What this covers
This policy explains how GigaCAD handles personal data when you use gigacad.site, app.gigacad.site, the Windows drive and tray app, the SolidWorks add-in, the command-line tool, and the API. The Terms of Service cover the rest of our agreement with you.
What we collect
Your account
Your email address, username, and password (stored only as a secure hash). If you sign in with GitHub or Google, we receive your name, email address, and profile picture from them.
Your projects
The files you upload and what we derive from them: thumbnails, 3D previews, and the list of files each assembly or drawing references. We also store the project history you create: branches, versions and their messages, release requests, picks, rebuild reports, and approvals.
Activity in a project
Who checked out which branch, when, and from which computer (by its Windows computer name), plus force-releases, approvals, and releases. These are kept in the project’s activity log.
Technical data
IP addresses, browser and operating system versions, desktop app versions, and error reports. We use these to keep the service secure and to fix problems.
How we use it
- to run GigaCAD: sync your files, show previews, enforce check-outs, and record releases;
- to sign you in and keep your account secure;
- to send emails about your account and projects, such as sign-in links and release requests awaiting your approval;
- to find and fix bugs, and to prevent abuse.
We don’t sell personal data, we don’t show ads, and we don’t use your files to train machine learning models.
Who can see your data
- Private projects are visible only to their members. Members see each other’s usernames, the project’s history, and who has each branch checked out, including the computer name.
- Public projects are visible to everyone, including their files, releases, history, and the usernames of the people who contributed.
- Your profile shows your username, profile picture, and public projects. Your email address is never shown publicly.
GigaCAD staff access project content only when you ask us to help, or when we need to investigate abuse or a security problem.
Service providers
We use a small number of companies to run GigaCAD. They process data only on our instructions:
- Cloudflare stores your files and previews, and hosts and protects our websites.
- Supabase hosts our database, handles sign-in, and delivers live updates.
- Our application host runs the GigaCAD API and the background jobs that generate previews.
- Stripe sells paid plans through Link and processes their payments under its own privacy policy. We never see your full card number; we keep your plan, billing status, and Stripe customer ID.
- GitHub and Google, only if you choose to sign in with them.
These providers may process data in the United States and other countries. Where the law requires it, we use standard contractual safeguards for those transfers.
How long we keep data
- Autosaves are deleted when you commit the next version on that branch, or when the branch is released.
- Releases are kept for as long as their project exists. They can’t be deleted one at a time.
- A deleted project can be restored for 30 days, then it’s permanently deleted. Files no other project uses are removed from storage after that.
- Technical logs are kept for up to 90 days.
- Backups expire on a rolling schedule of up to 35 days after data is deleted.
Your choices and rights
You can:
- update your email address, username, and profile picture in your settings;
- download any file or release from projects you can see;
- make a project private, or delete it;
- delete your account, which also deletes the projects you own.
Depending on where you live, you may also have the right to access, correct, export, or delete your personal data, or to object to how we use it. Email us to use any of these rights. Some things stay by design: your username stays in the history of other people’s projects you contributed to, and existing forks of your public projects belong to the people who made them.
Security
Data is encrypted in transit and at rest. Files are stored under content hashes and reached only through short-lived signed links. Access to production systems is limited and logged. If a breach affects your data, we’ll tell you without undue delay.
Children
GigaCAD isn’t meant for children under 13, and we don’t knowingly collect their data. If you think a child has given us personal data, contact us and we’ll delete it.
Changes to this policy
If we change this policy in a way that matters, we’ll email you and show a notice in the app before the change takes effect.
Contact
Privacy questions and requests go to privacy@gigacad.site.