Skip to content
Legal

Privacy Notice

How MEASORA handles information about the people who visit this site, write to us, sign in and measure drawings — what we hold, why, where it goes and how long it stays.

Last updated 27 September 2026

Who we are

This notice is issued by MEASORA, the operator of measora.ai and of the takeoff service behind it. For anything in this notice, including a request about your own information, write to info@measora.ai. We answer within one working day.

We are the controller of the personal information described here. Where we use other companies to run the service they act on our instructions, and they are named below.

What this notice covers

It covers the public site (the front page, Services, About, Contact and the pages linked from them), the contact form, signing in with a Google account, and the product itself: the drawings you upload, the takeoffs you ask for and the results you take away.

Information we collect, and where it comes from

Almost everything we hold, you gave us directly. In detail:

  • Visiting the site. Our web server records each request — the address it came from, the page asked for, the time, the browser's description of itself — in a log that is kept for 30 days and then deleted. On the public pages we count page views with PostHog, and we record how a page is used — scrolling, clicks, where a visitor stops — with Microsoft Clarity, as anonymised session recordings and heatmaps in which the text you type is masked. Neither sets a cookie or stores an identifier on your device, so neither can recognise you when you come back, and neither runs in the workspace where drawings are open. If you arrived from an advert, the campaign named in the link is counted with the page view. Your choice of light or dark theme is kept in your own browser and is not sent to us.
  • Writing to us. The contact form asks for your name, work e-mail, company, role and a line about the project. It is delivered to us as an e-mail, with your address as the reply-to, and is not written to a database. Please do not attach tender documents to the form; we agree a secure way to share them.
  • Signing in. You sign in with a Google account. We ask Google for your identifier, e-mail address and name (the standard "openid email profile" scopes) and nothing else — no contacts, no files, no calendar. We keep those three things in a signed cookie in your browser for 30 days. Your workspace is keyed by a one-way hash of that identifier; it is derived, never chosen, so no one can name themselves into somebody else's account. Anyone with a Google account may sign in and gets a workspace of their own.
  • Setting up your workspace. After your first sign-in we ask about the company behind the account: its name, country and website, the trades it prices, how many people it has and how many of them will measure here, what you take off with today, the kind of work you price and what you want from MEASORA. Each answer is a choice from a short list, with a free line where you want one. It is kept with your account, shown to you under Settings → Company where you can change it, and used to shape the workspace to your trade. Nothing in it is used to measure a drawing.
  • Sharing a workspace. You may invite colleagues into your workspace by the e-mail address they sign in with, each with a role — admin, estimator or viewer. We keep the addresses you invite, who invited them and when they first opened the workspace, so the list under Settings → Members is a record and not a guess. A colleague you invite sees every project in that workspace unless its owner or an admin has limited a project to named colleagues; you can remove them at any moment and their access ends at once. Which workspace your browser is acting in is a cookie, measora_workspace, and is honoured only for an address the owner has invited.
  • Working alongside colleagues. While you are signed in, the people in your workspace can see that you are there and which project and drawing you have open — the small initials on a project card and on a drawing's bar — and you can see the same of them. That is a fact about the present minute: it is held in the service's memory for as long as your browser keeps saying it is there, is never written down, and is gone within a minute of you leaving. A takeoff records who started it, by name and e-mail address, so colleagues know whose work it is.
  • Pricing. The rates you enter under Library — a description, a unit and a price in your workspace's currency — and, for each takeoff, which rate you chose for which row. They are yours, kept with the workspace, and never used to measure anything.
  • Using the product. The drawings you upload (vector PDF), the requests you type, the results the system produces — outlines, quantities, the marked-up PDF, the schedule, the spreadsheet — and a running count of how much processing your account has used.

What we use it for, and the legal basis

UK data protection law asks us to say why we hold each thing and on what basis. The reasons are the obvious ones:

  • To answer you when you write to us and to arrange a demo — our legitimate interest in responding to an enquiry, and the steps you ask us to take before a contract.
  • To provide the service to a signed-in account: to store your drawings, run the takeoff you asked for and hand back the results — performance of our contract with you.
  • To keep the service secure and running — our legitimate interest in knowing that requests are genuine, that an account is who it says it is and that a failure can be traced.
  • To meet a legal obligation, if one arises.

We do not sell information, we do not build profiles for advertising and we do not use your drawings or your results to train any model.

