Privacy Policy
Last updated: 28 May 2026
Controller
Quentin Arragon, sole proprietor (Entrepreneur Individuel), 39 avenue Verdier, 92120 Montrouge, France (SIRET 847 907 698 00041). Contact: contact@bristol3d.app.
Scope
This policy applies to the Bristol desktop application and to the bristol3d.app website, including the user dashboard.
Account
Account creation requires an email address. Authentication is operated by Supabase (EU region) and is available in two forms:
- Email and password — the password is stored as a hash by Supabase.
- Sign-in with Google — Google transmits the email address, name and profile picture associated with the Google account. The transfer to Google LLC (United States) is framed by the European Commission's Standard Contractual Clauses (Decision 2021/914) and Google's certification under the EU-US Data Privacy Framework.
Providing an email address is required to use the service. Legal basis: performance of the contract.
Device record
Bristol enforces one signed-in device per account. On sign-in, a record is created containing:
- a locally generated device identifier;
- the device name reported by the operating system;
- the platform (macOS, Windows, Linux);
- the application version;
- first-seen and last-seen timestamps.
The last-seen timestamp is refreshed periodically while the application is running. The record is deleted on sign-out or replaced when the account is used on another device. Legal basis: legitimate interest in preventing account sharing.
Website analytics
The website uses Vercel Web Analytics, which records aggregate traffic without cookies and without individual profiling. No advertising cookies are set.
Newsletter
Newsletter subscription transmits the email address to Brevo (EU). The address is used only to send Bristol-related emails. Unsubscription is available in every email. Legal basis: consent.
Document content
By default, .bristol documents are stored
locally on the user's device. The Bristol application and
infrastructure do not upload, read or back up their content.
When a signed-in user explicitly chooses to share a document through the Bristol Viewer (view.bristol3d.app), the file is uploaded to Vercel Blob (United States) and made accessible at a public URL that does not require authentication. In that case:
- Sharing is reserved to signed-in users.
- Uploaded documents are automatically deleted seven days after upload.
- The user can revoke a shared document at any time from the desktop application; the corresponding file is then deleted.
- The user is responsible for any personal data contained in shared documents and for the legality of the content being made public.
Legal basis: performance of the contract (user-initiated sharing feature). Transfers to Vercel Inc. are framed by the European Commission's Standard Contractual Clauses (Decision 2021/914) and Vercel's certification under the EU-US Data Privacy Framework.
Cookies and local storage
Bristol uses the following local storage mechanisms:
- Website — Supabase authentication token in browser local storage for signed-in users, and browser local storage for interface preferences.
- Desktop application — session token in the operating-system keychain (Keychain on macOS, Credential Manager on Windows, libsecret on Linux), and preferences in a local file.
No third-party advertising or tracking cookies are set.
Sub-processors
- Supabase — authentication and device record (EU region).
- Vercel Inc. (United States) — website and dashboard hosting, cookieless web analytics, and hosting of documents shared via the Bristol Viewer (Vercel Blob). Transfers framed by the European Commission's Standard Contractual Clauses (Decision 2021/914) and Vercel's certification under the EU-US Data Privacy Framework.
- Brevo — newsletter delivery (EU).
- Google LLC (United States) — only when sign-in with Google is used. Transfers framed by Standard Contractual Clauses and the EU-US Data Privacy Framework.
Retention
- Account and device data — retained while the account exists, and deleted within one month of a deletion request.
- Newsletter subscribers — retained until they unsubscribe, and at the latest three years after the last interaction with an email.
- Documents shared through the Bristol Viewer — deleted within seven days of upload, or earlier if the user revokes the share.
Rights
Under the EU General Data Protection Regulation, individuals have the right to:
- access their personal data;
- request its rectification or erasure;
- restrict or object to processing based on legitimate interest;
- receive their data in a portable format;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Requests should be sent to contact@bristol3d.app and will be answered within one month. Complaints may be lodged with the French data protection authority (CNIL — cnil.fr).
Changes
This policy may be updated. Material changes will be reflected on this page, with the "Last updated" date above.