Privacy Policy
Effective Date: September 12, 2026
This Privacy Policy explains how CoreShape ("we," "us," or "our") collects, uses, shares, and protects personal information when you visit our website or use the CoreShape web application (together, the "Service"). It is incorporated into our Terms of Use by reference.
1. Introduction
CoreShape is a parametric CAD application that runs in your browser. Most of what the Service does — sketching, modeling, and rendering — happens locally on your own device, and the geometry kernel itself never sends your designs anywhere. Personal information reaches our servers only when you create an account, sign in, save a project to the cloud, or contact us.
We have tried to keep this policy specific rather than generic: where a section says we do not do something, that reflects how the Service is actually built today, and we will update this policy before that changes.
2. Information We Collect
2.1 Information You Provide
- Account information. When you sign up we collect your name, email address, and a password. Your password is never stored in readable form — we keep only a salted cryptographic hash of it, and we cannot recover or tell you your password.
- Country (optional). When you sign up we invite you to choose your country from a list. You do not have to — the field starts unset and leaving it that way costs you nothing: your account is created the same way and works identically. We use this for one purpose only: to understand which countries CoreShape is used in, so we can see where our user base is and plan accordingly. It is not used to decide anything about your individual account — not your pricing, not what features you get, and not whether you may use the Service. It is the country you select, not a location we detect: we do not use IP geolocation, GPS, or any other means of working out where you are, and we do not store a region, city, or address.
- Account status. We store which plan you are on, whether your email address has been verified, and the date your account was created.
- Verification and reset codes. When you verify your email or reset your password, we temporarily store a hash of the one-time code, its expiry time, and a count of failed attempts. These are deleted or expire shortly after use.
- Projects you save. If you save a project to your CoreShape account, we store the project's name, its design data (the parametric feature timeline that defines your model), and the times it was created and last updated. See Section 6.
- Payment records. If you subscribe to a paid plan, we record which plan you bought, the amount, and the date. We do not receive or store your card number, expiry date, or security code — those go directly to our payment processor (see Section 7).
- Communications. If you email us for support or any other reason, we keep your message and our reply so we can answer you and keep a record of the issue.
2.2 Information Collected Automatically
- Session records. When you sign in, we create a random session token, record when it was created, when it expires, and the time of your most recent request on it, and associate it with your account. The token is stored in your browser so you stay signed in. It stops working when you sign out, when you change your password, after 24 hours without using CoreShape, or 30 days after you signed in — whichever comes first. The record of your most recent request exists only to enforce that 24-hour inactivity limit, which is there so a session left open on a shared or borrowed computer does not stay signed in indefinitely.
- Server logs. Our servers record standard technical information about requests, which may include your IP address, the date and time, the page or endpoint requested, HTTP status, and your browser's user-agent string. These logs are used for security, abuse prevention, rate limiting, and diagnosing faults.
- Page view counts. When you open a page on our website, it tells our server which page was opened, and we add one to a counter for that page for that day. That counter is all we keep: no IP address, no cookie, no visitor identifier, no referring site, and nothing about your browser or device. Because there is no identifier, these counts cannot be linked to you or to each other — we can see that a page was viewed a thousand times, but not whether that was a thousand people or one person a thousand times.
- Affiliate referrals — only if you were referred and you agree. If you arrive at CoreShape through an affiliate's link, we first ask whether you allow cookies. Until you answer, nothing is sent to anyone and no cookie is set; the only thing we keep is the affiliate's code from the link you followed — nothing about you — in that browser tab, so the question can still be asked if you open another page first. It is deleted as soon as you answer, either way, or when you close the tab. If you allow them, a script from our payment provider, Lemon Squeezy, sends them the address of the page you opened, the site that referred you, the affiliate's referral code, and an identifier for your device calculated from characteristics of your browser and hardware (a technique known as device fingerprinting), and sets a cookie so that a subscription you buy later is credited to that affiliate. If you decline — or if you did not arrive through an affiliate link at all — none of this happens and Lemon Squeezy's script is never loaded. See Section 3.
