Data Protection & Privacy

Privacy Policy

Last Updated: October 2026 • GDPR & HIPAA Data Principles
timer Ephemeral Processing Architecture

Exo2STL is built on a zero-retention philosophy for dental CAD meshes. Uploaded preview files and generated STL files are stored temporarily in high-security, encrypted cloud storage (Cloudflare R2) with a strict 1-hour time-to-live. After 60 minutes, files are permanently and irreversibly purged from our servers. You may also trigger immediate deletion at any moment.

1. Introduction

Exo2STL (“we”, “our”, or “us”) provides an automated web service and API converting Exocad 3D preview HTML documents into binary STL meshes. This Privacy Policy details the types of information we collect, how that data is processed, and our strict safeguards regarding clinical file privacy and personal data protection under the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA).

2. Clinical CAD Data & Patient Information (HIPAA / GDPR)

As a technical file formatting utility, Exo2STL does not index, extract, catalog, or aggregate patient identities, patient medical records, or clinical diagnostic data.

  • De-Identification Requirement: Users (dental clinicians, labs, and technicians) are required to ensure that files submitted for conversion do not contain unredacted Protected Health Information (PHI) or personal identifiable patient details.
  • No Permanent Medical Records: We do not act as an electronic health record (EHR) custodian. Models converted through our pipeline are not archived or retained beyond the temporary 1-hour conversion lifecycle.
  • No AI Model Training: Your uploaded 3D meshes, dental scan geometries, and files are never used to train machine learning models or artificial intelligence algorithms.

3. Information We Collect

To provide access to the platform and process payments, we collect minimal personal data:

Account & Authentication Data: When you sign in via Magic Link or Google OAuth, we store your email address and authentication session tokens.
Billing Information: Credit purchases are processed by Stripe. We store transaction timestamps, credit quantities, and Stripe customer identifiers. We never store credit card numbers on our servers.
API Tokens: If you generate developer API keys, we store an irreversible SHA-256 cryptographic hash and a masked display prefix. The raw token is displayed to you once and never saved.
Technical Logs: Temporary server access logs (IP addresses, user-agent headers, conversion status codes) maintained for security audit and abuse prevention.

4. How We Use Your Information

We use collected information solely for:

  • Authenticating user sessions and providing access to the Clinical Portal;
  • Tracking account conversion credits and processing Stripe checkout sessions;
  • Executing algorithmic mesh extraction in secure, stateless serverless worker nodes;
  • Defending our infrastructure against denial-of-service attacks, brute force, and abuse.

5. Infrastructure & Subprocessors

We partner with enterprise-grade cloud infrastructure providers that adhere to ISO 27001, SOC 2 Type II, and GDPR compliance standards:

Cloudflare, Inc.

Global edge hosting (Pages), D1 encrypted database, and ephemeral object storage (R2).

Amazon Web Services (AWS)

Stateless Lambda execution environment executing sandboxed mesh extraction.

Stripe, Inc.

PCI-DSS Level 1 certified payment processing for credit purchases.

Google LLC

Optional OAuth 2.0 social identity verification and sign-in provider.

6. Data Retention & Destruction Lifecycle

Our data retention schedule is strictly enforced:

  • Uploaded HTML Documents: Automatically deleted via Cloudflare R2 bucket lifecycle rules after 1 hour.
  • Generated STL Archives: Automatically deleted via Cloudflare R2 bucket lifecycle rules after 1 hour.
  • Manual Purge: Clicking “Purge Cloud Data Now” in the dashboard deletes both the source file and STL archive immediately.
  • Account Data: Retained until the user requests account deletion.

7. Cookies & Local Storage Technologies

Cookies and local browser storage are utilized strictly to ensure operational security, authenticate your user session, and remember essential interface settings:

Strictly Necessary Cookies: better-auth.session_token (session management) and better-auth.csrf_token (security against forged requests). These are mandatory for secure account login.
Edge & Security Cookies: Cloudflare security tokens (such as __cf_bm) to protect our edge network against automated malicious bots and DDoS attacks.
Functional Storage: sidebar:state (persisting your menu preferences) and exo_cookie_consent (storing your cookie choice in browser localStorage).
No Advertising or Behavioral Tracking: We do not install cross-site marketing trackers, advertising cookies, or third-party tracking pixels on your device.

You may choose “Essential Only” on our cookie banner or clear your browser cookies at any time through your browser settings.

8. Your Rights Under GDPR & CCPA

Depending on your location, you hold statutory rights regarding your personal information:

  • Right of Access & Portability: You may request a copy of the personal data held about you;
  • Right to Rectification: You may update your account details at any time;
  • Right to Erasure (“Right to be Forgotten”): You may request complete deletion of your account and related records;
  • Right to Object: You may object to data processing based on legitimate interests.

9. Security Safeguards

All communications between your browser, our edge workers, and storage endpoints are encrypted in transit using Transport Layer Security (TLS 1.3). Cloud storage repositories are encrypted at rest using industry-standard AES-256 encryption. We enforce least-privilege IAM credentials across all cloud microservices.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact:

Privacy Office: [email protected]

Trademark Notice & Non-Affiliation Disclaimer

Exo2STL is an independent file format conversion and 3D mesh extraction utility. Exo2STL is not affiliated with, sponsored by, endorsed by, or in any way associated with exocad GmbH or Align Technology, Inc. “exocad” and “DentalCAD” are registered trademarks of exocad GmbH. All product names, logos, and brands are property of their respective owners. Any reference to exocad is for nominative purposes to describe software file compatibility and technical interoperability only.

Medical Device & Clinical Validation Disclaimer

Exo2STL is a technical data formatting utility and is not a medical device, diagnostic system, or clinical treatment planning tool. Reconstructed 3D meshes and STL files must be thoroughly inspected, validated, and approved by a licensed dental practitioner or dental technician prior to milling, 3D printing, or patient placement.

Data Ephemerality & Healthcare Privacy

Exo2STL enforces an ephemeral 1-hour cloud retention policy. Uploaded files and generated STL archives are automatically and permanently purged from server memory and storage. Users are responsible for ensuring that uploaded files comply with applicable healthcare privacy regulations (such as HIPAA and GDPR) and are de-identified of sensitive patient health information.

© 2026 Exo2STL. All Rights Reserved.

timer 1-Hour Ephemeral Purge lock TLS Encrypted Terms • Privacy • Cookies