Privacy & security
What happens to your data when you use LIMES, and how the service is protected. Last updated 10 October 2026.
Summary
- The website and the documentation work without an account.
- A free account is needed to use the tool and its examples, and to upload your own files. It stores your name, e-mail address, optional organisation and role, and the files you choose to keep.
- You can download or delete any file, or delete the whole account, at any time.
- Visits are counted anonymously, without cookies; no advertising, no third-party analytics, scripts or fonts.
- All traffic is encrypted with HTTPS.
Accounts
When you create an account, LIMES stores your name, e-mail address, an optional organisation and role, the date the account was created and the time of your last sign-in. Passwords are never stored: only a salted scrypt hash. If you sign in with Google, Google tells LIMES your name, e-mail address and a Google account number; LIMES receives no password and no access to your Google data.
With e-mail sign-up, LIMES sends you a confirmation code; password-reset codes are sent the same way. These messages are the only e-mails LIMES sends.
The data is used only to run your account and to count how many people use LIMES. It is not sold, shared or used for advertising. The site owner (the administrator) can see the list of accounts. You can change your profile or delete the account on the My account page; deletion removes the profile and all your files immediately.
Your files
Without "My files". A file uploaded to the tool is held in the server's memory, linked only to your browser session, while you work. It is discarded when the session ends (closing the tab, or after a period of inactivity) or when you click Start a new session, and it is not visible to other users.
My files. If you are signed in and the setting Keep a copy of my uploads is on (you can switch it off), the 3D models (STL, STEP, IGES) and G-code programs you upload are also kept in your account, and you can save programs generated by LIMES there. They are stored on the LIMES server under random file names, are accessible only through your account, and are deleted when you delete them or your account. Each account has a storage limit.
Files sent to the programmatic API are processed from a private temporary file that is deleted immediately afterwards. Generated G-code, reports and data exports are created on request and downloaded directly to your device.
Visitor statistics
To know how many people use the project, LIMES counts page views and tool sessions on its own server. It records the page, the time, the name of the referring website (for example google.com, never the full address), the device type (desktop, tablet or mobile) and, if you are signed in, your account. To count different visitors without cookies, the server combines your IP address and browser version with a random value that changes every day and keeps only a short hash of the result; the daily value is then deleted, so visits cannot be linked from one day to the next or back to an IP address. Browsers that send Do Not Track or Global Privacy Control are not counted. Statistics are kept for at most 400 days.
Cookies
LIMES uses only technical cookies; there are no advertising or tracking cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-aa_session | Keeps you signed in. Random value, not readable by scripts (HttpOnly), sent only over HTTPS and only to this site. | 30 days or until you sign out |
aa_signed_in | Lets the website show "My account" instead of "Sign in". Contains only the value 1. | Same as the session |
__Host-aa_oauth | Protects Google sign-in against forgery; set only while you sign in with Google. | 10 minutes |
_streamlit_xsrf | Protects file uploads in the tool against cross-site request forgery. | Browser session |
Server logs
Like any web server, the service records technical access logs: time, requested page, status code, browser type and IP address. They are used only to operate and protect the service, for example rate limiting and investigating errors. They are deleted automatically after 14 days. Application error logs contain a reference code and the type of error, but never passwords or the contents of uploaded files. To stop password guessing, failed sign-in attempts are counted per e-mail address and per network for 15 minutes to 24 hours (network addresses only as a hash).
Third parties
Pages and the tool are served entirely from this server. No external content-delivery networks, analytics services or fonts are used, so your browser makes no requests to third parties while you use LIMES. Exceptions you choose yourself: if you click Continue with Google, your browser goes to Google to sign in (Google's own privacy policy applies there); and confirmation and password-reset e-mails are delivered through the site's e-mail provider. The TLS certificate is issued by Let's Encrypt.
Security measures
| Area | Measure |
|---|---|
| Transport | HTTPS only (TLS 1.2+), HTTP redirected, HSTS |
| Browser protections | Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy |
| Uploads | Type allow-list, size limit, structural check, triangle limit, coordinate sanity check, no storage by default |
| Input validation | Bounded numeric inputs in the tool; strict schemas, ranges and identifier patterns in the API |
| Errors | Users see a friendly message and a reference code; details stay in the server log |
| Accounts | scrypt password hashes, password rules, e-mail confirmation codes that expire after 15 minutes, throttling of failed sign-ins, HttpOnly/Secure/SameSite session cookies, same-origin checks against cross-site requests, Google sign-in with state, PKCE and nonce |
| My files | Only 3D models (STL, STEP, IGES) and G-code, validated by content; size and storage limits; random file names; every download checks that the file belongs to the signed-in account |
| Access control | Administrative functions need a secret token and are blocked at the proxy; the statistics page is visible only to the site owner's confirmed account; the application services listen only on localhost |
| Abuse protection | Rate limits on sign-in, uploads and API calls; request-size limits |
| Configuration | Secrets only in a root-owned environment file, never in source code |
| Operating system | Firewall (only 22, 80, 443), unprivileged service account, systemd sandboxing, automatic security updates |
Report a vulnerability
If you believe you have found a security problem, please email hakimov99h@gmail.com with a description and steps to reproduce it. Please do not test against other users' sessions, run denial-of-service tests, or disclose the issue publicly before it is fixed. The machine-readable contact is published at /.well-known/security.txt.