Privacy policy
What we do with your personal data, why we do it, and what you can require of us.
Last updated 2026-09-12.
This is a translation. The Swedish text is the binding one.
Mängda’s legal documents are written in Swedish, and only the Swedish version has legal effect. This English page is a convenience translation, provided so that you can read what you are agreeing to. If the English and the Swedish differ in meaning, the Swedish version prevails. Read the Swedish version.
Who is responsible
The data controller for the processing described here is To be filled in: registered company name, company registration number To be filled in: company registration number, To be filled in: postal address, Sweden.
Questions about personal data go to sales@mangda.app.
Two roles, and why the difference matters
Mängda processes personal data in two entirely different capacities, and they are governed by different rules.
- As data controller for data about you as a customer and user: your account, your payment, your contact with us, and the statistics on how AI readings are corrected. That is the processing this page is about, together with how we use de-identified content to develop the service’s AI.
- As data processor for what you put into the service yourselves: drawings, projects and price lists. If there is personal data in your drawings, you are the one who decides about it, and we process it only on your instructions. That is governed by the data processing agreement.
What we collect, and why
Account details (email address, name, and company if you fill it in) are processed in order to give you an account and a workspace. The legal basis is performance of the contract with you.
Payment details (name, email address, billing details and subscription status) are processed in order to take payment. You give your card number directly to Stripe, it never passes through our systems. The legal basis is the contract, and for the accounting records a legal obligation under the Swedish Bookkeeping Act (bokföringslagen).
Technical logs (IP address, time and which request was made) arise from running the service, and are used to keep it working and to detect misuse. The legal basis is our legitimate interest in operating a working and secure service.
The security log shows when a member of our staff has opened the administration view and what they did there, with time and IP address. It exists so that it is possible to see afterwards who did what. The legal basis is our legitimate interest in traceability.
From 2026-09-11, statistics on how AI readings are corrected are processed in order to find where the reading goes wrong and to make it better. The legal basis is our legitimate interest in making the AI reading more accurate. What the statistics contain, and what they do not contain, is set out in the section on how we improve the AI reading below.
We do not currently collect the drawings themselves, images of them or text from them for our own purposes. The terms of use give us the right to use de-identified content to develop the service’s AI, and how that works is set out in the section on it below.
AI reading of drawings
If you press the button that asks for an AI reading of a drawing, the drawing page you selected is sent to Anthropic, who run the model that reads it. No account, organisation or payment details go with it, only the page.
It never happens automatically. No drawing leaves the service for AI reading without someone at your end clicking the button first. Under Anthropic’s terms for their API, what is sent in is not used to train their models.
The processing takes place in the United States. See the section on transfers outside the EU/EEA below.
How we improve the AI reading
This section applies from 2026-09-11. No such statistics are collected before that date.
When someone at your end has had a drawing read by AI and then carries on working on it, the take-off view compares what the reading drew with how it looks afterwards. We keep the result as statistics on how AI readings are corrected. This only happens when someone at your end has chosen to use the AI reading themselves, and nothing is collected for drawings that have never been read by AI.
The comparison is made in your browser, so positions, lines and measurements never leave your computer for this purpose. All that is sent to us is numbers and values from the service’s own lists:
- How many pipe runs and objects the reading drew, how many of them were left in place, deleted, changed, moved or redrawn by hand, and how much was added by hand on the same drawing page.
- Which values were changed, and from what to what, for example dimension 160 to 315, material PP to PVC, object type or load class. They are always values from the service's own lists, never free text.
- What kind of drawing it was (VA or foundation, plan or section), what became of the scale the reading read (whether it was kept, changed, set by hand, removed, not used or not read at all) and which scales were involved, for example 1:400.
- The reading's own figures: how many pipe runs and objects it proposed, how many of them were filtered out before anything was drawn, how many runs had no printed size, and whether it rounded the positions instead of following the lines.
- How long after the reading the comparison was made, and on which day.
The statistics contain no coordinates, lengths or areas, and nothing else a quantity could be worked out from. They contain no drawing, image or page, and no text from the drawing, such as legend text, notes or names. They contain no project names, nothing about who made the changes, and no IP address.
The workspace appears only as a code. The code is calculated with a secret key that is kept outside the database, and it changes every calendar month. From the statistics, therefore, it is not possible to see which workspace a code belongs to, and they are not linked to our log of AI readings. The code exists so that a single workspace with many drawings does not weigh too heavily. This is pseudonymisation, not anonymisation: using the key, we can work out the code for a particular workspace ourselves, and that is how we find what has been collected from you if you object.
