← Filafy
Privacy Policy
Last updated September 8, 2026
This Privacy Policy explains what personal information Filafy collects, how it is used, and the choices you have. It applies to the Filafy website and web application at https://filafy.app (the "Service").
Filafy is operated by an individual sole proprietor based in Nova Scotia, Canada (referred to here as "the developer," "we," "us," or "our"). We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and, where they apply, the General Data Protection Regulation (GDPR) for users in the European Economic Area and the United Kingdom and applicable U.S. state privacy laws.
By using the Service, you agree to the practices described in this Policy. This Policy is incorporated into the Terms of Service.
1. SUMMARY OF OUR APPROACH
A few things that shape everything below:
• Live previews are never saved. You can adjust settings as much as you like without anything being stored.
• When a conversion completes successfully, it is saved automatically as a project so you can reopen and re-edit it. Projects are deleted automatically after 30 days.
• Your images are processed on our own server. Background removal and subject isolation, and the automated content review described in Section 3, use machine-learning models that run on our infrastructure. Your images are never sent to a third-party AI or image-processing service, and are never used to train any model.
• We use analytics and advertising technology (Google Analytics and Meta advertising tools) to understand how the Service is used and to reach potential users. This can include matching a scrambled ("hashed") version of your email address to a Meta account. You can control all of it, and where the law requires it we ask for your consent first. See Sections 6 and 8.
• We do not sell your personal information for money. Some U.S. state privacy laws define "sale" or "sharing" broadly enough to include advertising technology like ours; Section 6 explains how to opt out.
• Marketing email is strictly opt-in and separate from account creation.
• You can delete your account yourself, at any time, from Settings.
2. INFORMATION WE COLLECT
2.1 Information you provide
• Account information. Your email address and, if you set one, a securely hashed version of your password. We store password hashes using a strong, salted algorithm, never your password in plain text.
• Email confirmation records. When an address needs to be confirmed, at registration, when you ask us for a new link from Settings, or when you change your address, we store the address being confirmed, a hashed single-use token, and the times that record was created and expires. The link is valid for 24 hours and works once. You can request a new one from Settings, within a rate limit. Nothing in the Service is gated on confirming your address; confirmation matters only for the automatic provider match described below.
• Email address changes. If you change your address, we send a confirmation link to the new address, and your account keeps the old one until that link is opened, so for a period we hold an address that is not yet your account's. We also notify the old address as soon as the change is requested, while there is still time to stop it. This is deliberate: it stops a typo from stranding your account on an address nobody can read, which is also the address a password reset would be sent to.
• Connected sign-in accounts. If you sign in with Discord or Google, or create your account that way, we store the provider's name, that provider's permanent account identifier for you, the email address the provider confirmed at the time, and when you connected it. We do not receive or keep your provider password. We request only the minimum sign-in permissions from the provider (for Google: openid, email, and profile; for Discord: identify and email); these do not let us read your contacts, see your servers or friends, post as you, or browse your activity. Google also sends your name and profile picture as part of sign-in; we discard both and store neither. Connecting a provider does not remove your password or your two-factor authentication; they keep working alongside it. If you created your account through a provider and have no password, you can set one at any time using the "Forgot your password?" link on the sign-in page. If the provider confirms an email address that already belongs to a Filafy account, and that Filafy account has itself confirmed the same address through our confirmation link, we connect the two and sign you in, so both ways of signing in reach the same projects. We do this only when both sides have been confirmed, because a match on an address that nobody has ever proved they control is not evidence that the two accounts belong to the same person. If the Filafy account has not confirmed its address, we do not connect anything and do not sign you in; we ask you to sign in with your password and connect the provider from Settings instead. You can connect more than one provider, and you can disconnect any of them in Settings, as long as you keep one way to sign in.
• Two-factor authentication data. If you enable TOTP two-factor authentication, we store the secret needed to verify your one-time codes.