Where a drawing goes when it is measured

A takeoff runs in an isolated session that has no network access at all: the drawing goes in, code runs against its geometry, the results come out, and the session is discarded. The drawings themselves and the results are stored on our own Azure infrastructure in the Sweden Central region, in the European Union, in a space that belongs to your account and no other.

When a sheet has to be looked at rather than measured — to read a title block, to decide which trade a drawing belongs to, to check that an outline landed where it should — a rendered image of the page and the text printed on it are sent to a Claude model running in our own Azure AI Foundry resource in Sweden Central, in the European Union. The model is hosted by Microsoft under its enterprise terms, which exclude the use of customer content for training; the image is not sent to a public consumer service. The model writes code; the code produces the numbers. No figure is read off the drawing by eye.

Who we share it with

Nobody sees your information for their own purposes. The companies below process it for us, to run the service:

  • Microsoft Azure (Sweden Central): hosting, storage, the e-mail service that carries the contact form to us, and the logs.
  • Microsoft Azure AI Foundry (Sweden Central): the model that reads a page image, as described above. The model is developed by Anthropic and hosted by Microsoft.
  • Google, as the sign-in provider. When you sign in, Google handles your credentials under its own privacy notice; we receive only the identifier, e-mail and name it confirms.
  • Stripe, as the payment provider. When you buy a plan, the card form, the card details and the invoices are Stripe's, under its own privacy notice; we receive your workspace's customer reference, the plan, its status and the billing e-mail and address you give Stripe — never a card number.
  • PostHog (United States): the page-view counts and the few events described above, on the public pages only, without a cookie or an identifier we could tie to a person.
  • Microsoft Clarity: anonymised session recordings and heatmaps of the public pages, with typed text masked and without a cookie.

We would disclose information if the law required it, or to protect the rights and safety of our users or ourselves. We have not been asked to.

Transfers outside the United Kingdom

Storage, hosting and the model are in Sweden, in the European Union, which the UK recognises as providing adequate protection under the UK GDPR adequacy regulations; no further safeguard is needed for that transfer. Page-view counts from the public pages go to PostHog in the United States under the safeguards in its data processing agreement; they carry no cookie and no identifier we could tie to a person. Microsoft processes Clarity's recordings, and Google a sign-in, in other countries under their own transfer arrangements.

How long we keep it

  • Contact-form messages: for as long as the conversation, and the business relationship it may lead to, is live. Ask and we delete them sooner.
  • The sign-in cookie: 30 days, then it expires. A short-lived cookie used during the sign-in itself lasts 10 minutes.
  • Server logs: 30 days.
  • Your company profile: for as long as the account is live. Change it under Settings → Company, or ask and we delete it.
  • Drawings: until you delete the project or the file, or ask us to. Deleting a project removes its drawings from storage, not just a row in a list.
  • Results of finished takeoffs — the marked-up PDF, the schedule, the run's record: these go when the project goes. Deleting a project deletes the takeoffs made from its drawings along with their files, and there is no undo. A takeoff that is still running is not deleted out from under itself: delete the project once it has finished.

How we look after it

Every connection is encrypted. Each account's files are held apart from every other's. A takeoff runs in a sandbox with no network egress, so nothing in a drawing can call out. Storage does not allow anonymous or shared-key access, and the services that need it authenticate with managed identities rather than passwords. Access to production is limited to the people who run it.

Cookies and local storage

The site sets three cookies, all strictly necessary and all first-party: measora_session, which holds your signed sign-in for 30 days; measora_oauth, which lasts 10 minutes while a sign-in completes; and measora_workspace, which remembers which workspace you chose to work in when you have been invited into more than one. None is used for analytics or advertising, and the analytics on the public pages set no cookie of their own, which is why the site has no cookie banner. Preferences — the theme, the language of the workspace, the layout of a project you were working on — are kept in your browser's local storage and never leave it.

Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it, to delete it, to restrict what we do with it, to give it to you in a portable form, or object to our processing it. Where we rely on your consent you can withdraw it at any time. Write to the address above; we will answer within one month, and sooner where we can.

If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office at ico.org.uk. We would rather hear from you first.

Children

MEASORA is a professional tool for people who price construction work. It is not directed at anyone under 18 and we do not knowingly hold information about them.

Changes to this notice

When what we do changes, this page changes with it, and the date under the title moves. A change that matters to you — a new purpose, a new recipient — is one we will tell signed-in users about directly.