This privacy policy is available in German and English. The English version applies to all other app languages.
Effective date: 25 September 2026 · Controller: Software Notion, Sebastian Kruse, Kornblumenring 40, 31600 Uchte, Germany, contact@software-notion.de
This policy describes what the Print Doctor apps for iOS and Android do with your data. It matches the app's actual behaviour. The short version: photos, notes, chats and your history stay on your device. Nothing is uploaded unless you explicitly choose Remote AI for a specific request.
Print Doctor analyses photos of 3D prints, the print settings and notes you enter, and your answers to follow-up questions on your device. This includes image quality checks, the local diagnostic engine and, where your device supports it, the operating system's on-device language model (Apple Intelligence / Foundation Models on iPhone, Gemini Nano on Android). These models run locally; the app does not send this data to Apple or Google.
Stored on your device: diagnoses with their photos (re-encoded without location or camera metadata) and the fixes you marked as tried, before-and-after photos, chat conversations, printer and material profiles with calibration values, maintenance records, drying timers, results of pre-print checks, the printer cameras you added (an API key you enter is kept in the system keychain / Android Keystore), preferences and any AI feedback you leave. You can delete individual items, your whole history, or everything (Settings › Data › Delete all local data). Uninstalling the app also removes this data. Device backups (iCloud / Google backup) may include your history according to your system settings; temporary analysis files are excluded from backups.
Photos are chosen with the system photo picker, which gives the app only the photos you select. The camera is used only when you take a photo of a print.
Print files (G-code, 3MF) you open or share with the app are read on your device to fill in the print settings; the file itself is neither uploaded nor kept, only the values you confirm are stored with the diagnosis.
If you add a printer camera (OctoPrint, Moonraker or a snapshot address), the app connects only to the address you entered, which must be in your local network, and loads still images from it while the camera screen is open. These images stay on your device unless you start a check with Remote AI (section 3). For this the app asks for access to your local network.
Reminders (checking a fix, maintenance, drying timer) are local notifications scheduled on your device; no notification server and no push token are used. The app store's rating dialog is shown by the operating system; we receive nothing from it.
Remote AI is optional. Nothing leaves your device until you choose Remote AI for a request: the app first shows what will be sent and to whom, and you confirm. You can turn Remote AI off and revoke your consent at any time in Settings › Remote AI.
What is sent: the selected photos (downscaled, without metadata) — for the pre-print check the slicer screenshots you chose, for the before-and-after comparison the before and after photos, for a camera check the current camera image —, your observations, print and material settings, notes and, for chat, the conversation and any photos you attach; your language; a pseudonymous customer identifier from our purchase provider; and an app-integrity token from Apple or Google.
Who processes it: our gateway service (hosted by Hetzner Online GmbH in Germany) forwards the request to OpenAI (OpenAI Ireland Ltd., Dublin, Ireland), which runs the AI models for standard analysis, chat and Deep Analysis on our behalf. Our gateway does not store your photos or the text you entered; it keeps only the AI's answer for a short time (see section 10). Your customer identifier is not passed to OpenAI. OpenAI processes the content as our processor under its API terms and data processing addendum: API data is not used to train OpenAI's models, and our gateway instructs OpenAI not to store responses. OpenAI may keep request content for up to 30 days in abuse-monitoring logs; images flagged by OpenAI's child-safety classifier may be retained for manual review even under zero data retention. Processing location: our gateway in Germany; OpenAI processes requests in the USA. Transfers to the USA are based on the EU Standard Contractual Clauses in OpenAI's data processing addendum.
Legal basis: your consent (Art. 6(1)(a) GDPR). Any transfer to the USA relies on the EU-US Data Privacy Framework and/or standard contractual clauses.
To enforce purchased allowances and prevent abuse, our gateway keeps, per pseudonymous customer identifier: plan, units used in the current period, credit purchases already credited, timestamps and abuse flags. It contains no photos and no text you entered. In Settings › Remote AI › Delete stored Remote AI data you can delete the results and reports our gateway holds for you at any time; a request that is still running finishes normally. The counters and the list of credited purchases are kept, because deleting them would credit units and credit packs you have already used a second time. Legal basis: performance of the contract (Art. 6(1)(b)) and our legitimate interest in preventing fraud (Art. 6(1)(f)).
Next to every AI answer in the assistant you can report it, for example if it is offensive, unsafe or wrong. Only when you tap Send, the app sends the reported answer, the reason you picked, your optional comment, the app version, platform, language, whether the answer came from Remote AI or the on-device model, and the pseudonymous customer identifier to our gateway. Nothing else from the conversation and no photos are sent. We read reports to find and fix problematic answers. Reports are kept for up to 90 days and are deleted earlier with Settings › Remote AI › Delete stored Remote AI data. Legal basis: our legitimate interest in keeping the AI answers safe and accurate (Art. 6(1)(f) GDPR) and the app store requirement to offer in-app reporting.
Subscriptions and credit packs are sold through the Apple App Store or Google Play and managed with RevenueCat, Inc. (USA), which receives the store transaction and a pseudonymous identifier. We never receive your payment details. No account is required.
If Remote AI is available in your build, the app downloads non-sensitive settings (e.g. quota sizes, maintenance status) from our gateway. The request contains only the app version, platform and language.
Links to official articles (e.g. Prusa Knowledge Base, Bambu Lab Wiki) open only when you tap them; the respective website's privacy policy applies.
No advertising, no advertising identifier, no tracking across apps or websites, no analytics or crash-reporting SDKs, no sale of data, no training of AI models on your photos.
Device data: until you delete it. Remote request content: not stored by us; for OpenAI see section 3. Results of Remote AI requests (the AI's answer, without photos or text you entered): kept by our gateway for 24 hours so that an automatic retry is not charged twice and deleted by the next daily clean-up, so at most 48 hours. Reports of AI answers: up to 90 days. Usage record: kept while a subscription it accounts for is active or purchased credits remain, then erased; on request earlier, as long as no purchase would be credited again. Server access logs: up to 30 days.
You have the right to access, rectification, erasure, restriction, data portability and objection, and to withdraw consent at any time without affecting prior processing. Most data never leaves your device, so you can exercise these rights directly in the app. For stored Remote AI results and reports, use the in-app deletion; for the usage record, contact contact@software-notion.de. You may lodge a complaint with a supervisory authority.
Print Doctor is not directed at children under 16.
We will update this policy when the app's data handling changes and show the effective date above.