Privacy

This policy explains which data MakeFont needs to provide font generation, how long it is kept, and which service providers participate in the workflow.

Last updated August 13, 2026

Data we collect

We collect account identifiers, verified email or Google identity information, session records, subscription status, credit ledger operations, profile names, source images, glyph revisions, font builds, processing events, and security events needed to operate MakeFont.

We do not need or request payment-card numbers. Stripe collects payment details on its hosted checkout pages and returns billing identifiers and payment status to MakeFont.

  • Guest file, default recognition language, and creation time stored locally in your browser before sign-in.
  • Uploaded source images, normalized images, vector glyphs, edit commands, and compiled fonts stored privately after sign-in.
  • Operational metadata such as job IDs, stages, durations, error categories, and idempotency keys.

Guest local storage

Selecting a file while signed out does not send it to MakeFont. The browser stores the file in IndexedDB so a Google or email sign-in redirect can resume the workflow. The local draft is designed to expire after twenty-four hours and is removed after successful authenticated upload. Clearing site data removes it sooner.

How we use data

We use uploaded material to recognize supported characters, prepare glyph crops, convert marks into vector outlines, present an editor, build requested font formats, detect failures, protect accounts, calculate credits, provide support, and meet legal obligations.

Automated suggestions are treated as untrusted assistance. Provider output is schema-validated and does not decide account permissions, charges, or final glyph mappings on its own.

Service providers

Cloudflare provides application delivery, private object storage, database, queues, containers, abuse controls, email delivery, and AI gateway infrastructure. OpenAI may process images for an optional alphabet-completion request routed through the configured gateway. Stripe handles checkout, subscriptions, invoices, refunds, and disputes. Google handles OAuth when you choose Google sign-in.

Actual provider settings must disable user-image caching and payload logging where supported. Privacy-sensitive production features are not launched until those settings and contractual boundaries are verified.

Retention

Unclaimed server temporary data and guest drafts are scheduled for removal after twenty-four hours. Account source images, SVG glyphs, commands, and font builds remain until you delete the profile or account. A deleted profile enters a thirty-day recovery period before its private objects are removed. Security, ledger, payment, and deletion audit records may be retained longer when necessary for fraud prevention, disputes, accounting, or law.

Security

MakeFont uses private storage, short-lived upload and download authorization, owner checks, secure session cookies, origin validation, file signature and dimension limits, image rewriting, restricted SVG elements, non-root processing containers, rate limits, and signed payment webhooks. No internet service can promise absolute security, so we also limit the data included in logs and processing messages.

Your choices and rights

You may delete a profile, request account deletion, ask for access or correction, withdraw optional processing by not starting it, and manage a subscription through billing controls. Applicable law may provide additional access, portability, restriction, objection, or complaint rights. Contact support with the account email and a clear request; never send an OTP or password.

Contact

Privacy requests can be sent to support@makefont.app. Identity verification may be required before data is disclosed or deleted. This policy will be updated when production processors, retention periods, or product behavior materially change.