- Preferences stored on your device. Your light/dark theme choice and similar interface settings are saved locally in your browser and are not transmitted to us. See Section 3.
2.3 Information We Do Not Collect
To be explicit, the Service does not use:
- Advertising networks, ad pixels, or retargeting tags;
- Third-party web analytics or product-analytics services (our page view counts, described above, are counted by our own server and shared with nobody);
- Session recording, heatmapping, or mouse-movement tracking;
- Cross-site or cross-device tracking — with one exception: the affiliate referral tracking described in Section 2.2, which happens only if you were referred by an affiliate and agree to it;
- Data brokers or purchased marketing lists;
- Biometric data, precise geolocation, or contact-list access.
The country on your account, if you gave one, is the one you chose from a list when you signed up. It is optional, and it is not geolocation: we do not look up your IP address to work out where you are, and we do not record anything more precise than the country you told us.
We also do not ask for and do not want any special-category personal data (such as health, political, or biometric information). Please do not put such information into project names, design data, or support messages.
3. Cookies and Local Storage
CoreShape itself does not use cookies. The one exception is a referral cookie set by our payment provider, and only if you arrived through an affiliate link and agreed to it (the last row of the table below). Everything else uses your browser's localStorage instead, which keeps the data on your device and — unlike a cookie — is not automatically attached to every request sent to a server. Two items use sessionStorage, which disappears when you close the tab: if an email fails to send while you are signing up, the message explaining that is carried to the next page and discarded as soon as it is shown; and if you arrive through an affiliate link, the affiliate's code is kept until you answer the cookie question (see the table below).
What is kept in your browser falls into the groups below. Only your session is ever sent to us, and only to prove who you are. The affiliate referral cookie is used by Lemon Squeezy and is never sent to us.
| What | Why it exists | Lifetime |
|---|---|---|
Your sessioncoreshape-session-token, coreshape-session-user |
The token keeps you signed in and identifies your account to our API. Alongside it we cache your name, email address and plan so the page can show the right navigation and plan limits before it has finished talking to the server. The cached copy is only a copy — the server is always the authority on what your account may do. | Until you sign out, change your password, go 24 hours without using CoreShape, or 30 days pass — whichever comes first |
Work you have not saved to your accountcad-forge-design-v1 |
A local copy of the document you have open, so closing the tab or losing your connection does not lose it. It can hold the design's name and feature timeline, any CoreShape AI conversation attached to it, any 2D drawings, and the contents of a STEP file you imported. This never leaves your device — it is separate from the projects you save to your account, which are described in Section 6. | Until you clear your browser storage |
| Editor preferences theme, units, grid size and visibility, zoom speed, icon size, keyboard shortcuts, panel widths, AI quality setting, printability defaults |
Remembers how you like the editor set up so it looks the same next time. Read on your device only and never sent to us. The AI setting records which quality level you picked, not any key or credential — CoreShape AI is reached through our server, and your browser never holds an API key. | Until you clear your browser storage |
Your affiliate choicecoreshape-affiliate-consent |
Only exists if you arrived through an affiliate link and answered the prompt asking whether to allow cookies. It records your answer so you are asked once rather than on every page. Read on your device only and never sent to us. | Until you clear your browser storage |
Affiliate code awaiting your answer (sessionStorage)coreshape-affiliate-pending |
Only exists if you arrived through an affiliate link and have not answered the cookie question yet. It holds the affiliate's code from that link — nothing that identifies you — so the question can still be asked if you open another page before answering. Nothing is sent anywhere because of it; if you allow cookies, it is what tells Lemon Squeezy which affiliate referred you. | Until you answer, or close the tab |
Affiliate referral (a cookie, set by Lemon Squeezy)ls_aff_ref |
Only set if you arrived through an affiliate link and agreed. It identifies the referral, so a subscription you buy later is credited to the affiliate who sent you. It does not identify your CoreShape account and is never sent to us. If you decline, CoreShape removes any such cookie it finds. | The period Lemon Squeezy sets for crediting a referral, or until you clear your browser storage |
Everything except the affiliate items is strictly necessary to operate features you have asked for, or is a preference you set yourself, so ordinary visitors never see a consent prompt. The affiliate referral cookie is not necessary, so it is only ever set after you allow cookies, in a prompt shown only to visitors who arrive through an affiliate link. That prompt simply asks whether to allow cookies; this section is what allowing them covers, including the device identifier described in Section 2.2. None of it is used for advertising or analytics. To withdraw your agreement, clear this site's data in your browser settings — that removes both the cookie and your recorded choice (and, as noted below, any unsaved work).
