← Back to Cadre

Privacy

Effective 28 September 2026 · Cadre3D Inc.

Cadre is a place to design 3D parts and get feedback on them. This page explains exactly what we collect, why, and who can see it — without the legalese.

The short version

  • What you make stays on your device until you sign in, share, or ask for a review.
  • When you're signed in, we autosave your open project to your private workspace so a closed tab never loses your work.
  • An AI review sends measurements and your design's parameters — not your actual model file — to Anthropic to generate it.
  • We never sell your data, never show ads, and use no third-party trackers.
  • Your designs are yours. Export them anytime, and ask us to delete your account whenever you like.

What we collect, and why

Your account. To sign you in and keep your work with you, we store your email address, how you signed in (an emailed link, or Google), and a display name and color you can change. Your display name and color are visible to people you collaborate with.

Your designs. What you make lives in your browser first. It reaches us only when you sign in (we autosave your open project to your private cloud workspace so you don't lose work), run an AI review, or share a link. Files you import or export — STL, STEP, OBJ, 3MF, GLB — are read and written in your browser and are never uploaded.

AI review. When a review runs, we send your design to Anthropic (the makers of Claude) to generate it — but not your actual model file. We send measurements our software computes (wall thickness, overhang angles, whether the part is watertight), your design's parameters (the shapes and dimensions that make up the part), and the names in your project — the name you gave each part and, for a file you imported, its filename. We don't send your name, email, or account. Anthropic uses it only to return the review and, under their commercial terms, does not use it to train their models.

A review runs when you ask for it, with one exception: if you were offered a review before signing in, signing in within fifteen minutes runs that one review on the part you had open, so you land on the result you came for. It runs once and never repeats on a reload. If you would rather it did not run, sign in from a page that has not offered you a review, or wait out the fifteen minutes.

Improving the reviews. When you rate a flag or accept a suggested fix, we keep the outcome — which kind of issue was flagged, what you did with it, and whether our software confirmed the fix worked. We use these results to measure how good the reviews are and to choose the best model over time. These records are structured signal (the issue type and the result), never a copy of your design — and this is measurement, not AI training.

Collaboration. Sharing is asynchronous: someone opens your link, works on their own copy, and sends a suggestion back. There is no live shared session today, so nothing of yours streams to anyone as you work. What we keep is the same as any saved project: the current version, plus any suggestions someone submits. Sharing isn't end-to-end encrypted, which means our server holds what you share. We never sell or mine it.

How Cadre gets used. To improve the product, we record how Cadre itself gets used — and you can turn it off in one click with the toggle at the top of this page. Here is exactly what a usage record contains:

  • Which features get used — a named event when you use a feature (a shape added, a file imported, an AI review run, and the like) with a timestamp, the feature's category, and a little detail about the action itself, such as which demo scene loaded or which kind of page started the visit (the editor or a tools page). Never your model's geometry.
  • A per-visit session record — a random session id minted fresh for each page load (it is not a cross-visit identifier), when the visit started and ended, per-feature counters for that visit, whether the page load counts as a return visit (see the next point), and whether the visit looks automated, so bots don't pollute our numbers.
  • How often you come back, as ranges — your browser keeps three small values on your own device: the date it first loaded Cadre, the time of its previous page load, and how many page loads it has made. From those we send the page-load count and two ranges rather than times — how long ago that first load was (same day, 1 day, 2–6 days, 7–29 days, or 30+ days), and how long since the previous page load (under 30 minutes, 30 minutes–6 hours, 6–24 hours, 1–7 days, 7–30 days, 30+ days, or that there was no previous load, or that we don't know when it was). A page load counts as a return visit only when that gap is at least six hours, so a refresh, a move between pages, or the round-trip through Google sign-in isn't one. We never send the dates themselves and never a lasting visitor id: a timestamp accurate to the millisecond would work as a permanent identifier for your browser, and we deliberately don't ship one. While usage stats are off these values stop being updated, so turning the toggle off stops this the same way it stops everything else in this list. If your browser blocks local storage, these values are simply absent and everything else works the same.
  • How you found us — how you arrived: the referring site's domain and any campaign tag in the link (?src=...), so we know which channel works — never the full URL of the page you came from.
  • Errors — when something crashes, the error message, the page it happened on, and your browser and operating system (the technical browser identification string), as described under "Diagnostics and feedback" below. Error reports are part of the same collection and stop with it when you opt out.

Signed in, these records are tied to your account; signed out, only to that visit's temporary session id. Your name and email are never part of a usage record, and none of it ever goes to an outside advertising or analytics company — the records land in our own database, readable only by the app's owner.

Outside the EU/UK this is on by default, and we show a small one-time notice saying so. Within the EU/UK we ask first and record nothing until you agree; if you decline, we record only that someone declined — nothing else, then or ever. Turning usage stats off (the toggle at the top of this page) stops all collection immediately in that browser; the choice is stored on your device, not with us.

Diagnostics and feedback. When something crashes, we log the error, the page it happened on, and your browser type so we can fix it. When you send feedback, we keep your message and anything you include. To stop abuse of the AI service, we keep a one-way hashed form of your IP address — never the address itself.

Where your data goes

A short list of the companies that help us run Cadre.

Companies that store or process your data:

ProviderWhenWhat it handles
SupabaseAlwaysOur database and sign-in. Stores your account, saved projects, and powers live collaboration.
AnthropicOnly on AI reviewReceives your design's measurements and parameters to generate a review. Not your name, email, or model file.
GoogleOnly if you use itIf you choose "Sign in with Google," Google confirms your identity and shares your email and name. Use an emailed link instead and Google isn't involved.

Infrastructure we run on. Like any website, Cadre is served through a hosting provider (Netlify), which sees standard request logs such as your IP address, and uses Google Fonts to display type. These handle traffic, not your account or designs.

What we never do. We never sell your data or share it for advertising. No third-party trackers or ad pixels. We never use your designs to train AI, and neither does Anthropic under their commercial terms.

How long we keep it

WhatHow long
Your projects and designsUntil you delete them
AI reviewsKept with your account until you delete them
Usage analyticsUp to 12 months, then auto-deleted
Crash and error logs90 days
Security logs (hashed IP)7 days

Your rights and choices

  • Take your work with you. Export any design in open formats (STL, STEP, OBJ, 3MF, GLB) right from the editor.
  • Delete your account. Ask us to delete your account and everything tied to it, and we will.
  • Choose how you sign in. Use an emailed link and skip Google entirely.
  • Control the AI. A review runs when you ask for it. The one exception is the review you were offered before signing in, described under "What we collect": it runs once, on the part you had open, and only within fifteen minutes of being offered.
  • Opt out of usage stats. One click: the toggle at the top of this page stops all collection immediately in that browser. Want what's already tied to your account cleared too? Email us.
  • See what we hold. Ask for a copy of the personal data associated with your account.

The fine print

Who we are. Cadre3D Inc. is responsible for the data described here.

Where it's handled. Your data is processed on servers in the United States by the providers listed above.

Children. Cadre isn't intended for children under 16, and we don't knowingly collect their data.

Changes. If we change this policy, we'll update the date at the top and, for anything significant, tell you before it takes effect.

Cookies. We use a little local storage to keep you signed in, remember your preferences, and hold the first-load date and page-load count described under "What we collect." We don't set third-party or advertising cookies.

Questions, or want something deleted?

Email spencer@cadre3d.com and a real person will answer — a copy of your data, a deletion, or a question about anything above.