This version takes effect on September 7, 2026. Until that date, the current version applies.
Privacy Policy
Last updated: September 7, 2026
Controller
Quentin Arragon, sole proprietor (Entrepreneur Individuel), 39 avenue Verdier, 92120 Montrouge, France (SIRET 847 907 698 00041). Contact: contact@bristol3d.app.
Scope
This policy applies to the Bristol desktop application and to the bristol3d.app website, including the user dashboard.
Account
Account creation requires an email address. Authentication is operated by Supabase (EU region) and is available in two forms:
- Email and password. The password is stored as a hash by Supabase.
- Sign-in with Google. Google transmits the email address, name and profile picture associated with the Google account. The transfer to Google LLC (United States) is framed by the European Commission’s Standard Contractual Clauses (Decision 2021/914) and Google’s certification under the EU-US Data Privacy Framework.
Providing an email address is required to use the service. Legal basis: performance of the contract.
Device record
Bristol enforces one signed-in device per account. On sign-in, a record is created containing:
- a locally generated device identifier;
- the device name reported by the operating system;
- the platform (macOS, Windows, Linux);
- the application version;
- first-seen and last-seen timestamps.
The last-seen timestamp is refreshed periodically while the application is running. The record is deleted on sign-out or replaced when the account is used on another device. Legal basis: legitimate interest in preventing account sharing.
Workspace data
Workspaces are shared spaces. When a user joins a workspace:
- their name, email address, avatar, role and seat status are visible to the other members of that workspace, in particular on the People page;
- workspace admins can manage their membership, role and seat.
Inviting a person to a workspace requires their email address. The invitation record (email address, role, status) is stored by Supabase (EU region) and visible to the workspace’s admins until the invitation is accepted, revoked or replaced. Invitation links are bound to the invited address and expire after 7 days.
Legal basis: performance of the contract (workspace collaboration). For invitees who do not yet have an account: legitimate interest in letting workspace admins invite their team.
Billing
Subscriptions are sold by Paddle, acting as merchant of record (see the Terms of Service). When a workspace subscribes:
- Paddle collects the data needed for the purchase directly at checkout (email address, country, payment details). Payment card details are collected and processed by Paddle; the Publisher does not receive them.
- Paddle processes this data as its own controller for payment processing, tax collection and invoicing, as described in Paddle’s privacy policy.
- Paddle sends invoices, receipts and payment notifications by email.
- The Publisher stores a mirror of the subscription state (plan, billing period, seat counts, subscription status, payment method brand and last four digits) in Supabase (EU region), to display billing information in the dashboard and to determine each member’s access level.
Legal basis: performance of the contract. Billing records are also retained by Paddle in accordance with its own legal obligations (tax and accounting).
Legal records
To be able to prove that our Terms of Service were accepted, and that the statutory right of withdrawal was waived when a subscription was purchased, we keep a record each time you accept the Terms (the version accepted, the version of this Privacy Policy in force at that time, and the date) and each time a withdrawal waiver is given at checkout (the exact wording shown, the related transaction, the workspace and the date). These records are stored by Supabase (EU region). Legal basis: legitimate interest in establishing proof of acceptance (art. 1119 French Civil Code). These records are kept for five years after the account is deleted (statute of limitations, art. 2224 French Civil Code).
Website analytics
The website and the Bristol Viewer use Vercel Web Analytics, which measures traffic in aggregate and does not use cookies or build individual profiles. Bristol does not use advertising cookies.
Error monitoring
The website and dashboard use Sentry to detect and diagnose technical errors. Error reports are minimised before transmission: the application does not attach session cookies or authorization headers, and redacts identifiers such as email addresses and authentication tokens. Error data is stored in Sentry’s European Union data region and is retained for a limited period. Legal basis: legitimate interest in maintaining a reliable service.
Newsletter
Newsletter subscription transmits the email address to Brevo (EU). The address is used to send Bristol-related emails. Unsubscription is available in every email. Legal basis: consent.
Document content
By default, .bristol documents are stored locally on the user’s device and
their content is not transmitted to the Publisher.
When a signed-in user explicitly chooses to share a document through the Bristol Viewer (view.bristol3d.app), a copy of the file is uploaded to Supabase (EU region) and made accessible at a public URL that does not require authentication. In that case:
- Sharing is reserved to signed-in users on the Pro plan.
- A shared document remains accessible until the user revokes it. The user can revoke a shared document at any time; the corresponding file is then deleted, subject to a short content-delivery propagation delay.
- Shared documents are deleted when the user’s account is deleted.
- The Viewer does not identify visitors; traffic is measured in aggregate as described in the “Website analytics” section.
- The user is responsible for any personal data contained in shared documents and for the legality of the content being made public.
Legal basis: performance of the contract (user-initiated sharing feature).
Workspace asset library
Workspace members can upload 3D models and related files to their workspace library. These files are stored by Supabase (EU region) and are accessible to the members of that workspace. They are deleted with the workspace. The user is responsible for any personal data contained in uploaded files. Legal basis: performance of the contract.
Cookies and local storage
Bristol uses the following local storage mechanisms:
- Website. Supabase authentication token in browser local storage for signed-in users, and browser local storage for interface preferences.
- Desktop application. Session token in the operating-system keychain (Keychain on macOS, Credential Manager on Windows, libsecret on Linux), and preferences in a local file.
Bristol does not use third-party advertising or tracking cookies.
Sub-processors and recipients
- Supabase (EU region). Authentication, device record, workspace data, asset library, billing mirror, and hosting of documents shared via the Bristol Viewer.
- Vercel Inc. (United States). Website, dashboard and Bristol Viewer hosting, and web analytics. Transfers framed by the European Commission’s Standard Contractual Clauses (Decision 2021/914) and Vercel’s certification under the EU-US Data Privacy Framework.
- Paddle (merchant of record). Checkout, payment processing, invoicing and billing emails, as its own controller (see Billing).
- Sentry (EU data storage region). Error monitoring (see “Error monitoring”).
- Brevo (EU). Newsletter delivery.
- Google LLC (United States). When sign-in with Google is used. Transfers framed by Standard Contractual Clauses and the EU-US Data Privacy Framework.
Retention
- Account and device data. Retained while the account exists. Deleted when the account is deleted from the account settings, or within one month of a deletion request sent by email.
- Workspace membership data. Retained while the user is a member of the workspace; removed when the member leaves or is removed, or when the workspace is deleted.
- Invitations. Invitation records are retained while the workspace exists and are deleted with it. Invitation links stop working when the invitation expires, is revoked or is replaced.
- Billing mirror data. Retained while the workspace exists. Invoices and transaction records are retained by Paddle under its own legal obligations.
- Legal acceptance records (Terms acceptance, withdrawal waiver). Kept for 5 years after account deletion (statute of limitations, art. 2224 French Civil Code).
- Workspace asset library. Retained until deleted by a member or with the workspace.
- Newsletter subscribers. Retained until they unsubscribe.
- Documents shared through the Bristol Viewer. Retained until the user revokes the share or deletes their account.
- Error reports (Sentry). Retained for the monitoring period configured in Sentry.
Rights
Under the EU General Data Protection Regulation, individuals have the right to:
- access their personal data;
- request its rectification or erasure;
- restrict or object to processing based on legitimate interest;
- receive their data in a portable format;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Requests should be sent to contact@bristol3d.app and will be answered within the GDPR time limits (one month, extendable by two further months for complex requests). Complaints may be lodged with the French data protection authority (CNIL).
Changes
This policy may be updated. Material changes will be reflected on this page, with the “Last updated” date above.