The short version
Report Makeover runs in your browser. The documents you open and the reports you make never leave your computer — we have no copy of them, and no way to get one. What we do hold is the minimum needed to sell you access and let you sign in: your email address, a username, a record of your payment, and the technical traces any website keeps. This page lists all of it.
1. Who we are
Report Makeover (“we”, “us”) operates the website and web application at reportmakeover.com from the United Kingdom. For anything in this policy, email [email protected].
2. What we collect, and why
- Email address
- To deliver your account setup link, receipts and account notices, and to identify your account when you write to us. Given to us by you at checkout or by whoever set your account up.
- Username
- Your login name. It is also used, together with a fixed site value, to protect your password (see 4).
- Name
- If you gave one at checkout. Shown only to us, in our customer list.
- Payment record
- The amount, currency, date, your billing country, and the payment reference issued by our payment processor. We never see or store your card number.
- Account state
- Your plan (trial, paid), whether the account is active, when it was created, when you last signed in, when your password was last changed, and any note we add about a support conversation or refund.
- Devices
- A random identifier your browser generates and keeps, so we can count the devices signed into one account (the limit is three). It identifies a browser profile, not you.
We do not collect anything else about you, we do not profile you, and we do not buy or combine data about you from anyone.
3. What we never collect
- Your documents and reports. Files you open, text you edit, brand settings, logos and finished PDFs are stored by your browser on your own device. Nothing is uploaded to us. Clearing your browser’s site data deletes them; exporting a project keeps a copy.
- Your AI API key or AI conversations. If you use the optional AI features, your browser talks directly to the AI provider you chose, with a key you supply. We are not in that path and see none of it. That provider’s own privacy policy applies to what you send it.
- Your password. Your browser turns it into a key before anything is sent; we store only a one-way fingerprint of that key, which cannot be turned back into your password.
4. Cookies and browser storage
- Session cookie
- Set when you sign in so you stay signed in. Essential; expires or is cleared when you log out.
- Device id
- Kept in your browser’s local storage (see 2).
- Bot protection
- Sign-in and setup forms use Cloudflare Turnstile to tell people from bots. It may set a cookie of its own; see Cloudflare’s privacy policy.
We use no advertising or analytics cookies, and no third-party trackers.
5. Who else handles your data
We use a small number of providers to run the service. Each receives only what its job needs.
- Stripe
- Takes your payment. Stripe holds your card details and billing information under its own privacy policy; we receive the payment record described in 2.
- Cloudflare
- Hosts the website and our account database, and provides bot protection and network security. Standard server logs (IP address, request path, time) are kept briefly by Cloudflare for security and debugging.
- Resend
- Sends our emails (setup links, receipts, account notices) to your address.
We do not sell your data, share it with advertisers, or give it to anyone else, except where the law requires us to.
6. How long we keep it
Your account record is kept while your account exists. You can ask us to delete your account at any time (see 8), and we will remove your login and account details. Payment records are kept for six years after the transaction, because HMRC requires us to keep business records for that long; they are held for that purpose only. Your documents are not ours to keep or delete — they are on your device.
7. Where it is stored
Our systems run on Cloudflare’s global network. Data may be processed outside the United Kingdom and the European Economic Area by the providers in 5, each of which operates under recognised data-transfer safeguards.
8. Your rights
Under UK and EU data-protection law you can ask us to show you the data we hold about you, correct it, delete it, or stop processing it, and you can complain to the UK Information Commissioner’s Office. To exercise any of these, email [email protected] from the address on your account. We answer within 30 days, usually much sooner. Account deletion is handled by email for now; a self-service option may be added later. Deleting your account does not remove the payment record we must keep under 6 above.
9. Children
Report Makeover is for adults running a business. We do not knowingly collect data from anyone under 18.
10. Changes
If this policy changes in a way that matters, we will email account holders and update the date at the top. Continued use after that date means you accept the updated policy.