Last updated: 22 September 2026
Privacy Policy
Introduction and our commitment to privacy
Slice Shelf (“Slice Shelf”, “we”, “us”, or “our”) is a desktop and web library for organizing and previewing 3D print files. The product is offered by Rooteny. This Privacy Policy explains, in plain language, how we handle personal data when you use the Slice Shelf desktop application (Electron, for macOS, Windows, and Linux), the web app at https://app.slice-shelf.com, the website at https://slice-shelf.com, and related account, licensing, and support services.
Slice Shelf is offline-first. Your local 3D print files stay on your device unless you choose an optional cloud connection. We designed the product so that organizing and previewing a library does not require uploading those files to us.
We take that trust seriously and handle personal data in line with the Brazilian General Data Protection Law (Lei nº 13.709/2018, “LGPD”) and, where they apply to you, the EU and UK General Data Protection Regulation (“GDPR”) and other applicable privacy laws. For the rules that govern use of the product, subscriptions, and acceptable conduct, please also read our Terms of Service.
Legal bases and purposes
We process personal data for specific purposes and only where a lawful basis applies. Under the LGPD, processing follows the principles in article 6, including purpose limitation, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability. Where the GDPR applies, we rely on the corresponding lawful bases in that regulation. The bases we use include:
Contract
To create and maintain your account, authenticate you, provide the Free and Pro plans you choose, verify a license, process a subscription, and deliver the features you ask the desktop or web app to perform.
Consent
When we ask for a freely given, specific, and informed choice. Connecting Google Drive is optional and depends on the permissions you grant in Google’s OAuth screen. You may withdraw consent at any time, including by unlinking Drive in the app. Withdrawal does not affect processing that was already lawful.
Legitimate interests
Where the interest is compatible with your reasonable expectations and is balanced against your rights. Examples include securing accounts, preventing fraud and abuse, keeping the service reliable, and understanding aggregate product usage that does not identify you. You may object where the law gives you that right.
Legal obligation
When we must keep or disclose information to meet tax, accounting, consumer-protection, or other legal duties, or to respond to a valid request from a competent authority.
Data we collect
What we process depends on how you use Slice Shelf. Local library use, an account, a paid plan, and an optional cloud connection each involve different data.
Account and profile
Email address, password, and an optional display name. We store the password only as a cryptographic hash. We never store the password you type. If you sign in on the website or in the app, we keep a session token on that device so you can stay signed in.
License, plan, and device context
Plan (Free or Pro), subscription status, and the information needed to confirm that a license is valid. A Pro license is intended for a limited number of your own devices. When the app checks a license, we may process technical context such as app version, operating system, and a device identifier associated with your account.
Optional material records
If you save print-material details in your account (for example brand, type, color, price, currency, and notes used for cost estimates), we store those records with your account so they are available when you sign in.
Payments
Pro is billed as a subscription through Stripe. Stripe collects payment-card and billing details under its own terms. We receive and store limited billing records such as a Stripe customer identifier, subscription identifier, price, plan, status, billing period, currency, and the amount of a completed charge. We do not store your full card number or card security code.
Technical and connection data
IP address, date and time of a request, browser or app version, language, and diagnostic events needed to operate, secure, and troubleshoot the service. These logs are about the account and the connection, not the contents of your local 3D files.
Support messages
If you email us, we keep the message, any attachments you include, and the metadata needed to reply and resolve the issue.
Sensitive data. We do not ask for special-category or sensitive personal data (such as health, biometric, or government-identification data). Please do not send that kind of information to support unless we specifically request it and tell you why.
Local files and the offline-first library
By default, the files you organize in Slice Shelf remain on your device. That includes 3D print and related project files (such as STL, OBJ, 3MF, FBX, glTF/GLB, and slicer formats), previews and thumbnails generated on the device, notes, tags, and local library settings.
We do not upload that local library to Slice Shelf servers as part of ordinary use. Previews, diagnostics, and cost estimates run in the app. Uninstalling Slice Shelf or signing out does not delete those files from your disk. You control them with your own backups and file tools.
The desktop app does contact our servers for account sign-in, license checks, subscription management, and, only if you turn it on, an optional cloud connection. Those calls are separate from the local library.
