Privacy Policy

Last updated

Cover Page Maker is a free tool for building university assignment cover pages. You can use all of it without an account, and when you do, your cover page is put together and turned into a PDF inside your own browser. This page explains the parts where data does reach us.

1. Who runs this site

Cover Page Maker is provided by Acamatic Ltd ("we", "us"), a private limited company registered in England and Wales under company number 15068064, whose registered office is at 2nd Floor College House, 17 King Edwards Road, Ruislip, London HA4 7AE, United Kingdom. Acamatic Ltd is the data controller for this service. Engineering and day-to-day operation of this service are carried out on our behalf by our engineering team in Bangladesh, acting as our processor under a written data processing agreement. This means personal data is accessed from outside the UK — see “Where your data is held” below.

For anything in this policy, including a request about your own data, write to support@acamatic.com. We have not appointed a data protection officer or an EU or UK representative, because we are not required to.

2. What never leaves your browser

The cover page editor runs entirely on your own device. The text you type — your name, student number, course title, module code, submission date — is held in the page while you work on it, and the PDF is drawn and downloaded by your browser. Making and downloading a cover page does not send that content to us.

There are two exceptions, both of which you choose: creating an account, and saving a template. Both are covered below.

3. What we collect when you do use an account

An account is optional. It exists so you can save cover page templates and open them again later. If you create one, we collect:

  • Your first name, last name and email address, which you enter when you register.
  • A phone number, which the registration form asks for.
  • A password, which is sent to our authentication service to sign you in. It is stored only as a bcrypt hash by our own API. We never store or log the password itself, and we cannot recover it — a forgotten password can only be reset, not retrieved.
  • An email verification code, sent to the address you gave, to confirm the address is yours.
  • Multi-factor authentication details, if you turn MFA on.
  • A session token, kept in your browser's local storage so you stay signed in between visits. Signing out removes it.

4. Templates you save

If you are signed in and you save a template, that template is stored on our cloud object storage and linked to your account. What gets stored is whatever the template contains: its name and description, the page layout, the text on it, any images or logos you added, the university you picked, and a small preview image.

A template you publish to the community is PUBLIC: the design you saved and the display name on your account become visible to anyone who visits that university's page, and can be copied. Your email address is never published. We ask you to confirm this on the save dialog before anything is shared. Treat a saved template as published — do not put anything in one you would not want the world to read. You can delete a template you saved from within the tool, and deleting it removes it from our storage. Deleted objects and database rows can survive in our providers’ encrypted backups for a short period after deletion — no longer than 30 days — after which they are overwritten and irrecoverable.

5. The university catalogue

The site serves a catalogue of 60,918 university records — institution names, locations, websites and logos — so a cover page can be pre-filled for your institution. That catalogue describes institutions, not people. Picking your university from it does not tell your university anything, and it does not associate you with that institution anywhere in our records unless you save a template.

6. Technical data and logs

Like any website, requests to this site reach a web server and a content delivery network, which keep operational logs (typically IP address, timestamp, requested URL, browser user agent). We use these to keep the service running and to investigate abuse. Those logs are held on our behalf by Vercel, DigitalOcean and Cloudflare, and are kept for no longer than 30 days.

As published, this site loads no third-party advertising or analytics trackers, and it does not build an advertising profile of you. If any analytics, error-reporting or marketing tool is added later, it will be named here and in the cookie section below before it goes live.

7. Cookies and local storage

We use browser storage for the things the tool needs in order to work: keeping you signed in, and holding the cover page you are editing. We do not use it for advertising or cross-site tracking.

We set no advertising, analytics or profiling cookies, so there is no consent banner to click through. The only thing stored in your browser is what signing in requires — a session token kept in local storage so you stay signed in — which is exempt from consent because the service cannot work without it. If we ever add analytics or any other non-essential storage, we will ask for your consent first and update this section before it is switched on.

8. Who else can see this data

We do not sell your personal data, and we do not share it for anyone else's marketing. Data reaches other companies only where they run part of the service for us:

  • Our engineering team in Bangladesh — operating and maintaining the service as our processor.
  • Vercel — hosting and delivery of this website.
  • DigitalOcean — application servers, database, and the Spaces object storage and CDN that hold saved templates and site assets.
  • Cloudflare — network and delivery in front of our application servers.
  • MailerSend — delivery of account verification and password-reset email. We use no other processors: there is no third-party error monitoring, analytics or support-desk service in use.

This site does not include an in-page AI assistant. Nothing you type into the cover page tool is sent to an AI provider. If an assistant is added in future, this policy will be updated to name the provider before it is switched on.

We may also disclose data where we are legally required to, or to protect the service and its users from abuse.

9. Where data is held, and for how long

Account data and saved templates are kept for as long as your account exists. Close your account and they are deleted. Account data, saved templates and site assets are held in DigitalOcean’s Singapore region. Our engineering team in Bangladesh accesses them as our processor, under a written data processing agreement, with the UK International Data Transfer Agreement as the safeguard for that transfer. Account records are kept while the account exists and are deleted when it is closed. Operational logs are kept for no longer than 30 days, and backups are overwritten within 30 days.

10. Your rights over your data

Depending on where you live, you may have the right to ask for a copy of the data we hold about you, to have it corrected, to have it deleted, to object to or restrict what we do with it, and to complain to a data protection regulator.

Because Acamatic Ltd is established in the United Kingdom, this service operates under the UK GDPR and the Data Protection Act 2018, and you may complain to the Information Commissioner's Office (ico.org.uk). We rely on performance of a contract to run your account and store the templates you save, on our legitimate interests to keep the service available and investigate abuse, and on your consent where you choose to publish a template to the community. We answer a rights request within 30 days. The transfer to our processor in Bangladesh is made under the UK International Data Transfer Agreement.

To make a request, email support@acamatic.com. We will need to be reasonably satisfied you are the account holder before acting on it.

11. Age

This tool is built for university and college students and is not aimed at children. You must be at least 16 years old to hold an account.

12. Security

The site is served over HTTPS, the endpoints that read and write saved templates check who is calling before they touch storage, and accounts can be protected with multi-factor authentication. No online service can promise perfect security, so please use a password you do not reuse elsewhere.

If you believe you have found a security vulnerability, report it to support@acamatic.com and we will acknowledge it. If a personal data breach occurs and is likely to present a risk to you, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell you directly where the law requires us to.

13. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects what we do with your data, we will make that clear rather than quietly editing the text.