Privacy
Last updated 6 October 2026
You can use every builder on Slatfinity without an account. You sign in only to download files. This page lists what we keep, why, and who else handles it.
What we keep when you sign in
- Your email address, so you can sign in and so we can reach you about your account.
- If you sign in with Google or GitHub: your name and your profile picture's web address from them, your account id there, and the tokens they give us (an access token, and a refresh token and an ID token when they send them). We don't use the picture or the tokens for anything after you sign in.
- A profile with a handle and a display name, made from your name or your email address. It also holds your role (admin or not) and a trust level (new, verified, trusted or admin).
- Your sign-in sessions, each with the IP address and the browser user-agent from when you signed in. A session ends 30 days after you last use it, or when you sign out. Signing out deletes it; an expired session can stay in the database until a cleanup we plan removes it. We use sessions to keep you signed in and to spot misuse.
- Your downloads: which design, which version, a fingerprint of the settings you chose, the file format, the slicer and the time. We use them to enforce the download limit and to count downloads.
- For sign-in by email: a record of each sign-in link we send (the link works once and expires after 15 minutes), and a counter of how many sign-in emails each address has been sent in a 15-minute window. It holds the email address, the window's start and the count, and it stops anyone flooding an address with emails. A cleanup job that removes old rows is planned but does not exist yet, so for now these counter rows stay until we remove them.
What stays in your browser
Your setup (wall, colours, printer, fit and units) is saved in your browser's local storage. It is not sent to us.
If you click Download while signed out, or Sign in at the top of a design page, the design you were configuring is kept in your browser's local storage for up to 30 minutes, so you can continue after you sign in. It is removed when you continue, when you sign out, or on your next visit after it expires.
When you sign out, the sign-in library leaves a small note in local storage (better-auth.message) so your other open tabs sign out too. It holds no personal data.
When you start signing in, we note which sign-in method you chose, for up to 30 minutes, and only when visitor statistics are on (slatfinity.signInStarted), so the statistics can count sign-ins that finish. It is removed the next time a page sees you signed in.
Visitor statistics
We count visits with Umami, an open-source statistics tool that runs on our own server. It uses no cookies. It records the pages you visit (their address, without anything after # in the address, and of the part after ? only the campaign tags that start with utm_, plus the page's title), the site that sent you (its address only, not the page), your browser, operating system and device type, screen size and language, and the country, region and city your connection comes from.
Your IP address is used to work out the country and an anonymous visitor code, and is not stored; the code changes each month, so visits can't be linked from one month to the next. We also count a few actions, such as opening a design, changing your printer or slicer, or downloading a file. Those carry only the design, the wall or setting you picked, the file format and slicer, the number of files, a refusal code (such as the download limit), and the sign-in method you chose and why you signed in (to download, or from the menu), never your email address or the text on your parts.
If your browser sends Do Not Track, nothing is recorded. The statistics can't be tied to your account, so there is nothing of yours in them to show or delete.
Cookies
We set only the cookies that keep you signed in, and a short-lived one during Google or GitHub sign-in. The first two are a session token and a copy of your session details that lasts a few minutes. The third protects the sign-in step against forged requests. Our visitor statistics use no cookies, there is no advertising and no third-party cookies, and we don't sell or share your data.
Services that handle your data
- Resend sends the sign-in emails, so it receives your email address.
- Google and GitHub handle sign-in only if you choose them.
- Railway hosts the site and the database.
- Cloudflare runs the domain name (DNS) and forwards mail sent to hello@slatfinity.com, so it handles the emails you send us.
- Sentry receives a report when something breaks on the site: what failed and where, the page address without anything after ? or #, and your browser type. It doesn't store your IP address (that setting is on in our Sentry project) and doesn't receive your cookies, what you typed, or who you are.
Seeing and deleting your data
To see or delete your data, email hello@slatfinity.com from the address you sign in with. There is no delete button in the app yet, so we do it by hand.
Changes
If this page changes, the date at the top changes too.