Google Drive and Limited Use
Pro users may optionally connect Google Drive with OAuth. The connection is off unless you start it and approve it on Google’s consent screen. You can unlink Drive at any time in Slice Shelf settings. Unlinking deletes the stored connection from our systems. It does not delete files from your Google Drive.
What the Drive connection can see
We request the Google Drive scope drive.file (https://www.googleapis.com/auth/drive.file), together with basic account scopes for email and profile so we can show which Google account is connected. The drive.file scope is limited to files you create or open with Slice Shelf. It does not grant Slice Shelf access to the rest of your Google Drive.
In practice, Slice Shelf uses that access to create and maintain an app workspace (a Slice Shelf folder and the files the app writes there), and to read, update, or remove files you choose to sync or open with the app. File contents are transferred between the app on your device and Google. We do not copy your Drive file contents into a Slice Shelf content library on our servers.
We do store, on our servers, the connection record needed to keep the link working: the Google account email, the granted scopes, an optional root-folder identifier, and a refresh token. The refresh token is encrypted at rest. We use it only to obtain short-lived access tokens so the app can perform the Drive actions you requested.
Google API Services User Data Policy
Slice Shelf’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For Google user data, Limited Use means in particular that:
- We use Google user data only to provide or improve user-facing features that are prominent in Slice Shelf, such as showing, organizing, previewing, and syncing the files you open or create with the app.
- We do not sell Google user data.
- We do not use or transfer Google user data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising.
- We do not allow humans to read Google user data unless you give us affirmative consent, it is necessary for security (such as investigating abuse), it is necessary to comply with applicable law, or the data is aggregated and used for internal operations in line with privacy law.
- We do not transfer Google user data to others except to provide or improve those user-facing features, for security, to comply with law, or as part of a merger or sale of the business with notice and, where required, your consent.
Other optional cloud storage
Slice Shelf may also offer an optional connection to Microsoft OneDrive, limited to the app’s own folder rather than your entire OneDrive. If you connect it, we store an encrypted refresh token and the account email for that connection, and the app reads and writes files in that app folder on your behalf. Microsoft’s terms and privacy policy govern Microsoft’s processing. You can unlink the connection at any time.
How we use data
Purposes
- Create, authenticate, and secure your account.
- Provide the desktop and web library, including license checks for Free and Pro.
- Process subscriptions, receipts, and billing status through Stripe.
- Connect and operate optional Google Drive or OneDrive sync when you ask for it, within the scopes described above.
- Store optional material and account settings you choose to save.
- Keep the service reliable, diagnose errors, and protect against fraud, abuse, and unauthorized access.
- Send transactional messages about your account, license, or security. We do not send marketing email unless the law allows it and, where required, you have agreed.
- Comply with law and respond to valid legal process.
- Establish, exercise, or defend legal claims.
- Produce aggregate statistics that do not identify you.
We do not sell personal data. We do not use your local library, your Drive files, or your account data to train public machine-learning models or to build advertising profiles.
When we share data
We share personal data only as needed for the purposes in this policy, and only with parties who have a defined role.
Service providers
Vendors that host or support the service under contracts that require confidentiality and data protection. They include Amazon Web Services (AWS) for hosting and infrastructure, Stripe for payments, and Google when you connect Drive. If you connect OneDrive, Microsoft processes that connection under its own terms. Providers may process data only on our instructions or, for payment and identity flows, as independent controllers of their own services.
Authorities
When a law, regulation, or binding order requires it, or when disclosure is necessary to protect the rights, safety, and integrity of users, the public, or Slice Shelf.
Business transfers
If Rooteny or Slice Shelf is involved in a merger, acquisition, or sale of assets, personal data may transfer to the successor, which must protect it consistently with this policy and applicable law. Google user data remains subject to the Limited Use limits above, including any consent Google’s policy requires.
International transfers
Slice Shelf is hosted on Amazon Web Services. Production infrastructure runs in the United States (AWS region us-east-1). Stripe, Google, and Microsoft also process data in the United States and, depending on the service, in other countries. If you use Slice Shelf from Brazil, the European Economic Area, the United Kingdom, or anywhere else, your account, billing, and connection data may be transferred to and stored in the United States or other countries that may not provide the same statutory protections as your home country.
