Draft for legal review. The bracketed details are placeholders, and this text has not been reviewed by a lawyer. It is not yet an agreement.
Privacy Policy
[COMPANY LEGAL NAME] · Effective [EFFECTIVE DATE]
What we collect
- Account details: your email address, an optional display name, and a password stored only as a salted, slow hash. We cannot read your password.
- Your jobs: the materials, stock, parts and settings you submit, the layouts we compute, and the drawings rendered from them.
- Records of use: how much optimization you used, for plan limits and billing, and a security log of sign-ins, key changes and membership changes.
- Billing: if you subscribe, our payment processor holds your card; we receive your plan, its status and billing period, never your card number.
What we do with it
We use your data to run the service: to compute and show cutting layouts, keep your jobs, enforce plan limits, bill you, send the account emails you need (address confirmation, password reset, invitations), and keep the service secure. We do not sell personal data.
No AI system decides how your material is cut. Layouts are computed by a deterministic optimizer and independently checked before they are shown.
Cookies and browser storage
- A session cookie that keeps you signed in. It is essential and cannot be turned off.
- A cookie remembering which organization you last chose.
- Your workspace draft, kept in your browser's local storage on this device so a refresh does not lose it. Clearing site data removes it.
We use no advertising or cross-site tracking cookies.
Product usage events
When you are signed in, the app records which features you use, such as loading a saved list, turning cuts on or off, or choosing an optimization effort, so we can improve it. An event holds only its name and a few counts or settings (for example, how many cuts, or which effort level), never your part names, labels, dimensions or other job contents. Events are tied to your organization and the member who acted, are sent only to our own servers with no third-party analytics, and are not recorded at all when you are signed out.
Who processes it for us
We use these service providers to host and operate NestSmart. They process data only on our instructions.
- Render — application hosting and the database, in the United States (Oregon).
- Cloudflare — storage for rendered drawings (PDF, DXF and SVG files), in North America, and the domain's DNS.
- Resend — sending account email, once email is enabled.
- Stripe — payment processing, once paid plans are available.
How long we keep it
Today, your projects, saved lists, optimization runs and drawings are kept until you delete them or ask us to delete your account. Records we must keep for billing and tax are kept after an account is deleted, reduced to the organization and the amounts. [Retention periods for runs, drawings, usage events and backups are a business decision to be set before publication; they are not yet enforced by the system.]
Your choices and rights
You can delete your saved lists and revoke your API keys in the app. To change your account details, get a copy of your data, or have your account deleted, write to [privacy@yourdomain.com]; these are handled on request today. Depending on where you live, you may have further rights under local law; we will honor them.
Security
Every organization's data is isolated from every other's at the database level. API keys are stored only as hashes and shown once. Traffic is encrypted in transit. If we learn of a breach affecting your data we will tell you as the law requires.
Changes
If we change this policy materially we will say so on this page and, for account holders, by email before the change takes effect.
See also the Terms of Service and the Privacy Policy. Questions: [privacy@yourdomain.com].