Document
In twelve sections, everything we do with your data.
No dark patterns, no opaque collection: section by section we explain what comes in, where it lives, for how long, and how we protect it. Your GDPR rights and the controller’s contacts are at the bottom.
01
/ 12 · Opening
Introduction
G-Loop is a desktop software application for continuous 3D printing G-code processing, developed and operated by MEGADV di Andrea Tedesco, with registered office at Piazza dei Mille 18, 88049 Soveria Mannelli (CZ), Italy (hereinafter “we”, “us”, “our”). MEGADV di Andrea Tedesco is the data controller pursuant to Art. 4(7) GDPR. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our software and website (g-loop.it).
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Italian data protection laws. If you have any questions about this policy, you can contact us at info@g-loop.it.
02
/ 12 · Inventory
Data We Collect
We collect only the minimum data necessary to provide and secure our service:
Account Data (Direct Registration)
- Email address
- First and last name
- Password (stored as a bcrypt hash — never in plaintext)
Account Data (Google OAuth Login)
If you choose to sign in with Google, we receive your first name, last name, and email address from your Google account. No password is stored unless you choose to set one from your account dashboard.
License Data
- License ID and plan type
- Device IDs associated with your license
Device Data
- Unique device identifier (for license enforcement)
- Device name (for device management in your account)
Technical Data
- IP address — used for rate limiting and security only, not stored long-term
Website Usage Data
We use Google Analytics 4 (GA4) to collect aggregated and anonymized website usage statistics. GA4 is activated only with your explicit consent via our cookie banner. IP addresses are anonymized. Desktop application usage is handled separately, as described in the two items below.
Application usage statistics (desktop app)
To understand how the desktop application is used and to improve its reliability and features, we collect limited usage statistics, sent during periodic license validation, at login and when the session ends. These include: application version, operating system, session duration, app sections used, number of files processed and printer model, associated with the device identifier and your account ID. We do not collect the content of your prints or your G-code files, and we do not use this data for advertising or marketing profiling. This processing is based on our legitimate interest in improving the product; you may object at any time (see Section 6).
Diagnostic data and error reports (desktop app)
When the desktop application encounters a critical error (crash), it automatically sends a diagnostic report that allows us to identify and fix malfunctions. The report may contain: event type, application version, plan type, printer model, number of files processed, technical logs, the error stack trace and basic system information (e.g. operating system), together with the device identifier and, if you are logged in, your account ID. Before sending, we automatically remove any credentials, tokens and keys detected in the logs. We do not transmit your G-code files or the content of your prints. You may also voluntarily send us ratings and bug reports through the same feature. This processing is based on our legitimate interest in providing stable and secure software; you may object at any time (see Section 6).
Payment and Billing Data
All payments are processed exclusively through PayPal (monthly and annual subscriptions). We do not collect or store any credit card numbers, bank details, or PayPal transaction details. For each payment we retain date, amount, status (completed, pending, refunded), PayPal transaction ID and subscription ID for subscription management, automated reconciliation and receipt generation. On your request, from the account dashboard you can generate and download a PDF receipt for each completed payment; the receipt includes a detailed breakdown of the plan (printers, addons, PC workstations).
Receipts and Accounting Records
The first time you download a receipt for a payment, we generate and store a record bound to the PayPal transaction ID containing a yearly progressive number, date, total amount and a snapshot of the plan items at the time of payment. The document is a non-fiscal receipt and is retained for the terms required by Italian civil and tax obligations (see Section 5).
G-code Files
All G-code files are processed locally on your device. Your files are never uploaded to our servers. If you use the remote printer management feature of G-Print, print files and commands are transmitted directly over your local network (LAN) or the network you have configured to the authorized hosts you have registered in your account: traffic flows point-to-point, does not transit through our servers and is not retained by us.
Support, Chatbot and Tickets
When you interact with the AI chatbot or request escalation to a human operator, we retain the conversation history (message text, timestamps, status), any support tickets generated and moderation incidents (see Section 8 for details on the use of the OpenAI Moderation API). The chatbot is available only to authenticated users. We limit message length, history and frequency to prevent abuse.
