Privacy policy
Effective 6 October 2026
3dspriter is a browser app for making low-poly 3D pixel art. This page says what data we keep about you, why, where it goes, how long we keep it, and what you can do about it.
Who we are
3dspriter is a product of Softaleo, operated by Leonid Haimov (an individual), Israel. The controller of your personal data is Leonid Haimov, trading as Softaleo. “We” and “us” mean him. Contact for anything in this policy: leoisprogramming@gmail.com.
The short version: if you use the app without an account, we have no data about you. Your projects stay in your browser. We only store data when you create an account, and your projects only leave your device when you turn on sync for them. We don’t sell your data, show ads or track you.
Using the app without an account
- You don’t need an account. Your projects are saved in your browser’s storage (IndexedDB) on your device, with a few settings in its local storage (saved camera views, which project is open, whether you’ve seen a hint). None of it is sent to us.
- The app works offline: a service worker keeps the app’s own files on your device.
- There are no analytics, no ads, no tracking and no third-party scripts, except on the payment page (see “Payments” below). The fonts and the 3D engine are served from our own site. Without an account, the app doesn’t contact our server at all, unless you open the Account panel or someone’s share link.
- Like any website, our host Cloudflare receives your IP address and browser details with each request, to deliver the site and protect it from attacks (see “Who receives data”).
Your account
If you sign in, we store:
- your email address;
- how you sign in (email link, Google or GitHub) and, for Google or GitHub, the account ID that service gives us;
- when the account was created, and your plan;
- a record for each browser you’re signed in on (a hashed session token and its dates).
We don’t store your name, your profile picture or anything else about you.
- Email link. We send a one-time sign-in link to your address through Resend, an email delivery service. The link works once and for 15 minutes. We don’t send you marketing email or newsletters. Apart from sign-in links, we only email you about your account, such as important changes to our terms or this policy.
- Google or GitHub. You sign in on their site, and we ask them only for your email address. We use a verified email address and your account ID from them, only to sign you in, and keep nothing else. Nothing from Google or GitHub is loaded into the app.
- Your browser also keeps your email address and plan in its local storage, so the app knows you’re signed in.
Cloud sync, version history and share links
These are part of the paid Individual plan, and are off until you turn them on.
- Sync is per project. A project is uploaded only after you turn on sync for it (or press “Sync all projects”). After that, saved changes are uploaded as whole copies of the project: its name and contents, including any reference images you added to it.
- Project copies are stored in Cloudflare R2. The list of your projects and versions (names, dates, sizes, version numbers) is stored in a Cloudflare D1 database.
- We use your projects only to store them and to deliver them to your devices and to people you share them with. We don’t look at them, analyze them, sell them or use them for anything else. Our server only checks that an upload is a project file and isn’t too big.
- Version history. Older versions of a synced project are kept, then pruned automatically. The current version and the 3 newest are always kept. An older version is deleted once it’s more than 30 days old and not among the 20 newest, or when the project’s history passes 256 MB (oldest first). A version that a working share link points to is kept for as long as the link works. Pruning happens the next time you sync that project.
- Removing a project from the cloud. It leaves your list but can be restored for 30 days. After that it’s deleted with its history and its share links the next time you sync any project; if you never sync again, it stays until you delete your account. The copy on your device isn’t touched.
- Share links. Anyone who has a link can open the project (view-only, or as an editable copy, as you chose) and keep a copy on their own device. They see the project’s name and contents, not your email address. We count how many times a link has been opened, and keep a record of each link (when it was made, when it expires or was revoked, how often it was opened) until the project is deleted from the cloud or you delete your account. A link can expire after 7 or 30 days, and you can revoke it at any time. Revoking stops new openings, but it can’t remove copies people have already made.
Payments
- The Individual plan is sold by Paddle, which acts as our merchant of record: Paddle is the seller, takes the payment and handles tax, invoices and refunds. For your payment details and the purchase, Paddle is a separate controller under its own privacy policy. We never see or store your card details.
- When you start a checkout, we give Paddle your account email address (to find or create your customer record there, so you don’t have to type it at checkout) and an internal account ID (so we know whose subscription it is).
