with them.
- Google Fonts: page fonts load from Google's servers, which receive your IP address.
Publicly visible: your name and profile photo on analyses you share, your comments and (if you chose to show it) your name on showcase designs.
International transfers
Cloudflare, Anthropic, Paddle and the sign-in providers may process data on servers outside Türkiye and the EU. These transfers are needed to provide the service and rely on the transfer mechanisms provided for by KVKK and GDPR (for example standard contractual clauses).
How long we keep data
- Your account details and the content in your account are kept until you delete your account.
- When you delete your account, your account, projects, analyses (including shared ones), comments, stars, follows and subscription records are deleted. Paddle keeps payment records as required by law.
- Records kept for sign-in attempts and rate limits are kept for at most 24 hours; error logs are kept for a short period.
Your rights
Under Article 11 of KVKK and the GDPR you have the right to know whether your data is processed, to access and receive a copy, to rectification, to erasure, to object, to data portability and to withdraw consent you gave (for example by unsharing an analysis). Send requests to [email protected]; we reply within 30 days. You can also complain to the Turkish Personal Data Protection Authority or the data protection authority where you live.
Security
The site runs over HTTPS, passwords are stored only as irreversible hashes, and payment and analysis services are accessed only with secret keys held on our server. No system is completely secure; if a breach occurs we will notify you as the law requires.
Children
The service is not intended for anyone under 16 and we do not knowingly collect data from people under that age.
Changes
We may update this policy and will announce significant changes on the site or by email. The current version is always on this page.