• Invite code. If you register with an invite code, the code is recorded and associated with your account, so we can understand where sign-ups come from ("source attribution").
• Legal acceptance. The version of the Terms of Service and Privacy Policy you accepted.
• Marketing consent. Whether you opted in to marketing email, and the date and time you did so (see Section 5).
• Uploaded content. Images you upload for conversion, any 3D model files you upload, and associated conversion settings, crops, and face selections. A single project can hold more than one image.
• Your equipment and preferences. The filaments you indicate you own (including per-filament priority), the printers you own and your default printer, nozzle size, print-quality tier, preferred slicer, default and hidden styles, filament-library display preferences, and advanced-feature toggles.
• Locale settings. Your time zone, unit preference (metric or imperial), and country. Country decides which filament retailers and "Buy" links you are shown: which regional Amazon marketplace you are sent to, and whether country-routed retailers such as 3DJake and MatterHackers appear at all.
• Support communications. If you contact us, through the support channel, the in-app "Report an issue" tool, or email, we receive whatever information you choose to share. A report sent with the in-app tool also carries a small context block, attached automatically so that the report can be diagnosed: the printer and nozzle size set on your account, which project you were looking at, and your browser's user-agent string. Your description and that block are both scrubbed of email addresses and long tokens before they are stored.
• Content reports. Anyone can report content on the Service using the form at https://filafy.app/report, whether or not they have an account. That form is the subject of Section 2.4.
2.2 Information generated by your use of the Service
• Saved projects. When a conversion completes successfully it is saved automatically, together with your uploaded source images, any attached model, the generated result, and the settings needed to reopen and re-edit the project. Live previews are not saved.
• Job records. Operational records of conversion jobs, including the style and settings used and timing.
• Content review records. We record when each saved conversion was scanned by the automated content review described in Section 3, so that it is scanned once rather than repeatedly. If a scan scores above our review threshold, we also record a review entry for it: the score, the model's full set of label scores, the name of the model, the threshold that was in force at that moment, the project's title, timestamps, and, once a person has looked at it, what they decided. Each review action a person takes is recorded as well, so that the history of an account is accurate. These entries carry your numeric user ID; your email address is not copied into them.
• Credit ledger. An append-only record of credit events (consumption, refunds, and, in future, purchases or grants) used to operate the credit system accurately.
• Aggregate style statistics. Daily per-style rollups of slider values from completed jobs, used to tune default settings. These are aggregate figures, not tied to your identity.
• Filament catalogue telemetry. When you import filaments and a row does not match anything in our catalogue, we record the unmatched row itself: brand, material, type, color name, hex value, the reason it did not match, when it was first and last seen, and how many times it has been seen. This record contains no user identifier and no reference to your spools, so it is not linked to you or your account. We use it to find gaps in the filament catalogue, and we contribute those gaps upstream to the Open Filament Database, the public data source our catalogue is built from.
• Session information. When you log in we create a session and store a hashed session token; a corresponding cookie is set in your browser (Section 8).
• Error records. If something goes wrong, we record a structured error entry to diagnose it. These are deliberately minimal: they contain at most a numeric user ID (never your email), a request identifier, a coarse category, a status, and a curated message. Messages and details are scrubbed of email addresses and long tokens before storage, and we never record request bodies, uploaded file contents, passwords, or tokens. This describes what our error records contain, not who at Filafy can open a saved project; Section 3 covers that.
2.3 Information collected automatically
• Server and proxy logs. The Service and the reverse proxy in front of it record technical information such as IP address, user agent, requested paths, and timestamps. Your IP address is also used to enforce rate limits that protect the Service from abuse.
• Analytics and advertising data. Subject to your consent where required, our analytics and advertising providers collect information about your visit, such as pages viewed, referring site, approximate location derived from IP address, device and browser characteristics, and interactions like sign-ups or conversions. This is described in detail in Section 6.
