Legal
Privacy Policy
Last updated 23 August 2026
1. Who is responsible
GeoFilament (“we”, “us”) operates terraprint.web.app and is the data controller for the personal data described here. GeoFilament is established in Iceland. For anything in this policy, including any of the rights in section 8, write to info@mochi.is.
2. What we collect, and when
Browsing and building a model — nothing
The studio is a static site: the map is framed, the data is fetched and the mesh is generated in your browser. We do not run analytics, advertising, session recording or error reporting, and we do not receive the place you searched for, the frame you chose or the model you built. If you never reach checkout, we hold no personal data about you at all.
Buying a model — an order record
When you complete a checkout, one document is written to our database. It contains:
- the email address you enter for your receipt;
- the name of the place, the centre coordinates, the compass bearing and the width of the frame;
- the print settings — plate size, grid, scale, terrain exaggeration and which layers are switched on;
- the share link, which is those same settings encoded as a URL;
- what the build came out as — building, tree and triangle counts, volume and relief;
- the price, the currency and the time of purchase.
We keep the description rather than the mesh: the link rebuilds the identical plate from the same open sources, so there is no copy of your model on our servers.
That order record cannot be read from a browser at all — not by you, and not by anybody else. So a second, separate document is written beside it, holding only what you need to open your model again: the share link, the place name, the plate size and grid, and the date. It contains no email address and no price. It is readable by anyone who has the address we give you at checkout — a long random one, which is what keeps it yours — and it is what the “print it again” link on your receipt reads. If you would rather it did not exist, ask us and we will delete it; your order record and your files are unaffected.
Payment details — none
Checkout currently runs in demo mode. No card is charged, the card fields on the form are fixed placeholder values, and no card data is collected, transmitted or stored by anyone. When real payments are introduced they will be handled by a payment provider, this policy will be updated to name it, and card details will go to that provider rather than to us.
On your own device — local storage
We set no cookies. A few values are kept in your browser’s local storage, where they stay on your device and are never sent to us:
geofilament_orders— your receipts, so the studio can re-open a model you have paid for (andterraprint_orderson a device that bought one before we changed our name);geofilament_auth— if you have signed in, the token that keeps you signed in. It is sent to Google’s identity service to renew your session and to us to prove which account is asking for its own list of models, and to nobody else. Signing out removes it;- which map data source the studio last used;
- which map servers recently answered or failed, so a slow one is not tried first every time.
Clearing site data in your browser removes all of it.
3. Why we are allowed to hold it
- To perform our contract with you — the order record and the email address exist so we can deliver what you bought, send a receipt and answer a question about a purchase.
- Our legitimate interests — keeping a record of sales, understanding what was actually built when something goes wrong with a file, and preventing abuse of the service.
- Legal obligation — sales records have to be retained for accounting and tax purposes once real payments begin.
4. Services your browser talks to
Building a model means requesting open map and elevation data. Those requests go directly from your browser to the services below — they do not pass through us — so each of them sees your IP address, your browser’s user agent and the area you asked about, exactly as it would if you visited its own website. Each operates under its own privacy policy.
This is the whole list, and it is the same list the software is built from rather than a description of it: the hostnames under each entry are the ones in our source code, and a check that runs before every change refuses any host that is reachable and not named here. Everything else the site needs — the code, the pictures and the typefaces — is served from our own domain.
- OpenStreetMap data (Overpass API) — the buildings, roads, water and woodland your model is built from. These are public mirrors of the same data and a build may go to any of them, because we ask more than one and keep whichever answers first.
overpass-api.demaps.mail.ruoverpass.openstreetmap.froverpass.kumi.systemsoverpass.private.coffee - Nominatim (OpenStreetMap Foundation) — the place search in the picker, queried when you submit a search rather than as you type.
nominatim.openstreetmap.org - AWS Terrain Tiles (Amazon S3) — the elevation data the ground of your model is shaped from.
s3.amazonaws.com - Open-Meteo — a cross-check on a handful of elevation points, used to catch faults in the data above.
api.open-meteo.com - OpenFreeMap — the map drawing in the picker, so you can see the place you are framing. They publish the map itself and ask for no account, so nothing identifies you to them beyond the request.
tiles.openfreemap.org - Stadia Maps — aerial imagery for the picker, where this deployment is configured for it. The plain map view needs nothing from them.
tiles.stadiamaps.com - Firebase Authentication (Google) — the optional account. If you sign in, your email address and password are handled by Google’s identity service on our behalf — we never see the password — and your browser renews that sign-in with them while you stay signed in. Nothing here is reached unless you create an account or sign into one.
identitytoolkit.googleapis.comsecuretoken.googleapis.com - Google account sign-in — signing in with Google, if you choose to. Pressing that button opens Google’s own sign-in page, where you deal with Google directly; they tell us your email address and the name on your account and nothing else. Where this deployment has no Google sign-in configured, the button is not shown and nothing is sent to them.
accounts.google.com - Google Cloud Firestore — where the single order document is stored, the re-open record that lets you download a model you have bought again, the list of those records shown on your account page if you have one, and the link preview picture for a model you share.
firestore.googleapis.com - Stripe — takes the payment. Pressing the buy button sends you to their page, where you give them your card details and your email directly; they tell us only that a particular order was paid for, and they send your receipt. We never see or store a card number. Where this deployment has no payment configured, checkout is a demo and nothing is sent to them.
checkout.stripe.com - Google Firebase Hosting — serves this site — the pages, the code and the typefaces — and logs requests for it as any web host does.
terraprint.web.app
Google and Amazon process data outside the European Economic Area. Where that happens, transfers rely on the European Commission’s standard contractual clauses or an equivalent safeguard.
5. Who we share it with
We do not sell personal data and we do not share it for advertising. The order record is held by Google Cloud on our behalf as a processor. Beyond that, we disclose personal data only where we are legally required to.
6. How long we keep it
Order records are kept for as long as we need them to support the purchase, and thereafter for as long as accounting and tax law requires a record of a sale. You can ask us to delete an order earlier; where a retention obligation applies to part of it, we will tell you which part and why. Anything in your browser’s local storage stays until you clear it.
7. Security
The site is served over HTTPS. Your order record — the one holding your email address and what you paid — accepts a new order from a browser and nothing else: it cannot be read, changed or deleted from the public site, so no customer can retrieve another customer’s order.
The separate re-open record described in section 2 can be read, which is what makes your “print it again” link work. Two things bound that. It holds no email address and no price, so there is nothing in it to identify you; and it can only be fetched one document at a time, at an address of twenty random characters, so the collection cannot be listed or walked and an address cannot be arrived at by guessing. Neither record can be edited or deleted from a browser once written. No system is perfect, and we do not claim otherwise.
8. Your rights
If you are in the EEA or the UK you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable form. Email info@mochi.is from the address you used at checkout and we will act on it. There is no charge, and we will answer within one month.
If you think we have handled your data badly, you may complain to a data protection authority — for us that is Persónuvernd (the Icelandic Data Protection Authority), and you may also complain to the authority where you live.
9. Children
GeoFilament is not aimed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us their details, write to us and we will delete them.
10. Changes
When this policy changes, the date at the top of the page changes with it. Material changes — a new category of data, a new processor, a payment provider — will be described here rather than folded in silently.