Legal
Privacy Policy
Last updated 23 August 2026
1. Who is responsible
GeoFilament (“we”, “us”) operates geofilament.mochi.is and is the data controller for the personal data described here. GeoFilament is established in Iceland. For anything in this policy, including any of the rights in section 8, write to info@mochi.is.
2. What we collect, and when
Browsing and building a model — counts, with nothing that names you
The studio is a static site: the map is framed, the data is fetched and the mesh is generated in your browser. What leaves it is a short record of what happened, so we can tell which parts of the studio work — a page was opened, a model started building, a build finished or failed, a checkout was opened, a file was downloaded, a link was shared. Each one carries:
- the path of the page (
/studio,/gallery/paris) — never the query string, which for a model is the centre coordinates; - the print settings — plate size, grid, whether the frame is turned, the price band — and, for a build, what it came out as: the triangle count, the number of buildings and how long it took;
- the name of the place, as the picker labelled it (“Bergen”, “Custom area”), which is the name we publish for 247 cities in the gallery already;
- the domain that linked you here, your screen size, and the random identifier described under local storage below.
It carries no email address, no account, no coordinates and no share link. We cannot tell from it who you are, and we cannot reconstruct the frame you chose. We do not run advertising, session recording or error reporting of any kind.
We use PostHog for this, on their European servers; they are listed in section 4 with everyone else your browser talks to. If you would rather send nothing, use the button below — and if your browser already sends Global Privacy Control or Do Not Track, we honour it and this was never on in the first place.
That includes crashes. If a screen stops drawing, the page offers to copy a short report — the build, the address you were on, the error and your browser version — to your clipboard, and shows you the text first. Nothing is sent anywhere unless you send it to us yourself.
Buying a model — an order record
When you complete a checkout, one document is written to our database. It contains:
- the email address you enter for your receipt;
- the name of the place, the centre coordinates, the compass bearing and the width of the frame;
- the print settings — plate size, grid, scale, terrain exaggeration and which layers are switched on;
- the share link, which is those same settings encoded as a URL;
- what the build came out as — building, tree and triangle counts, volume and relief;
- the price, the currency and the time of purchase.
We keep the description rather than the mesh: the link rebuilds the identical plate from the same open sources, so there is no copy of your model on our servers.
That order record cannot be read from a browser at all — not by you, and not by anybody else. So a second, separate document is written beside it, holding only what you need to open your model again: the share link, the place name, the plate size and grid, and the date. It contains no email address and no price. It is readable by anyone who has the address we give you at checkout — a long random one, which is what keeps it yours — and it is what the “print it again” link on your receipt reads. If you would rather it did not exist, ask us and we will delete it; your order record and your files are unaffected.
Signing in — the account a purchase is filed under
Buying a model is done signed in: the studio asks for your account before the checkout opens, and the purchase is written onto it — so the models you have bought stay findable when a browser is cleared or you print from another machine, not only for as long as you keep the address on your receipt. Everything else needs no account: browsing, building a preview, and re-opening or downloading a model you already bought all work from the receipt address alone.
If you sign in, we hold:
- your email address, and the name you give if you give one — handled for us by Google’s identity service, which is also where your password is set and checked. We never see or store a password;
- an account identifier, written onto the purchases you make while signed in. That identifier is the whole of the link between you and them: it is what your own list matches on, and our database refuses a request for anybody else’s.
Signing in with Google tells us your email address and the name on your Google account and nothing else — no contacts, no calendar, no profile picture. A purchase made before signing in was required carries no identifier and simply does not appear in the list; it keeps working exactly as it did, from the address on its receipt. Ask us and we will delete an account, which does not delete the orders the law requires us to keep a record of.
Payment details — handled by Stripe, never by us
Payments are taken by Stripe. Pressing the buy button sends you to a page on Stripe's own domain, where you give them your card details and your email address directly. Those never reach this site: no card number is collected, transmitted or stored by us at any point, and there is no card field anywhere in this app.
Stripe tells us that a particular order was paid for and passes on the email address you gave them, which is what the order record and your receipt are written from. Stripe acts as the merchant of record for the sale, which is why they collect your billing address: it is what any VAT or sales tax is calculated from, and Stripe collects and remits that tax rather than us. Stripe is an independent controller of the payment data you give them and processes it under their own privacy policy; what we hold afterwards is described under “What is stored” above.
On your own device — local storage
We set no cookies. A few values are kept in your browser’s local storage, where they stay on your device and are never sent to us:
geofilament_orders— your receipts, so the studio can re-open a model you have paid for (andterraprint_orderson a device that bought one before we changed our name);geofilament_auth— if you have signed in, the token that keeps you signed in. It is sent to Google’s identity service to renew your session and to us to prove which account is asking for its own list of models, and to nobody else. Signing out removes it;geofilament_bed— the size of your printer’s bed, if you have entered one, so the studio can offer plates that fit it without asking again. It is not part of a model and is never written into a link, an order or a file;geofilament_analytics— a random identifier, so a page opened and a model built in the same visit are counted as one visit rather than two. It is not derived from anything about you or your device, it is not shared with anyone but the analytics service named in section 4, and it is the one value on this list that is sent off your device. Switching analytics off with the button above deletes it;- which map data source the studio last used;
- which map servers recently answered or failed, so a slow one is not tried first every time.