4. How We Use Your Information
We use the information described above only for the following purposes:
- To provide the Service — creating your account, signing you in, saving and loading your projects, and applying the limits of your plan;
- To verify your identity and secure your account — email verification, password resets, and invalidating sessions when a password changes;
- To process payments and maintain a record of your subscription;
- To communicate with you about the Service — verification and password-reset emails, billing notices, security alerts, and material changes to our terms or this policy;
- To keep the Service safe — detecting and preventing abuse, fraud, credential-stuffing, and denial-of-service attempts, and enforcing rate limits;
- To diagnose and fix problems and to understand which parts of the Service are failing so we can improve reliability;
- To see which countries CoreShape is used in — we count how many accounts selected each country, so we know roughly where our user base is. This is the only use we make of the country you give us, and we look at it as a count per country, not account by account. Because the field is optional, these counts cover only the accounts that chose one;
- To comply with legal obligations and to establish, exercise, or defend legal claims.
We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not sell or rent it. If we ever want to send you optional marketing email, we will ask you to opt in first, and every such message will include an unsubscribe link. Service messages such as password resets are not marketing and cannot be unsubscribed from while your account is open.
5. Legal Bases for Processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
| Basis | Where we rely on it |
|---|---|
| Contract | Creating and maintaining your account, storing and returning your projects, processing your subscription — the processing needed to give you the Service you signed up for. |
| Legitimate interests | Securing the Service, preventing abuse and fraud, maintaining server logs, and diagnosing faults. Also counting how many accounts are in each country, so we understand where our user base is — a coarse, self-declared figure we look at in aggregate. We balance these against your rights and use the least data that achieves the purpose. |
| Legal obligation | Retaining payment and tax records, and responding to lawful requests from authorities. |
| Consent | Affiliate referral tracking, which happens only if you arrive through an affiliate link and agree to it. Any optional marketing email. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. |
6. Your Designs and Files
Your designs are yours. Our Terms of Use confirm that you retain ownership of your User Content; this section explains how we handle it as a privacy matter.
- Local by default. Modeling happens in your browser. A design does not leave your device until you choose to save it to your CoreShape account. Exports to STL, OBJ, or STEP are generated locally and downloaded directly to your computer — they do not pass through our servers.
- We do not train on your work. We do not use your designs, project names, or file contents to train, fine-tune, or evaluate machine-learning models, our own or anyone else's. Should we ever want to offer a feature that requires this, it will be optional, clearly explained, and off unless you turn it on.
- We do not browse your projects. Our staff do not access the contents of your saved designs except in narrow cases: when you explicitly ask us to for support, when it is strictly necessary to investigate a specific technical fault or security incident, or when we are legally required to. Such access is limited to what the task requires.
- Sharing is your decision. Saved projects are private to your account. If we introduce sharing or collaboration features, content becomes visible to others only through an action you take.
- Deletion. Deleting a project from your dashboard removes it from our active systems. Residual copies may persist briefly in encrypted backups, as described in Section 9.
8. International Data Transfers
We operate from the United States, and our service providers may process information in other countries. If you are located in the EEA, the UK, or Switzerland, this means your personal information may be transferred to a country whose data-protection laws differ from those of your own.
Where we make such a transfer, we rely on an appropriate safeguard recognized under applicable law — typically the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), or a finding of adequacy for the destination country. You may request a copy of the safeguards we use by writing to legal@coreshape3d.com.