• Approximate country from your IP address. If you have not set a country in Settings, we work out an approximate country from your IP address so that the filament "Buy" links in My Filaments point at shops that can actually ship to you. The lookup runs on our own server against a local copy of MaxMind's GeoLite2-Country database, so your IP address is not sent to MaxMind or to anyone else. The country is used to build the links on that page and is then discarded: we do not store it, we do not log it, and we do not attach it to your account. If you have set a country in Settings, we use that and no lookup happens on your behalf. Section 13 explains how to opt out of this entirely.
We do not intentionally collect special categories of sensitive personal information, and you should not upload such information.
2.4 Content reports, including from people who have no account
The Service publishes a content report form at https://filafy.app/report. It needs no account and no sign-in, because the person who most needs it is usually not a member: somebody who has come across content on Filafy that should not be there. This section is about the information that form collects, and it is the one place in this Policy where the person described may never have used the Service at all.
• What the form asks for. Where you saw the content, in your own words or as a link; which of five categories the problem falls into; and, if you have no account, an email address we can reply to. The address is required for a report from someone with no account, because a report we cannot ask a question about, and cannot answer, is often a report we cannot act on. If you are signed in when you use the form, the form does not ask for an address at all: your account is attached to the report instead, and no separate address is stored.
• What we do with it. We read every report by hand, decide whether the content breaches the Acceptable Use section of our Terms, and act on it. A report in the category covering the safety of a minor also sends an alert to the developer, so that it is seen quickly rather than at the next sign-in. That alert carries only a reference code and the category. It never carries what you wrote, and it never carries your address.
• What we never do with your address. We do not pass it to the person you are reporting, we do not add it to any mailing list, and we do not use it for anything other than replying to you about your report.
• Your description. It is stored as you wrote it, scrubbed of email addresses and long tokens like every other piece of free text described in this Policy. Please do not put anything in it you would not want kept.
• How long. The report itself is kept, because it is the record of what was reported and what we did about it. Your address is not: the moment we mark the report complete, the address is deleted from it permanently. See Sections 9 and 10.
• Your reference code. Every report is given a short code, shown to you when you send it. It does not identify you. It is what to quote if you want to ask us about a report later.
• Rate limiting. The form limits how many reports can be sent from one internet connection in an hour, to keep it usable. If you reach that limit we tell you so, on the page, rather than accepting a report we are not going to keep.
3. HOW WE USE YOUR INFORMATION
We use the information above to:
• create and manage your account and authenticate you, including two-factor authentication;
• provide the core Service (decoding, cropping, resizing, background removal, conversion, preview generation, and export) and let you save and reopen projects;
• apply the correct printer, nozzle, slicer, and print-quality presets to your exports;
• operate the free monthly credit system, including refunds for failed or cancelled conversions, and, in future, any paid-credit purchases;
• gate registration by invite code where enabled, and understand where sign-ups originate;
• send you service and security email, such as confirming that an address is yours, telling you that a change of address has been requested or has taken effect, telling you that a sign-in method has been connected, welcoming you, confirming a deletion, resetting your password, and letting you know that a queued conversion is ready. These messages are part of the Service rather than marketing, and they are not subject to marketing consent;
• confirm that an email address belongs to you: at registration, when you ask for a new confirmation link, and before a change of address takes effect;
• send you marketing email only if you have opted in (Section 5);
• measure how the Service is used, and measure and target advertising (Section 6);
• find and fill gaps in the filament catalogue, and contribute those gaps upstream to the public data source it is built from (Section 2.2);
• show relevant filament "Buy" links for your region;
• maintain the security and integrity of the Service, enforce rate limits, prevent abuse, enforce our Terms, and diagnose errors;
• review saved conversions automatically for content that may breach the Acceptable Use section of our Terms, as described at the end of this section;
• receive, read, and act on reports about content on the Service, including reports from people who have no account (Section 2.4), and reply to the person who sent one;
• improve the Service using aggregate usage patterns;
• comply with legal obligations.
