Legal
Privacy notice
Anvil (anvilpaper.com) is operated by Abdelrahman Moustafa, an individual seller based in Kuwait, who is the data controller for the personal data described here. This notice explains what we collect, why, who we share it with, and your rights.
Last updated 29 August 2026
What we collect
Account data: your email address, login credentials and authentication metadata, handled by our managed authentication provider.
Project data: the briefs, uploaded PDFs, specifications, bills of material, supplier offers, rate cards, quotes and chat messages you create in the workspace.
Usage and device data: error logs, basic performance telemetry, device identifiers and IP address, used to keep the service reliable and secure.
Support data: messages you send us through the contact page or support channels.
Why we use it and our legal basis
To create your account and provide the service you request — extracting facts from a brief, proposing components, sourcing prices, running preflight checks and generating your DOCX proposal (performance of a contract).
For security and fraud prevention, and to keep the service reliable (legitimate interests).
For product improvement using aggregated or anonymised telemetry (legitimate interests).
To respond to your support requests (performance of a contract / legitimate interests), and to meet legal obligations where they apply (legal obligation).
Brief text and component requirements are sent to our AI model provider and to distributor and search APIs strictly to produce the results you request. We do not sell your data and we do not use your project content to advertise to you.
Who we share it with
Service providers and subprocessors: hosting, database, authentication, AI model and analytics providers that process data on our behalf under contract.
Our Merchant of Record, Paddle, for the sale of the product, subscription management, payment processing, tax compliance and invoicing. Paddle processes payment-related data as an independent controller under its own privacy terms.
Professional advisers (legal and accounting) where needed, and authorities where required by law.
Storage, security and international transfers
Data is stored in a managed Postgres database and object storage with row-level security, so each account can read and write only its own rows. We apply appropriate technical and organisational measures, including encryption in transit and access controls.
Access is restricted to the account owner and, for support or incident response, to the operator of the service.
Some of our service providers process data outside your country. Where data leaves your jurisdiction, transfers are protected by contractual safeguards such as standard contractual clauses or transfers to jurisdictions with adequacy decisions.
Retention and deletion
Proposals and uploads persist until you delete them. We keep personal data only for as long as needed for the purposes above, after which it is deleted or anonymised.
Ask us to delete your account and we will remove your proposals, uploaded briefs and rate card.
Your rights
Depending on your jurisdiction, you may have the right to access your data, have inaccurate data corrected, have your data erased, restrict or object to processing, receive a portable copy of your data, and withdraw consent where processing is based on consent.
You can exercise any of these rights, or ask a question about your data, by contacting us. We respond within one month. If you are in the EEA or UK, you also have the right to complain to your supervisory authority.
Cookies
We use essential cookies and storage required for sign-in and security, and limited analytics storage to measure performance. You can manage cookies through your browser settings; blocking essential cookies will prevent sign-in.
Questions? Contact us.