Maket logo

Maket

maket.ai
High Risk
Updated August 13, 2026

Maket is an AI-powered residential design platform (floorplans, layouts, 3D renderings) serving homeowners, builders, and professionals. Users retain ownership of their Customer Data and AI Outputs, and Maket states it does not sell personal information. However, the Terms grant Maket a broad, perpetual, sub-licensable license and an express right to train, fine-tune, and test its AI systems on Customer Data and AI Inputs by default, with opt-out from training reserved only for certain paid plans. The policy relies heavily on 'commercially reasonable' anonymization it admits it cannot guarantee, discloses no third-party security certifications (no SOC 2, ISO, etc.), and the vendor-favorable liability caps, indemnity, and class-action waiver make this moderate risk for professional or client-confidential work without contractual protections.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Low Risk

Users retain ownership of the Customer Data (files, prompts, images, plans) they upload. However, ownership is subject to a broad license granted to Maket in Section 6, so ownership is nominal rather than exclusive in practice.

Confidence
90%

Output Data Ownership

Moderate Risk

Users own the AI Outputs they generate, but only to the extent local law permits IP rights in AI output, and Maket expressly disclaims any guarantee that outputs are unique, original, or non-infringing. Maket also retains a perpetual license to anonymized/aggregated versions of outputs.

Confidence
85%

Training Data Usage

High Risk

By default Maket may train, fine-tune, test, and validate its AI systems on Customer Data and AI Inputs. It commits only to 'commercially reasonable' efforts to anonymize and admits it cannot guarantee anonymization; opt-out from training is reserved to certain paid plans, so the standard consumer default is training-on.

Confidence
90%

Data Retention & Deletion

Moderate Risk

The policy provides retention categories and a deletion pathway (account settings or contact) but uses vague timeframes ('within a reasonable timeframe', 'a limited period') rather than firm SLAs. Audit logs are retained up to one year; anonymized/aggregated data may be kept indefinitely.

Confidence
80%

Third-Party Data Sharing

Moderate Risk

Maket discloses sharing with service providers/sub-processors (cloud hosting, LLM providers, payment, analytics, support) and states it does not sell personal information. Some Customer Data is transmitted to third-party LLM providers, and the sub-processor list is only available on request rather than published, limiting user visibility.

Confidence
82%

Opt-Out Rights

Moderate Risk

Users can opt out of marketing and non-essential cookies, and can exercise deletion/objection rights depending on jurisdiction. However, opting out of AI training is not universally available — it is tied to subscribing to a plan with 'enhanced data controls', so free/standard users lack a clear training opt-out.

Confidence
80%

Compliance & Certifications

Moderate Risk

The Privacy Policy references GDPR/UK GDPR legal bases, Standard Contractual Clauses, and Canadian/Québec privacy regulators, and describes GDPR-style data subject rights. However, no security certifications (SOC 2, ISO 27001, ISO 27018, ISO 42001) are claimed or attested, and CCPA/CPRA and US state laws are not named. Compliance is asserted/aligned rather than third-party attested.

Confidence
72%

Model Explainability & Auditability

High Risk

The documents provide no meaningful transparency into model behavior and no enterprise auditing mechanism. They state Maket uses third-party LLMs and describe training data sources at a high level, but offer no explainability, model documentation, or audit rights to users.

Confidence
70%

Security Practices & Breach History

Moderate Risk

The Privacy Policy discloses concrete controls: TLS 1.2+ in transit, encrypted storage with key management, role-based least-privilege access, MFA, encrypted backups, real-time monitoring, and an incident-response/notification process. No breach history is disclosed, but there is also no independent attestation (no SOC 2/ISO/pen test/bug bounty) and no dedicated trust center referenced.

Confidence
80%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The Terms reference paid plans that may include 'enhanced data controls' or a training opt-out, implying a materially better data posture for paying tiers, but the actual differences are not spelled out in the supplied documents. Free plans appear to carry the default training-on posture with no published carve-out.

Confidence
68%

Human Review of User Inputs

Moderate Risk

Maket reserves broad rights to access and process Customer Data for quality assurance, research, and security monitoring, and states internal staff may access data on a least-privilege basis. It also lists 'training, quality assurance or administration purposes' as a processing purpose, which implies possible human review, though no explicit human-review-of-prompts statement is made.

Confidence
65%

Regulatory & Litigation Exposure

Moderate Risk

The documents describe cooperation with lawful government requests, fraud-related disclosures, and a class-action/jury-trial waiver with mandatory Québec jurisdiction. No pending litigation or law enforcement history is disclosed, but the legal-disclosure and dispute provisions favor the vendor.

Confidence
75%

PII & SPI Data Inventory

Moderate Risk

Maket collects a range of PII: name, email, password, billing address, IP address, device identifiers, approximate location, usage data, and any personal data embedded in project inputs. It states it does not intend to collect sensitive information and asks users not to upload it, but acknowledges it will process SPI if voluntarily provided — placing responsibility on users while allowing SPI ingestion.

Confidence
80%

Policy–Product Currency

Low Risk

Both the Terms and Privacy Policy are dated June 15, 2026 (Version 2026-1), within 12 months of the analysis date, and they substantively address the AI capabilities the product surface shows: floorplan/3D generation, uploading existing plans, third-party LLM providers, and AI training. The policy demonstrably covers the shipped AI features.

Confidence
88%

Cross-Document Consistency

Low Risk

Two document types (Terms and Privacy Policy) were supplied, plus a duplicate copy of the Terms at a second URL. The Terms and Privacy Policy align on training use, non-sale of data, retention, and deletion; no material contradictions were found between them. The training-anonymization language in both is consistent.

Confidence
78%

You've read all 15 risk ratings for Maket. Create a free account to see the exact policy wording behind each rating.