Privacy Policy

1. Data Controller and Data Protection Officer

Data Controller under GDPR: Spooly Tobias Terzer Bertha-von-Suttner-Gasse 8/1/57 1220 Vienna, Austria Email: support@spooly.eu Website: https://spooly.eu As we employ fewer than 20 employees who are constantly involved in automated processing of personal data, the appointment of a Data Protection Officer is not required. For any data protection questions, please contact us at the email address above.

2. Overview of Processing

The following information provides a simple overview of what happens to your personal data when you visit our website or use our services.

3. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR:

  • Art. 6(1)(a) GDPR: Consent (e.g., newsletter, optional features)
  • Art. 6(1)(b) GDPR: Contract performance (providing Spooly service, payment processing)
  • Art. 6(1)(c) GDPR: Legal obligation (tax retention requirements)
  • Art. 6(1)(f) GDPR: Legitimate interests (security, fraud prevention, analysis for improvement)

4. What Data Do We Collect?

When using Spooly, we collect the following categories of personal data:

Data CategoryExamplesPurposeLegal Basis
Account DataEmail, name, password (encrypted)Account creation & authenticationArt. 6(1)(b) GDPR
Google OAuth DataName, email, profile pictureSimplified loginArt. 6(1)(b) GDPR
Profile Picture (optional)User-uploaded image (max. 5 MB)Personal customizationArt. 6(1)(a) GDPR
Usage DataFilaments, print jobs, consumptionCore functionalityArt. 6(1)(b) GDPR
Push TokensFCM token (Android) or Web Push subscriptionPush notificationsArt. 6(1)(a) GDPR
Login AttemptsFailed logins (email, timestamp, IP)Brute-force protection, account lockoutArt. 6(1)(f) GDPR
Bambu Lab DataAccount token (encrypted), print historyOptional integrationArt. 6(1)(a) GDPR
Prusa Connect DataOAuth2 token (encrypted), print history, printer IDsIntegration on requestArt. 6(1)(a) GDPR
Klipper/Bridge DataAPI key (SHA-256 hash), print history, filament metadataIntegration on requestArt. 6(1)(a) GDPR
Anycubic Cloud DataWeb token (encrypted), account ID, print history, printer list, ACE slot stateIntegration on requestArt. 6(1)(a) GDPR
Creality Cloud DataSession cookies (encrypted), account ID, print history, printer listIntegration on requestArt. 6(1)(a) GDPR
AI-processed DataFilament photos (photo import only), texts (translations only)Photo import, translationsArt. 6(1)(a) GDPR
Feedback DataFeedback text, email (optional), screenshotsProduct improvementArt. 6(1)(f) GDPR
Payment DataCustomer ID at Stripe or Polar, billing name and address (no card data)Subscription management, invoicingArt. 6(1)(b) GDPR
Technical DataIP address, browser, deviceSecurity, error analysisArt. 6(1)(f) GDPR

5. Data Retention and Deletion

We store your data only as long as necessary for the respective purposes:

  • Account data: Until account deletion
  • Usage data (filaments, prints): Until account deletion
  • Invoice data: 10 years (legal retention requirement)
  • Server logs: Maximum 30 days
  • Bambu Lab token: Until integration deactivation or account deletion
  • Prusa Connect Token: Until integration deactivation or account deletion
  • Klipper Bridge API Key: Until integration deactivation or account deletion
  • Anycubic and Creality credentials: Until integration deactivation or account deletion
  • AI-processed photos: NOT stored by Spooly. OpenAI may retain data for up to 30 days for abuse monitoring per API terms, then deletes it automatically
  • Push tokens (FCM/Web Push): Until notifications are disabled or account deletion
  • Login attempts: Max 15 minutes after last failed attempt (for account lockout)
  • Abuse prevention (pseudonymised email hash): 12 months after account deletion, then deleted automatically
  • PostHog analytics data (only with "Analytics" consent): events up to 7 years, session replays 30 days

After account deletion, all personal data will be completely removed from our systems within 30 days, unless legal retention requirements apply.

