TM ← Back to CoreShape Open Dashboard →
Legal

Privacy Policy

Effective Date: September 12, 2026

This Privacy Policy explains how CoreShape ("we," "us," or "our") collects, uses, shares, and protects personal information when you visit our website or use the CoreShape web application (together, the "Service"). It is incorporated into our Terms of Use by reference.

1. Introduction

CoreShape is a parametric CAD application that runs in your browser. Most of what the Service does — sketching, modeling, and rendering — happens locally on your own device, and the geometry kernel itself never sends your designs anywhere. Personal information reaches our servers only when you create an account, sign in, save a project to the cloud, or contact us.

We have tried to keep this policy specific rather than generic: where a section says we do not do something, that reflects how the Service is actually built today, and we will update this policy before that changes.

The short version. We collect the account details you give us and the projects you choose to save. We count how many times each page is viewed, but we do not use advertising networks, third-party analytics, or session recording, and nothing we count identifies you. We do not sell your personal information, and we do not use your designs to train machine-learning models.

2. Information We Collect

2.1 Information You Provide

  • Account information. When you sign up we collect your name, email address, and a password. Your password is never stored in readable form — we keep only a salted cryptographic hash of it, and we cannot recover or tell you your password.
  • Country (optional). When you sign up we invite you to choose your country from a list. You do not have to — the field starts unset and leaving it that way costs you nothing: your account is created the same way and works identically. We use this for one purpose only: to understand which countries CoreShape is used in, so we can see where our user base is and plan accordingly. It is not used to decide anything about your individual account — not your pricing, not what features you get, and not whether you may use the Service. It is the country you select, not a location we detect: we do not use IP geolocation, GPS, or any other means of working out where you are, and we do not store a region, city, or address.
  • Account status. We store which plan you are on, whether your email address has been verified, and the date your account was created.
  • Verification and reset codes. When you verify your email or reset your password, we temporarily store a hash of the one-time code, its expiry time, and a count of failed attempts. These are deleted or expire shortly after use.
  • Projects you save. If you save a project to your CoreShape account, we store the project's name, its design data (the parametric feature timeline that defines your model), and the times it was created and last updated. See Section 6.
  • Payment records. If you subscribe to a paid plan, we record which plan you bought, the amount, and the date. We do not receive or store your card number, expiry date, or security code — those go directly to our payment processor (see Section 7).
  • Communications. If you email us for support or any other reason, we keep your message and our reply so we can answer you and keep a record of the issue.

2.2 Information Collected Automatically

  • Session records. When you sign in, we create a random session token, record when it was created, when it expires, and the time of your most recent request on it, and associate it with your account. The token is stored in your browser so you stay signed in. It stops working when you sign out, when you change your password, after 24 hours without using CoreShape, or 30 days after you signed in — whichever comes first. The record of your most recent request exists only to enforce that 24-hour inactivity limit, which is there so a session left open on a shared or borrowed computer does not stay signed in indefinitely.
  • Server logs. Our servers record standard technical information about requests, which may include your IP address, the date and time, the page or endpoint requested, HTTP status, and your browser's user-agent string. These logs are used for security, abuse prevention, rate limiting, and diagnosing faults.
  • Page view counts. When you open a page on our website, it tells our server which page was opened, and we add one to a counter for that page for that day. That counter is all we keep: no IP address, no cookie, no visitor identifier, no referring site, and nothing about your browser or device. Because there is no identifier, these counts cannot be linked to you or to each other — we can see that a page was viewed a thousand times, but not whether that was a thousand people or one person a thousand times.
  • Affiliate referrals — only if you were referred and you agree. If you arrive at CoreShape through an affiliate's link, we first ask whether you allow cookies. Until you answer, nothing is sent to anyone and no cookie is set; the only thing we keep is the affiliate's code from the link you followed — nothing about you — in that browser tab, so the question can still be asked if you open another page first. It is deleted as soon as you answer, either way, or when you close the tab. If you allow them, a script from our payment provider, Lemon Squeezy, sends them the address of the page you opened, the site that referred you, the affiliate's referral code, and an identifier for your device calculated from characteristics of your browser and hardware (a technique known as device fingerprinting), and sets a cookie so that a subscription you buy later is credited to that affiliate. If you decline — or if you did not arrive through an affiliate link at all — none of this happens and Lemon Squeezy's script is never loaded. See Section 3.
  • Preferences stored on your device. Your light/dark theme choice and similar interface settings are saved locally in your browser and are not transmitted to us. See Section 3.