We do not use your uploaded images or models to train machine-learning models, and we never share the contents of your uploads or your saved projects with analytics or advertising providers.
To answer a support request, diagnose a fault, or investigate suspected abuse, an administrator can open your saved projects through the administrative interface described in Section 12 and view the pictures you uploaded, the results produced from them, and the settings each conversion used; that view is read only and changes nothing in your account.
Automated content review. When a conversion is saved, the saved result is scanned automatically by a machine-learning classifier running on our own server, to find content that may breach the Acceptable Use section of the Terms of Service. The scan happens after the conversion is already saved. It does not delay, alter, or block any conversion, it never changes your artwork, and nothing is sent to any third party. The scan produces a score, and a score above our threshold records the project for review by a person. Nothing else follows automatically. Whether anything happens after that is a decision a person makes, and the choices are closing the review as acceptable, sending you a warning email, or suspending the account under the Terms. Sections 9 and 10 explain how long review records are kept, and what happens to them when you delete a project or your account.
4. LEGAL BASES AND CONSENT
Under PIPEDA we collect, use, and disclose personal information with your knowledge and consent, except where the law permits otherwise. By creating an account you consent to the processing described here. Much of it is necessary to provide a service you requested: we cannot convert an image without processing it.
For users in the EEA or UK, our legal bases under the GDPR are:
• Performance of a contract: operating your account, running conversions, storing your projects, and providing support;
• Legitimate interests: securing the Service, preventing abuse, rate limiting, diagnosing errors, reviewing saved conversions for content that may breach our Terms, receiving and acting on content reports (including from people who are not users, whose interest in being able to report is the same interest), maintaining the filament catalogue, and improving the product using aggregate data;
• Consent: marketing email, and analytics and advertising cookies and similar technologies. You may withdraw consent at any time;
• Legal obligation: where we must retain or disclose information by law.
You may withdraw consent to optional processing at any time (Sections 5, 6, and 8), and you may withdraw consent more broadly by deleting your account.
5. MARKETING EMAIL (OPT-IN ONLY)
Marketing email is entirely optional and separate from account creation. You are never subscribed by default, and consent to marketing is never bundled with acceptance of the Terms.
• You may opt in during registration, or later in Settings, using a distinct, unticked control.
• When you opt in, we record the date and time of your consent, as required by CASL and the GDPR.
• You may withdraw consent at any time in Settings, or by using the unsubscribe link in any marketing message.
• When you withdraw consent, we clear your opt-in and instruct our marketing-email provider to suppress your address, so a later re-import cannot silently resubscribe you.
If marketing is enabled, we share your email address, your consent timestamp, and your country with our marketing-email provider (Section 7) for that purpose only. Withdrawing marketing consent does not affect service and security email: address confirmations, notices that your address or a sign-in method has changed, password resets, and job notifications are all part of the Service, and you cannot opt out of them while you have an account.
Marketing email consent is separate from advertising (Section 6). Opting in to email does not authorize us to include you in advertising audiences, and opting out of advertising does not unsubscribe you from email. Each is controlled independently.
6. ANALYTICS AND ADVERTISING
We use two categories of third-party technology to understand and grow the Service.
Google Analytics helps us understand how visitors find and use Filafy in aggregate: which pages are visited, how people navigate, roughly where visitors are located, and which sources bring sign-ups. Google Analytics sets cookies or similar identifiers and receives your IP address, device and browser information, and details of your activity on the site. Where consent is required, Google Analytics runs in the denied consent state described in Section 8 until you consent.
Meta advertising tools let us measure and target advertising. A measurement tag on the site reports events such as page views and sign-ups back to Meta, so we can see which ads work and show ads to people who have visited Filafy or who resemble our existing users. Meta receives your IP address, device and browser information, and the events you triggered, and may match this to a Meta account if you have one.
