PRESTILON is an AI-powered 3D printer fleet monitoring platform. We provide real-time diagnostics, anomaly detection, and predictive maintenance tools for professional print operations.
Our platform operates via prestilon.com and a locally installed backend application. We are the data controller for any personal information processed through our services.
We collect only what is necessary to provide and improve our service:
- Email address (used for authentication and communication)
- Display name (optional, set by you)
- Password (hashed and salted — never stored in plain text)
- Account creation date and subscription status
- Hardware ID (HWID) of machines running the PRESTILON backend
- Machine label and registration timestamp
- Last-seen timestamp for active devices
- Browser type and version (for compatibility)
- IP address (processed by Cloudflare, not stored by us)
- Authentication events (sign-in, sign-out, password reset)
We do not collect printer telemetry data on our servers. All print job metrics, sensor readings, and AI diagnostics are processed locally on your machine and stored in a local database.
Your data is used solely to operate and improve PRESTILON:
- Authenticating your identity and managing your account session
- Verifying your license and printer binding limits
- Sending transactional emails (password reset, email confirmation)
- Providing customer support when you contact us
- Detecting and preventing unauthorized account access
- Improving platform reliability and user experience
We do not use your data for advertising, profiling, or sale to third parties.
Account data (email, name, subscription) is stored securely via Supabase — a GDPR-compliant cloud database provider. Data is stored on servers located within the European Union.
Printer telemetry, AI inference results, and local sensor data are stored exclusively on your own machine in a local SQLite/DuckDB database. This data never leaves your network unless you explicitly export it.
We use a minimal, carefully selected set of third-party services:
- Supabase — Authentication and account database (GDPR compliant, EU servers)
- Resend — Transactional email delivery (password reset, verification emails)
- Cloudflare — DNS, DDoS protection, and CDN (processes IP address in transit)
Each of these providers is contractually bound to process your data only as instructed by us and in compliance with applicable data protection laws. For a full list of sub-processors, see Section 12.
Under GDPR and other applicable privacy regulations, you have the following rights:
To exercise any of these rights, contact us at the address listed in Section 12. We will respond within 30 days.
We retain your personal data for as long as your account is active. Upon account deletion, your data is permanently removed from our systems within 30 days, except where retention is required by law.
Authentication logs (sign-in events) are retained for a maximum of 90 days for security purposes, then permanently deleted.
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.3
- Passwords are hashed using bcrypt — never stored in plain text
- Authentication uses short-lived JWT tokens with secure refresh handling
- Database access is restricted to authorised services only
- Regular security reviews are conducted on our infrastructure
In the event of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours as required by GDPR.
We use only strictly necessary (functional) cookies required to operate the platform. We do not use any third-party tracking cookies, advertising cookies, or analytics cookies of any kind. No cookie consent banner is required because we only use cookies that are technically essential to provide the service you requested.
- Session token — Authenticates your session with Supabase. Expires on sign-out or after 1 hour of inactivity.
- Refresh token — Silently renews your session so you stay signed in. Stored in
localStorage, not a cookie. Cleared on sign-out.
You can remove all session data at any time by signing out, or by clearing your browser's localStorage and cookies for prestilon.com.
PRESTILON's AI engine operates entirely on your local machine. Under GDPR Article 22, you have the right to know whether automated decision-making is applied to you. We are transparent about this:
- Configured and enabled by you in the backend settings
- Fully reversible — you can resume or override at any time
- Based on local sensor data only — not on your personal data
All subscription payments are processed by our third-party payment provider. PRESTILON does not store, see, or have access to your full card number, CVV, or banking credentials at any point.
- Cardholder name and billing address
- Last 4 digits of card number (for your reference only)
- Card expiry date
- Payment amount, currency, and transaction timestamp
Our payment provider is PCI-DSS Level 1 certified. The data they collect is governed by their own privacy policy. We receive only a payment confirmation token and subscription status — nothing more.
Invoices sent to your email will contain your billing name, address, and subscription details. These are stored for 7 years as required by financial regulations.
The following third-party sub-processors may handle personal data on our behalf. Each has entered into a Data Processing Agreement (DPA) with us and is bound to GDPR-compliant data handling standards.
Data: Email, display name, HWID, subscription status
Location: European Union
Data: Email address, email content (reset links, confirmations)
Location: United States (Standard Contractual Clauses apply)
Data: IP address (in transit only, not logged by us)
Location: Global (EU nodes used where possible)
Data: Billing name, address, payment token
Location: To be confirmed on payment integration
We will update this list within 30 days of adding any new sub-processor and notify active users by email of any significant changes.
PRESTILON is designed for professional and commercial use. We do not knowingly collect personal data from individuals under the age of 16 years. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page.
Continued use of PRESTILON after any changes constitutes your acceptance of the updated policy.
For any privacy-related questions, data subject requests (access, erasure, portability), or concerns, please contact our Data Privacy contact directly. We will respond within 30 days as required by GDPR.