Effective date: September 5, 2026 - Last updated: September 5, 2026
Partsmith is a parametric 3D model generation service operated by Baked Bean LLC, an Illinois single-member LLC doing business as BakedBean3D (referred to below as “Partsmith,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, share, and protect information about you when you use partsmith.dev (the “Service”).
When you create an account, we collect your email address. We use this to authenticate you, send transactional emails (download confirmations, plan receipts, quota notifications), and - if you opt in - lifecycle messages (new models matching your history, announcements). We do not collect your name unless you provide it. Sign-in itself is handled by Firebase Authentication, a Google service: when you create an account or sign in (including with Google sign-in), your email and credentials are processed by Google acting as our authentication provider.
The parameter sets you configure (e.g., enclosure dimensions, fastener sizes) are sent to our servers to generate your files. Generated files are kept in a content-addressed cache - keyed by a hash of the model and parameters, not by your identity - so repeat requests are fast. The cache is not linked to your account.
We collect usage metering data: which model you generated or downloaded, the action taken, and the date, counted against your account. This powers quota enforcement and rate limiting. For guests without an account, the daily download quota is counted against your IP address instead, and your guest download count is also remembered in your own browser’s local storage.
If you join the STEP-export waitlist, we store your email address and which page you joined from. We use it solely to tell you when STEP export launches (and about the founding-member terms we promised); you can ask us to remove it at any time.
Paid plans aren’t live yet, so today we collect no billing information at all. When billing launches, payments will be handled by a dedicated payment processor (we’ll name it here the day it goes live); we will never store raw card data ourselves - only the billing status (plan tier, renewal date, credit balance) needed to gate features correctly.
We automatically collect standard server log data when you use the Service: IP address, browser user-agent, pages visited, timestamps, and HTTP status codes. This data is used for security, debugging, and aggregate analytics. Logs are retained for 30 days by default. When our error-monitoring service (Sentry) is enabled, unhandled server errors are reported to it with request metadata so we can fix them; it is configured not to receive personal data by default.
We set no cookies at all - not for sessions, analytics, or advertising. Your sign-in state lives in your own browser’s storage (managed by Firebase Authentication, plus a small local cache of your plan and guest download count) and is sent to our API only to authenticate your requests. Even our fonts are served from our own domain. There is no third-party analytics on this site - no Google Analytics, no fingerprinting, no ad pixels. We record funnel events (page views, downloads, waitlist joins) with our own first-party counter; when you are signed in, an event carries your account id so quota and plan behavior can be debugged, and we analyze these only in aggregate. We do not sell data to anyone.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not use your generation parameters or download history to build advertising profiles. Your data is used only to operate the Service and improve it for you.
We share personal data only as follows:
We retain account data and generation history for as long as your account is active, plus a reasonable period afterward to support re-download guarantees and dispute resolution. You may request deletion of your account and associated data at any time (see Section 7). Anonymized aggregate usage statistics may be retained indefinitely.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact us at privacy@partsmith.dev. We will respond within 30 days. Deleting your account removes your download history and quota records; files you already downloaded are yours to keep.
We use industry-standard technical and organizational measures to protect your data - TLS in transit, encrypted storage at rest, access controls, and regular dependency audits. No system is perfectly secure. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at privacy@partsmith.dev and we will delete it.
The Service is hosted on Google Cloud in the United States. If you use it from elsewhere, your data is processed in the US; we do not currently offer regional hosting.
We may update this Privacy Policy from time to time. We will provide notice of material changes by email or in-app notice. Continued use of the Service after the effective date of any change constitutes acceptance of the updated policy.
This policy is governed by the laws of the State of Illinois, United States, without regard to conflict-of-law rules.
Privacy questions or requests: privacy@partsmith.dev.