Custom Audiences. We may also upload a hashed (irreversibly scrambled) version of your email address to Meta so it can be matched against Meta accounts. This lets us show Filafy ads to existing users, exclude existing users from sign-up ads, and build "lookalike" audiences of people with similar characteristics. Hashing means we do not hand Meta your email address in readable form, but a match still links you to a Meta profile, so we treat this as a disclosure of your personal information for advertising.
This is a separate purpose from marketing email. Consenting to marketing email does not authorize audience matching, and audience matching does not subscribe you to email. You can opt out of Custom Audience matching at any time (see "Your choices" below), and doing so does not affect your use of the Service.
What we never share. We do not send your uploaded images, 3D models, saved projects, conversion settings, filament library, or password to any analytics or advertising provider.
Your choices. You can:
• decline or withdraw consent for analytics and advertising cookies where a consent control is shown (Section 8);
• opt out of Custom Audience matching, which stops us including your email in advertising audiences and removes you from existing ones;
• use your browser's cookie controls, or a tracking-blocking extension;
• install Google's browser opt-out add-on for Google Analytics;
• adjust your Meta ad preferences within your Facebook or Instagram account settings, including the "Off-Facebook activity" and advertiser-audience controls;
• use the industry opt-out tools at youradchoices.ca (Canada), youradchoices.com (U.S.), or youronlinechoices.eu (Europe);
• send a Global Privacy Control (GPC) signal, which we honor as an opt-out request where required by law.
A note on "sale" and "sharing." We do not sell your personal information for money. However, some U.S. state privacy laws, including California's, define "sale" and "sharing for cross-context behavioral advertising" broadly enough that our use of advertising technology may qualify. If you are covered by such a law, you may opt out using the controls above, and we will not discriminate against you for doing so.
Advertising and children. We do not knowingly target advertising to anyone below the age requirement in our Terms of Service.
7. THIRD PARTIES AND SERVICE PROVIDERS
We share personal information only as needed to run the Service, and only with the categories of providers below.
• Vultr Holdings: hosting (virtual server, Toronto, Canada) and object storage for database backups (New York, United States). May receive: all Service data, as the hosting environment.
• Apple (iCloud+): transactional email delivery (password resets, job-ready notices). May receive: your email address and message contents.
• Google (Sign in with Google): identity verification, only if you choose to sign in this way. May receive: the fact that you signed in to Filafy. We receive a provider account identifier, your confirmed email address, and your name and profile picture, and we keep only the identifier and the email.
• Discord (Sign in with Discord): identity verification, only if you choose to sign in this way. May receive: the fact that you signed in to Filafy. We receive a provider account identifier and your confirmed email address.
• EmailOctopus: optional marketing-email list, only if you opt in. May receive: your email address, consent timestamp, country.
• MaxMind: the country database behind region-appropriate "Buy" links, and the "Do Not Sell My Personal Information" exclusion list described in Section 13. May receive: nothing about you. We download their database to our own server and look addresses up locally, so no request about you is ever sent to MaxMind.
• Google (Analytics): website analytics. May receive: IP address, device and browser data, pages viewed, on-site activity.
• Meta Platforms: advertising measurement, targeting, and audience matching. May receive: IP address, device and browser data, events such as page views and sign-ups, and a hashed version of your email address.
• Cloudflare: DNS, and, where enabled, reverse proxy, TLS termination, and content delivery. May receive: domain lookup data; where proxying is enabled, also your IP address, request metadata, and traffic in transit.
• Open Filament Database: the public filament data source our catalogue is built from. May receive: aggregate catalogue gap data as described in Section 2.2. It receives no personal information, no user identifier, and nothing about your spools or your projects.
• Buy Me a Coffee: voluntary donations, if you choose to donate. May receive: whatever you provide to that platform directly.
• Discord (community server): community and support channel, if you choose to join. May receive: whatever you provide to that platform directly.
