Privacy policy
What the workspace stores, why it needs it, and how it stays connected to your group.
Last updated: September 17, 2026
Who operates the service
This notice covers PartShaper’s website, browser workspace, and MCP endpoint. The operator is responsible for processing described here. Client Explorer and any AI or MCP client you choose also process information under their own privacy notices.
Ed in Park City LLC
Questions about these policies, support, data handling, billing, or account administration should be sent through Ed in Park City LLC’s support or account channel. See contact and support.
Information we process
- Identity and access: user, OAuth client, and group identifiers; group names; granted scopes; installation state; and session expiry. Sign-in requests profile and email scopes from Client Explorer; the local installation record uses identifiers rather than a separate email profile.
- Credentials: encrypted OAuth tokens and hashed personal MCP tokens, with token labels, permissions, expiry, revocation, and use information.
- Project content: descriptions, constraints, geometry, suppliers, costs, parts, assemblies, notes, tests, and numerical or build evidence submitted by you or your connected agent.
- History: immutable revisions, author identifiers, timestamps, and saved reports, including prior versions of edited or hidden content.
- Operation and security: sign-in events and error categories. Hosting providers may process network information such as IP addresses, request timestamps, browser details, and service logs.
- Browser preferences: essential sign-in cookies and the cookie-notice preference described in our cookie policy.
Why we process it
We use this information to sign you in, check current group access, operate agent connections, display and export designs, preserve traceable revisions, run requested analyses, respond to support requests, and protect the service. We use Vercel Speed Insights to measure page loading and responsiveness. Performance events include page timings, browser and device information, and a generalized route. We remove query strings, fragments, and workspace, project, model, and part identifiers from those URLs before sending them. We do not send design contents or credentials in these events and do not use advertising pixels.
Where data-protection law requires a legal basis, providing requested service functions relies on performance of a contract; proportionate security and reliability work relies on legitimate interests; and legally required processing relies on legal obligations. Optional processing that requires consent will be explained separately before it is introduced.
Who can receive information
Project content is shared within the authorized group. Connected agents and MCP clients can retrieve data and make changes according to their granted permissions. Choose clients and permissions carefully: PartShaper cannot control how an external agent provider uses information it receives.
The documented production service uses Vercel for hosting, Prisma Postgres for database infrastructure, and Client Explorer for identity and group access. These providers process the information needed for their roles. Information may also be disclosed when required by law, to respond to a valid legal request, or to protect users and the service. We do not sell workspace data or share it for targeted advertising.
Storage, security, and international processing
OAuth credentials are encrypted in storage, personal MCP tokens are hashed, and access checks scope workspace data to the authorized group. See our security overview for the implemented controls. No system can guarantee absolute security.
Providers may operate in countries other than yours. The operator is responsible for transfer mechanisms required for its users, groups, providers, and contracts. This notice does not make a particular data-residency commitment or certification claim.
Retention and immutable history
Project content, prior revisions, and saved evidence are retained to support the workspace and its revision history. Hiding or deleting a design through normal tools is reversible and does not permanently erase it. Signing out or revoking an MCP token also does not delete project content.
Browser sessions expire after up to 30 days, pending login state after 30 minutes, and the cookie-notice preference after 180 days. Expiry of a credential is not a promise that all related database records or logs are erased at that moment. Retention of logs, backups, and account records depends on deployment settings, contracts, and legal or operational requirements. Some records may remain for legal, security, billing, or dispute purposes. Privacy or erasure requests should be sent through the operator’s support or account channel; there is no self-service permanent-purge workflow.
Your choices and rights
You can revoke your personal MCP tokens, stop connecting an external agent, sign out, and manage cookies in your browser. Your group administrator controls group membership. Depending on applicable law, you may have rights to access, correct, export, erase, or restrict processing of personal information, object to certain processing, and withdraw consent where processing is based on consent.
Contact the operator to make a request. Identity verification may be needed, and group records, legal obligations, other people’s rights, and technical history constraints will be considered. These constraints do not remove statutory rights. You may also complain to the relevant data-protection authority. Avoid adding unnecessary personal information or secrets to design notes and source materials.
Children and policy updates
The service is intended for people who can lawfully use it and is not directed at children under 13. If you believe a child’s personal information has been provided inappropriately, contact the operator. We will update this notice when the service or its processing changes and identify the latest revision date above.