The purpose is to find where the AI reading goes wrong and to make it better, both by improving the instructions and rules it works to and by training and evaluating the service’s AI features. The statistics are not sold, and they are not sent to Anthropic or to anyone else. They are stored in Stockholm, with the same provider as your accounts and drawings.
The legal basis is our legitimate interest in making the AI reading more accurate, under Article 6(1)(f) of the General Data Protection Regulation. We have weighed that interest against your privacy in a balancing test. For these statistics Mängda is the data controller, not a data processor.
The statistics are kept for twelve months and then deleted automatically. If your workspace is deleted, its statistics are deleted with it.
If you do not want them collected for your workspace, write to sales@mangda.app. We then stop collecting them for your workspace and delete what has already been collected from it.
How we use content to develop the service’s AI
Under the terms of use, we may use what you put into the service, such as drawings, AI readings and take-offs, and information about how the service is used, to improve Mängda and to train and evaluate the service’s AI features. For the information about how the service is used, the legal basis is our legitimate interest in developing the service, under Article 6(1)(f) of the General Data Protection Regulation.
Before any of your content is used for this, we de-identify it: we remove what identifies you, your customers or individual people, such as names and addresses in a title block, coordinates, project names and contact details. We carry out that de-identification on your behalf, under the data processing agreement. We then use the de-identified material on our own account.
We do not sell your content and we do not give it to anyone else to train their AI models. We may keep de-identified material after an account has ended, and what has been used to train a model cannot be removed from it afterwards.
At present no content is collected for training. What is collected is the statistics described above. Before that changes, we will set out here what is kept and for how long.
If you do not want your content or your use of the service used in this way, write to sales@mangda.app. We will then exclude your workspace, both from the statistics and from anything collected to train the service’s AI.
Who gets to see the data
We do not sell personal data and we do not disclose it for anyone else’s marketing. The providers that process data on our behalf are:
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, sign-in and file storage.Account and organisation details, uploaded drawings, take-offs, price lists and logs. | eu-north-1 (Stockholm) |
| Vercel | Hosting of the website and the application.Everything that passes through the service during a request, plus technical logs with an IP address. | arn1 (Stockholm) |
| Stripe | Payments and subscriptions.Name, email address, billing details and payment details. Card numbers are given directly to Stripe and never pass through Mängda. | EU and the United StatesOutside the EU/EEA |
| Anthropic | AI reading of drawings, only when someone at your end asks for it.The drawing page you chose to have read, as a PDF or an image. No account or customer details are sent with it. | United StatesOutside the EU/EEA |
| Resend | Sending email: invitations and password resets.The recipient's email address and the content of the message. | United StatesOutside the EU/EEA |
Beyond that, data may be disclosed where we are obliged to do so by law or by a decision of a public authority.
Transfers outside the EU/EEA
Your accounts, drawings and take-offs are stored in Stockholm and do not leave the EU in normal use of the service.
Three of the providers above process data in the United States: Stripe for payments, Anthropic when you request an AI reading yourselves, and Resend for sending email. The transfers are made on the basis of the European Commission’s standard contractual clauses and, where the provider is certified under it, the EU–US Data Privacy Framework.
How long we keep it
Account details and content are kept for as long as the account exists. If you delete the account under Settings, the account and the data belonging to it are removed.
Accounting records are kept for seven years after the end of the calendar year in which the financial year ended, because the Swedish Bookkeeping Act requires it. That covers invoices and payment records, not your drawings.
Technical logs and the security log are kept for as long as they are needed for operations and traceability.
The statistics on how AI readings are corrected are kept for twelve months and then deleted automatically. If a workspace is deleted, its statistics are deleted with it.
Your rights
- To be told what data we process about you, and to get a copy of it.
- To have inaccurate data corrected.
- To have data erased, where we are not obliged by law to keep it.
- To request that the processing be restricted, or to object to processing we base on legitimate interest.
- To receive data you have given us in a machine-readable format, and to have it transferred.
Get in touch at sales@mangda.app and we will help you. If you think we are processing your data wrongly, you have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten), imy.se.
Cookies
We use no cookies for tracking, analytics or marketing. What is actually stored in your browser is set out in the cookie policy.
Changes
If we change this text, we update the date at the top. If the change is material, we get in touch with those of you who have an account before it takes effect.
Questions about this text? Get in touch.