LEGAL · PRIVACY

Privacy Policy

Effective: January 1, 2026 GDPR Compliant Last updated: January 2026
Overview
PRESTILON ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have over your data. By using prestilon.com and our software, you agree to the practices described here.
01
Who We Are

PRESTILON is an AI-powered 3D printer fleet monitoring platform. We provide real-time diagnostics, anomaly detection, and predictive maintenance tools for professional print operations.

Our platform operates via prestilon.com and a locally installed backend application. We are the data controller for any personal information processed through our services.

02
Data We Collect

We collect only what is necessary to provide and improve our service:

Account Data
  • Email address (used for authentication and communication)
  • Display name (optional, set by you)
  • Password (hashed and salted — never stored in plain text)
  • Account creation date and subscription status
Device & Hardware Data
  • Hardware ID (HWID) of machines running the PRESTILON backend
  • Machine label and registration timestamp
  • Last-seen timestamp for active devices
Usage & Technical Data
  • Browser type and version (for compatibility)
  • IP address (processed by Cloudflare, not stored by us)
  • Authentication events (sign-in, sign-out, password reset)
Crash Reports (Diagnostic Data)
If the PRESTILON backend encounters a critical error, a minimal crash report may be generated locally. These reports contain only: error type, software version, and your HWID. They are never automatically transmitted — upload is always explicit and optional. If you choose to send a report, the HWID constitutes personal data and is processed under this policy.

We do not collect printer telemetry data on our servers. All print job metrics, sensor readings, and AI diagnostics are processed locally on your machine and stored in a local database.

03
How We Use Your Data

Your data is used solely to operate and improve PRESTILON:

  • Authenticating your identity and managing your account session
  • Verifying your license and printer binding limits
  • Sending transactional emails (password reset, email confirmation)
  • Providing customer support when you contact us
  • Detecting and preventing unauthorized account access
  • Improving platform reliability and user experience

We do not use your data for advertising, profiling, or sale to third parties.

04
Data Storage & Location

Account data (email, name, subscription) is stored securely via Supabase — a GDPR-compliant cloud database provider. Data is stored on servers located within the European Union.

Printer telemetry, AI inference results, and local sensor data are stored exclusively on your own machine in a local SQLite/DuckDB database. This data never leaves your network unless you explicitly export it.

05
Third-Party Services

We use a minimal, carefully selected set of third-party services:

  • Supabase — Authentication and account database (GDPR compliant, EU servers)
  • Resend — Transactional email delivery (password reset, verification emails)
  • Cloudflare — DNS, DDoS protection, and CDN (processes IP address in transit)

Each of these providers is contractually bound to process your data only as instructed by us and in compliance with applicable data protection laws. For a full list of sub-processors, see Section 12.

06
Your Rights

Under GDPR and other applicable privacy regulations, you have the following rights:

Access
Request a copy of your personal data
Rectification
Correct inaccurate data we hold
Erasure
Request deletion of your account and data
Portability
Export your data in a standard format
Objection
Object to processing of your data
Restriction
Request limited processing of your data

To exercise any of these rights, contact us at the address listed in Section 12. We will respond within 30 days.

07
Data Retention

We retain your personal data for as long as your account is active. Upon account deletion, your data is permanently removed from our systems within 30 days, except where retention is required by law.

Authentication logs (sign-in events) are retained for a maximum of 90 days for security purposes, then permanently deleted.

08
Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted using TLS 1.3
  • Passwords are hashed using bcrypt — never stored in plain text
  • Authentication uses short-lived JWT tokens with secure refresh handling
  • Database access is restricted to authorised services only
  • Regular security reviews are conducted on our infrastructure

In the event of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours as required by GDPR.

09
Cookies

We use only strictly necessary (functional) cookies required to operate the platform. We do not use any third-party tracking cookies, advertising cookies, or analytics cookies of any kind. No cookie consent banner is required because we only use cookies that are technically essential to provide the service you requested.

Cookies & Storage we use
  • Session token — Authenticates your session with Supabase. Expires on sign-out or after 1 hour of inactivity.
  • Refresh token — Silently renews your session so you stay signed in. Stored in localStorage, not a cookie. Cleared on sign-out.

You can remove all session data at any time by signing out, or by clearing your browser's localStorage and cookies for prestilon.com.

10
AI & Automated Decision-Making

PRESTILON's AI engine operates entirely on your local machine. Under GDPR Article 22, you have the right to know whether automated decision-making is applied to you. We are transparent about this:

How our AI works
Anomaly detection, failure prediction, and print diagnostics are processed locally using on-device inference. No print data, sensor readings, or AI results are sent to PRESTILON servers.
Automated Actions (GDPR Art. 22 disclosure)
The PRESTILON backend may automatically pause a print job when the AI detects a high-confidence failure condition (e.g. layer delamination, extruder clog). This action is:
  • Configured and enabled by you in the backend settings
  • Fully reversible — you can resume or override at any time
  • Based on local sensor data only — not on your personal data
We do not perform automated profiling of users, nor do we make decisions with legal or similarly significant effects based on personal data.
11
Payment Processing

All subscription payments are processed by our third-party payment provider. PRESTILON does not store, see, or have access to your full card number, CVV, or banking credentials at any point.

Data handled by payment processor
  • Cardholder name and billing address
  • Last 4 digits of card number (for your reference only)
  • Card expiry date
  • Payment amount, currency, and transaction timestamp

Our payment provider is PCI-DSS Level 1 certified. The data they collect is governed by their own privacy policy. We receive only a payment confirmation token and subscription status — nothing more.

Invoices sent to your email will contain your billing name, address, and subscription details. These are stored for 7 years as required by financial regulations.

12
Sub-processors

The following third-party sub-processors may handle personal data on our behalf. Each has entered into a Data Processing Agreement (DPA) with us and is bound to GDPR-compliant data handling standards.

Supabase, Inc.
Purpose: Authentication, account data, license management
Data: Email, display name, HWID, subscription status
Location: European Union
Resend
Purpose: Transactional email delivery
Data: Email address, email content (reset links, confirmations)
Location: United States (Standard Contractual Clauses apply)
Cloudflare, Inc.
Purpose: DNS, CDN, DDoS protection
Data: IP address (in transit only, not logged by us)
Location: Global (EU nodes used where possible)
Payment Processor (TBD)
Purpose: Subscription billing and payment processing
Data: Billing name, address, payment token
Location: To be confirmed on payment integration

We will update this list within 30 days of adding any new sub-processor and notify active users by email of any significant changes.

13
Children's Privacy

PRESTILON is designed for professional and commercial use. We do not knowingly collect personal data from individuals under the age of 16 years. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it promptly.

14
Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page.

Continued use of PRESTILON after any changes constitutes your acceptance of the updated policy.

15
Contact & Data Requests

For any privacy-related questions, data subject requests (access, erasure, portability), or concerns, please contact our Data Privacy contact directly. We will respond within 30 days as required by GDPR.

Data Privacy — Direct Email
General Support
Website
Home Docs Community Pricing Support Sign In →
🧠 AI Assistant AI