Privacy Policy, CutBridge
Controller: Edits Krystian Łupiński, Wólka Waniewska 54a, 18-100 Łapy, Poland, NIP 9662065316 — contact@cutatlas.io.
The short version
CutBridge runs on your computer. Your projects, media and deliverables never leave it. Three things do: your licence details, an optional usage report, and — if you send one — an error report. Before anything is sent, file names, sequence names and paths are replaced with anonymous fingerprints.
1. Licence data
What: your e-mail address, licence key, a device identifier we generate
(a random value stored in ~/.cutbridge/device-id.txt — it is not your serial
number, MAC address or anything Apple assigned), activation timestamps, and the
name and version of the Software. When your computer activates, deactivates or
re-validates a licence, or records that you accepted these documents, we also
store the IP address the request came from, together with the time.
Why: to issue the licence, to enforce the number of activations you paid for, and to let you move a licence to a new computer. The IP address is kept as a security record — to detect a single licence being shared across many machines and to have proof of when the terms were accepted.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for the licence data; our legitimate interest in preventing licence abuse and in keeping proof of acceptance (Art. 6(1)(f) GDPR) for the IP address.
Kept: for as long as the licence is active, then for the period required by Polish accounting and tax law (currently 5 years from the end of the tax year).
2. Usage reports — only if you say yes
We ask once, in the panel, and remember your answer. If you say no, nothing is collected and we do not ask again. You can change your mind at any time.
What is sent after each release:
| Field | Example |
|---|---|
| Software version and channel | 2.4.0, stable |
| Operating system, major version | darwin, 24 |
| Python runtime version, major.minor | 3.14 |
| Licence kind — never the key | trial, active |
| Device identifier | the random value above |
| Whether the run succeeded, and how long it took | false, 93.4 s |
| Counts | 4 sequences, 61 shots |
| Which parts were rebuilt | grade, online |
| Fingerprint of the project name | 1a2b3c4d |
| Failure notes, with names removed | render failed: <path:7ebe8cbd.mp4> |
What is NOT sent (in a usage report): your project file, your media, your output, sequence names, file names, folder names, paths, your e-mail address, your licence key, your name. A usage report is not tied to your IP address — the IP is used only to rate-limit and is not stored with the report. (Licence and acceptance requests are a separate channel and do store the IP — see section 1.)
Fingerprints. A path such as
/Users/jan/Clients/Spring/spot.prproj is sent as <path:7ebe8cbd.prproj>.
The fingerprint is the first 8 characters of a SHA-256 hash. Its only purpose is
to let us see that the same file failed more than once. It cannot be turned
back into the path, and we do not attempt to.
Why: to see whether a version is failing more often than the one before it. Error counts alone grow with the number of users and say nothing.
Legal basis: your consent (Art. 6(1)(a) GDPR). Withdrawing it stops collection immediately and deletes anything still queued on your computer.
Kept: 180 days, then deleted automatically.
3. Error reports
If the Software fails, it may send the exception type, the name of the step that was running, the (redacted) message and the (redacted) stack trace, alongside the fields in section 2. The same redaction is applied, and applied again on our server before storage.
Legal basis: your consent, as in section 2.
Kept: 180 days.
4. Purchases
Sales are processed by Paddle.com Market Ltd, acting as merchant of record. Paddle collects and processes your payment and billing data as its own controller, under its own privacy policy. We receive from Paddle only what we need to issue your licence: your e-mail address and the transaction reference. We never see your card details.
5. Who else processes this data
| Processor | What for | Where |
|---|---|---|
| Supabase | database (licences, telemetry) | Frankfurt, Germany (eu-central-1) |
| Fly.io | the licensing service | Frankfurt, Germany (fra) |
| Resend | sending your licence key by e-mail | delivery: Ireland (eu-west-1) — metadata and logs: United States |
| Paddle | payments (own controller) | EU / UK |
Your licences, your telemetry and the licensing service itself stay inside the EEA. One transfer leaves it, and we would rather name it than bury it in a general sentence: Resend, which sends you your licence key, delivers from Ireland but keeps account data, e-mail metadata, logs and API records in the United States regardless of the delivery region. What reaches them is your e-mail address and the fact that a message was sent to it.
We have a data processing agreement with each processor. That transfer relies on the European Commission's standard contractual clauses.
6. Your rights
You may ask us to: show you your data, correct it, delete it, restrict or object to processing, or give it to you in a portable form. You may withdraw consent to usage reports at any time without affecting the lawfulness of what was collected before.
Deleting usage reports is built in. Ask us and we remove every record tied to your device identifier. There is a function in our database for exactly this purpose — it is not a manual favour.
Write to contact@cutatlas.io. If you are unhappy with how we respond you may complain to the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa) or the authority in your own country.
7. What we do not do
We do not sell your data. We do not use it for advertising. We do not profile you. We make no automated decisions that produce legal effects for you. We do not use tracking cookies in the Software.
8. Changes
If we change this policy in a way that affects you, you will be asked to read and accept the new version in the panel before continuing. Older versions remain available at https://cutatlas.io/legal.
9. Contact
contact@cutatlas.io · https://cutatlas.io