CutClean
Privacy Terms Refunds Accessibility

Privacy Policy

Last updated: July 6, 2026

Not A Cult LLC ("we", "us") operates CutClean at cut-clean.com. CutClean repairs DXF and SVG cut files. This policy explains what we collect, why, and your choices.

Our commitment about your files

We never sell your data, and we never use your files (or anything in them) to train AI or any other model. Your designs are yours. We use your files only to perform the repair you ask for, and nothing else.

How CutClean handles your files

  • Free, single-file repair runs entirely in your browser. The repair engine is WebAssembly that runs on your device. Your file is never uploaded to us. It never leaves your computer.
  • Pro batch processing uploads your files only to repair them. Files are sent over an encrypted connection, stored briefly and encrypted at rest, processed to produce the cleaned output you requested, and automatically deleted as soon as the job finishes. We do not read, keep, share, sell, or train on the contents of your files.
  • The project vault stores files you choose to save — until you delete them. If you save a file to your vault (a Pro feature), that file and any version history you create are kept in encrypted storage so you can reopen them across sessions and devices. Unlike batch inputs, vault files are not auto-deleted: they are retained until you delete the file or version, or delete your account (which erases your entire vault). We still never read, share, sell, or train on their contents.

Information we collect

  • Account data: your email address and a hashed password. We never store plaintext passwords.
  • Payment data: processed by Stripe. We never see or store your card number.
  • Usage data: counts we need to run the service (repairs performed, processing time, and file counts) tied to your account to enforce free-tier limits and to meter higher-tier usage. This is metadata about activity, never the contents of your files.
  • Technical data: minimal server logs (such as IP address and timestamps) kept for security and abuse prevention. If we enable analytics, it is privacy-respecting and cookieless, honors your browser's Do Not Track / Global Privacy Control signal, and never includes any file content.
  • Feature data you create: depending on which features you use, we also store the metadata of files you save to your vault (name, format, size, version history), your saved machine/material profiles, the quotes and material-inventory records you create, your team's membership list (invited members' email addresses and roles), any API keys you issue (stored hashed) and webhook endpoint URLs you register, and the buyer labels described under Seller tools & buyer information below. All of it exists only to provide the feature it belongs to and is erased with your account.

Seller tools & buyer information

If you use the seller tools to issue fingerprinted downloads, you may enter a label for the buyer (such as a name or order number). We store that label and the generated fingerprint token so you can see which download went to which buyer. This information is about your customers, not ours: you are responsible for having a lawful basis to share it with us, we process it only to provide the feature, and it is deleted when you delete the associated file or your account. We never use it for marketing or share it with anyone else.

How we use it

To provide and improve the service, operate your account, process payments, enforce limits, secure the site, and meet legal obligations. We do not sell your personal information, and we do not use your files to train any model.

Third-party processors

We share data only with the providers that help us run the service:

  • Stripe, which processes subscription and credit-pack payments. Stripe handles your card data; we do not.
  • Railway, which hosts the application and database.
  • Cloudflare R2 or Backblaze B2 (depending on deployment), object storage where Pro batch-job files are held briefly (encrypted, short-lived) and auto-deleted after the job, and where vault files you save are kept encrypted until you delete them.
  • Resend, a US-based provider that delivers our transactional email: password-reset messages and contact-form relays. It receives only what is needed to deliver each message (the recipient address and the message itself), never your files. Email features are inactive until this provider is configured.

If you use the one-click send-to-bureau feature, the file you choose is handed to the cutting service you pick (for example SendCutSend or OSH Cut) under their privacy policy — we transmit only that file, only when you ask.

We do not sell your personal information.

Contact form

If you write to us through the contact form, we collect the name (optional), email address, and message you provide. We use them only to reply to you: the message is relayed to our support inbox, is never used for marketing, and is retained only as long as needed to handle the inquiry.

Cookies & local storage

We use a single essential session cookie to keep you signed in (set httpOnly, Secure, and SameSite). The app also stores a few small, functional values in your browser's local storage — your theme preference and the free-tier daily counter — which never leave your device and identify nothing about you. We do not use advertising or cross-site tracking cookies.

Your rights

You may request access to, a copy of, or deletion of your personal data, and you may delete your account by contacting us. Residents of the EU/UK (GDPR) and California (CCPA/CPRA) have additional rights; contact us to exercise them. We retain account and billing data for as long as your account is active or as needed to provide the service and meet legal obligations. Batch-job uploads are deleted right after each job finishes; files you save to your vault are retained until you delete them or your account, as described above.

Data security

We use industry-standard measures, including encryption in transit, hashed passwords, encryption of batch files at rest, and access controls. No method of transmission or storage is 100% secure.

Children

CutClean is not directed to children under 13 (or under 16 in the EU).

Changes & contact

We may update this policy; we will post the new date above. Questions or requests: [email protected].

Not A Cult LLC, 1500 N Grant St, Ste R, Denver, CO 80203, USA.

© 2026 Not A Cult LLC · Back to CutClean