🧊 3D Viewer

Privacy Policy

Last updated: September 2026

This policy covers the web version at 3dviewer.doriangrey.info. The iOS app has its own policy: /privacy.html.

Controller

Operator: private individual, non-commercial test site, 1016 Vienna, Austria. Email: cardrevolution@gmail.com. More information: /en/imprint/.

Your 3D models are never uploaded

Loading, viewing, the print check, repair and export all run entirely in your browser. There is no server that receives model files, and no cloud processing. File names, file contents and check results never leave your device.

This is not just a promise, it is tested: the automated test β€œno-upload.spec.ts” loads a 5 MB model on every release, runs the print check, the repair and the STL and AR exports, and fails the release if a single network request leaves this page carrying model data. On top of that, this site's Content Security Policy limits outgoing connections to its own domain (connect-src 'self', plus data:/blob: for locally created files and β€” only once a payment route is active β€” RevenueCat's payment API); none of them ever receives model data, and the browser itself would block it.

Local storage in your browser

To make the site usable, it remembers a few settings in your browser's local storage (localStorage). This data stays on your device, is never transmitted, and can be cleared at any time through your browser settings:

No cookies

This site sets no cookies β€” neither its own nor third-party. There is therefore no cookie banner either. The local storage above is technically not a cookie and is never sent to the server.

An in-browser database (IndexedDB) is not currently used.

Server log files

When you request the site, our web server processes the technically necessary connection data: timestamp, requested address, status code, bytes transferred, browser/device identifier (user agent), referring page and IP address.

The IP address is already truncated at the point of logging: IPv4 to its first three blocks (/24), IPv6 to its first four groups (/64). A full IP address is not stored in the access log.

Purpose is safe and stable operation (Art. 6(1)(f) GDPR β€” legitimate interest in operating the site and defending against attacks). Logs are rotated daily and automatically deleted after 14 days.

Exception: on a server error, a technical error log may additionally contain the full IP address. That log is also deleted after 14 days.

Cookieless, third-party-free analytics

No third-party analytics services are embedded β€” no Google Analytics, no tag manager, no pixels, no ad networks, no external fonts or CDNs.

Traffic measurement is done exclusively through our own cookieless counter on the same server: the browser calls the address /v for this. Only coarse, non-personal information is transmitted β€” which event occurred (e.g. page view, example loaded, print check run), the language, whether the view was mobile or desktop, the referring domain, the app version and rounded load times.

Never transmitted: file names, model data, check results, email addresses or recognisable identifiers. The request is logged as described above, with a truncated IP address and the same retention period. The legal basis is Art. 6(1)(f) GDPR.

No accounts, no newsletter

There is no registration, no sign-in and no newsletter. No payment method is active; no payment or billing data is processed.

Contacting us by email

If you write to us β€” for example to be notified at launch, or to report a bug β€” we process your email address and the content of your message solely to handle your request (Art. 6(1)(f) GDPR) and delete it once it is no longer needed.

The mailbox is operated via Google Mail (Google Ireland Limited, Dublin). If you would rather avoid that, please use a different contact channel.

Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). An informal email to cardrevolution@gmail.com is enough.

Note: since no accounts are kept and log data is only stored truncated and for 14 days, there is usually no data on file that can be attributed to you.

You may also lodge a complaint with the supervisory authority: Austrian Data Protection Authority (DatenschutzbehΓΆrde), Barichgasse 40–42, 1030 Vienna, Austria β€” www.dsb.gv.at.