Who runs PanelOrca
PanelOrca ("we", "us") is an independent, remote-first project. We are in the process of formalising the operating entity; this page will be updated when that happens.
For privacy questions, contact hello@panelorca.com.
What data we collect
Account data
- Email address (required to create an account)
- Full name (optional, displayed in your organization)
- Password (stored as a bcrypt hash — we never see the plaintext)
- Profile photo (optional, uploaded by you)
- Preferred language
- System role (admin / user — defaults to user)
If you sign in with Google
- Your Google account email and full name
- Your Google profile photo URL
- A Google-issued user identifier ("sub") to recognise you on return
We do not receive or store any other Google data (contacts, calendar, drive, etc.).
Project data
- Project files you choose to sync — names, descriptions, model JSON, BOM data, machining instructions, label designs, custom materials and connectors you create
- Thumbnails generated from your projects
- Membership in organizations and which projects you have access to
Technical data
- IP address and request metadata (URL, user agent, response time, error code) — kept in server logs for up to 30 days for diagnostics and abuse prevention
- Authentication tokens issued to your device
Which tools you use
When you are signed in, the SketchUp extension counts how many times each of its tools is opened and sends those counts every few minutes. A count is the name of a tool and a number — nothing about what you were working on.
- What is sent — the tool's internal name (for example
create_layoutbox) and how many times it was used - What is never sent — anything from your model: part names, dimensions, geometry, materials, file names or file paths
- Why — to develop the product. A tool almost nobody opens tells us either that we explained it badly and owe you a tutorial, or that it needs to work differently. Without this we are guessing at which parts of PanelOrca are worth our time
- When — only while you are signed in. It is not a setting you switch on or off in the extension; signing out stops it, and deleting your account removes the counts with it
What we do not collect
- Payment information — payments are processed by Paddle as Merchant of Record; we never receive or store your card details
- Content telemetry — we count tool usage as described above, but never the contents of a model, a screen recording, or anything you type
- Third-party tracking — the landing site does not embed advertising trackers
Why we use it
- To create and authenticate your account
- To sync your projects between SketchUp and the cloud, and between your devices
- To deliver transactional email (account verification, password reset, organization invitations)
- To enforce free-tier limits (e.g. number of projects per organization)
- To diagnose errors and prevent abuse
- To develop the product — including seeing which tools go unused, so we know what to document better or redesign
We do not sell your data, share it with advertisers, or use it to train external AI models.
How long we keep it
- Account data — for as long as your account is active
- Project data — until you delete the project or the account
- Server logs — up to 30 days
- Tool usage counts — for as long as your account is active, and removed with it
- Transactional email metadata at Resend — per Resend's retention policy
- Deleted accounts and projects — soft-deleted for up to 30 days, then permanently removed from primary storage. Backups containing soft-deleted rows roll off within 90 days
Where it's stored
- Primary database: PostgreSQL on a DigitalOcean Droplet in Singapore (Asia-Pacific)
- Files (thumbnails, avatars, project assets): same Droplet's disk
- Off-site database backups: Cloudflare R2 (object storage), retained for disaster recovery — see Cloudflare's privacy policy
- Transactional email: Resend — see their privacy policy
- Inbound email forwarding: Cloudflare Email Routing — see their privacy policy
- DNS & edge: Cloudflare
Your rights
You can:
- Access your data — visit Settings to view your account fields, or export projects you own
- Correct your data — edit your profile or organization in-app
- Delete your account and projects — write to hello@panelorca.com and we will delete within 30 days. You may also delete individual projects yourself
- Object to specific uses — write to us and we will respond
- Withdraw consent — where we ask for consent, you can withdraw it at any time without losing access to the product
If you are in the EU/EEA, UK, or another jurisdiction with similar laws, you also have the right to lodge a complaint with your local data protection authority. We will cooperate with reasonable requests from such authorities.
Children
PanelOrca is not directed at children under 16. If you believe a child has created an account, contact hello@panelorca.com and we will delete it.
Security
We use industry-standard practices — TLS everywhere, bcrypt for passwords, short-lived access tokens with refresh-token rotation, server-side authorization on every protected endpoint, and per-organization access scoping. See Security Overview for more detail.
No system is perfectly secure. If you discover a vulnerability, please email hello@panelorca.com rather than disclose it publicly, so we can fix it before it is exploited.
Changes to this policy
We will update this page when our data practices change. The effective date at the top shows when the current version was published. For material changes, we will additionally notify active users by email.