9. How Long We Keep Your Information
| Information | Retention |
|---|---|
| Account details | For as long as your account is open |
| Saved projects | Until you delete them, or for 30 days after your account is closed |
| Session records | Until you sign out, change your password, go 24 hours without using CoreShape, or 30 days pass — whichever comes first |
| Page view counts | Kept indefinitely. They are counters per page per day, contain no identifier of any kind, and so are not personal information |
| Verification & reset codes | Minutes — they expire quickly and are cleared once used |
| Server logs | 30 days, then deleted |
| Payment records | As long as required by tax and accounting law, typically several years |
| Support emails | Until we determine they are no longer needed for support, legal, or record-keeping purposes |
When you delete your account, we remove your account record, sessions, and projects from our active systems. Encrypted backups are rotated on a fixed cycle, so residual copies may persist for a short period before being overwritten. We may retain a minimal record of the deletion itself, and any information we are legally required to keep, such as payment history.
10. How We Protect Your Information
- Passwords are stored only as salted hashes produced by a slow, purpose-built password-hashing function (Argon2id where available, otherwise PBKDF2 with a high iteration count). Plaintext passwords are never written to disk or logged.
- Sessions use long random tokens with a fixed expiry, and every session is invalidated when you change your password.
- Transport to the production Service is encrypted with HTTPS.
- Application defenses include a Content Security Policy on every page, restrictive CORS rules, security response headers, request rate limiting, request-size caps, and server-side validation of everything a client sends.
- Access to production systems is limited to the people who need it to operate the Service.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by applicable law. If you believe you have found a security vulnerability, please report it to support@coreshape3d.com rather than disclosing it publicly.
11. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access — ask what personal information we hold about you and get a copy of it;
- Correction — have inaccurate or incomplete information fixed;
- Deletion — ask us to erase your personal information;
- Portability — receive certain information in a structured, machine-readable format, or have it sent to another provider;
- Restriction and objection — ask us to pause certain processing, or object to processing based on our legitimate interests;
- Withdraw consent — where we rely on consent, withdraw it at any time;
- Non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service for exercising these rights.
Exercising them. You can update your name, change your password, and permanently delete your account and its projects yourself from your account settings — no request needed. For anything else, or if you have already closed your account, email legal@coreshape3d.com.
We will respond within the period required by applicable law (generally one month under the GDPR and 45 days under US state privacy laws), and we may need to verify your identity before acting, usually by confirming control of your account's email address. An authorized agent may submit a request on your behalf with proof of authorization.
Complaints. If you are in the EEA or UK and believe we have handled your information improperly, you may lodge a complaint with your local data-protection supervisory authority. We would appreciate the chance to address your concern first.
12. Children's Privacy
The Service is not directed to children. Consistent with our Terms of Use, you must be at least 16 years old to create a CoreShape account, and we do not knowingly collect personal information from anyone under that age.
If you are a parent or guardian and believe your child has given us personal information, contact us at legal@coreshape3d.com and we will delete the account and its data promptly.
13. Do Not Track and Global Privacy Control
Because we do not track users across websites or over time, and do not sell or share personal information for advertising, there is no cross-site tracking for a Do Not Track or Global Privacy Control signal to switch off. We honor these signals by default in the only way that is meaningful: we never engage in the behavior they are designed to prevent.
14. Changes to This Policy
We may update this Privacy Policy as the Service changes or as the law requires. When we do, we will revise the Effective Date at the top of this page.
If a change materially affects how we handle your personal information — for example, collecting a new category of data, using it for a new purpose, or sharing it with a new kind of recipient — we will give you advance notice by email or through a prominent notice in the Service before the change takes effect. Your continued use of the Service after that date means you accept the updated policy.
15. Contact Us
For any question about this policy or about how we handle your information — our Contact page lists the right address for each kind of enquiry:
- Data controller: CoreShape 3D CAD Solutions
- Privacy enquiries: legal@coreshape3d.com
- Security reports: support@coreshape3d.com
- Website: coreshape3d.com
TM