• Amazon, 3DJake, MatterHackers, and other retailers: affiliate "Buy" links, chosen based on your country, if you click one. May receive: referral or tracking identifier and their own cookies once you land on their site.
• Payment processor (future): paid credits, if introduced. May receive: payment details, handled by them. We will not store full card numbers.
A note on Cloudflare. Cloudflare provides DNS for filafy.app, and we may also route traffic through Cloudflare's network as a reverse proxy and content-delivery layer to improve performance and protect against attacks. When proxying is enabled, your requests pass through Cloudflare's servers before reaching ours, so Cloudflare processes your IP address, request metadata, and the traffic itself in transit, and may terminate the encrypted connection at its edge. Cloudflare operates a global network, so this processing may occur outside Canada (Section 11). Cloudflare acts as our service provider for this purpose and does not use your data for its own advertising.
We may also disclose information if required by law, or where we reasonably believe disclosure is necessary to comply with legal process, enforce our Terms, or protect the rights, safety, or property of the developer, our users, or the public.
8. COOKIES AND SIMILAR TECHNOLOGIES
The Service uses three categories of cookies and similar technologies:
• Essential cookies. Set when you log in so the Service can keep you authenticated, and marked Secure in production. The Service cannot function without them; they are not used for advertising or cross-site tracking, and they do not require consent.
• Analytics cookies. Set by Google Analytics to measure how the Service is used (Section 6), only after you consent. Until you consent, and whenever you have declined, Google Analytics runs in a denied consent state: it sets no cookies and stores no identifiers on your device, but basic, cookieless measurement signals, such as the page viewed and your IP address, are still sent to Google so that visits can be counted in aggregate.
• Advertising cookies and pixels. Set by Meta advertising tools to measure and target ads (Section 6). The Meta pixel is not loaded at all until you consent.
Consent. Where the law requires it, including in the EEA, the UK, and Quebec, we ask for your consent before any analytics or advertising cookies are set or the Meta pixel is loaded, through a consent control shown on your first visit. You can accept or decline each optional category, we record your choice, and you can change it at any time using the same control. Declining optional cookies does not affect your ability to use the Service.
Note that the cookie control governs technology running in your browser. Custom Audience matching (Section 6) happens on our side rather than in your browser, so it is controlled separately, through the opt-out described in that section.
Third-party cookies on other sites. If you follow an affiliate "Buy" link, the destination retailer may set its own cookies under its own policy. That happens on their site, not ours.
Most browsers let you block or delete cookies, but blocking the essential session cookie will prevent you from logging in.
9. DATA RETENTION
We keep personal information only as long as needed, unless a longer period is required by law. Current periods:
• Live previews: never saved.
• Rendered results of conversions that were not saved: about 1 hour.
• Session uploads: about 6 hours.
• Per-job upload and model copies for jobs that did not complete: about 1 day.
• Saved projects (your uploaded source images, any attached model, the generated result, and the settings): 30 days, then automatically deleted.
• Job records (operational): 7 days.
• Content review records: kept for as long as the account exists, and deleted with it (Section 10). Deleting the project a record refers to does not delete the record, but strips it back to a score and some timestamps (Section 10).
• Issue reports you submit through "Report an issue": kept indefinitely, as the record of what has been reported and dealt with. If you delete your account, the link to you is removed and the report stays (Section 10).
• Content reports sent through the public form (Section 2.4): the report itself is kept indefinitely, for the same reason. A reporter's email address is not: it is deleted from the report as soon as the report is marked complete, and that deletion is permanent and cannot be undone. Reports sent by a signed-in member store no separate address at all.
• Credit ledger, consumption and refunds: 62 days.
• Credit ledger, purchases and grants, if introduced: retained, as a financial record.
• Aggregate per-style statistics: about 35 days (aggregate, not identifying).
• Filament catalogue telemetry: about 180 days (contains no user identifier).
• Error records: 14 days.
• Email confirmation records: 24 hours, single use.
• Account information: until you delete your account.
