Skip to main content

Legal · Privacy

Privacy policy.

We design for minimal data. Many apps run fully on-device; AuraLinter and other agentic features use transparent cloud with clear retention. This hub collects only what you deliberately send.

Updated August 25, 2026

Scope

This policy covers makerportal.ai (the hub) and describes how MakerPortal studio products approach privacy. Individual app subdomains may publish product-specific notices; where they conflict, the product notice controls for that app.

Hub website

This paragraph changed on 25 August 2026, and the previous version was wrong. It said this site loads no third-party analytics. That stopped being true on 24 August 2026, when Vercel Web Analytics was enabled, and nothing changed the sentence. What is true now:

  • Vercel Web Analytics runs on every page. It records the address of the page you loaded (including any instrument settings a shared link carries in its query string), the referring site, country and device type. It sets no cookie and builds no cross-site profile, and we chose it over a self-hosted alternative for that reason. Its data lives with Vercel, this site's host, under Vercel's own privacy terms.
  • Simulator interaction events are a second, smaller stream. Each is written to a rolling 100-event localStorage log named mp_analytics_log, and since 5 September 2026 the keys marked "sent" in the table below are also transmitted to Vercel Web Analytics: an instrument or page name, a count, a partner or product name — values this site chose, never anything you typed.

Contact form submissions are processed only to respond to your message (including spam prevention). Hosting logs may include standard technical data (IP, user agent) for security and reliability.

Where advertising may appear

Display advertising is confined to the markets tools, and nowhere else. Those pages are:

  • /library/ticker/
  • /library/tickers
  • /library/markets
  • /library/stock-screener
  • /library/penny-stock-integrity

Every other page — the whole Lab, every field note, the app matrix, the shop and the studio pages — carries no advertising and no ad-network code. That boundary is enforced in the site's source rather than by convention: ad placements are gated on the same list printed above (src/data/ad-policy.ts), with tests asserting the Lab and the blog cannot be admitted to it. If this page and the code ever disagree, the code is what actually runs.

As of 2026-09-16 no advertising network is configured and no ad code is served on any page, including those listed above. The placements are reserved but empty. If that changes, this paragraph changes with it, and the network in use will be named here.

Theme preference is stored in localStorage on your device only — it never leaves your browser.

Some gear cards lazy-load product artwork from a merchant image host only when the card approaches the viewport. Those requests use referrerpolicy="no-referrer"; as with any direct web request, the image host can still receive your IP address and user agent. These are product images, not tracking pixels. Provider requests from BYO-key playgrounds occur only after you explicitly run them, and go directly from your browser to the named provider.

Applications

Most MakerPortal apps are built for on-device processing where possible. AuraLinter and future agentic titles use cloud for audio upload, LangGraph orchestration, and clang++ verification — with temporary file retention (30min sync, 4h long jobs) and run records disclosed in each product’s privacy policy. We do not sell personal data and disclose cloud use per-app.

Affiliate disclosure

Some resource, playground, or shop links are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. We only recommend tools we believe are useful. Affiliate relationships never require us to share your personal browsing data with partners beyond what the merchant’s own checkout requires.

Approved partners today:

  • Amazon Associates — tag engineersport-20. Commission varies by category (often ~1–4.5% on books/tools/electronics). 24h cookie; Creators API cache is build-time only, no runtime calls (D-015).
  • SparkFun Affiliate — referral code rOtrc44SZw (?ref= on sparkfun.com URLs). 10% on SparkFun Original products; third-party catalog items (e.g. Raspberry Pi boards, Jetson, Teensy) are tracked but may pay $0 under SparkFun’s program rules.
  • PCBWay Referralhttps://pcbway.com/g/VJp6Xm — friend gets $5 new-user credit, you get $10 coupon + 5% of 1st order cash (excludes coupons/shipping/components/fees). Live 2026-07-19, low effort. Shared Projects (10% PCB + 10% SMT) still pending — needs real boards, see roadmap.
  • ElevenLabs PartnerStack — approved destination try.elevenlabs.io/jzowx8mw6p6b. MakerPortal may earn a 22% recurring commission for up to 12 months on eligible plans started through the link. This is compensation to MakerPortal, not a customer discount; no “22% off” claim is made.

Pending / shelved: Pinecone Affiliate Partner — application submitted, no tracked URL or public commission rate yet; PCBWay Shared Projects — tabled until a real reviewed board design exists; JLCPCB Brand Advocate / referral — deferred; Buttondown Newsletter is live as of 2026-08-06: signup forms submit to buttondown.com/makerportal, and where you tick the separate unchecked opt-in on an export gate, that address is sent there too — see the export-gate row above for exactly what is stored locally versus sent. Lemon Squeezy is live as this site's only payment processor and Merchant of Record: the pay-what-you-want tip has been checking out through it since July 2026. The three archive products and Lab Pro are not built yet — no files are packaged and no products exist in the store — so their cards show a pre-order state and take no payment. Modal and Fly.io labs are educational only with informational links because no verified stable public affiliate program exists; owner rejected free-token / credit-grant DevRel programs 2026-07-19. Empty partner constants never receive a sponsored label. See docs/growth/MONETIZATION.md.