2.3 Information We Do Not Collect

To be explicit, the Service does not use:

  • Advertising networks, ad pixels, or retargeting tags;
  • Third-party web analytics or product-analytics services (our page view counts, described above, are counted by our own server and shared with nobody);
  • Session recording, heatmapping, or mouse-movement tracking;
  • Cross-site or cross-device tracking — with one exception: the affiliate referral tracking described in Section 2.2, which happens only if you were referred by an affiliate and agree to it;
  • Data brokers or purchased marketing lists;
  • Biometric data, precise geolocation, or contact-list access.

The country on your account, if you gave one, is the one you chose from a list when you signed up. It is optional, and it is not geolocation: we do not look up your IP address to work out where you are, and we do not record anything more precise than the country you told us.

We also do not ask for and do not want any special-category personal data (such as health, political, or biometric information). Please do not put such information into project names, design data, or support messages.

3. Cookies and Local Storage

CoreShape itself does not use cookies. The one exception is a referral cookie set by our payment provider, and only if you arrived through an affiliate link and agreed to it (the last row of the table below). Everything else uses your browser's localStorage instead, which keeps the data on your device and — unlike a cookie — is not automatically attached to every request sent to a server. Two items use sessionStorage, which disappears when you close the tab: if an email fails to send while you are signing up, the message explaining that is carried to the next page and discarded as soon as it is shown; and if you arrive through an affiliate link, the affiliate's code is kept until you answer the cookie question (see the table below).

What is kept in your browser falls into the groups below. Only your session is ever sent to us, and only to prove who you are. The affiliate referral cookie is used by Lemon Squeezy and is never sent to us.

WhatWhy it existsLifetime
Your session
coreshape-session-token, coreshape-session-user
The token keeps you signed in and identifies your account to our API. Alongside it we cache your name, email address and plan so the page can show the right navigation and plan limits before it has finished talking to the server. The cached copy is only a copy — the server is always the authority on what your account may do. Until you sign out, change your password, go 24 hours without using CoreShape, or 30 days pass — whichever comes first
Work you have not saved to your account
cad-forge-design-v1
A local copy of the document you have open, so closing the tab or losing your connection does not lose it. It can hold the design's name and feature timeline, any CoreShape AI conversation attached to it, any 2D drawings, and the contents of a STEP file you imported. This never leaves your device — it is separate from the projects you save to your account, which are described in Section 6. Until you clear your browser storage
Editor preferences
theme, units, grid size and visibility, zoom speed, icon size, keyboard shortcuts, panel widths, AI quality setting, printability defaults
Remembers how you like the editor set up so it looks the same next time. Read on your device only and never sent to us. The AI setting records which quality level you picked, not any key or credential — CoreShape AI is reached through our server, and your browser never holds an API key. Until you clear your browser storage
Your affiliate choice
coreshape-affiliate-consent
Only exists if you arrived through an affiliate link and answered the prompt asking whether to allow cookies. It records your answer so you are asked once rather than on every page. Read on your device only and never sent to us. Until you clear your browser storage
Affiliate code awaiting your answer (sessionStorage)
coreshape-affiliate-pending
Only exists if you arrived through an affiliate link and have not answered the cookie question yet. It holds the affiliate's code from that link — nothing that identifies you — so the question can still be asked if you open another page before answering. Nothing is sent anywhere because of it; if you allow cookies, it is what tells Lemon Squeezy which affiliate referred you. Until you answer, or close the tab
Affiliate referral (a cookie, set by Lemon Squeezy)
ls_aff_ref
Only set if you arrived through an affiliate link and agreed. It identifies the referral, so a subscription you buy later is credited to the affiliate who sent you. It does not identify your CoreShape account and is never sent to us. If you decline, CoreShape removes any such cookie it finds. The period Lemon Squeezy sets for crediting a referral, or until you clear your browser storage

Everything except the affiliate items is strictly necessary to operate features you have asked for, or is a preference you set yourself, so ordinary visitors never see a consent prompt. The affiliate referral cookie is not necessary, so it is only ever set after you allow cookies, in a prompt shown only to visitors who arrive through an affiliate link. That prompt simply asks whether to allow cookies; this section is what allowing them covers, including the device identifier described in Section 2.2. None of it is used for advertising or analytics. To withdraw your agreement, clear this site's data in your browser settings — that removes both the cookie and your recorded choice (and, as noted below, any unsaved work).

Clearing your browser storage deletes unsaved work. You can clear this data at any time through your browser's site-data settings, and clearing the session token simply signs you out — but the local copy of an open document goes with it. Save your projects to your account, or export them, if you want them to survive.

