Privacy Policy
SpoolState for Android and the web version · Last updated: 6 September 2026
SpoolState is an app for managing 3D printing filament. It is developed as a private project and is currently distributed as a beta version. This policy describes which data arises in the process and what happens to it.
The most important points first: SpoolState contains no advertising, no analytics tools, no crash reporting and no tracking. No cookies are set. Without an account, your stock stays on the device. Only when you use a clearly identified online feature, such as the optional Prusament lookup, is the single item described for that feature transmitted. Without any action on your part, the app only asks at startup whether there is a service notice about maintenance or a disruption (section 3.8); no information about you is transmitted in the process.
1. Controller
Controller within the meaning of the General Data Protection Regulation (GDPR):
Hendrik Sachs
Johann-Sebastian-Bach-Straße 22
88097 Eriskirch
Germany
Email: fowermig.labs@gmail.com
For all questions about data protection and to exercise your rights, an email to this address is enough.
2. Principle: the app also works without an account
Without an account, SpoolState stores your stock locally on the device. An account is optional and is used to back up the same stock through Supabase and use it on several devices. In local mode there is no stock synchronisation with SpoolState servers. Separate online features initiated by you are described in sections 3.6 and 3.7; the retrieval of service notices, which runs at startup without any action on your part, is described in section 3.8.
Android app and web version
This policy covers the Android app and the web version at
spoolstate.pages.dev. Both are the same application and use the same online
services. There are two differences:
- Prusament lookup (section 3.7): it happens only in the Android app.
In the browser the request does not take place for technical reasons, so nothing is
transmitted to
prusament.comthere. - Android backup (section 5): the exclusion rules for cloud backup and device transfer apply, by their nature, only to the Android app. In the browser the local data lives in the browser's storage and is subject to its settings and to any browser synchronisation you may have enabled.
Opening the web version also produces the usual server access data at Cloudflare (section 6).
3. Data processed when you use the app
3.1 Account and sign-in
If you create an account, the following are processed:
- Email address — for signing in, for confirming registration and for resetting the password.
- Password — it is stored at the provider exclusively as a cryptographic hash, never in plain text. It must be at least eight characters long; this requirement applies not only in the input form but is also enforced on the server.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract governing your use of the app).
An email address and password are required only if you wish to use an account. Without them, you cannot create an account and do not receive cloud synchronisation; local use without an account remains available.
3.2 Stock data
With an active account, the data you record is synchronised with the server. This includes manufacturers, material and product data, colours, EANs, spool type, tare and stock weights, status, purchase date, price, vendor, batch, the ID of an attached NFC tag, drying time, storage locations, threshold rules and settings. The history may contain timestamps, weighing, consumption, movement, status and drying events, plus freely entered notes, device labels and print or project names.
These entries are factual data and are assigned to you via your account identifier. What you write into free-text fields is up to you — the app does not request any personal data there.
The NFC ID is the factory number of the sticker on the spool — not an identifier of your phone. It is only stored if you assign a tag to a spool yourself, and it is deleted together with the spool.
Legal basis: Art. 6(1)(b) GDPR.
3.3 Selected files and imports
SpoolState has no general access to your files and requests no storage permission. You can, however, select a SpoolState, CSV or Spoolman file for import yourself. Its content is read on the device. The filename may be stored as an origin note on imported events and, with an active account, synchronised.
For a G-code or 3MF file selected by you, the app locally reads only the metadata needed for the consumption entry. The extracted consumption amount and a print name are stored and may be synchronised; if the file contains no print name, one may be derived from its filename. The raw file itself is not uploaded.
Legal basis: Art. 6(1)(b) GDPR.
3.4 Feedback from the app
In the settings you can send feedback. This happens exclusively on an explicit action; nothing is transmitted without you doing so. Alongside your text, technical details that are necessary to classify a fault are sent as well:
| Detail | Example |
|---|---|
| App version and time sent | 0.5.11, ISO timestamp |
| Platform | android |
| Browser identifier (user agent) | device model and Android version |
| Window size including pixel density, and screen size | 412 × 915 @2.6, 392 × 872 |
| System bar insets, configured font size, orientation | 24/0/48/0, factor 1, portrait |
| Whether the on-screen keyboard was open when sending | yes/no |
| Language and colour scheme | de-DE, dark |
| Storage mode, connection status, synchronisation state | cloud, online, last sync |
| Number and types of pending or failed transfers, last error message | error text truncated to 200 characters |
| Number of your spools, events, locations and products | plain numbers |
Stock data itself is not sent — no notes, no location names, no product designations. The browser identifier does, however, contain the device model and system version; it is therefore a technical characteristic of your device.
