Legal & Privacy
Last updated 2026-10-02.
Controller & contact
The data controller for calcnote is an independent sole-proprietor operator based in Türkiye, operating under the trade name Foundry Core Labs. Data subjects can exercise all their rights via contact@foundrycorelabs.com. The operator's legal identity is available to competent authorities on request.
Reach us at contact@foundrycorelabs.com, or use the form at the bottom of this page.
What we collect and why
Everything calcnote collects, why we collect it, and the legal basis under GDPR Article 6:
- Account email — to create and authenticate your account. Legal basis: contract (Art. 6(1)(b)).
- Waitlist email — to notify you when a specific feature ships. Legal basis: consent (Art. 6(1)(a)).
- Feedback text (via the "Was this useful?" form on a calc result) — to improve the product. Legal basis: legitimate interest (Art. 6(1)(f)).
- Contact-form messages (via the form on this page) — to respond to your inquiry. Legal basis: legitimate interest.
- Calculation inputs and results — to compute your requested output. The inputs themselves are not stored; operational logs may incidentally capture request data on error. Legal basis: contract.
- AI narrative data — stored when a result page requests a narrative, which it does automatically. For signed-in visitors, a record of each request (account id, time and outcome; no calculation data). When a narrative is generated, a one-way hash of the request and the model’s prose, served for 24 hours; see Automated narrative generation below. Legal basis: legitimate interest (Art. 6(1)(f)).
- Session cookie
cn_analytics_id— a per-visit random identifier used only to aggregate visit counts within a single session. Legal basis: legitimate interest. - Visitor cookie
cn_visitor_id— a pseudonymous random identifier kept for 180 days from your last visit, used only to measure returning-visitor counts on this site. First-party only; it contains no personal details and is not shared with anyone. Legal basis: legitimate interest (Art. 6(1)(f)). - Operator cookie
cn_internal— set only on the site operator's own devices to mark their visits as internal so they can be excluded from visitor statistics. Not set for normal visitors. Kept 180 days. Legal basis: legitimate interest. - IP address and User-Agent — retained in server request logs for operational monitoring and security. Legal basis: legitimate interest.
No third-party analytics services, ad networks, or marketing trackers are loaded on any page.
Who processes it
Three processors handle data on our behalf:
- Supabase (Supabase Inc., US parent; EU-region hosting) — hosts the authentication database, waitlist, and analytics events.
- Google Cloud Run (Google LLC, US parent; region europe-west1, Belgium) — hosts the calcnote application.
- Google Vertex AI (Google LLC; Gemini 2.5 Flash model) — generates the plain-English narrative, which every result page requests automatically. See Automated narrative generation below for what is sent, how it is checked and what is stored.
All three are US-parent companies with EU-region infrastructure or EU-egress paths. Any implicit onward transfer to the United States relies on the EU–US Data Privacy Framework adequacy decision and, where applicable, Standard Contractual Clauses.
Automated narrative generation
calcnote adds an AI-generated plain-English restatement to each calculation result. Every result page requests one automatically when it opens; there is no setting to turn this off. This is a free-tier feature for now; it may move to a paid tier as calcnote’s pricing lands.
When the model is called: opening a result page requests a narrative, and calcnote sends the calculation to Google unless a narrative for the same numbers is already cached or a limit described below has been reached. Closing the tab or navigating away does not stop the request; the server already has it. The deterministic result (the verdict, the P-M diagram and the D/C ratios) is produced without any AI processing and does not depend on the narrative.
Sub-processor: Google LLC (Vertex AI, Gemini 2.5 Flash model). What Google retains of a request is governed by Google’s own terms, which calcnote does not control.
What is sent per request: the calculation, and nothing else. Section geometry (width and depth for a rectangular column; diameter, tied or spiral, and spiral pitch for a circular one); concrete and steel strengths (f′c, fy); bar count and size, tie or spiral size, and clear cover; the factored loads (Pu, M2, M1); the verdict; both D/C ratios and which one controls; the section-behaviour class; φPn and φMn at the operating point; and the code and full text of any advisory warning. For a circular column two more items are sent: which of the two checked ring positions governs the verdict (one bar on the compression axis, or the ring turned half a bar spacing), and whether both positions agree. For a slender column the eight values of the moment-magnification chain are also sent (kl/r and its limit, Cm, βdns, EIeff, Pc, δns, Mc). For a rectangular column the bending axis (about X or about Y) is sent. The unsupported length, the effective-length factor, the bar layout chosen for a rectangular column (bars on two faces or on all four), and the tie spacing are not sent. A retry after a timeout or an error re-sends the identical request. No free text of any kind is sent. Project name and engineer name reach calcnote’s own server, where they are printed into the Word note; they do not reach Google. No email address, IP address, session or visitor identifier, or account identifier is sent.
