Privacy policy
Effective date: 2026-08-10
Who operates OpenFilament
Operator: OpenFilament by Raymond Davelaar
Privacy contact: info@openfilament.nl
Hosting: Self-hosted VPS (IONOS), application and SQLite on-server (EU (Germany))
What we process
- Account data (email, username, display name, password hash) when you register.
- Authentication sessions (hashed API tokens).
- Cloud My Spools and related private notes when you sync.
- Local My Spools stored only in your browser IndexedDB until you sync.
- Public community contributions (profiles/calibrations) you choose to publish.
- QR / RFID identifiers you attach to spools.
- Consent preferences (categories, version, timestamp, locale).
- Server and security logs (see retention policy).
- Optional Google Analytics 4 after analytics consent only.
Legal bases
- Contract / requested service — accounts, cloud My Spools, exports.
- Legitimate interests — security, abuse prevention, service integrity.
- Consent — analytics cookies/storage; withdraw anytime via Cookie settings.
- Legal obligation — where applicable for security incident records.
Local-only My Spools
Local My Spools stay on your device. Clearing site data, losing the device, or switching browsers can remove them. We do not upload local spools when you merely sign in.
Cloud My Spools
Optional sync requires an account and an explicit confirmation step. Ownership checks apply to every read and write. Private notes, storage locations and identities are not exposed via public QR resolution.
Your rights
You may request access, correction, deletion, restriction, portability and objection, and withdraw consent. Use Account → Export / Delete, Cookie settings, or email info@openfilament.nl. You may complain to Autoriteit Persoonsgegevens (NL)(https://www.autoriteitpersoonsgegevens.nl/).
International transfers
If analytics is enabled, Google may process data outside the EEA under its own terms and safeguards. Hosting region: EU (Germany). Exact processor agreements must be confirmed by the operator — see docs/SUBPROCESSORS.md.
Retention
See docs/DATA_RETENTION.md. Soft-deleted spools are purged on a schedule. Backups may retain deleted data until backup expiry — not instantaneous.
Policy changes
Material changes update the consent version and may re-prompt for consent.