NestorCut
Features How it works Pricing FAQ Blog
FR Log in Start free

Privacy

Last updated: August 2026. We would rather under-promise than over-claim: everything below describes what the service actually does today.

NestorCut nests your parts. That requires your geometry, and geometry from a workshop is often sensitive: quotes, customer parts, production methods. This page explains, mode by mode, exactly where your data goes, how long it stays, and where the limits of our promises are.

1. The three ways to compute

Local mode (“On your machine”): 100% private by default

New projects are 100% private by default: your source file (DXF/SVG) is parsed in your browser and never uploaded, the nesting engine runs in your browser (WebAssembly), and your results never leave it either. Layouts, exports and reports are stored in your browser's local storage (IndexedDB). For these projects the server only receives administrative metadata (project name, quota counters), never file content, never geometry.

Two limits, stated plainly. A 100% private project lives only in the browser that created it: your account lists it on every device, but its files and results exist on that machine alone. And DWG files still require server-side conversion: importing a DWG means unchecking the 100% private option at creation; the source file is then uploaded and purged after 24 hours like any Server-mode file, while on-device compute still keeps your results in your browser.

Server mode

The engine runs on our servers, in France. Your file is processed in memory during the job, then both the source file and the results are deleted automatically after 24 hours. The report we keep holds numbers only: material density, compute time, number of sheets. No geometry. You can also delete a project yourself at any time, from your account, without waiting for the purge.

Vault (zero-knowledge, opt-in on every plan)

The Vault is optional and available on all plans. It is never a paid feature. When you enable it, your files are encrypted at rest with AES-256-GCM, using a key that only you hold (a downloadable key file). Without that key, the data is permanently unreadable, including by us, including with full access to our servers and backups.

The trade-off is absolute: lose the key and the data is gone; there is no recovery procedure, and we cannot help.

During an unlocked session, the key lives only in the server's volatile memory, never written to disk, not even encrypted, and it is handed to the compute workers job by job through an ephemeral key exchange. Vault files are exempt from the 24-hour purge: they stay encrypted, readable by you alone, until you delete them.

2. Retention

  • Account (email, preferences): kept until you delete your account, self-service, from your account settings.
  • 100% private projects (Local mode default): nothing to purge. File content and results never reach the server. The project entry holds a name and counters only, and is deleted with the project.
  • Server-mode files (sources and results): deleted automatically after 24 hours. Reports keep only figures (density, compute time, sheet count).
  • Vault files: kept encrypted until you delete them.
  • Product events (e.g. which buttons are clicked): retained to improve the product. They never contain file content or geometry. The server accepts only a strict allowlist of event names.

3. What we do not claim

This section exists because trust is the whole point, and trust dies on vague promises.

  • During processing, your file exists in cleartext in the server's RAM, for a few seconds to a few minutes. That is the only moment, and it is never written to disk. A malicious administrator or a compromised machine could theoretically access it. We promise processes (automatic purging, encryption at rest, a key that is never persisted), not magic.
  • Local mode removes that exposure entirely for 100% private projects: files, compute and results all stay in your browser. The exception is the cloud project you explicitly choose at creation (DWG import, multi-device access): its source file transits through the server, and we say so plainly rather than hide behind the word “local”.
  • We do not claim “end-to-end encryption” (the server processes cleartext in memory), nor “no logs”, nor anonymity.

4. Hosting and subprocessors

The application (app.nestorcut.com), its database and your files are hosted in France, on infrastructure operated by Guillaume Jerke EI (APlasma). This marketing website (nestorcut.com) is hosted by Cloudflare, Inc. (USA); see the Legal Notice.

  • Stripe: payment processing. We never see or store your card numbers.
  • Resend: transactional emails (account, receipts, support).

The marketing website measures its audience in aggregate form using Google Analytics 4 with IP anonymization enabled. No file content, no geometry and no application data are involved.

5. Your rights (GDPR)

Under the GDPR you have the right to access, rectify and erase your personal data, and to receive an export of it on request. Account deletion is self-service from your account settings. For anything else, write to [email protected].

The data controller is Guillaume Jerke EI (APlasma), Saint Martin Lalande, 11400, France. If you believe your rights are not respected, you may lodge a complaint with the CNIL (cnil.fr).

6. Contact

Questions about this page or about how a specific mode handles your data: [email protected].

NestorCut

True-shape nesting for laser, plasma & CNC cutting. Made by APlasma.

Newsletter

Release notes & nesting tips. No spam — unsubscribe in one click.

Product

Features Pricing Start free

Resources

Blog FAQ How it works Contact us Discord community

Legal

Legal Notice Terms of service Privacy policy Refund policy

© 2026 NestorCut · APlasma. All rights reserved.

NestorCut is under very active development — a bug you hit today may already be fixed tomorrow.