Privacy Policy
Effective date: August 23, 2026
Controller
Quentin Arragon, sole proprietor (Entrepreneur Individuel), 39 avenue Verdier, 92120 Montrouge, France (SIRET 847 907 698 00041), referred to below as “the Publisher”. Contact: contact@bristol3d.app.
Scope
This policy applies to the Bristol desktop application, to the bristol3d.app website, including the user dashboard, and to the Bristol Viewer (view.bristol3d.app).
Account
Account creation requires an email address. Authentication is operated by Supabase (EU region) and is available in two forms:
- Email and password. The password is stored as a hash by Supabase.
- Sign-in with Google. Google transmits the email address, name and profile picture associated with the Google account. The transfer to Google LLC (United States) is framed by the European Commission’s Standard Contractual Clauses (Decision 2021/914) and Google’s certification under the EU-US Data Privacy Framework.
Account emails (such as sign-up confirmation and password reset) are delivered through Resend (see “Sub-processors and recipients”). Providing an email address is required to use the service. Legal basis: performance of the contract.
Device record
Bristol enforces one signed-in device per account. On sign-in, a record is created containing:
- a locally generated device identifier;
- the device name reported by the operating system;
- the platform (macOS, Windows, Linux);
- the application version;
- first-seen and last-seen timestamps.
The last-seen timestamp is refreshed periodically while the application is running. The record is deleted on sign-out (when the device is online) or replaced when the account is used on another device. Legal basis: legitimate interest in preventing account sharing.
Activity record
We keep, for each account, the calendar days (in UTC) on which the desktop application was used. This record is derived from the last-seen timestamp described in the “Device record” section. It contains no information about what was done in the application, only the fact that the application was used on a given day. It is used to monitor the adoption and the proper functioning of the service, and is accessible to platform administrators only. Legal basis: legitimate interest in measuring the use of the service.
Workspace data
Workspaces are shared spaces. When a user joins a workspace:
- their name, email address, avatar, role and seat status are visible to the other members of that workspace, in particular on the People page;
- the workspace’s Owner and Admins can manage their membership, role and seat.
Inviting a person to a workspace requires their email address, provided by the person who invites them. The invitation record (in particular the email address, the role and seat to be granted, the person who sent it, its status and dates) is stored by Supabase (EU region) and visible to the workspace’s Owner and Admins while the workspace exists. The invited person can also see their own invitation. Invitation links are bound to the invited address and expire after 7 days. The invitation email is delivered through Resend (see “Sub-processors and recipients”).
Legal basis: performance of the contract (workspace collaboration). For invitees who do not yet have an account: legitimate interest in letting the workspace’s Owner and Admins invite their team.
Billing
Subscriptions are sold by Paddle, acting as merchant of record (see the Terms of Service). When a workspace subscribes:
- Paddle collects the data needed for the purchase directly at checkout (email address, country, payment details). Payment card details are collected and processed by Paddle; the Publisher does not receive them.
- Paddle processes this data as its own controller for payment processing, tax collection and invoicing, as described in Paddle’s privacy policy.
- Paddle sends invoices, receipts and payment notifications by email.
- The Publisher stores a mirror of the subscription state (plan, billing period, seat counts, subscription status, payment method brand and last four digits) in Supabase (EU region), to display billing information in the dashboard and to determine each member’s access level.
Legal basis: performance of the contract. Billing records are also retained by Paddle in accordance with its own legal obligations (tax and accounting).
Legal records
To be able to prove that our Terms of Service were accepted, and that immediate performance of the service was expressly requested when a subscription was purchased (see the Terms of Service, section 8), we keep a record each time you accept the Terms (the version accepted, the version of this Privacy Policy in force at that time, and the date) and each time this request is made at checkout (the exact wording shown, the related transaction, the workspace and the date). These records are stored by Supabase (EU region). Legal basis: legitimate interest in establishing proof of acceptance (art. 1119 French Civil Code). These records are kept for 5 years after the account is deleted (statute of limitations, art. 2224 French Civil Code).
Security log
Actions performed in the dashboard and through its interfaces (for example: changes to a workspace, its members, seats, assets or billing) are recorded in a security log containing the account identifier of the user who acted, the workspace concerned, the action, its outcome and the date. Entries contain internal identifiers only. The log is kept for 90 days, including after the account is deleted, then deleted automatically. Legal basis: legitimate interest in securing the service and keeping a trace of account and billing operations.
Application usage analytics
The desktop application can send usage data to help us see which features are used and which are not. When enabled, the following is sent:
- usage events (for example: application opened, document created, artwork placed, wall drawn, screenshot taken), with basic counts and durations such as time spent in the application;
- the technical environment: operating system and version, hardware model and processor, screen resolution, interface language, and application version;
- a pseudonymous identifier derived from the operating system’s machine identifier, used to count distinct devices.
Usage data contains no name, no email address and no document content, and is not linked to the user’s account. No geographic information is collected, and IP addresses are not stored with usage events.
Usage data is sent only after the user accepts the ask shown in the application, and sending can be turned off at any time in the application settings. It is processed by PostHog (hosted in the European Union) and retained for at most 25 months. Legal basis: consent.
Aggregate usage statistics
We keep aggregate statistics on the use of the application: the number of active users per day, per week and per month, and the breakdown of recently active users by platform and application version. These statistics are derived from the device records described in the “Device record” section (the last-seen timestamp, the platform and the application version), which are processed to enforce the single-device rule.
The statistics that are kept are aggregate counts. They contain no account identifier and no device identifier. Legal basis: legitimate interest in measuring the audience of the application and improving the service.