4. How We Use Your Information

We use the information described above only for the following purposes:

  • To provide the Service — creating your account, signing you in, saving and loading your projects, and applying the limits of your plan;
  • To verify your identity and secure your account — email verification, password resets, and invalidating sessions when a password changes;
  • To process payments and maintain a record of your subscription;
  • To communicate with you about the Service — verification and password-reset emails, billing notices, security alerts, and material changes to our terms or this policy;
  • To keep the Service safe — detecting and preventing abuse, fraud, credential-stuffing, and denial-of-service attempts, and enforcing rate limits;
  • To diagnose and fix problems and to understand which parts of the Service are failing so we can improve reliability;
  • To see which countries CoreShape is used in — we count how many accounts selected each country, so we know roughly where our user base is. This is the only use we make of the country you give us, and we look at it as a count per country, not account by account. Because the field is optional, these counts cover only the accounts that chose one;
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not sell or rent it. If we ever want to send you optional marketing email, we will ask you to opt in first, and every such message will include an unsubscribe link. Service messages such as password resets are not marketing and cannot be unsubscribed from while your account is open.

6. Your Designs and Files

Your designs are yours. Our Terms of Use confirm that you retain ownership of your User Content; this section explains how we handle it as a privacy matter.

  • Local by default. Modeling happens in your browser. A design does not leave your device until you choose to save it to your CoreShape account. Exports to STL, OBJ, or STEP are generated locally and downloaded directly to your computer — they do not pass through our servers.
  • We do not train on your work. We do not use your designs, project names, or file contents to train, fine-tune, or evaluate machine-learning models, our own or anyone else's. Should we ever want to offer a feature that requires this, it will be optional, clearly explained, and off unless you turn it on.
  • We do not browse your projects. Our staff do not access the contents of your saved designs except in narrow cases: when you explicitly ask us to for support, when it is strictly necessary to investigate a specific technical fault or security incident, or when we are legally required to. Such access is limited to what the task requires.
  • Sharing is your decision. Saved projects are private to your account. If we introduce sharing or collaboration features, content becomes visible to others only through an action you take.
  • Deletion. Deleting a project from your dashboard removes it from our active systems. Residual copies may persist briefly in encrypted backups, as described in Section 9.

7. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose it only in the situations below.

7.1 Service Providers

We use a small number of vendors to run the Service. Each receives only what it needs, is bound by contract to protect it, and may not use it for its own purposes.

ProviderWhat it receivesWhy
HostingEverything stored by the Service, as the operator of the servers and databaseRunning the application and storing your account and projects ([Hosting Provider])
Email deliveryYour email address, your name, and the message contentsSending verification, password-reset, and service emails (Resend)
PaymentsYour payment details, billing address, and email address, collected directly by themProcessing subscription payments (Lemon Squeezy)
Affiliate referral trackingOnly if you arrived through an affiliate link and agreed: the page address, the referring site, the affiliate's referral code, an identifier for your device calculated from your browser and hardware, and — as with any web request — your IP address and user-agentCrediting the affiliate who referred you if you subscribe (Lemon Squeezy)
AI processingYour typed request, a snapshot of the design you are working on, the list of available operations, and — on a revision — a report of what the previous plan didGenerating the CoreShape AI Builder's modeling plans (Anthropic)
Software CDNYour IP address and browser user-agent, as an unavoidable part of any web requestDelivering the open-source 3D and geometry libraries the app loads at runtime (unpkg.com)
About the AI Builder. The AI Builder is optional — every tool in the editor works without it, and nothing is sent for AI processing unless you use it. When you do, your browser does not contact Anthropic directly; the request is brokered through CoreShape's own servers, and no Anthropic credential is ever held by or exposed to your browser. Anthropic acts as a service provider processing that data on our behalf to return a plan, not as an independent recipient free to use it for its own purposes. As of the effective date of this policy, Anthropic's standard commercial API terms do not permit data submitted through the API to be used to train their models; see Anthropic's privacy policy for their current terms, which CoreShape does not control. We do not use your designs to train any model — see Section 6. The full description of this feature is in Section 10 of our Terms of Use.
About the CDN. The CAD editor loads two large open-source libraries — three.js and opencascade.js — from the public unpkg.com CDN when the page opens. Your browser therefore contacts unpkg.com directly, and that request necessarily reveals your IP address and user-agent to the CDN, as it would to any website you visit. Nothing about your account or your designs is included in these requests. See our Licenses & Credits page for what these libraries are.

7.2 Legal and Safety Disclosures

We may disclose information if we believe in good faith that it is reasonably necessary to comply with a law, regulation, subpoena, court order, or other valid legal process; to enforce our Terms of Use; to detect or prevent fraud, security incidents, or technical abuse; or to protect the rights, property, or safety of our users, the public, or us. Where we are legally permitted to notify you of such a request, we will make reasonable efforts to do so.