• Database backups (New York, U.S.): rolling backup window of about 30 days.
• Server whole-disk backups: per the hosting provider's rotation.
• Analytics and advertising data: held by those providers under their own retention settings and policies.
Retention periods are configurable and may change. Because saved projects are deleted automatically, keep your own copies of any outputs you want to preserve. Filafy is not a backup service.
10. DELETING YOUR ACCOUNT
You can permanently delete your account yourself, at any time, from Settings. You do not need to contact us or give a reason. To confirm it is really you, we ask you to re-enter your password. If your account has no password and you sign in with Google or Discord, we ask you to re-authenticate with that provider instead.
What deletion does. Your account record, email address, password hash, two-factor secret, saved projects, uploaded source files and models, filament and printer library, preferences, active sessions, any pending email confirmation records, and any content review records and review history attached to your account are removed from the live Service. Any unused credits are forfeited. Where you had opted in to marketing email, we also instruct our marketing provider to suppress your address, and we remove your email from any advertising audiences we maintain. If you connected any sign-in accounts, the stored records for them are removed with the rest of your account. Deleting your Filafy account does not affect your Google or Discord account itself.
What may briefly remain.
• Backups. Deleted data may persist in database and server backups until they age out of the normal backup rotation (about 30 days), after which it is gone. We do not restore backups to recover deleted accounts.
• Minimal records. We may retain limited records we are required to keep for legal, security, or accounting reasons, for example records of any payments, or a suppression entry that prevents marketing email from being sent to you again.
• Filament catalogue telemetry. Because it carries no user identifier and no reference to your spools, it cannot be traced back to your account and is not removed by deletion. It ages out on its own schedule (Section 9).
• Issue reports. A report you sent through "Report an issue" stays in our support record, with the link to your account removed, so that we keep an accurate history of what was reported and what was done about it. The report is no longer connected to you, though anything you typed into it remains as you wrote it. The same applies to a content report you sent through the public form while signed in.
• Third-party data. Information already collected by analytics or advertising providers is held under their own policies; use the controls in Section 6 to manage it.
Deleting a single project. You can delete any one project without deleting your account, and its files and settings go the same way. One thing does not go with it: if that project had been recorded for content review (Section 3), the review record survives, stripped. The project's title is cleared and the link to the project is removed, so what is left is a score, a model name, a threshold, and timestamps. We keep it because a review history has to stay accurate whether or not the project it concerned still exists, and we strip it because the title is your text describing something we have just deleted. That record is deleted in full when you delete your account.
Deletion is irreversible. We cannot restore a deleted account or its projects, so download anything you want to keep first.
11. WHERE YOUR INFORMATION IS STORED
Primary storage, Canada. The Service runs on a virtual server located in Toronto, Canada. Your account, your saved projects, and your uploaded images and models are served from there.
Database backups, United States. The Filafy database is backed up continuously to object storage located in New York, United States. These backups contain the contents of the database, including account records, email addresses, hashed passwords, two-factor secrets, preferences, consent records, and project metadata. Because these backups are stored in the United States, they are subject to U.S. law, and U.S. authorities may be able to compel access to them through U.S. legal process, regardless of where you are located. Your uploaded images and 3D models are stored as files on the server and are not part of this continuous database backup.
Server backups. Our hosting provider also takes periodic whole-disk backups of the server, which do include uploaded files. These are managed by the provider as part of the hosting environment.
Developer-held copies. A copy of backups may also be pulled to separate storage controlled by the developer in Canada, so that a compromise of one provider account cannot destroy every copy.
Several third parties in Section 7 operate globally and process data outside Canada, including in the United States and the European Union. In particular, Google and Meta process analytics and advertising data on infrastructure in the United States and elsewhere, and, where Cloudflare proxying is enabled, your requests are routed through whichever Cloudflare edge location is nearest to you, which may be in any country where Cloudflare operates. Information processed in another country may be subject to that country's laws, including lawful access by its authorities. We rely on our providers' contractual and technical safeguards, including standard contractual clauses where applicable. By using the Service, you acknowledge this cross-border storage and processing.
