Privacy Policy
SpoolState for Android · Last updated: 4 August 2026
SpoolState is an app for managing 3D printing filament. It is developed as a private project and is currently distributed only in a closed test. This policy describes which data arises in the process and what happens to it.
The most important points first: SpoolState contains no advertising, no analytics tools, no crash reporting and no tracking. No cookies are set. Without an account the app works entirely on the device — no stock data then leaves the phone.
1. Controller
Controller within the meaning of the General Data Protection Regulation (GDPR):
Hendrik Sachs
Email: fowermig.labs@gmail.com
For all questions about data protection and to exercise your rights, an email to this address is enough.
2. Principle: the app also works without an account
SpoolState initially stores your stock exclusively locally on the device. An account is optional and serves only to use the same stock on several devices. If you do not create an account, no stock data whatsoever is transmitted to a server.
3. Data processed when you use the app
3.1 Account and sign-in
If you create an account, the following are processed:
- Email address — for signing in, for confirming registration and for resetting the password.
- Password — it is stored at the provider exclusively as a cryptographic hash, never in plain text.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract governing your use of the app).
3.2 Stock data
With an active account, the data you record is synchronised with the server. This comprises: filament spools with weights, materials, colours, manufacturers, product lines, purchase date and price, locations including freely chosen names and notes, weighing and consumption events with time stamps, as well as freely entered notes and project names.
These entries are factual data and are assigned to you via your account identifier. What you write into free-text fields is up to you — the app does not request any personal data there.
Legal basis: Art. 6(1)(b) GDPR.
3.3 Feedback from the app
In the settings you can send feedback. This happens exclusively on an explicit action; nothing is transmitted without you doing so. Alongside your text, technical details that are necessary to classify a fault are sent as well:
| Detail | Example |
|---|---|
| App version | 0.4.7 |
| Platform | android |
| Browser identifier (user agent) | device model and Android version |
| Screen size | 412 × 915 @2.6 |
| Language and colour scheme | de-DE, dark |
| Storage mode, connection status, synchronisation state | cloud, online |
| Number of pending and failed transfers, last error message | truncated to 200 characters |
| Number of your spools, events, locations and products | plain numbers |
Stock data itself is not sent — no notes, no location names, no product designations. The browser identifier does, however, contain the device model and system version; it is therefore a technical characteristic of your device.
Before sending, the app shows which details will go along. Instead of that you can copy the same text to the clipboard or save it as a file — then nothing is transmitted.
Legal basis: Art. 6(1)(a) GDPR (consent given by sending).
3.4 Handing a scan over to a second device
If you scan a code with the phone, it can be handed over to a signed-in computer. Only the character string read from the code is transmitted in the process. The transmission runs via a realtime channel that is assigned solely to your account; the message is not stored but only passed through, and afterwards remains solely in the working memory of the devices involved.
Legal basis: Art. 6(1)(b) GDPR.
3.5 Password check during registration
So that you do not choose a password that has already appeared in a known data breach, the app queries the service Have I Been Pwned. Your password does not leave the device in the process: it is hashed locally, and only the first five characters of that hash value are transmitted (k-anonymity method). The answer is compared on the device again. No password can be reconstructed and no person identified from the transmitted fragment.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure access).
3.6 Looking up a scanned Prusament spool
If you scan the QR code of a Prusament spool, the app retrieves the corresponding product
page at prusament.com in order to take over material, colour and weight. Only
the spool number printed on the spool is transmitted in the process. No cookies are set and
no identifier of your account is transmitted.
This lookup can be switched off: Settings → Scanning → “Look up Prusament online”. The app remains fully functional afterwards; you then choose material and colour from the catalogue included with the app.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the automatic import of product data).
4. Camera
For the scanner the app needs access to the camera. The image is evaluated exclusively in the working memory in order to recognise a barcode or QR code. No photos are taken, no images are stored and no image data is transmitted. Only the character string contained in the code is recognised and processed further. Camera access ends as soon as you leave the scanner. Audio is never recorded.
If you refuse the permission, the app remains usable; codes can then be entered by hand.
5. Storage on your device
SpoolState stores data in the local storage of the device: your stock, changes not yet transmitted, the sign-in session as well as settings such as language, colour scheme and the unit last used. In addition, Prusament spool data already retrieved is cached (at most 100 entries) so that the same spool does not have to be queried twice.
No cookies are set, and no cross-device recognition takes place. If you uninstall the app or delete its data, this storage is removed completely.
6. Recipients and processors
| Recipient | Purpose | What they receive |
|---|---|---|
| Supabase Inc., San Francisco, USA | Account and data synchronisation | email address, password hash, stock data, feedback |
| Cloudflare, Inc., San Francisco, USA | Hosting of the app's web version and of this legal information (Cloudflare Pages) | IP address and technical access data (server log) |
| Have I Been Pwned (operated via Cloudflare) | Check for leaked passwords | five characters of a hash value — no password, no identifier |
| Prusa Research a.s., Prague, Czech Republic | Product data for a scanned spool | the printed spool number |
| Google Ireland Ltd. / Google LLC | Distribution of the app via Google Play | distribution data in accordance with Google’s own terms |
The database is operated in the Europe region; the stock data is held there. Supabase is a US company; access from a third country can therefore not be ruled out entirely. The transfer is based on the standard contractual clauses of the EU Commission and on the data processing agreement concluded with the provider.
With every connection to one of these services your IP address is transmitted for technical reasons and may be stored there in server logs. SpoolState has no influence over this; the terms of the respective provider apply.
7. Storage period
- Account and stock data remain stored for as long as the account exists.
- Deleted spools and locations are first moved to the trash and remain there until you remove them permanently.
- Feedback is kept until the reported point has been dealt with, at most 24 months.
- Local data remains on the device until you reset it or uninstall the app.
8. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent you have given at any time with effect for the future.
You also have a right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
What you can do directly in the app
- Take your data with you: Settings → Export data. This produces a complete JSON or CSV file of your stock (Art. 20 GDPR).
- Delete your stock: Settings → Reset. This removes your stock data on the server as well; the account remains.
- Delete the account and all data: Settings → Delete account (Art. 17 GDPR) — see below.
- Switch off the Prusament lookup: Settings → Scanning.
Deleting the account. In the app under Settings → Account → Delete account. After a security prompt your account is removed immediately and permanently — together with all spools, the history, the locations, the manufacturers, your settings and all feedback you have sent. The data stored locally on the device is deleted in the process as well.
The operation cannot be undone. The app therefore offers you, immediately beforehand, to save your stock as a file.
If the route via the app is not possible for you, an email to fowermig.labs@gmail.com is enough; the erasure then takes place within 30 days.
9. What SpoolState does not do
- no advertising and no resale of data
- no analytics, statistics or tracking tools
- no automatic crash reporting
- no cookies and no cross-device recognition
- no access to location, contacts, phone state or files
- no fonts or scripts from third-party servers — everything is contained in the app
- no automated decision-making and no profiling
The app requests exactly two permissions: internet and camera. The camera is marked as optional.
10. Children
SpoolState is aimed at adults and is not offered specifically for children.
11. Changes to this policy
As the app develops further, this policy will be adapted. The authoritative version is the one published here with the date given above.