7.3 Business Transfers

If CoreShape is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your personal information becomes subject to a materially different privacy policy, and you will be able to delete your account if you do not wish to continue.

8. International Data Transfers

We operate from the United States, and our service providers may process information in other countries. If you are located in the EEA, the UK, or Switzerland, this means your personal information may be transferred to a country whose data-protection laws differ from those of your own.

Where we make such a transfer, we rely on an appropriate safeguard recognized under applicable law — typically the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), or a finding of adequacy for the destination country. You may request a copy of the safeguards we use by writing to legal@coreshape3d.com.

9. How Long We Keep Your Information

InformationRetention
Account detailsFor as long as your account is open
Saved projectsUntil you delete them, or for 30 days after your account is closed
Session recordsUntil you sign out, change your password, go 24 hours without using CoreShape, or 30 days pass — whichever comes first
Page view countsKept indefinitely. They are counters per page per day, contain no identifier of any kind, and so are not personal information
Verification & reset codesMinutes — they expire quickly and are cleared once used
Server logs30 days, then deleted
Payment recordsAs long as required by tax and accounting law, typically several years
Support emailsUntil we determine they are no longer needed for support, legal, or record-keeping purposes

When you delete your account, we remove your account record, sessions, and projects from our active systems. Encrypted backups are rotated on a fixed cycle, so residual copies may persist for a short period before being overwritten. We may retain a minimal record of the deletion itself, and any information we are legally required to keep, such as payment history.

10. How We Protect Your Information

  • Passwords are stored only as salted hashes produced by a slow, purpose-built password-hashing function (Argon2id where available, otherwise PBKDF2 with a high iteration count). Plaintext passwords are never written to disk or logged.
  • Sessions use long random tokens with a fixed expiry, and every session is invalidated when you change your password.
  • Transport to the production Service is encrypted with HTTPS.
  • Application defenses include a Content Security Policy on every page, restrictive CORS rules, security response headers, request rate limiting, request-size caps, and server-side validation of everything a client sends.
  • Access to production systems is limited to the people who need it to operate the Service.

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by applicable law. If you believe you have found a security vulnerability, please report it to support@coreshape3d.com rather than disclosing it publicly.

11. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights over your personal information:

  • Access — ask what personal information we hold about you and get a copy of it;
  • Correction — have inaccurate or incomplete information fixed;
  • Deletion — ask us to erase your personal information;
  • Portability — receive certain information in a structured, machine-readable format, or have it sent to another provider;
  • Restriction and objection — ask us to pause certain processing, or object to processing based on our legitimate interests;
  • Withdraw consent — where we rely on consent, withdraw it at any time;
  • Non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service for exercising these rights.

Exercising them. You can update your name, change your password, and permanently delete your account and its projects yourself from your account settings — no request needed. For anything else, or if you have already closed your account, email legal@coreshape3d.com.

We will respond within the period required by applicable law (generally one month under the GDPR and 45 days under US state privacy laws), and we may need to verify your identity before acting, usually by confirming control of your account's email address. An authorized agent may submit a request on your behalf with proof of authorization.

Complaints. If you are in the EEA or UK and believe we have handled your information improperly, you may lodge a complaint with your local data-protection supervisory authority. We would appreciate the chance to address your concern first.

12. Children's Privacy

The Service is not directed to children. Consistent with our Terms of Use, you must be at least 16 years old to create a CoreShape account, and we do not knowingly collect personal information from anyone under that age.

If you are a parent or guardian and believe your child has given us personal information, contact us at legal@coreshape3d.com and we will delete the account and its data promptly.

13. Do Not Track and Global Privacy Control

Because we do not track users across websites or over time, and do not sell or share personal information for advertising, there is no cross-site tracking for a Do Not Track or Global Privacy Control signal to switch off. We honor these signals by default in the only way that is meaningful: we never engage in the behavior they are designed to prevent.

14. Changes to This Policy

We may update this Privacy Policy as the Service changes or as the law requires. When we do, we will revise the Effective Date at the top of this page.

If a change materially affects how we handle your personal information — for example, collecting a new category of data, using it for a new purpose, or sharing it with a new kind of recipient — we will give you advance notice by email or through a prominent notice in the Service before the change takes effect. Your continued use of the Service after that date means you accept the updated policy.

15. Contact Us

For any question about this policy or about how we handle your information — our Contact page lists the right address for each kind of enquiry:

  • Data controller: CoreShape 3D CAD Solutions
  • Privacy enquiries: legal@coreshape3d.com
  • Security reports: support@coreshape3d.com
  • Website: coreshape3d.com