Privacy Policy
SpoolHoarder Last Updated: July 16, 2026
Introduction
SpoolHoarder ("the App") is a 3D printer filament inventory management application.
The App is designed local-first: your spool, project, and usage data is stored on your device. Some optional features use network services and may send data off-device, as described below.
What Data We Process
Data you enter in the App (local by default)
SpoolHoarder stores your inventory and project data locally, including:
- Spool details (brand, material, colors, weights, prices, temperatures, notes)
- Project details and usage logs
- Printer profiles and related settings
- Optional local photos you attach, such as project thumbnails and spool sample print photos
- On supported desktop platforms, Print Library metadata such as library root paths, indexed model/file paths, preview or cover image paths, notes, tags, and extracted file metadata
- Order import drafts and parsed order details when you choose to use order import features
- Preferences and app settings
On native platforms, the app uses SQLCipher keying with key material in secure storage for encrypted databases. Some legacy installs created before encryption support may still have plaintext local databases unless manually migrated. On web builds, storage uses browser-supported Drift/WASM storage.
Account and cloud data (only when you use cloud features)
If you choose to sign in and use cloud-backed features, SpoolHoarder processes account and cloud data through Supabase, such as:
- Account identifiers (for example, email and auth user ID)
- Synced inventory/project/usage data
- Subscription and credit status
- Purchase validation metadata
- AI credit usage and operational metadata, such as feature name, provider/model, token counts, credit changes, timestamps, request source, parse status, and estimated processing cost
- Confirmed filament metadata synced across your devices, such as TD/hex measurements and related spool metadata
Cloud sync and cloud account features are optional and feature-flag dependent.
Shared filament measurement contributions (optional)
If you enable "Share Confirmed TD/Hex Measurements," SpoolHoarder may submit TD1-confirmed filament measurement data to help improve filament data quality. Contributions may include:
- Brand, material, name, colors, product family, and diameter
- Transmission distance and/or color hex codes
- Confirmation method, source, measurement time, app version, and platform
- If you are signed in, your authenticated account ID may be associated with the contribution. If you are not signed in, contributions may be submitted without an account identifier.
Notes, prices, inventory locations, and general project data are not included in these measurement contributions.
Feedback data (optional)
If you submit feedback from the in-app Contact form or website support form, we process:
- Your message
- Optional email address (if you provide one)
- App version and platform
- Optional diagnostic logs (if you choose to attach them)
- If you are signed in, your authenticated account ID may also be associated with the submission
If backend notifications are configured, feedback details may also be forwarded to a maintainer support inbox for review.
Website usage
If you visit the SpoolHoarder website, standard website hosting logs may be processed by our hosting providers. The public website may also use privacy-respecting configuration of Google Analytics to understand aggregate page usage. The website support form sends the information you enter to the same feedback backend described above.
Crash and Error Reporting
On iOS, Android, and macOS release builds, the App uses Firebase Crashlytics for crash and error reporting. Crash reporting is not enabled on Windows or Web.
Crash/error reports can include technical diagnostics such as:
- Device and OS information
- Crash stack traces
- Error timestamps
- App log context associated with errors
For details, see Google's Firebase Privacy Policy.
Optional Network Features
These features make network requests only when enabled/used.
Cloud account, sync, and subscription services (Supabase)
When enabled and used, the App can connect to Supabase for:
- Sign-in (email/password and supported OAuth providers such as Apple or Google)
- Data sync across devices
- Subscription/credit status checks
- Purchase validation, credit provisioning, and related account status updates
- Deletion of synced cloud records through current in-app account/data deletion controls
Some purchase flows may create or use an anonymous Supabase session when you are not otherwise signed in. This is used to validate receipts, attach subscription or credit records, and account for consumable AI credits.
AI-powered spool scanning
SpoolHoarder supports multiple AI scan and import paths:
- On-Device mode (Apple platforms): OCR/parsing runs locally on-device.
- Included cloud scan mode: photo is sent through SpoolHoarder cloud function for processing.
- Legacy BYOK provider mode (if configured): photo may be sent directly to configured external AI provider APIs.
- Order text import: pasted order confirmation text is sent through a SpoolHoarder cloud function for AI parsing when you choose to use that feature.
For cloud scan paths:
- Images are compressed (up to 1024x1024 for scan flows)
- EXIF metadata is stripped before transmission
- Temporary image files are deleted after processing (best effort)
For included cloud AI features, SpoolHoarder may store account-linked operational usage metadata for credit accounting, abuse prevention, cost monitoring, and debugging. This can include token counts, model/provider names, credit changes, request source, timestamps, parse status, and estimated processing cost. It does not intentionally store the original image or pasted order text in the usage log, though AI responses returned for the active app workflow may contain extracted fields from the submitted content.
