Privacy policy
Updated 24 September 2026
CadFreely is a web app for viewing and editing CAD drawings. Local drawing tools work without an account. Email and password, Google or Facebook sign-in is used for optional online storage and AI assistance, when that method is available.
Local drawings and browser storage
Your browser stores drawing recovery copies, recent-session information and drafting preferences on your device. The app asks before restoring a previous session. Local Save uses your connected file when the browser supports it; otherwise you can download a copy.
DWG import can run in your browser. When server conversion or file export is used, the file or drawing data is sent to CadFreely's server for processing. Server import copies and conversion caches can remain available to your browser session for reopening files and loading block definitions. These processing copies are separate from drawings you deliberately save online.
Google sign-in
When you choose Google sign-in, CadFreely receives your Google account identifier, verified email address, name and profile-picture address. The server uses these details to identify your account, display your profile, restrict access to your online drawings and track AI usage. CadFreely does not receive your Google password or request access to your Gmail, Google Drive or contacts.
Email, passwords and linked accounts
When email sign-in is enabled, Google Firebase Authentication verifies email ownership, stores password credentials securely and sends verification and password-reset emails. Your password travels over HTTPS through CadFreely's server to Firebase; CadFreely does not store it in its account database or browser storage. CadFreely stores the verified account identifier, email, available sign-in methods and a private link to your existing CadFreely account. Connecting Google requires verified access, so linked methods use the same online drawings, AI allowance and permissions. Accounts are not merged merely because an unverified email matches.
Private sign-in cookies last up to seven days. Password recovery or disabling an account invalidates Firebase-backed CadFreely sessions, with revocation status cached for up to 30 seconds. Temporary abuse-prevention counters use hashed email and network identifiers and expire after their rate-limit window; database deletion can occur later. Firebase processes authentication under Google's Privacy Policy.
Facebook sign-in
When you choose Facebook sign-in, CadFreely receives your app-scoped Facebook identifier, name, profile-picture address and email address if Facebook provides it with your permission. These details identify your CadFreely account, display your profile and associate your online drawings and AI usage with that account. CadFreely does not request your Facebook password, friends, posts, pages or messages.
Facebook verifies your identity in its own window. CadFreely's server uses the resulting authorization code and access token to verify the app and user, then discards the access token. The token is not sent to the drawing app or saved in your account. Short-lived login states prevent replay; expiration stops a state from being used but does not guarantee immediate deletion of its stored record.
Google and Facebook are separate sign-in methods. CadFreely does not combine their accounts based on matching email addresses. Use the same method to return to your existing drawings and subscription. Facebook processes sign-in according to its Privacy Policy.
Sign-in and import-session cookies keep account access and import files associated with the correct browser. Signing out ends your CadFreely sign-in session; it does not delete your account or drawings.
Online storage
When you choose online storage, CadFreely's server stores your drawing content, its name, revision and save time under your account. Drawings are private unless you deliberately create a sharing link or authorize an integration. Local drawings are not automatically added to online storage when you sign in.
Drawing sharing
You can create Viewer, Editable or Full access links for saved online drawings. Anyone holding a link can use its permissions, including someone it is forwarded to. The interactive viewer sends drawing geometry to the recipient's browser for pan, zoom, dimension inspection and measurements. Viewer mode disables editing and object copying. Editable access requires sign-in and lets recipients save changes to your shared drawing and copy/paste objects between drawings, even when file downloads are disabled. Explicitly copied objects may be retained in the recipient's tab clipboard and cannot be recalled by closing a link. Full access also permits independent downloads and printing. Sharing is optional and links are excluded from our sitemap and marked not to be indexed.
CadFreely stores permission records, hashed link tokens, drawing previews and the account identifier responsible for the latest shared edit. Shared recipient pages keep their state in memory rather than creating automatic browser recovery copies. You can close a link to block future server access; open pages periodically check access. Closing a link cannot recall prior downloads, screenshots or data already received. Copy, download and print controls restrict the app's tools; they cannot prevent screenshots or deliberate extraction of geometry from an interactive viewer or editor.
