Legal
Privacy Policy
RouterCut keeps CNC project content and CAM computation local by default. This policy explains the limited account, licensing, purchase, integrity, analytics, and diagnostic data used to operate the product.
1. Scope
This policy applies to RouterCut on the web, Windows, macOS, and Android, the RouterCut website, accounts, licensing services, and related support. Third-party payment providers have their own privacy notices.
2. Information RouterCut processes
- Account data: email address, email-verification state, Firebase user ID, and authentication security metadata.
- Licensing and device data: account ID, entitlement version, random installation UUID, user-visible device label, platform, application version, activation time, and last verification time.
- Purchase data: product, entitlement, store, transaction status, price, currency, country, purchase and refund timestamps, and processor identifiers supplied by RevenueCat, Paddle, or Google Play. RouterCut does not receive full payment-card details.
- App-integrity data: reCAPTCHA Enterprise, Play Integrity, and related Firebase App Check signals used to distinguish authentic clients and reduce abuse.
- Limited analytics: coarse events such as starting the web app or download, importing an SVG, completing a simulation, producing valid G-code, and encountering a Pro workflow. These events do not include project contents or toolpath coordinates.
- Diagnostics: crash and technical diagnostic information on supported platforms, such as app version, device and operating-system characteristics, stack traces, and failure context.
- Support communications: information you choose to send when requesting help.
3. Information that stays local by default
RouterCut does not upload project names or contents, SVGs, built-in shapes, toolpaths, G-code, coordinates, controller addresses, machine commands, stock dimensions, tool settings, or material settings for licensing, commerce, or analytics. These remain on your device unless you deliberately share them, attach them to a support request, or use a separately disclosed feature that requires transmission.
4. Why information is used
- Authenticate accounts and verify email ownership.
- Process purchases, restore entitlements, enforce the three-device limit, and issue signed offline licenses.
- Protect RouterCut and its customers from fraud, abuse, and unauthorized clients.
- Operate, troubleshoot, secure, and improve the application and support customers.
- Comply with tax, accounting, consumer-protection, fraud-prevention, and other legal obligations.
Depending on your location and the activity, processing is based on performing the contract with you, legitimate interests in operating and securing RouterCut, consent where required, and compliance with legal obligations.
5. Service providers and disclosures
Information is disclosed only as needed to operate RouterCut, process purchases, comply with law, or protect rights and safety. Key providers include:
- Google Firebase: Authentication, Firestore, App Check, Analytics, Hosting, Cloud Functions, and Crashlytics. See Google’s Privacy Policy.
- RevenueCat: entitlement and purchase orchestration. See the RevenueCat Privacy Policy.
- Paddle: merchant of record for web and desktop purchases, including checkout, payment, tax, fraud prevention, and receipts. See the Paddle Privacy Notice.
- Google Play: payment processing and store services for Android purchases.
Personal information is not sold. RouterCut does not use CNC project content for advertising.
6. Retention and account deletion
Account and active licensing records are retained while the account exists and as reasonably needed to provide the service, resolve disputes, prevent fraud, and meet legal obligations. You can permanently delete the RouterCut account and its device-activation record at routercut.kasem.dev/account. Deletion also requests removal of the associated RevenueCat customer profile.
Payment processors may retain transaction, tax, fraud, and accounting records when legally required. Aggregated analytics and processor backups may persist according to provider retention schedules. Local project files are not deleted by deleting the online account.
7. International processing and security
Providers may process information in Canada, the United States, the United Kingdom, the European Economic Area, and other locations where they operate. RouterCut uses HTTPS, authenticated APIs, restricted database rules, signed device-bound offline licenses, and access controls intended to protect information. No system can guarantee absolute security.
8. Your choices and rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where consent is the basis for processing. You may delete the account in RouterCut or contact routercut@kasem.dev. Identity verification may be required before fulfilling a request, and some records may be retained where the law permits or requires it.
9. Children
RouterCut is not directed to children under 13, and RouterCut does not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact RouterCut so it can be investigated and removed where appropriate.
10. Changes and contact
Material policy changes will be posted with a revised effective date and may also be communicated through the application or account email. Privacy questions and requests may be sent to Kasem Stacey at routercut@kasem.dev.