Filament catalog (SpoolmanDB)
The App downloads public catalog data from SpoolmanDB for suggestions and normalization. This request does not include your inventory payload and is cached locally (refresh window up to 7 days).
Optional self-hosted Spoolman server lookup
If you enable Spoolman QR lookup and configure a server URL, the App may query your configured Spoolman server to resolve tag/QR spool references.
Contact/feedback submission
If you use Contact Us, the App sends feedback payloads to a Supabase Edge Function, including optional logs when selected.
Order text import
If you use order import, the pasted order confirmation text is sent to a Supabase Edge Function and then to Google Gemini for parsing. Order text may include retailer names, product lines, quantities, prices, dates, discounts, shipping/tax lines, and any other text you paste. You should avoid pasting unrelated personal information that is not needed for filament import.
In-app purchase validation and credit provisioning
On supported platforms, purchase validation and credit/subscription provisioning calls are made to backend endpoints.
Permissions
Camera and Photo Library
When granted, camera/gallery access is used for:
- AI spool scanning
- Project thumbnail photos
- Spool sample print photos
You can deny permissions, but related photo-based features will be unavailable.
NFC (where supported)
NFC permission is used for optional filament tag reading and writing features.
Bluetooth, USB, and serial device access (where supported)
Bluetooth, USB, or serial device access may be used to discover and connect to compatible TD-1 filament devices for scanning and data transfer. Device names and connection events may appear in local diagnostic logs.
Security and Storage
- Local database: SQLCipher keying is used on native encrypted databases, with key material in secure storage (legacy plaintext databases may exist on older installs).
- Secure storage: used for sensitive local secrets/tokens (for example, auth session persistence and API keys where applicable).
- Preferences: non-sensitive app settings are stored in platform preferences.
- Log files: diagnostic logs are stored locally and can be manually exported/shared by you; they may include technical app activity and error context.
- AI usage records: for included cloud AI features, account-linked usage records may be stored remotely for credit accounting, operations, and abuse prevention.
Account and Data Deletion
Delete your SpoolHoarder account and associated cloud data
You can permanently delete your SpoolHoarder cloud account in the App:
- Open Settings.
- Open Account & Cloud Sync.
- Select Delete Account.
- Type DELETE and confirm.
This deletes your SpoolHoarder cloud account and the cloud records associated with it, including synced inventory, projects, usage logs, printer data, subscription and credit records, purchase-validation records, AI usage records, and account-linked feedback and uploaded support attachments. Your local data remains on your device.
Deleting your SpoolHoarder account does not cancel a subscription managed by the Apple App Store, Google Play, or Microsoft Store. Cancel an active store subscription through the store where you purchased it to avoid future charges.
If you cannot access the App, you can request account deletion by email. Send the request from the email address associated with your account, or include that address in your message. We may request additional information to verify that you own the account before processing the request.
Data-only deletion
SpoolHoarder does not currently provide a separate cloud-data deletion option that keeps your cloud account active. You can remove local data by deleting it in the App or uninstalling the App.
Data Retention and Deletion
Local data
- Data remains on your device until you delete it in-app or uninstall.
Cloud data (if you used cloud features)
- Synced/account-linked data may be stored remotely while your account is active.
- Account-linked subscription, credit, receipt-validation, AI usage, and optional measurement-contribution records may be stored remotely while needed for account operations, fraud prevention, support, or compliance.
- When an account-deletion request is completed, we delete the cloud records described in the account-deletion section above and sign the account out of the App.
- We retain indefinitely a minimal deletion record: a one-way hash of the former account ID, the deletion timestamp, and deletion-request metadata. We use this record for security, fraud prevention, operational integrity, and compliance; it does not retain the former account ID or email address.
- Optional shared filament or UPC contributions may remain after account deletion, but their account association is removed. Anonymous feedback that was not linked to an account is not part of an account-deletion request.
Third-Party Services
SpoolHoarder may interact with:
- Supabase (auth, sync, edge functions, storage)
- Firebase Crashlytics (crash/error reporting on supported platforms)
- Google Gemini API (included cloud AI scan and order import paths)
- OpenAI and Anthropic (legacy BYOK AI provider paths, if configured)
- Google Analytics (aggregate website analytics, if enabled on the public website)
- SpoolmanDB public catalog (GitHub Pages-hosted public dataset)
- Email delivery infrastructure used for feedback notifications, if configured by us
SpoolHoarder does not include advertising SDKs or ad-network tracking.
Children's Privacy
SpoolHoarder is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted here with a revised "Last Updated" date.
Contact
If you have questions about this Privacy Policy, please open an issue on our GitHub repository.
This Privacy Policy applies to SpoolHoarder on supported platforms, including iOS, Android, macOS, Windows, and Web builds where available.