Live compensated links use rel="sponsored noopener noreferrer"; informational provider links are not labeled sponsored. We do not use undisclosed native ads.

Export gate & email (soft list)

Simulator exports—including code/config, measurement JSON/CSV, topology, and recorded WAV outputs—have two paths:

  • Free: watermarked file (small footer makerportal.ai brand line) — always available, no email.
  • Clean: watermark removed after soft email unlock. Email is stored in localStorage key mp_export_email_{sim} + unlock flag mp_export_unlock_{sim} per simulator. If Buttondown is configured, a separate unchecked opt-in controls whether the address is sent to Buttondown; export works without subscribing.

No hard paywall, no Clerk. You can re-lock via DevTools → Application → Local Storage.

Every interaction event this site can emit

All 20 of them are first-party CustomEvent('mp:analytics') events. Each is written to the local rolling log, and the keys marked "sent" below are additionally transmitted to Vercel Web Analytics. Nothing else in the payload is. Payloads carry no email address, no hostname you typed, no API key, no licence key, no endpoint token, and no text you typed into a simulator. The table is generated from the same file the code reads, so it cannot fall behind the code.

EventWhat it recordsSent to Vercel
acoustic_calc_export_unlockthe acoustics calculators clean export was unlockedsim
aha_cta_clickthe call to action shown after that milestone was clickedpartnersim
aha_momenta solver reached the state its page exists to demonstratemetricsim
closed_circuit_validatedthe agentic circuit proposer returned a validated designcircuit_domain
export_downloada simulator export was downloadedsimvariant
export_gate_unlockthe clean-export gate was unlockedsim
fab_jlcpcb_clickthe JLCPCB order link was clickedsim
fab_pcbway_clickthe PCBWay order link was clickedsim
gear_clicka gear card was clickedidmerchant
kit_cta_clicka build-kit call to action was clickedkitId
newsletter_subscribea newsletter signup form was submittedsource
pro-buy_clickthe Lab Pro checkout link was clickedproduct
pro_activatea Lab Pro licence was activated in this browsertier
pro_signoutLab Pro was signed out of in this browsertier
saas_partner_clicka partner link in a lab instrument was clickedpartnersim
share_link_copythe copy-link button on a lab instrument was pressedconfiguredsim
shop-buy_clicka shop checkout link was clickedproduct
shop_clicka shop link with no explicit label was clickedproduct
tip_clickthe pay-what-you-want tip link was clickedproduct
vector_retrieval_sweep_completethe recall sweep finishedsim

The complete set of payload values that can be transmitted is circuit_domainconfiguredidkitIdmerchantmetricpartnerproductsimsourcetiervariant— every one of them a value this site chose (a page slug, a product id, a partner name, a tier), never a value you supplied. Continuous solver outputs and the destination URL of a checkout link stay in your browser.

The checkout events additionally record which link was clicked — the product id and that link's own destination URL. Both are this site's values, not yours.

Lab Pro licences

Lab Pro is a paid tier that turns the clean export on across every gated simulator at once. It is sold through Lemon Squeezy, and a purchase produces a licence key. Activating it works like this, and this paragraph exists in the same commit as the code it describes:

  • What your browser stores: the licence key you paste, in localStorage under mp_pro_license_key, plus a small verdict record under mp_pro_license holding only { tier, checkedAt } — a tier name and a timestamp, no key, no email, no name. Both stay on your device. Deleting them, or using the "Sign out of Pro" button on the shop page, removes the unlock from that browser.
  • What leaves your browser: the licence key, sent to this site's own /api/license/validate endpoint, which forwards it to Lemon Squeezy's licence API to ask whether it is an active Lab Pro key. That request is repeated at most once a day while Pro stays active; an activation that cannot reach the network keeps working for seven days before it lapses.
  • What this site keeps: nothing. There is no account, no user database, and no stored record of a key or a purchase on our side. The endpoint answers only { valid, tier, checkedAt } — it never returns, logs, or retains the customer name and email address that Lemon Squeezy sends back with a validation, and a recently-checked verdict lives in one server's memory for a few minutes and then is gone.
  • What is never in an analytics event: the key. The local pro_activate and pro_signout events carry the tier name and nothing else.

Lemon Squeezy is the Merchant of Record for the purchase itself and holds its own customer record under its own privacy policy; billing questions and cancellations go through its customer portal.

Contact

Privacy questions: Contact the studio.