Before sending, the app shows which details will go along. Instead of that you can copy the same text to the clipboard or save it as a file — then nothing is transmitted.
Legal basis: Art. 6(1)(a) GDPR (consent given by sending).
3.5 Handing a scan over to a second device
If you scan a code with the phone, it can be handed over to a signed-in computer. Only the character string read from the code is transmitted in the process. The transmission runs via a realtime channel that is assigned solely to your account; the message is not stored but only passed through, and afterwards remains solely in the working memory of the devices involved.
Legal basis: Art. 6(1)(b) GDPR.
3.6 Password check when setting a password
This check takes place when you register and when you change your password — that is, wherever you set a new password. It does not take place when you sign in with a password that has already been set.
So that you do not choose a password that has already appeared in a known data breach, the app queries the service Have I Been Pwned. Your password does not leave the device in the process: it is hashed locally, and only the first five characters of that hash value are transmitted (k-anonymity method). The answer is compared on the device again. No password can be reconstructed and no person identified from the transmitted fragment.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure access).
3.7 Looking up a scanned Prusament spool
If you scan the QR code of a Prusament spool, the app retrieves the corresponding product
page at prusament.com in order to take over material, colour and weight. Only
the spool number printed on the spool is transmitted in the process. No cookies are set and
no identifier of your account is transmitted. This lookup happens only in the Android
app; in the web version it does not take place.
This lookup can be switched off: Settings → Scanning → “Look up Prusament online”. The app remains fully functional afterwards; you then choose material and colour from the catalogue included with the app.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the automatic import of product data).
3.8 Retrieval of service notices
At startup the app asks Supabase whether a service notice is available — for example scheduled maintenance or a known disruption. If there is one, it appears as a banner above the content; for maintenance or a disruption it additionally appears as a notice window at startup. If there is none, or if the request cannot be made, nothing happens and the app behaves exactly as before.
Unlike the requests in sections 3.6 and 3.7, you do not initiate this one. It runs at every startup, regardless of whether you use an account or keep your stock on the device only. No information about you, your account or your stock is transmitted — the app asks solely which notices exist. Nothing is counted and no identifier is sent. Your app version is not transmitted either; the device itself decides which notice applies to it. As with any request over the internet, your IP address and the time of the request are technically unavoidable at Supabase (section 6).
Which notices you have already dismissed is remembered on the device only (section 5); this information is not transmitted.
So that a disruption already reported still reaches you if your device subsequently loses its connection, the app stores the most recently confirmed disruption notice on the device (section 5). It is then shown with the addition that it could not be checked whether the disruption still persists. It is only displayed up to the end set for it — and if no end has been set, for at most 24 hours after the last confirmation. The entry itself remains stored until the next successful request replaces or removes it; it is therefore not deleted automatically after a fixed period. You can remove it at any time together with the rest of the app data (section 5). This too stays on the device and is not transmitted.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in being able to inform you about maintenance work and disruptions).
4. Camera
For the scanner the app needs access to the camera. The image is evaluated exclusively in the working memory in order to recognise a barcode or QR code. No photos are taken, no images are stored and no image data is transmitted. Only the character string contained in the code is recognised and processed further. Camera access ends as soon as you leave the scanner. Audio is never recorded.
If you refuse the permission, the app remains usable; codes can then be entered by hand.
5. Storage on your device
SpoolState stores data in the local storage of the device: your stock, changes not yet transmitted, the sign-in session as well as settings such as language, colour scheme and the unit last used. In addition, Prusament spool data already retrieved is cached (at most 100 entries) so that the same spool does not have to be queried twice. The device also keeps track of which service notices you have dismissed (at most 50 identifiers, section 3.8) so that the same notice does not reappear at every startup, as well as the most recently confirmed disruption notice (a single entry) so that a reported disruption still reaches you without a connection. That entry remains until a successful request replaces or removes it; it is displayed only within the limits stated in section 3.8.
No cookies are set, and SpoolState performs no cross-device recognition. If you uninstall the app or delete its data, the app storage on that device is removed.
From version 0.5.4 onwards the Android app technically excludes its data from Android cloud backup and from the device-transfer mechanisms that the app can control. In particular, local stock and the sign-in session should therefore not enter a Google backup automatically. Earlier versions of the app did not yet have this exclusion. Details of Android system behaviour may vary by operating-system version and device manufacturer.