6. Recipients and Data Processors

We only share your data with third parties when necessary for contract performance or with your consent. The following service providers process data on our behalf:

Service ProviderPurposeLocationPrivacy Policy
Hetzner CloudServer and database hosting (self-hosted PostgreSQL)EU (Germany)hetzner.com/legal/privacy-policy
StripePayment processingUSA (EU Standard Contractual Clauses)stripe.com/privacy
Polar (Polar Software, Inc.)Payment processing and sale as merchant of record for billing countries outside the EUUSA (EU Standard Contractual Clauses)polar.sh/legal/privacy
Google OAuthAuthenticationUSA (EU Standard Contractual Clauses)policies.google.com/privacy
ResendEmail deliveryUSA (EU Standard Contractual Clauses)resend.com/legal/privacy-policy
Firebase Cloud MessagingPush notificationsUSA (EU Standard Contractual Clauses)firebase.google.com/support/privacy
Meta (Facebook)Conversion tracking (Meta Pixel)USA (EU Standard Contractual Clauses)facebook.com/privacy/policy
Bambu LabPrinter integration (Cloud API for print history and AMS state)China / USA (Bambu Lab Limited)bambulab.com/en/policies/privacy
Prusa Connect (Prusa Research)Printer integrationEU (Czech Republic)prusa3d.com/page/privacy-policy_231
AnycubicPrinter integration (cloud API for print history and ACE state)China (Shenzhen Anycubic Technology Co., Ltd.)anycubic.com (provider privacy policy)
CrealityPrinter integration (cloud API for print history)China (Shenzhen Creality 3D Technology Co., Ltd.)creality.com (provider privacy policy)
OpenAIAI filament recognition (photo import)USA (EU Standard Contractual Clauses)openai.com/policies/privacy-policy
Google GeminiAI translations (blog/changelog)USA (EU Standard Contractual Clauses)policies.google.com/privacy
Trello (Atlassian)Feedback processingUSA (EU Standard Contractual Clauses)atlassian.com/legal/privacy-policy
PostHogProduct analytics and campaign measurement (only with "Analytics" consent)EU (Frankfurt); provider PostHog Inc., USA (EU Standard Contractual Clauses)posthog.com/privacy
Apple App StoreApp distribution (iOS)USA (EU Standard Contractual Clauses)apple.com/legal/privacy
Google PlayApp distribution (Android)USA (EU Standard Contractual Clauses)policies.google.com/privacy

Payments with a billing country in the EU are processed by Stripe. For a billing country outside the EU (such as the USA, United Kingdom, Switzerland, Canada or Australia), Polar Software, Inc. is itself the seller (merchant of record) and processes the payment and billing data under its own privacy policy. For this purpose, Spooly transmits your email address, an internal customer ID, the billing country and your IP address to Polar.

7. Third Country Transfers

Some of our service providers are based in the USA. Data transfers are conducted based on EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. These ensure an adequate level of data protection.

You may request a copy of the Standard Contractual Clauses from us.

For the optional Anycubic and Creality printer integrations, data is transferred to servers in China. See Section 8.9 for details and the legal basis.

8. Bambu Lab Integration (Detailed)

The Bambu Lab integration is an optional feature that you must actively enable. Here we transparently explain which data is processed and how we protect it.

8.1 What Data Is Processed in the Bambu Lab Integration?

Data typeDescriptionStorage
Access tokenAn access key issued by Bambu Lab (NOT a password)Encrypted (AES-128, Fernet) in our database
Email addressThe email address you registered with Bambu Lab, used for identificationUnencrypted (not sensitive)
RegionYour chosen server region (Europe/China/Other)Unencrypted
Print historyCompleted print jobs with file name, duration, weightCompleted prints are imported automatically
Device IDsTechnical identifiers of your printersTemporarily during the query

8.2 What Is NOT Stored?

Your security matters to us. The following sensitive data is NEVER stored:

  • Your Bambu Lab password - it is only sent to Bambu Lab once to generate the token
  • Your two-factor authentication codes
  • Live print data or camera feeds
  • Personal data from your Bambu Lab profile

8.3 How Do We Protect Your Bambu Lab Credentials?

The access token is protected with state-of-the-art encryption:

  • Fernet encryption (AES-128 with HMAC authentication)
  • The encryption key is secured on the server side and not stored in the database
  • Even in the hypothetical case of database access, the tokens would not be readable
  • Tokens are automatically deleted when the integration is deactivated

8.4 Communication with Bambu Lab Servers

When you use the integration, Spooly communicates directly with the official Bambu Lab API servers:

  • All connections use HTTPS (TLS-encrypted)
  • We exclusively use the official Bambu Lab Cloud API
  • Your printers are NOT contacted directly (no local network connection)
  • After setup, Spooly retrieves completed prints automatically: about every 30 minutes via the cloud API and continuously via an encrypted connection (MQTT) to the Bambu Lab Cloud

8.5 Your Control Options

You have full control over the Bambu Lab integration at all times:

  • Activation: The integration must be actively set up by you
  • Deactivation: Possible at any time in the settings - all stored tokens are deleted immediately
  • Automatic import: After setup, completed prints are imported automatically. You end this by deactivating the integration
  • Account deletion: When you delete your Spooly account, all Bambu Lab data is irrevocably removed

8.6 Legal Basis for the Bambu Lab Integration

Your Bambu Lab data is processed exclusively on the basis of your explicit consent pursuant to Art. 6(1)(a) GDPR. You give this consent by actively setting up the integration in the settings.

You can withdraw this consent at any time by deactivating the integration. The withdrawal does not affect the lawfulness of the processing carried out until then.

8.7 Prusa Connect Integration

The Prusa Connect integration is an optional feature that you must actively enable. It allows importing print jobs from your Prusa printers.

  • Authentication: OAuth2 PKCE flow via Prusa Account server (account.prusa3d.com). Your password is NEVER stored by us.
  • Access Token: Stored encrypted (AES-128, Fernet), can be deleted at any time by deactivating the integration.
  • Print History: Completed print jobs with filename, duration, weight, filament type.
  • MMU3 Data: For multi-material prints, slot assignments and color information are processed.
  • Printer Information: Name, model, status, firmware version of your registered printers.
  • Preview Images: Thumbnails of print files are downloaded from Prusa Connect.

Legal basis: Consent under Art. 6(1)(a) GDPR. You can withdraw consent at any time by deactivating the integration in settings.

8.8 Klipper/Moonraker Bridge Integration

The Spooly Bridge is optional software you can install on your local printer (e.g., Snapmaker, Voron, Ender with Klipper). It enables automatic import of print jobs.

  • API Key: A unique access key is generated and stored as a SHA-256 hash in our database. The plaintext key remains only on your device.
  • Print History: Completed jobs with filename, duration, filament usage are automatically transmitted.
  • G-Code Metadata: Material type, color, print parameters from G-Code are used for automatic filament matching.
  • Thumbnails: Preview images of print files are transmitted.
  • Printer Information: Hostname, firmware version, online status.
  • Diagnostic Data (optional): Only when enabled in settings, extended G-Code metadata is stored for analysis.

The Bridge communicates exclusively with Spooly servers via HTTPS. NO data is shared with third parties. Legal basis: Consent under Art. 6(1)(a) GDPR.

8.9 Anycubic Cloud and Creality Cloud Integration

Both integrations are optional features that you must actively set up. They do not use an official manufacturer interface: you provide a credential from your own browser (Anycubic: web token, Creality: session cookies) that Spooly uses to retrieve your print history and printer list.

  • Credentials: Token or cookie values are stored encrypted (AES-128, Fernet). Your password is neither transmitted nor stored.
  • Print History: Completed and cancelled prints with filename, timestamps, duration and filament usage are retrieved every 30 minutes.
  • Printer List and Device State: Name, model and, for Anycubic, the slot state of the ACE filament station.
  • Preview Images: Thumbnails of print files are downloaded from the manufacturer server and stored in reduced size.

Requests go directly to the respective manufacturer servers in China (Anycubic: cloud-universe.anycubic.com, Creality: crealitycloud.com). There is no EU Commission adequacy decision for China; the transfer is based on your explicit consent under Art. 49(1)(a) GDPR, which you give by setting up the integration. You can disconnect the integration at any time in the settings; the credentials are then deleted immediately. Legal basis for processing: Consent under Art. 6(1)(a) GDPR.

