Privacy

What this site stores, why, for how long, and who can see it. Written from what the software actually does.

Dernière mise à jour :

Cette page n'existe pour l'instant qu'en anglais : c'est un brouillon en attente de relecture juridique, et une traduction suivra une fois le texte définitif.

Draft. This text has not yet been reviewed by a lawyer. The bracketed items are still to be filled in.

Who is responsible

The data controller is [fill in: the operating entity, its address and a contact email]. Questions and requests about your data go to that address or through the contact page.

If you have an account

Your email address, the name you chose to be called, and a hash of your password — the password itself is never stored and cannot be recovered from the hash. Alongside that: the plan you picked, when you signed up, roughly when you were last active, your time zone, the version of the terms you accepted, and, if you turn it on, the secret behind your authenticator app (stored encrypted) and the hashes of your recovery codes. Passkeys are stored as public keys, which cannot sign anything on their own.

Everything you catalogue is yours: filaments, spools, categories, photos, and the settings on your library. Nobody else sees any of it unless you publish your library or send someone the link.

The legal basis is the contract between us — you asked for an account and this is what running one takes — and, for the security records, our legitimate interest in keeping accounts from being taken over.

If you asked someone for a print

You do not need an account, and nothing here tries to talk you into one. What you send with a request — your name, your email address, your note, the filaments you picked, and any file or photo you attached — goes to the one person whose library you asked, and to nobody else. If you sign in while asking, the request is also listed under your own account so you can find it again.

The link to your request page is the credential that opens it. Anyone you forward it to can read that request, so treat it like a key rather than a bookmark. It is deliberately long and random, it is never indexed by search engines, and the preview card it produces when pasted into a chat names nobody.

The legal basis is your request: you asked for the print, and this is how the two of you keep track of it.

How long things are kept

Requester details — your name, email and messages on a request — are removed by the library owner's retention setting: between 30 and 730 days after the request reaches a final status, 180 by default. The request form tells you the number that applies before you send. Files you attached, and any slice files made from them, go sooner: between 7 and 365 days after the request is finished, 90 by default. The print and the filaments stay in the owner's records without your details.

Accounts are deleted fourteen days after you ask, together with everything in them. A sign-up that is never confirmed is deleted after seven days. Data exports are deleted seven days after they are made. The email on an abuse report, if you gave one, is deleted 180 days after the report is dealt with.

Backups of the database are taken daily and kept for up to [fill in: the backup window, currently up to six months]. Deleted data can survive in a backup for that long; backups are only ever used to recover from a failure, never to bring anything back that you deleted.

Your rights, and the buttons for them

You can see, correct, export and delete what is held about you. Most of it needs no request: anyone with an account can download their data from the account page and schedule the account's deletion there; a library owner can export the whole workspace from settings; a requester can download or delete their data from the request page, with a link sent to the address on file. Anything the buttons do not cover, and any objection or complaint, goes to the contact address above. You can also complain to your national data-protection authority — in Romania, the ANSPDCP.

Cookies

Two are strictly necessary: one that keeps you signed in, and one that remembers your language. Your answer to the analytics question below is remembered in your browser too, with no identifier in it. No advertising, and no third-party script runs unless you accept analytics.

Google Analytics (only if you accept)

[Draft, for review:] On this site's own address, and only after you press Accept analytics, we use Google Analytics 4 to count visits and learn which pages are useful. Until you accept, and if you reject, it is not loaded, sets no cookie and receives nothing. It never runs on a library's own custom domain or inside an embedded library on someone else's site.

Legal basis: your consent (GDPR Art. 6(1)(a); the ePrivacy rules for the cookies it sets). You can withdraw it at any time under Cookie settings at the foot of every page; that stops it at once and deletes its cookies (_ga and _ga_…). Your answer is asked again after twelve months.

What it receives: the page you are on, as its general template — a library page is recorded as /l/:library, a request status page as /r/:request — never a link's token or a library's name; campaign tags (utm_…) but no other part of the address; where you came from, cut to the other site's address alone; a generic page title; your browser, device, screen size, language and approximate location as Google derives them; and a few events (signing up or in, sharing, adding a filament or a photo, sending a request) with no personal detail. It never receives your name, your email address, anything you typed, or a user id. Google signals and advertising features are off.

Who: Google Ireland Limited acts as our processor. Data may be transferred to Google LLC in the United States under the EU–US Data Privacy Framework and the standard contractual clauses. [fill in: confirm the transfer basis]. Retention: fourteen months in Google Analytics, then deleted.

Other things the server records

Your IP address is used to rate-limit sign-in attempts, uploads and public forms, which is what stops this site being a convenient tool for guessing other people's passwords or mailbombing an inbox. Ordinary web server logs are kept short-term for the same reason.

If the spam check is switched on for public forms (the request form, the contact form, the report form), the challenge token and your IP address are sent to Cloudflare Turnstile to be verified when you submit one.

When language detection is switched on, your IP address is looked up in a copy of the MaxMind GeoLite2 database that lives on the server itself. Nothing leaves the server for that lookup, and only the country is read.

Who else touches your data

A short list, kept on its own page: subprocessors. In short: an email delivery provider, object storage for the photos and files, Cloudflare for the spam check, and the hosting the whole thing runs on. Nothing is sold, and nothing is shared with anyone for advertising. [fill in: where the servers are, and whether any of the above is outside the EU].

Changes

This policy has a version and a date at the top. When it changes in a way that matters, account holders are shown a notice at their next sign-in.