Contest Participation
If you submit an entry to a contest published on g-loop.it, we retain title, description, optional tags, images, 3D models (e.g. STL/OBJ/GLB), your public username/name, votes received and the moderation outcome (approved, in review, rejected). Approved entries are publicly visible on the contest page.
Remote Printers (G-Print)
For the remote printer feature we only retain the name you assign to each remote printer and the permissions you grant to authorized clients. We do not receive or store print data (G-code files, camera snapshots, machine commands): all traffic flows directly between your host and your clients on the network you have configured. When this feature is active, the desktop application may keep running in the background (system-tray icon) to maintain the connection with authorized clients and the periodic license validation. Background mode introduces no new data categories: any data transmitted remains as described in this Section 2 — in particular the license/device ID for validation and, where applicable, the usage statistics and diagnostic reports described above.
Device Synchronization (G-Storage Sync)
If you enable synchronization between your devices in G-Storage, each device registers with your account its own host name and its own Tailscale IP address (a private network address, not a public one), so that your devices can find each other; the registration is refreshed periodically and expires automatically. Our server also brokers the initial pairing between your devices, and if you pair using the mobile app it stores a phone identifier that cannot be traced back to your phone number, to enforce the device limit included in your license. Your inventory data is never uploaded to our servers: it always travels directly between your devices. You can remove a device from your account at any time. If synchronization is turned off, we do not collect any of this data.
03
/ 12 · Why
Purpose of Processing
We process your personal data for the following purposes:
- Account management and authentication — to create and maintain your account, verify your identity, and provide access to the software
- License validation and device management — to verify your subscription status and enforce device limits per your plan
- Rate limiting and abuse prevention — to protect our services from misuse and ensure fair access for all users
- Customer support — to respond to your inquiries submitted via the contact form
- Statistical analysis — aggregated analysis of website usage through Google Analytics 4, with your consent, to improve our service
- Payment management and billing — recording payment date, amount and status for subscription management and receipt issuance
- Support via chatbot and tickets — to answer your questions through the AI chatbot, manage escalation to a human operator and track open tickets
- Contests and content moderation — to manage participation in contests, publish approved entries and enforce the rules through automated review (Moderation API + LLM as judge) and human review
- Regulatory and accounting compliance — to comply with accounting, tax, anti-fraud and statutory obligations regarding payment documents
- Application diagnostics, usage statistics, stability and security — to detect and fix crashes and malfunctions, understand how the app is used, analyze reliability per version and improve its security and features
04
/ 12 · Law
Legal Basis (GDPR Art. 6)
We process your data under the following legal bases:
- Contract performance (Art. 6(1)(b)) — processing necessary for account management, license validation, and providing the software service you subscribed to
- Legitimate interests (Art. 6(1)(f)) — security measures, rate limiting, and abuse prevention to protect our infrastructure and users, as well as application diagnostics, usage statistics and stability to improve the product
- Consent (Art. 6(1)(a)) — analytics cookies (Google Analytics 4), beta program signup, and contact form submissions, where you voluntarily provide your data or give explicit consent
05
/ 12 · Timing
Data Retention
We retain your data only as long as necessary:
- Account data — retained until you request account deletion
- Rate limiting data — automatically deleted after 5 minutes
- Contact form messages and support tickets — retained for 1 year, then deleted (except as needed to handle any pending disputes)
- Beta signups — retained until the beta program ends
- Payment history — retained for the duration of your account and as required by Italian tax and accounting obligations
- Analytics data (GA4) — retained according to Google Analytics default retention policies (14 months)
- Receipts and accounting documents — retained for 10 years from the date of issue, in compliance with art. 2220 of the Italian Civil Code and Italian tax law
- Chatbot conversations — retained for 6 months from the last message, except when associated with an open support ticket
- Moderation incidents and blocks — retained until the natural expiry of the block; serious incidents may be retained longer to prevent repeated abuse
- Contest entries — published entries remain associated with the contest after it closes; you can request their removal by contacting us. Images and 3D models of rejected or removed entries are deleted from our servers within 30 days
- Diagnostic and crash reports — retained for as long as necessary to diagnose and fix malfunctions and to analyze stability per version, then deleted or kept only in aggregated and anonymous form
- Application usage statistics — retained for 180 days from collection, then automatically deleted
06
/ 12 · Rights
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — you can request a copy of the personal data we hold about you
- Right to rectification — you can ask us to correct inaccurate or incomplete data
- Right to erasure (“right to be forgotten”) — you can request deletion of your personal data
- Right to data portability — you can request your data in a structured, machine-readable format
- Right to object — you can object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please email us at info@g-loop.it. We will respond within 30 days as required by law. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
07
/ 12 · Browser
Cookies
We use the following categories of cookies:
Strictly Necessary Cookies
These cookies are essential for the website to function. They include your session cookie (PHPSESSID) for authentication and a language preference cookie (lang). These cannot be disabled.