8.10 AI-Powered Features (OpenAI, Google Gemini)

Spooly uses AI services for two optional features:

  • Photo Import (OpenAI GPT-4o): When you upload a photo of a filament spool, the image is sent to the OpenAI API to extract manufacturer, material, color, and other information. Spooly does not store the image. OpenAI may retain transmitted image data for up to 30 days for abuse monitoring per their API terms of service and deletes it automatically afterwards. The data is NOT used to train OpenAI models.
  • Automatic Translations (Google Gemini): Blog articles and changelog entries are automatically translated between German and English. Only editorial texts are processed, NO user data.

Legal basis: Consent under Art. 6(1)(a) GDPR (photo import is actively triggered by the user). The translation feature does not process personal data.

8.11 Feedback System (Trello)

When you send a message through the in-app feedback feature, it is transmitted to our Trello board (Atlassian). The following data is processed:

  • Your feedback text
  • Category (bug, improvement, question)
  • Your email address (if you wish to receive a response)
  • Optional: screenshots

Legal basis: Legitimate interest under Art. 6(1)(f) GDPR (product improvement). Providing your email address is voluntary.

8.12 Hosting Infrastructure

Spooly is hosted on servers of Hetzner Online GmbH in Germany. As a technical service provider, Hetzner processes data arising from hosting (IP addresses, server logs) in accordance with applicable data protection regulations.

Location: Hetzner data center in Germany (EU). Data Processing Agreement (DPA) is in place.

8.13 Analytics (Umami, self-hosted)

To improve Spooly we use the open source analytics software Umami. Umami runs entirely on our own servers in Germany (see 8.12); no data is transferred to third parties.

Umami works without cookies and without cross-device tracking. It only collects anonymized usage data: pages visited, referrer (which site you came from), browser type, device category, country, and anonymous events (for example which onboarding step was completed). IP addresses are not stored; identifying individual persons is not possible.

The legal basis is our legitimate interest in analyzing and improving our service (Art. 6(1)(f) GDPR). Since no cookies are set and no personal data is processed, no consent is required.

In the web app, we record the interaction flow for a portion of sessions (session replay): clicks, scrolling, and page changes. From these recordings we additionally create aggregated click and scroll overviews (heatmaps) that do not allow conclusions about individual persons. All input into form fields (such as email address or password) is technically masked and never transmitted. A recording stops after 5 minutes at the latest, stays on our own servers in Germany, and is automatically deleted after 30 days. No recording takes place in the native apps (iOS/Android). The legal basis is our legitimate interest in identifying and fixing usability friction (Art. 6 (1)(f) GDPR); you may object to this processing at any time (see the section on data subject rights).

If you reach Spooly via one of our campaign links (e.g. spooly.eu/go/…) and register within 24 hours, we store with your account which campaign brought you to Spooly. Only the campaign name is stored — no advertising IDs and no third-party data. We use this to evaluate the effectiveness of our campaigns. The legal basis is our legitimate interest in measuring the success of our marketing (Art. 6(1)(f) GDPR); this information is included in your data export (Art. 15/20 GDPR).

8.14 Product Analytics and Campaign Measurement (PostHog)

To improve Spooly and to measure the effectiveness of my marketing campaigns, I use PostHog, a product analytics platform. Processing takes place on servers within the European Union (Frankfurt); a data processing agreement pursuant to Art. 28 GDPR is in place with the provider. I plan to move to my own servers in the future.

PostHog collects usage data such as pages visited, clicks and interactions, features used, the origin of your visit (referrer and campaign parameters such as UTM), and device and browser information. For logged-in users, these events are linked to your internal user identifier (not to your email address or name) so that usage flows and conversion funnels can be analyzed. In addition, I record your sessions as session replay; all input into form fields (such as email address or password) is technically masked and never transmitted, as is the text rendered on screen.