When we transfer personal data internationally, we use measures designed to keep protection consistent with the LGPD and, where it applies, the GDPR. Those measures include contracts with our providers, encryption in transit, and encryption of cloud refresh tokens at rest. Where standard contractual clauses or another recognized transfer tool is required, we use it.
By creating an account or continuing to use Slice Shelf after this notice, you acknowledge that you have been informed of these transfers. You may still exercise the rights in “Your rights”, including asking where your data is processed.
Tracking technologies and usage data
Sessions, logs, and local storage
The website and web app store an authentication token in browser local storage when you sign in, so the session can persist on that browser. The desktop app stores your session and your local library on the device. We do not use third-party advertising cookies, and we do not sell browsing data to ad networks.
Our servers record technical logs (such as IP address, time, and the route requested) to operate, secure, and debug the service. Those logs are not a record of the contents of your 3D files. If we later add optional analytics or similar tools on the website, we will describe them here and, where the law requires a choice, ask before they run.
Security
How we protect data
We use reasonable technical and organizational measures suited to the data we hold. Passwords are hashed. Sessions use authenticated API access over encrypted connections (HTTPS). Google and Microsoft refresh tokens are encrypted before they are stored. Access to production systems is limited to people and services that need it to operate Slice Shelf.
No method of transmission or storage is perfectly secure. If we become aware of an incident that creates a relevant risk to people whose data we hold, we will notify affected users and the competent authorities when the law requires it, and we will describe the steps we are taking to respond.
Retention
How long we keep data
- Account, license, material, and cloud-connection records are kept while your account is active and for a limited period afterward so we can complete deletion, resolve disputes, and meet legal duties.
- Cloud refresh tokens are deleted when you unlink the provider or when we delete the account connection.
- Billing records may be kept for the period tax, accounting, and consumer laws require, even after the account is closed. Stripe keeps payment data under its own retention rules.
- Security logs are kept for a limited operational period and then deleted or aggregated.
- Local files, previews, notes, and tags on your device are not stored by us and are not deleted by account closure. You remove those yourself.
When the retention period ends, we delete or irreversibly anonymize the data, unless the law requires us to keep it.
Your rights
Depending on where you live, you may have the rights below. Under the LGPD (article 18) they include confirmation and access, correction, anonymization, blocking or deletion of unnecessary or unlawful data, portability, information about sharing, information about consent and the consequences of refusing it, and withdrawal of consent. Where the GDPR or a similar law applies, you may also have the right to object, to restrict processing, and to lodge a complaint with a supervisory authority.
Access and confirmation
Ask whether we process your personal data and receive a copy of it.
Correction
Ask us to correct incomplete, inaccurate, or outdated account data. You can also update your name in account settings.
Deletion
Ask us to delete personal data we no longer need, or data processed on the basis of consent, subject to records we must keep by law. Unlinking Google Drive or OneDrive removes that connection.
Portability and information about sharing
Ask for a portable copy of account data you provided, and for information about the private parties and public bodies with whom we share it, except where a trade secret applies.
Objection, restriction, and automated decisions
Object to processing based on legitimate interests where the law allows it, and ask for human review of a decision based solely on automated processing if one produces a legal or similarly significant effect. License checks and fraud controls may be automated; they do not make credit or lending decisions.
We will respond within the time the applicable law requires. We may ask for information to confirm that the request comes from you. You may also file a complaint with the Brazilian National Data Protection Authority (ANPD) at gov.br/anpd, or with your local supervisory authority.
Contact
To exercise your rights, ask a question about this policy, or raise a concern about personal data, email us. Please use the address on your account so we can identify the right record.
Email: contact@slice-shelf.com
Website: https://slice-shelf.com
Web app: https://app.slice-shelf.com
Operator: Rooteny
Changes to this policy
We may update this policy to reflect changes in the product, our providers, or the law. The date at the top of this page is the date of the current version. If a change is material, we will give notice by a reasonable means, such as a notice in the app or on the website, or by email when we have your address.
Where a change relies on consent, we will ask for that consent. Otherwise, continuing to use Slice Shelf after the updated policy is posted means you have been informed of the change, to the extent the law allows. If you do not agree, you may stop using the service and ask us to close your account.