Analytics Cookies
With your explicit consent, we use Google Analytics 4 to understand how visitors interact with our website. GA4 sets the following cookies:
- _ga — distinguishes unique users (duration: 2 years)
- _ga_<ID> — maintains session state (duration: 2 years)
Analytics cookies are loaded only after you give explicit consent via our cookie banner. The banner offers three options: “Accept All”, “Customize” (with a separate toggle for analytics), and “Reject”. You can change your preferences at any time by clicking “Cookie Settings” in the footer. IP addresses are anonymized.
08
/ 12 · Vendors
Third-Party Services
We use the following third-party services:
- PayPal — for payment processing. When you make a purchase, your payment data is handled directly by PayPal and is subject to PayPal’s Privacy Policy. We do not store your payment card details or PayPal transaction details. We only retain the date and status of each payment for subscription management.
- Google Fonts — web fonts are loaded from Google’s CDN. This means your browser makes requests to Google’s servers when loading our website. See Google’s Privacy Policy.
- Google Analytics 4 — website usage analytics, loaded only with your consent. IP addresses are anonymized. Aggregated analytics data is also accessible from our website’s admin interface. See Google’s Privacy Policy.
- Google OAuth — optional login via Google account. When you choose to sign in with Google, we receive your first name, last name, and email address. Your Google password is never shared with or stored by us. See Google’s Privacy Policy.
- OpenAI — we use OpenAI APIs for the support chatbot, automated content moderation (Moderation API) and contest entry review (LLM as judge). Transmitted data includes chatbot message text and the text/images of contest entries; we never transmit your credentials, payment data or G-code files to OpenAI. OpenAI does not use API data to train its models (OpenAI 2026 policy). See OpenAI’s Privacy Policy.
09
/ 12 · Defense
Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- HTTPS encryption for all data in transit
- Bcrypt password hashing (passwords are never stored in plaintext)
- Prepared statements for database queries to prevent SQL injection
- CSRF protection on all forms
- Rate limiting on authentication, contact, chatbot, voting and download endpoints
- Optional two-factor authentication (TOTP 2FA) and suspicious-login protection
- Automated moderation of user-generated content (chatbot and contests) via Moderation API + AI review before publication
- Distribution of the desktop application with code signing issued to MEGADV di Andrea Tedesco, to guarantee the authenticity and integrity of the executable and protect automatic updates from tampering
10
/ 12 · Geography
International Data Transfers
Your data is stored on EU servers provided by Aruba S.p.A., located in Italy. We do not transfer your personal data outside the European Economic Area (EEA), except where third-party services (PayPal, Google Fonts, Google Analytics, Google OAuth, OpenAI) may process data on their own infrastructure as described in Section 8. For transfers to third countries we rely on European Commission adequacy decisions or the Standard Contractual Clauses where required by the GDPR.
11
/ 12 · Updates
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.
12
/ 12 · Contact
Contact
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact the data controller:
MEGADV di Andrea Tedesco
Piazza dei Mille 18, 88049 Soveria Mannelli (CZ), Italy
Email:
info@g-loop.it
Website:
www.g-loop.it
Data controller
Have a GDPR request?
Write to us.
To exercise your rights, or for any other question regarding the processing of your data, please contact the controller at the details below.
MEGADV di Andrea Tedesco
Piazza dei Mille 18 · 88049 Soveria Mannelli (CZ) · Italia