In addition to the collection in your browser, my server also sends events to PostHog, exclusively about the subscription lifecycle: purchase, renewal, plan change, conversion from trial to a paid plan, and cancellation. What is transmitted is the name of the event, the package concerned, for payments the amount and currency, and your internal user identifier as the linking key. Your name, email address, postal address, and payment details are not transmitted. These events occur in the background during payment processing, that is, without any browser involved: renewals and cancellations would otherwise be entirely invisible in the analysis. The purpose is to evaluate which campaigns and which steps in the product actually lead to a subscription.

For the collection in your browser, PostHog uses cookies or comparable storage technologies. Both the collection in your browser and the server-side subscription events take place solely on the basis of your consent (Art. 6(1)(a) GDPR), which you provide via my cookie banner in the "Analytics" category. So that my server knows whether consent exists, I record your decision together with the time you made it on your account; this also serves as the record of consent under Art. 7(1) GDPR. Without your consent, PostHog is not even loaded in your browser, and my server transmits nothing either.

You can withdraw your consent at any time with effect for the future by clearing the website data for spooly.eu in your browser; the cookie banner will then appear again and you can decline the "Analytics" category. If you do not make a new choice in that case, server-side subscription events may still be transmitted on the basis of your earlier consent. You can also send the withdrawal informally to the address given in the legal notice, in which case I will reset the flag on your account.

PostHog does not run in the native apps (iOS/Android): nothing is collected there, and there is no cookie banner either. The server-side subscription events depend solely on the consent you gave in the web app, and are then transmitted regardless of which device you use to take out your subscription. If you never consented in the web app, no subscription events are sent to PostHog either.

9. Meta Pixel (Facebook Pixel)

We use the Meta Pixel (formerly Facebook Pixel) by Meta Platforms Ireland Limited to measure the effectiveness of our advertisements on Meta platforms (Facebook, Instagram) and to optimize our target audiences.

9.1 What Data Does the Meta Pixel Process?

The Meta Pixel tracks the following events and data:

  • Page views (PageView)
  • Completed registrations (CompleteRegistration)
  • Started trial periods (StartTrial)
  • Initiated checkouts (InitiateCheckout)
  • Completed purchases including amount and currency (Purchase)
  • Adding filament (Lead)

Technical data such as IP address, browser type, operating system, and referrer URL may be transmitted to Meta. Meta may associate this data with your Meta account if you are logged in.

9.2 Legal Basis for Meta Pixel

The use of the Meta Pixel is based on your consent pursuant to Art. 6(1)(a) GDPR, which you can provide via our cookie banner.

9.3 Disabling Meta Pixel

You can prevent tracking by the Meta Pixel as follows:

  • Adjust cookie settings in our cookie banner
  • Facebook ad preferences: https://www.facebook.com/adpreferences/ad_settings
  • Browser add-on for deactivation: https://www.facebook.com/help/568137493302217

10. Affiliate and Advertising Partner Programs

In some places, Spooly shows reorder links to partner shops that are clearly labeled as "Ad". If you make a purchase through such a link, I receive a small commission from the respective partner. There are NO additional costs for you.

As an Amazon Associate I earn from qualifying purchases.

10.1 Current Partner Programs

I currently participate in the following partner programs:

PartnerPurposePrivacy Policy
Amazon AssociatesFilament reordering (general)amazon.de/gp/help/customer/display.html?nodeId=201909010
Sunlu referralDirect purchase of Sunlu filamentssunlu.com/pages/privacy-policy
Prusa partner programDirect purchase of Prusa/Prusament filamentsprusa3d.com/page/privacy-policy_231

Additional advertising partners may be added in the future (e.g. retailers via the AWIN advertising network). This overview will be updated accordingly.

10.2 What Data Is Processed for Reorder Links?

When you click a reorder link, you are redirected directly to the respective partner shop. Only there may the partner set cookies, which is solely the responsibility of that partner. Spooly does not embed any partner content, widgets, or tracking pixels.

NO personal data is transmitted to the partners.

To evaluate which reorder links are used, I keep a fully anonymous click statistic. Only the following is stored:

  • Filament type (e.g. PLA, PETG)
  • Filament manufacturer
  • Partner (e.g. Amazon, Sunlu, or Prusa)
  • Location in the app (e.g. filament detail page or statistics)
  • Link type (search link or direct product link)
  • Time of the click

Neither a user ID nor an IP address is stored. The statistic cannot be linked to any person and cannot be re-identified afterwards.