Clearing site data in your browser removes all of it.
3. Why we are allowed to hold it
- To perform our contract with you — the order record and the email address exist so we can deliver what you bought, send a receipt and answer a question about a purchase.
- Our legitimate interests — keeping a record of sales, understanding what was actually built when something goes wrong with a file, and preventing abuse of the service. The usage counts in section 2 rest on this basis too: they carry nothing that identifies you, they exist so we can tell which parts of the studio work, and the balance is what the opt-out on this page is for — you can end that processing for your browser in one click, and we honour Global Privacy Control and Do Not Track without being asked.
- Legal obligation — sales records have to be retained for accounting and tax purposes once real payments begin.
4. Services your browser talks to
Building a model means requesting open map and elevation data. Those requests go directly from your browser to the services below — they do not pass through us — so each of them sees your IP address, your browser’s user agent and the area you asked about, exactly as it would if you visited its own website. Each operates under its own privacy policy.
This is the whole list, and it is the same list the software is built from rather than a description of it: the hostnames under each entry are the ones in our source code, and a check that runs before every change refuses any host that is reachable and not named here. Everything else the site needs — the code, the pictures and the typefaces — is served from our own domain.
- OpenStreetMap data (Overpass API) — the buildings, roads, water and woodland your model is built from. These are public mirrors of the same data and a build may go to any of them, because we ask more than one and keep whichever answers first.
overpass-api.demaps.mail.ruoverpass.openstreetmap.froverpass.kumi.systemsoverpass.private.coffee - Nominatim (OpenStreetMap Foundation) — the place search in the picker, queried when you submit a search rather than as you type.
nominatim.openstreetmap.org - AWS Terrain Tiles (Amazon S3) — the elevation data the ground of your model is shaped from.
s3.amazonaws.com - Open-Meteo — a cross-check on a handful of elevation points, used to catch faults in the data above.
api.open-meteo.com - OpenFreeMap — the map drawing in the picker, so you can see the place you are framing. They publish the map itself and ask for no account, so nothing identifies you to them beyond the request.
tiles.openfreemap.org - Firebase Authentication (Google) — the optional account. If you sign in, your email address and password are handled by Google’s identity service on our behalf — we never see the password — and your browser renews that sign-in with them while you stay signed in. Nothing here is reached unless you create an account or sign into one.
identitytoolkit.googleapis.comsecuretoken.googleapis.com - Google account sign-in — signing in with Google, if you choose to. Pressing that button opens Google’s own sign-in page, where you deal with Google directly; they tell us your email address and the name on your account and nothing else. Where this deployment has no Google sign-in configured, the button is not shown and nothing is sent to them.
accounts.google.com - Google Cloud Firestore — where the single order document is stored, the re-open record that lets you download a model you have bought again, the list of those records shown on your account page if you have one, and the link preview picture for a model you share.
firestore.googleapis.com - Stripe — takes the payment. Pressing the buy button sends you to their page, where you give them your card details and your email directly; they tell us only that a particular order was paid for, and they send your receipt. We never see or store a card number. Where this deployment has no payment configured, checkout is a demo and nothing is sent to them.
checkout.stripe.com - PostHog — product analytics — which pages are opened, how many models are built and how many of those are bought, so we can tell which parts of the studio work. It is sent from your browser to their European servers, it carries no name, email address or coordinates, and you can switch it off on this page. Where this deployment has no analytics configured, nothing is sent to them at all.
eu.i.posthog.com - Google Firebase Hosting — serves this site — the pages, the code and the typefaces — and logs requests for it as any web host does.
geofilament.mochi.is
Google and Amazon process data outside the European Economic Area. Where that happens, transfers rely on the European Commission’s standard contractual clauses or an equivalent safeguard.
5. Who we share it with
We do not sell personal data and we do not share it for advertising. The order record is held by Google Cloud on our behalf as a processor. Beyond that, we disclose personal data only where we are legally required to.
6. How long we keep it
Order records are kept for as long as we need them to support the purchase, and thereafter for as long as accounting and tax law requires a record of a sale. You can ask us to delete an order earlier; where a retention obligation applies to part of it, we will tell you which part and why. Anything in your browser’s local storage stays until you clear it.
7. Security
The site is served over HTTPS. Your order record — the one holding your email address and what you paid — accepts a new order from a browser and nothing else: it cannot be read, changed or deleted from the public site, so no customer can retrieve another customer’s order.
The separate re-open record described in section 2 can be read, which is what makes your “print it again” link work. Two things bound that. It holds no email address and no price, so there is nothing in it to identify you; and it can only be fetched one document at a time, at an address of twenty random characters, so the collection cannot be listed or walked and an address cannot be arrived at by guessing. Neither record can be edited or deleted from a browser once written. No system is perfect, and we do not claim otherwise.
8. Your rights
If you are in the EEA or the UK you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable form. Email info@mochi.is from the address you used at checkout and we will act on it. There is no charge, and we will answer within one month.
If you think we have handled your data badly, you may complain to a data protection authority — for us that is Persónuvernd (the Icelandic Data Protection Authority), and you may also complain to the authority where you live.
9. Children
GeoFilament is not aimed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us their details, write to us and we will delete them.
10. Changes
When this policy changes, the date at the top of the page changes with it. Material changes — a new category of data, a new processor, a payment provider — will be described here rather than folded in silently.