12. SECURITY
We take reasonable technical and organizational measures to protect your information, including:
• storing passwords only as salted hashes, never in plain text;
• storing session and administrative tokens in hashed form, and marking the user session cookie Secure in production;
• storing email confirmation and password reset tokens hashed, single use, and time limited;
• requiring you to re-authenticate before a sign-in method can be added or removed, rather than relying on an already signed-in session;
• offering optional two-factor authentication;
• keeping the administrative interface off the public internet entirely, reachable only from the server itself over an authenticated tunnel;
• rate-limiting authentication and other sensitive endpoints;
• restricting network access at the firewall to only the ports needed to serve the site;
• applying automatic security updates to the host, and scrubbing error logs of emails and tokens;
• maintaining continuous, tested database backups.
No method of transmission or storage is completely secure and we cannot guarantee absolute security. You are responsible for keeping your password and two-factor credentials confidential.
13. YOUR RIGHTS AND CHOICES
Subject to applicable law, you have the right to:
• Access the personal information we hold about you, and ask how it is used and disclosed;
• Correct inaccurate or incomplete information. Much of it is editable directly in Settings;
• Delete your account and associated personal information, yourself, from Settings (Section 10);
• Withdraw marketing consent at any time, in Settings or via any unsubscribe link;
• Opt out of analytics and advertising, using the controls in Sections 6 and 8;
• Opt out of IP-based country lookup, as described immediately below;
• Port your data. You can download your projects at any time while they are retained.
"Do Not Sell My Personal Information" and IP location. MaxMind, whose country database we use for the "Buy" links described in Section 2.3, maintains a list of "Do Not Sell My Personal Information" requests covering individual IP addresses and networks. You can submit a request for your own address directly to MaxMind through the form on their website, www.maxmind.com. We retrieve that list from MaxMind regularly, and an address on it is set aside before any lookup is attempted: we do not work out a country for it at all, and the region-specific retailer links simply do not appear. You do not need to tell us, and you do not need a Filafy account for this; honoring the list happens automatically. Two other routes reach the same place: set your country in Settings, in which case we use what you set and never consult the database, or contact us and we will confirm the position for your account.
If the GDPR applies to you, you also have rights to restrict or object to certain processing, to data portability in a machine-readable format, and to lodge a complaint with your local supervisory authority. If a U.S. state privacy law applies to you, you may have rights to know, delete, correct, and opt out of targeted advertising or "sale" and "sharing," and to be free from discrimination for exercising them.
To exercise any right that is not self-serve, contact us through the support channel linked in the Service. We may need to verify your identity, usually by confirming control of your account email, before acting. We will respond within the time required by applicable law.
If you have no account. The only personal information we are likely to hold about you is an email address you gave us on a content report (Section 2.4), and the report you wrote. Reply to the message we sent you about that report, or use the form again and quote your reference code, and tell us what you want us to do. We will act on the same rights and within the same time limits as for anyone else. If your report has already been marked complete, your address has been deleted from it and there is nothing left of you in it but the words you wrote.
If you have a concern we cannot resolve, you may contact the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or your applicable provincial or national privacy regulator.
14. CHILDREN'S PRIVACY
The Service is not directed to children. You must meet the age requirement in the Terms of Service to use the Service. We do not knowingly collect personal information from children below that age, and we do not knowingly target advertising to them. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
15. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. When we make material changes we will update the version and date shown at the top of this page, and we may notify you in the Service and ask you to acknowledge the revised version. Your continued use after the changes take effect means you accept the updated Policy.
16. CONTACT
If you have questions about this Privacy Policy or how your information is handled, contact the developer through the support channel linked within the Service. If you have no account, the content report form at https://filafy.app/report reaches the same person.