← lasertally.app

Privacy Policy

Effective July 20, 2026 · Last updated August 15, 2026 · Lasertally LLC (Texas, USA)

The short version

Your original CAD files never leave your computer. The Lasertally desktop app opens and measures them locally with its bundled geometry engine, and the STEP, DXF, IGES and NC1 files themselves are never uploaded.

What is uploaded is the geometry Lasertally measured out of them: the pierce counts, cut lengths, contours and part shapes it needs so a quote priced at the front desk can be opened on the shop floor, or re-opened from another seat. That geometry is encrypted on your machine before it leaves. There is a local-only switch that stops it entirely. The detail is in Part geometry and encryption below.

The app does require a Lasertally account to run, and it syncs your shop's working data (materials, rates, customers, saved quotes, and library parts) to Lasertally Cloud so your seats stay consistent and backed up. We collect the minimum needed to run the product, we don't run ads, we never sell your data, and the only analytics anywhere is a cookieless page-view counter on this website (see below).

What the desktop app sends

Account and device data: your email, a hashed device identifier, and a session token — used to verify your sign-in, enforce one-device-per-seat, and let your account admin manage devices.

Cloud sync data: your shop configuration (material libraries, rate profiles, machines), customers, saved quotes, and saved library parts (including their computed geometry summaries and thumbnails). Sync keeps your organization's seats consistent and provides a backup; the same data also always lives in local files on your machines.

Part geometry: the measured geometry of every part you analyze, encrypted on your machine before it is uploaded. See Part geometry and encryption below for exactly what that protects and what it does not.

Update checks: the app checks our release servers for new versions, which involves standard request data (version, platform, IP address).

Never sent: your original CAD files (STEP, DXF, IGES, NC1). The files themselves stay on your machine; only the measured geometry described below is uploaded.

Part geometry and encryption

Every part you analyze is encrypted on your machine with AES-256-GCM and uploaded. That is how a quote priced at the front desk arrives on the shop floor with its geometry intact, and how a part can be re-opened from another seat.

What that protects: the ciphertext lives in one store and the key in another, so a breach of the file store alone yields noise.

What it does not protect: Lasertally issues the key, so Lasertally is technically able to decrypt, and anyone who fully compromised our backend could too. This is not end-to-end encryption and we will not describe it as such. It is the same posture as every other cloud CAD tool, said out loud instead of implied away.

If your shop cannot accept that, a local-only switch stops all geometry upload and moves jobs over a folder on your own network instead.

What this website collects

Basic server logs (IP address, page requested, user agent) for security and capacity purposes, retained briefly. No advertising trackers, no marketing cookies, and nothing that follows you to another site.

Cloudflare Web Analytics runs on this website. It loads one script from static.cloudflareinsights.com and reports page views and load timings back to us. It sets no cookies, assigns no visitor identifier, and cannot track you across other sites — which is why it is here instead of Google Analytics. It runs on the marketing website only; the desktop app does not contain it. We had previously written that we run no third-party analytics at all. That was wrong, and this paragraph replaces it.

What we store when you subscribe

Your name, email, organization name (if provided), and your subscription details — what's needed to provision your account, provide support, and honor the license. There are no license keys; your account is the license. Payments are processed by Stripe (see their privacy policy); we receive transaction metadata but never see or store your card number. We send transactional email only (receipts, account setup, device notifications) — no marketing email without your consent.

Where your data lives

Account and sync data is stored with Cloudflare (encrypted at rest) and is accessible only to your organization's authenticated seats and to us for operating and supporting the service. Application downloads are served via GitHub releases. These providers, plus Stripe and our email delivery provider, are the only third parties that touch your data, and only to provide their function. Your data is never sold and never used for advertising or to train anything.

Retention & deletion

Sync data is retained while your account exists so canceled accounts can resubscribe without loss. Email hello@lasertally.app to delete your account and its synced data; we honor deletion requests within 30 days, except records we must keep for tax or accounting law.

Your rights

Email hello@lasertally.app to access, correct, export, or delete the personal data we hold about you. We respond to all requests regardless of where you live.

Changes

If this policy changes materially, we'll update this page and the effective date above.

Contact: hello@lasertally.app