STEP tools · No account needed · Temporary file processing
CADProps · CAD tools

CAD File Privacy, Security & Temporary Storage

Your files stay in a temporary, private guest workspace.

When files leave your browser

Selecting or dropping supported model files immediately starts uploading and processing. Public tool pages open the workspace automatically, including comparison and batch tasks. Files added within the workspace also upload immediately. Real samples use the same server processing pipeline.

What we process

The application temporarily stores the original file and its name, generated display meshes, calculated properties, processing status and error information. Processing runs on the server hosting CADProps; the application does not send CAD files to external processing services or offer public model sharing.

Temporary storage and deletion

The default retention period is one hour from task creation. Upload entry points display the configured duration. Files and results are stored outside the public website directory. Expired resources become inaccessible; physical cleanup runs periodically and resumes after a server restart if the server was offline. Use Files → Delete or Delete all temporary files to remove temporary files and results earlier. Cancelling processing also removes the temporary file. Closing a view, leaving the page or refreshing does not delete server files. Downloaded CSV and image exports remain on your device until you delete them.

Guest sessions and browser storage

An HttpOnly, SameSite session cookie identifies your guest workspace. Every task and model resource request is checked against that session. Workspace URLs alone do not grant access to another session. This is session-based access, not an account login; anyone using the same browser session can access its available files. CAD file contents are not saved in localStorage or IndexedDB. The browser saves unit and layout preferences locally, and closed-view identifiers for the current browser tab. Clearing cookies loses access to existing tasks but does not immediately delete their server files; normal expiry still applies.

Security controls and their limits

The application checks upload type and size, uses random internal file names, validates the origin of write requests and processes geometry in separate processes with resource limits. These controls reduce risk; they are not a guarantee of absolute security or a compliance certification. Connection encryption depends on the installation: an HTTPS address encrypts transport; an HTTP address does not. Storage encryption, infrastructure backups and server-administrator access depend on the operator's deployment. This application does not claim end-to-end encryption or secure erasure from operator-managed backups.

Logging and deployment scope

The application records operational events such as task IDs, formats, processing times, resource use and fixed error codes. It does not record uploaded file contents, original file names, raw IP addresses or session cookies in these events. Operational log files rotate daily and retain up to seven rotated daily files. Google Analytics 4 measures visits to public pages and the workspace and may use analytics cookies and process browser, device and network information through Google. Analytics is not initialized on localhost. Workspace visits use the generic /workspace/ path and page title. Page URLs configured for analytics omit query strings and fragments; initial referrers are reduced to their origin. CADProps does not send uploaded files, file names, task IDs or geometry as custom analytics events. Google Signals and advertising personalization signals are disabled. Hosting infrastructure and reverse proxies may keep separate access logs under the operator's configuration. This statement describes the current CADProps application, not additional services an operator may connect.

Contact

For product support or privacy questions, email support@cadprops.com.