6. Recipients and processors
| Recipient | Purpose | What they receive |
|---|---|---|
| Supabase Inc., San Francisco, USA | Account, database, realtime handover and synchronisation; triggering the account emails; providing the service notices (section 3.8) | email address, account identifier, password hash, stock data, feedback and technical access data. For the retrieval of service notices alone, only the IP address and the time, which are technically unavoidable |
| Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany (subsidiary of Sendinblue SAS, Paris) | Delivery of the account emails: registration confirmation and password reset | email address, the content of those messages, and delivery and access logs |
| Cloudflare, Inc., San Francisco, USA | Hosting of the app's web version and of this legal information (Cloudflare Pages) | IP address and technical access data (server log) |
| Have I Been Pwned, Troy Hunt / Cloudflare infrastructure | Check for leaked passwords | five characters of a hash value and, for technical reasons, the IP address — no password or account identifier |
| Prusa Research a.s., Prague, Czech Republic | Product data for a scanned spool | the printed spool number and, for technical reasons, the IP address |
| Google Ireland Ltd. / Google LLC | Distribution of the app via Google Play | distribution data in accordance with Google’s own terms |
This project's database runs in the Supabase region eu-central-1 (Frankfurt am
Main, Germany). Supabase and Cloudflare are nonetheless US providers, so access or processing
in a third country cannot be ruled out completely. Where no adequacy decision
applies, such transfers rely on the European Commission's Standard Contractual Clauses and
the provider's contractual data-protection terms. You can request a copy or further
information about the safeguards through the email address in section 1.
Every direct connection to an online service technically transmits your IP address, which may appear in that provider's security and access logs. Providers retain such logs under their contractual periods and only for as long as required for operation, security and abuse prevention.
7. Storage period
- Account and stock data remain stored for as long as the account exists.
- Deleted spools and locations are first moved to the trash and remain there until you remove them permanently.
- Feedback is kept until the reported point has been dealt with, at most 24 months. A daily database job automatically removes older entries.
- Sign-in sessions remain locally until you sign out, delete the account, or the session expires or is revoked.
- Local data remains on the device until you reset it or uninstall the app.
8. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent you have given at any time with effect for the future.
You also have a right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). In particular, you can contact the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.
What you can do directly in the app
- Take your data with you: Settings → Data → Export. The JSON export contains your entire visible stock — spools, event history, storage locations, manufacturers, products, threshold rules and app settings. Spools in the trash are not included. When an export file is read back in, the app assigns new identifiers; quantities and spool fields are preserved, but individual details of the history (time of creation, weighed gross weight, origin of a move) are not restored. CSV contains every spool field but not the complete history (Art. 20 GDPR).
- Delete your stock: Settings → Data → Delete all data. Removes manufacturers, products, spools, history, storage locations and threshold rules — with an active account on the server and on this device. The material catalogue, app settings, account and sign-in remain.
- Load demo data: Settings → Data → Load demo data replaces the current stock with examples after confirmation. This is a separate operation and not part of deletion.
- Delete the account and all data: Settings → Delete account (Art. 17 GDPR) — see below.
- Switch off the Prusament lookup: Settings → Scanning.
Deleting the account. In the app under Settings → Account → Delete account. After a security prompt, the account and its associated active server data are permanently removed, including spools, history, storage locations, manufacturers, settings and feedback you sent. On this device the sign-in session, stock, synchronisation queue and caches are deleted. Purely local interface preferences such as language, colour scheme, consumption unit and the Prusament switch are retained; you can remove them by clearing the app's data or uninstalling it.
The operation cannot be undone. The app therefore offers you, immediately beforehand, to save your stock as a file.
If the route via the app is not possible for you, an email to fowermig.labs@gmail.com is enough; the erasure then takes place within 30 days.
9. Security
Network connections use HTTPS or WSS encryption. Server access is restricted through user-specific database rules (Row Level Security); administrative keys are not shipped in the app. Passwords are stored only as hashes by the authentication provider. Despite these measures, no transmission or storage method can guarantee absolute security.
10. What SpoolState does not do
- no advertising and no resale of data
- no analytics, statistics or tracking tools
- no automatic crash reporting
- no cookies and no cross-device recognition
- no access to location, contacts or phone state and no general file permission; only files selected by you are read as described in section 3.3
- no fonts or scripts from third-party servers — everything is contained in the app
- no automated decision-making and no profiling
The app requests exactly two permissions: internet and camera. The camera is marked as optional.
11. Children
SpoolState is aimed at adults and is not offered specifically for children.
12. Changes to this policy
As the app develops further, this policy will be adapted. The authoritative version is the one published here with the date given above.