- One free month per account and email address. If Paddle already has a customer record for your email address, we ask Paddle whether it ever had a subscription to 3dspriter. If it did, the checkout has no free month. This keeps the free month to one per email address, even if an account is deleted and made again.
- From Paddle we receive and store your Paddle customer and subscription IDs, the ID of your last checkout, the status of your subscription, when the paid period or free month ends and when a cancellation takes effect. We also keep a list of the Paddle notifications we’ve processed (an ID, type and time, with no name or email address), so that none is applied twice.
- The payment page. The checkout opens on our payment page (
/pay). That page, and no other page of 3dspriter, loads Paddle’s checkout script (Paddle.js) from Paddle’s server (cdn.paddle.com), and the checkout form inside it is Paddle’s. So Paddle receives what any website gets from your browser, such as your IP address and browser details, and what you type into the checkout. Paddle.js and the checkout may use cookies or similar browser storage of their own, which Paddle says it needs to run the checkout reliably and to prevent fraud. On the live site, Paddle.js also loads a script from Paddle’s subscription tool Retain (from public.profitwell.com) by itself; we don’t use Retain’s features or give it any customer details. All of this is covered by Paddle’s privacy policy, not ours. Links in Paddle’s emails (for example, to update your payment method) also open this page.
Cookies and browser storage
We set two cookies. Both are only for signing in, and they’re only set when you sign in:
sessionkeeps you signed in. It can’t be read by scripts, is only sent over HTTPS and only to our API. It lasts 30 days, is renewed while you use it, and stops working a year after you signed in.oauth_stateis set only while you sign in with Google or GitHub, for at most 10 minutes. It makes sure the sign-in that comes back is the one you started.
We set no other cookies and no tracking cookies. On the payment page, Paddle may set its own (see “Payments”). In your browser, the app also uses IndexedDB (your projects), local storage (settings, and your email and plan when signed in), session storage (which project is open in a tab) and a service worker cache (the app’s files). You can clear all of this in your browser settings. Clearing it deletes any projects that aren’t synced.
Security
- The site only works over HTTPS. Session tokens, sign-in links, sign-in states and share links are stored only as hashes, so a copy of our database can’t be used to sign in or to open a link.
- Only we have access to the data on our servers. We don’t open your projects or account data except when you ask us to (for example, to help with a problem), to deal with abuse, or when the law requires it.
- Abuse protection. To stop abuse, we count requests for sign-in links (by email address and by IP address), share-link openings (by IP address), and checkout and billing requests (by account). Each record holds the address or account and a time, counts for 10 minutes, and is deleted when the next request is counted after that.
- Error logs. When something goes wrong, our server code writes a short message (for example, that a payment notification couldn’t be matched, with an internal account ID). Tokens and card details are never written to it. We use these messages only to fix problems, and Cloudflare keeps them for at most 7 days.
- No system is perfectly secure. If a breach affects your personal data, we’ll tell you and the authorities where the law requires it.
Why we use your data, and the legal basis
Under the GDPR and the UK GDPR, we need a legal basis for each use. We don’t rely on consent for anything.
- To provide what you asked for (performance of a contract with you): your account and sign-in, sync, version history and share links, the plan your subscription gives you, the checkout, and answering your emails about them.
- Security and preventing abuse (our legitimate interests in keeping the service working and safe, and yours in a safe account): rate limits, hashed tokens, error logs, and enforcing our terms.
- One free month per email address (our legitimate interest in not having the free month abused): the check with Paddle described under “Payments”.
- Telling you about important changes to our terms or this policy (legitimate interests, and where the law requires such notice, a legal obligation).
- Complying with the law (legal obligation): for example, answering a valid legal request. Paddle keeps payment and tax records as the law requires it to, as the seller.
Where we rely on legitimate interests, you can object (see “Your rights”).
Do you have to give us data? No law requires you to. You need an email address only if you want an account, and an account only for the paid cloud features. Without one, you can use the whole free app. We don’t make decisions about you based only on automated processing that have legal or similarly significant effects, and we don’t profile you. (Whether a checkout includes the free month is checked automatically from your subscription history; if you think it’s wrong, email us.)
Who receives data
These services process data for us, under their data processing terms, only to provide their service:
- Cloudflare hosts the site, runs our server code and stores our database and project files. Like any web host, it handles every request, including your IP address.
