Skip to content
NestSolver

Privacy Policy

Last updated July 11, 2026

What we collect

Account: your email address, sign-in provider, and for email accounts, a hashed form of your password (we never store the password itself).

OAuth sign-in (only if you use it): the sign-in provider's account id for your profile and whether the provider says the email is verified.

Sessions: a random token and when it was created, so signing in keeps working until the session expires.

Saved projects (only if you save one): the name you give it and the form values you saved with it — measurements, blocked zones, kerf, and the rest of the optimizer setup.

Saved presets (only if you save any): the name and measurements of each stock profile or cutter you reuse.

Feedback and contact messages: the email address and message you send, plus which account sent it when you're signed in.

Password reset tokens (only when you request a reset): stored hashed and short-lived, then deleted on use or expiry.

Billing (only if you subscribe): payment processor customer and subscription ids, subscription status, renewal/end date, and cancellation state.

Standard server logs (requested pages, timestamps) kept briefly to operate the service.

Aggregate product usage: daily counts of completed solve attempts, successful solves, and remnant offers included in solved responses, grouped only by public or workspace use and anonymous, Free, or Shop access. The aggregate rows contain no account ids, addresses, or optimizer values.

Aggregate subscription activity: daily counts of eligible pricing views, Stripe Checkout sessions, and verified purchases, grouped only by ordinary pricing, optimizer drop offers, or account settings. One-way hashes of Checkout and subscription identifiers prevent duplicate counts; these hashes are retained so old retries cannot recreate a purchase count and cannot be used to recover the original identifier. These rows contain no account ids, email addresses, or cut data.

DataFast and Google Ads analytics run only on eligible indexable public marketing pages. They do not load in the signed-in workspace, on authentication or password-reset pages, or on optimizer pages whose URL may contain shared cut-list state.

Those public-page analytics may set visitor or session cookies for visit and revenue attribution. If you later start checkout, available attribution identifiers and one fixed checkout-source label may be attached to Stripe Checkout metadata.

After a completed signup, project save, or purchase, a conversion-only analytics bootstrap may run on the completion page after its query string and fragment have been removed. Google Ads page-view tracking is disabled for that bootstrap.

For known crawler traffic on public, non-sensitive routes, the server sends DataFast the requested page path without its query string, response status, crawler user-agent, and a validated IP address from our trusted proxy, together with the site and crawler classification.

What we don't collect

The measurements you type into the optimizer are processed in memory to compute your cut plan and aren't stored on our servers unless you explicitly save them as a project or preset.

Your browser may keep an optimizer draft in local storage so a refresh doesn't lose work. You can clear it from your browser's site data.

The app sets service cookies for sessions, short-lived sign-in, and one-time messages. Public marketing-page analytics may also use visitor or session cookies as described above.

We do not store card numbers or payment details. Our payment processor handles checkout, billing, and payment methods.

Ahrefs provides separate cookieless traffic counts on indexable public pages only.

Service providers

A database hosting provider stores account, project, preset, and billing records.

An application hosting provider runs the web app.

An email delivery provider sends transactional email — password resets, feedback, and contact messages.

An OAuth sign-in provider handles optional third-party sign-in when you choose it.

A payment processor handles subscription checkout, billing, invoices, and payment methods.

DataFast provides eligible public-page analytics, revenue attribution, and server-side public-page crawler reporting as described above.

Google Ads measures ad visits and selected signup or purchase conversions from eligible public marketing pages. Ahrefs measures cookieless traffic on those pages.

Your data is not sold or shared beyond the providers above, all of which process it on our behalf to operate the service.

Current provider names are available on request.

Deleting your data

Email support@nestsolver.com from your account address and we'll delete your account and everything attached to it.