AI assistance
When you submit an AI request, CadFreely sends your prompt and relevant command or drawing context through its server to OpenAI. Copilot starts with a drawing overview and can request relevant geometry, labels, attributes, units, layer and block names or areas in bounded batches. It does not upload all drawing objects by default. Command-line AI help uses the same conversation. Ordinary drawing commands do not automatically request AI assistance.
To continue batch requests and prevent duplicate charges, CadFreely keeps up to four recent AI request records per account in private server storage, including the supplied context and replies. Continuations expire after ten minutes; records are replaced by later requests rather than accumulating a full chat archive. Expiration ends access to a continuation but does not automatically delete its stored record. These records are separate from aggregate usage statistics.
When you choose Render to 3D, CadFreely sends a raster view of the selected objects, current drawing or AI preview, bounded drawing measurements and recent chat to OpenAI's image service. Visible attached pictures may be included in that view. The generated concept image is stored privately for recovery and download; up to two recent render results per account are kept and replaced by newer renders. The download recovery link expires after 24 hours; expiry does not guarantee immediate deletion of stored image data.
CadFreely records AI usage and quota information against your account. OpenAI requests are subject to its Privacy Policy and applicable API terms. CadFreely disables response storage on OpenAI text drafting requests. Image requests use the Images API. These settings are not a guarantee of zero provider retention. Only include information you want to share with the provider shown in the AI panel.
The Past chats tab stores conversation history, previews and results privately in this browser, separated by signed-in account. This is not cross-device chat synchronization. Clearing site data can remove this history.
Optional AI message sharing
“Help improve CadFreely” is preselected when the sharing notice is first shown in the AI panel and you have no saved preference. You can uncheck it there or in AI → Advanced. An existing choice to switch sharing off stays off. When enabled, future AI requests and text replies can be saved privately for the CadFreely owner to review. These records include your account email, a conversation reference, task category, selected AI model, plan, result or failure code, response time, credits and reported provider cost. They help us understand requested workflows and fix poor results; no extra AI generation is performed to create this log.
Feedback records do not copy drawing files, geometry pages, images, attachments, internal tool messages, authentication headers or server credentials. Messages and replies are limited to 4,000 characters each. Common credential patterns, links, emails and international phone numbers inside message text are masked automatically, but free text can still contain personal or confidential information that automatic filters do not recognize. Avoid sharing confidential details. Your account email is retained separately so the owner can identify reports from your account.
You can switch off sharing in AI → Advanced at any time; this stops future feedback collection without changing your AI allowance or access. Turning it on does not import earlier chats. Shared feedback is unavailable in the owner dashboard after 30 days and scheduled for automatic database deletion; physical deletion and existing hosting backups can persist beyond that time. Existing shared messages remain subject to this retention period when you opt out. Contact us below to request their earlier deletion. Aggregate usage statistics and the short-lived operational records needed to complete AI requests are separate from this optional feedback.
Optional ChatGPT connection
When you connect CadFreely in ChatGPT, you explicitly grant access to your CadFreely identity, credit balance and saved online drawing list. ChatGPT can request bounded summaries, measurements, object pages and native previews for the Selected objects or model View you choose. Local files are not shared automatically. Drawing text and visible attached pictures can be included in requested previews. CadFreely receives only the tool inputs sent by ChatGPT, not your entire ChatGPT conversation. OpenAI handles your ChatGPT conversation under its own terms and privacy policy.
Temporary proposals are private to your account. Unfinished proposals expire after 30 minutes; published review links expire after seven days. Hosted integration records carry automatic database expiry timestamps; removal may occur after access has expired. Credit receipts remain as part of usage accounting. Public client registrations and connection status are retained so reconnection and revocation work reliably. Access tokens last one hour and refresh credentials up to 30 days; stored credentials are hashed. Disconnecting in CadFreely connection settings immediately revokes the connection's credentials. It does not delete drawings, refund consumed credits, or remove information already shared with ChatGPT.