Purpose and checking: the model restates what the deterministic engine already computed. Before a narrative is shown, cached or embedded in a Word note, calcnote checks its verdict, controlling ratio, section-behaviour class and warning code against the engine character for character, checks that a referenced warning is actually mentioned in the text, and rejects a warning reference the engine did not emit. For a slender column the model is instructed to use only the magnification values it was given. The other numbers in the prose are not checked against the engine.
What calcnote stores: a generated narrative is kept in calcnote’s own database, keyed by a one-way hash of the request, and served for 24 hours to any later request that produces the same hash; after that it is unusable and is deleted on a later sweep. The same section under the same loads produces the same hash, so a narrative generated for one request may be served for another, signed in or not. The stored narrative is the model’s six output fields and nothing else: no free text and no identifier. For signed-in visitors, one row per narrative request is kept, holding the account id, a timestamp and one outcome word, with no expiry; it enforces a limit of 100 generations per account in any 24 hours, counting only requests in which the model ran. A shared ledger holds one running spend total per day; the cap is $2.00 per day across all visitors, which is why a narrative can be unavailable. The structured log lines calcnote writes about a narrative carry an event name, a short diagnostic code, the hash and an outcome word, never narrative text and never anything you typed.
The Word note: the checkbox on the result page’s download form is off by default and becomes available only after a narrative has been shown on that page. Ticking it copies that narrative into the file; the download itself never calls the model. If you leave it unticked, your download contains no narrative. Every Word note prints the calculation’s full input set, so anyone holding the file can ask calcnote for a narrative of that calculation. A downloaded file is a snapshot: corrections to this page do not reach files already issued. Files downloaded before 2026-09-24 that include a narrative carry a disclosure sentence that pointed here for an “opt-out mechanism” that did not exist and stated that every number in the narrative was echoed from the engine; the accurate statements are the ones on this page.
Security
We use TLS for data in transit, at-rest encryption via our processors, and role-based access controls on the application database. Passwords are handled exclusively by Supabase Auth, which uses industry-standard hashing.
Retention
- Session cookie
cn_analytics_id: cleared when you close the browser session. - Visitor cookie
cn_visitor_id: 180 days from your last visit (rolling). - Operator cookie
cn_internal: 180 days (operator devices only). - Server request logs: kept for operational monitoring and security. The retention period is the hosting provider’s; calcnote does not set one.
- AI narrative cache: served for 24 hours from the last time the same request was generated, then unusable and deleted on a later sweep.
- AI narrative request records (signed-in visitors only): no expiry; deleted with the account.
- Account email and waitlist entries: retained until you request deletion.
- Feedback and contact-form messages: retained until you request deletion.
Your rights
Under GDPR and the Turkish KVKK you may:
- Access a copy of any data we hold about you.
- Correct anything that's inaccurate.
- Delete your account, waitlist entry, or past submissions.
- Object to processing based on legitimate interest.
- Restrict processing while a dispute is resolved.
- Receive your data in a portable format.
- Withdraw consent (waitlist) at any time.
- Lodge a complaint with your local EU/EEA data-protection authority or with the Turkish Kişisel Verileri Koruma Kurumu (KVKK).
Email contact@foundrycorelabs.com to exercise any of these rights. We respond within 30 days per GDPR Art. 12(3), typically much sooner.
Breach notification
If we become aware of a personal-data breach that presents a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours per GDPR Art. 33 and notify affected users directly where the risk is high per Art. 34.
Not directed to children
calcnote is intended for professional structural engineers and is not directed to users under the age of 16.
Terms
calcnote is provided as-is, with no warranty of any kind, express or implied, including no implied warranty of merchantability, fitness for a particular purpose, or non-infringement.
As stated in the site footer and on every generated calc note, calculation results require independent engineering review and signature/seal by a licensed Engineer of Record. The generated .docx is not a licensed deliverable. You are responsible for verifying every result and for compliance with all applicable codes and jurisdictional requirements.
Limitation of liability. To the maximum extent permitted by law, our aggregate liability for any claim arising from your use of calcnote is limited to the fees you have paid us in the twelve months preceding the claim — which, for the free tier, is zero. We are not liable for indirect, incidental, consequential, or punitive damages.
No third-party beneficiary. Nothing in these terms grants any right or benefit to any third party. No client, contractor, occupant, or other party who is affected by a design decision based in whole or in part on a calcnote output has any claim against the operator under these terms.
Your indemnification. You (the licensed engineer or user) agree to indemnify and hold harmless the operator from any third-party claim arising from your use of calcnote outputs in your professional work, including any structure designed, reviewed, or documented with the assistance of calcnote.
We may change, suspend, or discontinue the service at any time.
Changes to this notice
The "Last updated" date at the top of this page reflects the current version. Material changes to how we process personal data will trigger an email notice to registered users.
Jurisdiction
Any dispute arising from use of this service is governed by the laws of the Republic of Türkiye, without prejudice to consumer rights you may have in your country of residence.
Send us a message
Use this form for questions, feedback, or data-deletion requests. Reaches the same inbox as contact@foundrycorelabs.com.