10.3 Legal Basis for Reorder Links

The anonymous click statistic does not contain any personal data. To the extent that any processing takes place when you click, it is based on my legitimate interest pursuant to Art. 6(1)(f) GDPR (financing the service).

Pro users can disable the affiliate hints in the settings. The links remain functional, but the visual hints are hidden.

10.4 Transparency

All reorder links are visibly labeled as "Ad". I only recommend products and shops that I consider reputable. The commission does NOT influence the recommendations in the app.

11. Cookies and Storage Technologies

Spooly uses technically necessary cookies and, with your consent, analytics cookies (PostHog) and marketing cookies (Meta Pixel):

NamePurposeDurationType
session_tokenAuthenticationSession / 30 daysCookie (necessary)
spooly_auth_cacheAuth cache30 minutesLocalStorage
spooly_languageLanguage settingPermanentLocalStorage
spooly_cookie_consentCookie consentPermanentLocalStorage (necessary)
ph_… (PostHog)Product analytics & campaign measurement (only with "Analytics" consent)Up to 12 monthsCookie/LocalStorage (analytics)
_fbpMeta Pixel - Visitor identificationUp to 3 monthsCookie (marketing)
_fbcMeta Pixel - Click trackingUp to 3 monthsCookie (marketing)
frMeta Pixel - Advertising & analyticsUp to 3 monthsCookie (marketing)

12. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): You may request confirmation of whether we process your data and information about that data.
  • Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR): You may request deletion of your data ("right to be forgotten").
  • Right to restriction (Art. 18 GDPR): You may request restriction of processing under certain circumstances.
  • Right to data portability (Art. 20 GDPR): You may receive your data in a structured, machine-readable format.
  • Right to object (Art. 21 GDPR): You may object to the processing of your data.
  • Right to withdraw consent (Art. 7(3) GDPR): You may withdraw any given consent at any time.

13. Right to Lodge a Complaint

If you believe that the processing of your personal data violates GDPR, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

Competent supervisory authority in Austria: Austrian Data Protection Authority Barichgasse 40-42 1030 Vienna Phone: +43 1 52 152-0 Email: dsb@dsb.gv.at Website: www.dsb.gv.at

14. Automated Decision-Making

We do NOT use automated decision-making or profiling within the meaning of Art. 22 GDPR that would have legal or similarly significant effects on you.

15. Data Security

We implement extensive technical and organizational measures to protect your data:

  • SSL/TLS encryption for all data transfers
  • RSA encryption (2048-bit) for sensitive login data during transmission
  • Encrypted password storage (bcrypt with 12 rounds)
  • Encrypted storage of third-party tokens (AES-128, Fernet)
  • Temporary key pairs for credential transmission (hourly rotation)
  • Regular security updates
  • Access restrictions based on the principle of least privilege
  • Database hosting in EU data centers

15.1 End-to-End Encryption at Login

During registration and login, your credentials (email, password) are encrypted on the client side with RSA-2048 before they are transmitted to our server. This ensures that your passwords cannot be intercepted even if the network is compromised.

The encryption keys are automatically renewed every hour to ensure maximum security.

16. Account Deletion

You can delete your account and all associated data at any time:

  • Via account settings in the app
  • By email to support@spooly.eu

After deletion, all your personal data will be irreversibly removed. Recovery is not possible.

To prevent abuse of our free trial period (legitimate interest pursuant to Art. 6(1)(f) GDPR), we retain a cryptographically pseudonymised hash value (SHA-256 with server-side salt) of your email address after account deletion. The hash does not allow any inference about your email address. It is used solely to prevent repeated use of the trial period with the same email address. The hash is retained for 12 months after account deletion, then deleted automatically.

17. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal requirements or service changes. The current version is always available on our website.

For significant changes, we will notify you by email.

18. Contact

For questions about data protection or to exercise your rights, contact us at: Email: support@spooly.eu We will respond to your request as soon as possible, at the latest within one month.

Last updated: September 10, 2026

Help me make Spooly better?

I use cookies to improve Spooly. Necessary ones always run, the rest is your choice.

More in my .