Website analytics
The website and the Bristol Viewer use Vercel Web Analytics, which measures traffic in aggregate and does not use cookies or build individual profiles. Bristol does not use advertising cookies. Legal basis: legitimate interest in measuring the audience of the website and the Viewer.
Error monitoring
The desktop application, the website and the dashboard use Sentry to detect and diagnose technical errors and crashes. Error reports are minimised before transmission: they do not include session cookies or authorization headers, and identifiers such as email addresses and authentication tokens are redacted. The desktop application also reports whether a session ended normally or crashed. Error data is stored in Sentry’s European Union data region and is retained for a limited period. Legal basis: legitimate interest in maintaining a reliable service.
Newsletter
Newsletter subscription transmits the email address to Brevo (EU). The address is used to send Bristol-related emails. Unsubscription is available in every email. Legal basis: consent.
Document content
By default, .bristol documents are stored locally on the user’s device and
their content is not transmitted to the Publisher.
When a signed-in user explicitly chooses to share a document through the Bristol Viewer (view.bristol3d.app), a copy of the file is uploaded to Supabase (EU region) and made accessible at a public URL that does not require authentication. In that case:
- Sharing is reserved to signed-in users on the Pro plan.
- A shared document remains accessible until the user revokes it. The user can revoke a shared document at any time; the shared copy then stops being accessible, subject to a short content-delivery propagation delay. Revocation does not recall copies that visitors already downloaded or that their browser has cached.
- Shared documents stop being accessible when the user’s account is deleted.
- The Viewer does not require visitors to sign in. Visits are measured as described in the “Website analytics” section.
- The user is responsible for any personal data contained in shared documents and for the legality of the content being made public.
Legal basis: performance of the contract (user-initiated sharing feature).
Workspace asset library
The workspace’s Owner and Admins can upload 3D models and related files to the workspace library. These files are stored by Supabase (EU region) and are accessible to the members of that workspace. Files deleted by a member may be retained while the workspace exists, for support and recovery purposes; everything is removed with the workspace. The user is responsible for any personal data contained in uploaded files. Legal basis: performance of the contract.
Cookies and local storage
Bristol uses the following local storage mechanisms:
- Website. An authentication cookie set by Supabase for signed-in users (a first-party cookie, necessary to keep the user signed in), and browser local storage for interface preferences.
- Desktop application. Session token in the operating-system keychain (Keychain on macOS, Credential Manager on Windows, libsecret on Linux), and preferences in a local file.
Bristol does not use third-party advertising or tracking cookies.
Sub-processors and recipients
- Supabase (EU region). Authentication, device record, workspace data, asset library, billing mirror, legal records, security log, and hosting of documents shared via the Bristol Viewer.
- Vercel Inc. (United States). Website, dashboard and Bristol Viewer hosting, and web analytics. Transfers framed by the European Commission’s Standard Contractual Clauses (Decision 2021/914) and Vercel’s certification under the EU-US Data Privacy Framework.
- Paddle (merchant of record). Checkout, payment processing, invoicing and billing emails, as its own controller (see “Billing”).
- Resend (Plus Five Five, Inc., United States). Delivery of account emails and workspace invitation emails. Transfers framed by Standard Contractual Clauses and Resend’s certification under the EU-US Data Privacy Framework.
- Sentry (EU data storage region). Error monitoring (see “Error monitoring”).
- PostHog (EU hosting region). Application usage analytics (see “Application usage analytics”).
- Brevo (EU). Newsletter delivery.
- Google LLC (United States). When sign-in with Google is used. Transfers framed by Standard Contractual Clauses and the EU-US Data Privacy Framework.
- Competent authorities, where disclosure is required by law or by a binding request from a public authority.
If the Bristol business is transferred to another entity (see the Terms of Service, section 19), the personal data described in this policy may be transferred with it.
Retention
- Account and device data. Retained while the account exists. Deleted when the account is deleted from the account settings, or within one month of a deletion request sent by email.
- Activity record (days of use). Each entry is deleted automatically after 13 months. The whole record is deleted immediately when the account is deleted.
- Workspace membership data. Retained while the user is a member of the workspace; removed when the member leaves or is removed, or when the workspace is deleted.
- Invitations. Invitation records are retained while the workspace exists and are deleted with it. Invitation links stop working when the invitation expires, is revoked or is replaced.
- Billing mirror data. Retained while the workspace exists. Invoices and transaction records are retained by Paddle under its own legal obligations.
- Legal records (Terms acceptance, immediate-performance request). Kept for 5 years after account deletion (statute of limitations, art. 2224 French Civil Code).
- Security log. Kept for 90 days, then deleted automatically.
- Workspace asset library. Retained while the workspace exists, including files deleted by a member; removed with the workspace.
- Newsletter subscribers. Retained until they unsubscribe.
- Documents shared through the Bristol Viewer. Accessible until the user revokes the share or deletes their account.
- Error reports (Sentry). Retained for the monitoring period configured in Sentry.
- Usage analytics events (PostHog). Retained for at most 25 months.
Rights
Under the EU General Data Protection Regulation and French law, individuals have the right to:
- access their personal data;
- request its rectification or erasure;
- restrict or object to processing based on legitimate interest;
- receive their data in a portable format;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- define directives on what happens to their data after their death (art. 85, French Data Protection Act).
Requests should be sent to contact@bristol3d.app and will be answered within the GDPR time limits (one month, extendable by two further months for complex requests). The Publisher may ask for the information needed to confirm the identity of the person making the request. Complaints may be lodged with the French data protection authority (CNIL) or with the supervisory authority of the individual’s country of residence.
Changes
This policy may be updated. Material changes will be reflected on this page, with the “Effective date” above.