- Resend delivers our email: sign-in links and any notice about your account (your email address and the message).
These receive data as separate controllers, under their own privacy policies:
- Paddle, if you subscribe: see “Payments”.
- Google and GitHub, only if you choose to sign in with them. Google also hosts the mailbox of our contact address, so it holds any email you send us.
- People you send a share link to: the shared project.
We don’t sell or rent your personal information, and we don’t share it for advertising. We don’t give it to anyone else unless the law requires it, or to a successor if 3dspriter is ever transferred, who would have to keep this policy’s promises (we’d tell you first).
Transfers outside your country
We are in Israel, which the European Commission and the UK recognise as giving adequate protection to personal data. Cloudflare and Resend may process data for us in other countries, including the United States. Where data from the EU, the UK or Israel goes to a country without such recognition, it’s protected by the safeguards in their data processing terms, such as the European Commission’s standard contractual clauses. Paddle, Google and GitHub handle international transfers of the data they control under their own privacy policies.
How long we keep data
- Your account, sign-in methods and plan: until you delete your account.
- Session records: until you sign out in that browser or delete your account. A session stops working after 30 days without use, or a year after you signed in.
- Synced projects and their history, and share-link records: until you remove them or delete your account, following the rules under “Cloud sync, version history and share links”.
- Sign-in links and sign-in states: they stop working after 15 and 10 minutes, and are deleted when the next one is made.
- Abuse-protection counts: about 10 minutes (see “Security”).
- The list of Paddle notifications we’ve processed: kept, since it holds no name or email address.
- Emails you send us: as long as needed to deal with your request and any follow-up (such as a refund).
- Backups: our database provider keeps an automatic point-in-time history of the database for up to 30 days, so deleted records can remain there for up to 30 days. We use it only to recover from a failure.
- If your plan ends, nothing is deleted. You can still see and download your cloud projects and every kept version, and remove them. Your share links keep working until they expire or you revoke them. Uploads (including restoring an old version) and new share links stop until you subscribe again.
- Paddle keeps its own records of your purchases (for tax and accounting) for as long as the law requires it to, even after you delete your account with us.
Your rights
Wherever you live, you can:
- See your data. The Account panel shows your email address and plan, and the project list shows your synced projects. Ask us for a full copy of what we hold about you.
- Take it with you. Every synced project and every kept version can be downloaded as a project file, even after your plan ends.
- Correct it. Ask us to fix anything that’s wrong, such as your email address.
- Delete it. “Delete account” in the Account panel immediately deletes your account and everything stored for it on our servers: your synced projects and their history, your share links and your sessions. Projects on your device aren’t touched.
- If you have a subscription, deleting your account also cancels it immediately through Paddle, so you aren’t charged again. During the free month nothing has been charged. Otherwise the rest of the paid period isn’t refunded, but within 14 days of a payment you can still ask for a full refund of it (see the refund policy). If Paddle can’t cancel the subscription, nothing is deleted and you can try again.
If the GDPR or the UK GDPR applies to you, you also have the right to restrict our use of your data, to object to uses based on legitimate interests, and to receive the data you gave us in a machine-readable format. Under Israel’s Protection of Privacy Law, you have the right to inspect the data we hold about you and to ask us to correct or delete it.
To use any of these rights, or if you can’t sign in, email leoisprogramming@gmail.com, if you can from the address of your account (so we know it’s you). We’ll answer within 30 days. It’s free.
You can also complain to a data protection authority: the one where you live or work (in the EU), the Information Commissioner’s Office (in the UK), or Israel’s Privacy Protection Authority. We’d appreciate the chance to fix the problem first.
Children
3dspriter isn’t directed at children. You must be at least 16 to create an account. The free app needs no account and collects nothing, so anyone can use it. If we learn that someone under 16 has an account, we’ll delete it (cancelling any subscription first). If you believe a child has given us data, email us.
Changes
If we change this policy, we’ll post the new version here with a new date. If a change is important, for example if it changes how we use data you’ve already given us, we’ll email account holders before it takes effect.
Contact
Questions about privacy: leoisprogramming@gmail.com.