Privacy Policy
Last updated: February 2026
MEP Desk is built on a local-first principle. Your engineering data — projects, calculations, references, notes, and exports — is stored on your device by default and is not sent to our servers unless you enable cloud backup as a Professional subscriber. This policy explains what limited data we do collect and how we use it.
Who we are
MEP Desk is operated from England, United Kingdom. You can reach us at [email protected].
The operator details on this page will be updated when formal registration is complete.
What data stays on your device
By default, MEP Desk stores all data locally in your browser (using localStorage and IndexedDB). Your projects, calculations, and references are saved on your device and are not transmitted to our servers unless you are a Professional subscriber with cloud backup enabled.
- Projects, rooms, and unit data
- Calculation inputs, outputs, and saved results
- Assumptions and space-type configurations
- Equipment library entries and datasheets
- Notes, pinned references, and export preferences
- Search history and UI preferences
For Free users, we have no access to this data. We cannot read, recover, or back it up. If you clear your browser data, this data is permanently deleted. Professional users with cloud backup enabled have the option of automatic cloud recovery — see below.
Cloud Backup (Professional Users)
Professional subscribers have the option of automatic cloud backup. Here is what this means:
What is stored: Project data including project metadata, rooms, saved calculations, equipment links, and assumptions. This is the same data visible in your Project Pack export.
Where it is stored: Your data is stored on Supabase infrastructure hosted in the European Union. Supabase uses Amazon Web Services data centres with SOC 2 Type II compliance.
Encryption: All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256.
Who can access it: Only you. MEP Desk staff do not access your project data. We may access anonymised, aggregated usage statistics such as total number of projects created but never individual project content.
Data retention: Your cloud backup data is retained for as long as your Professional subscription is active. If you cancel, your cloud data is retained for 90 days, then permanently deleted. You can export all your data at any time before deletion.
Data deletion: You can request deletion of your cloud backup data at any time by emailing [email protected]. Deletion is completed within 30 days.
Free users: If you are on the Free plan, no data leaves your device. All storage is local to your browser. MEP Desk has no access to your project data.
Your choice: Cloud backup is automatic for Professional users but you can disable it in Settings at any time. With cloud backup disabled, Professional behaves identically to Free regarding data storage.
What data we do collect
Account data — When you create an account, we collect your email address and a hashed password. This is stored by our authentication provider (Supabase). We use this to manage your account and subscription tier (Free or Professional). We do not collect your name, company, job title, or any other personal information during signup.
Payment data — If you upgrade to Professional, payment is processed by Stripe. We do not see or store your card number, bank details, or billing address. Stripe provides us with confirmation of your subscription status and billing period only. See Stripe's privacy policy for how Stripe handles your payment data.
Email subscriptions — If you subscribe to updates (for example, standards change notifications or product news), we store your email address and the source of the subscription (such as Standards Tracker or the homepage). You can unsubscribe at any time.
Technical data — Our hosting provider may log standard web server data such as IP addresses, browser type, and pages visited. We do not run any analytics scripts, tracking pixels, or advertising tools on the MEP Desk website.
How we use your data
- Account data: to authenticate you and manage your subscription tier
- Payment confirmation: to grant or revoke Professional tier access
- Email subscriptions: to send product updates or standards change notifications (only if you opted in)
We do not sell, rent, or share your personal data with any third parties for marketing purposes.
Third-party services
| Service | Purpose | Data shared | Their privacy policy |
|---|---|---|---|
| Supabase | Authentication, user profiles, and cloud backup storage (Professional) | Email, hashed password, subscription tier, and project backup data (Professional only) | supabase.com/privacy |
| Stripe | Payment processing | Payment details (card, billing) — we never see this | stripe.com/privacy |
We do not use Google Analytics, Facebook Pixel, or any other tracking or advertising services.
Cookies
MEP Desk uses minimal cookies. See our Cookie Policy for full details. In summary: we use a session cookie for authentication if you are logged in, and localStorage for your engineering data and UI preferences. We do not use advertising or tracking cookies.
Your rights (UK GDPR)
Under UK data protection law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Object to processing of your data
- Data portability (receive your data in a structured format)
To exercise any of these rights, email [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.
Data retention
- Account data: retained for as long as your account exists. If you delete your account, your email and profile data are removed from our authentication system.
- Payment records: Stripe retains transaction records as required by financial regulations. We retain subscription status records for the duration of your account.
- Email subscriptions: retained until you unsubscribe.
- Local data: stored on your device only. We have no control over its retention — it persists until you clear your browser data or uninstall the application.
Children
MEP Desk is a professional engineering tool and is not directed at children under 16. We do not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. We will not reduce your rights under this policy without notifying you.
Contact
If you have questions about this policy or your data, email [email protected].