Usage statistics and bug reports
CadFreely records operational AI usage and quota information: AI model, task category, access, request outcome, credits, reported API cost and response time. These aggregate statistics exclude prompts, drawing content and filenames. Account identifiers are hashed for distinct-user counts; larger counts may be estimates.
Optional browser statistics start only when you allow them in Privacy & usage, also available from the app's account area and shared-drawing header. They count file opens, useful drawing actions, sharing, recipient-to-editor conversion and return visits. The server can confirm an active paid subscription during a measured visit; this is separate from authoritative billing records. We do not collect drawing geometry, filenames, comment text, share links, account IDs or browsing history in these browser statistics, and we do not send them to an advertising service.
After consent, first-party cookies named cad_growth and cad_insights may identify the browser for up to 30 days. Only purpose-specific hashes reach the statistics store. Growth profiles stop contributing after 30 days and are removed when their bounded storage bucket is maintained; dormant records and hosting backups can persist longer. Reports cover up to 90 days of anonymous cohort totals. Turning statistics off stops new reports and requests deletion of this browser's growth profile and cookies. A failed deletion can be retried from Privacy & usage. Existing aggregate counts remain. Clearing browser storage or changing devices can count as a different browser. Earlier activity is not backfilled.
If the owner enables client review on a sharing link, signed-in recipients may add comments, drawing-location pins, replies and revision-specific decisions. Account display names, timestamps and feedback are visible to the drawing owner and anyone with that same review link. Feedback is stored separately from native drawing geometry. Owners can resolve threads, disable review or close links; authors and owners can remove comment text. Earlier decisions keep their revision label and do not approve later revisions. Closing a link blocks future recipient access but does not erase retained review history. Contact us using the deletion instructions below for removal of retained reviews and backups.
If you choose Report a bug, your report text, issue category, mobile or desktop device type, sign-in status, app version and submission time are stored in the administrator inbox. A reply email is optional and is sent only with your permission. Drawings and screenshots are not attached automatically. Administrators can add private notes and track each report's status and history.
The app also reports a limited number of technical failures automatically, including their category, app version, browser family, screen size and location within the app bundle. Exception messages, stack traces, page URLs, file names, chat content and drawing data are excluded from these automatic reports. Repeated failures are grouped for troubleshooting. A separate first-party cad_diagnostics cookie, lasting up to one day, helps limit duplicate reports and abuse; it is not used for optional growth statistics.
Hosting, retention and your choices
CadFreely uses Google Cloud hosting. Network requests provide the hosting service with technical information such as your IP address and browser request details. This information may appear in operational and error logs.
To protect online services from excessive requests, CadFreely also keeps a bounded recent activity log for the platform owner. It records the network address (or hosting proxy address where the visitor address cannot be verified), signed-in account ID/name/email when available, action category, online drawing ID and file format where available, AI model, request outcome, transferred byte counts and duration. It does not record drawing contents, prompts, authentication tokens or full file paths. The activity view covers up to 24 hours and at most 1,000 recent records; stored records are pruned when activity is saved, so this is not a promise of immediate deletion after 24 hours. The owner can temporarily restrict an account or a verified network address and review a bounded history of these decisions.
Request, processing and storage safeguards may temporarily pause online operations during excessive usage. Existing local drawings remain open. Online storage reservations include space for original sources and backups; they can exceed the size of the currently saved drawing.
Browser recovery data remains until you clear the site's stored data or the browser removes it. Clearing it can remove unsaved recovery copies and access to cached imports, so save needed files first. Account records and online drawings are stored on the server; this beta does not yet provide automatic account deletion or a fixed automatic deletion period for server import copies.
To request access to, correction of or deletion of data stored by CadFreely, contact eng.kareem.hesham@gmail.com. Include your sign-in method, CadFreely account name, account email if provided, and the relevant drawing name when applicable. We may need to verify that the request concerns your account. See the data deletion instructions. You can also manage CadFreely's connection in your Google Account settings or Facebook's Apps and Websites settings.