Privacy & security

What happens to your data when you use LIMES, and how the service is protected. Last updated 10 October 2026.

Summary

  • The website and the documentation work without an account.
  • A free account is needed to use the tool and its examples, and to upload your own files. It stores your name, e-mail address, optional organisation and role, and the files you choose to keep.
  • You can download or delete any file, or delete the whole account, at any time.
  • Visits are counted anonymously, without cookies; no advertising, no third-party analytics, scripts or fonts.
  • All traffic is encrypted with HTTPS.

Accounts

When you create an account, LIMES stores your name, e-mail address, an optional organisation and role, the date the account was created and the time of your last sign-in. Passwords are never stored: only a salted scrypt hash. If you sign in with Google, Google tells LIMES your name, e-mail address and a Google account number; LIMES receives no password and no access to your Google data.

With e-mail sign-up, LIMES sends you a confirmation code; password-reset codes are sent the same way. These messages are the only e-mails LIMES sends.

The data is used only to run your account and to count how many people use LIMES. It is not sold, shared or used for advertising. The site owner (the administrator) can see the list of accounts. You can change your profile or delete the account on the My account page; deletion removes the profile and all your files immediately.

Your files

Without "My files". A file uploaded to the tool is held in the server's memory, linked only to your browser session, while you work. It is discarded when the session ends (closing the tab, or after a period of inactivity) or when you click Start a new session, and it is not visible to other users.

My files. If you are signed in and the setting Keep a copy of my uploads is on (you can switch it off), the 3D models (STL, STEP, IGES) and G-code programs you upload are also kept in your account, and you can save programs generated by LIMES there. They are stored on the LIMES server under random file names, are accessible only through your account, and are deleted when you delete them or your account. Each account has a storage limit.

Files sent to the programmatic API are processed from a private temporary file that is deleted immediately afterwards. Generated G-code, reports and data exports are created on request and downloaded directly to your device.

Visitor statistics

To know how many people use the project, LIMES counts page views and tool sessions on its own server. It records the page, the time, the name of the referring website (for example google.com, never the full address), the device type (desktop, tablet or mobile) and, if you are signed in, your account. To count different visitors without cookies, the server combines your IP address and browser version with a random value that changes every day and keeps only a short hash of the result; the daily value is then deleted, so visits cannot be linked from one day to the next or back to an IP address. Browsers that send Do Not Track or Global Privacy Control are not counted. Statistics are kept for at most 400 days.

Cookies

LIMES uses only technical cookies; there are no advertising or tracking cookies.

CookiePurposeLifetime
__Host-aa_sessionKeeps you signed in. Random value, not readable by scripts (HttpOnly), sent only over HTTPS and only to this site.30 days or until you sign out
aa_signed_inLets the website show "My account" instead of "Sign in". Contains only the value 1.Same as the session
__Host-aa_oauthProtects Google sign-in against forgery; set only while you sign in with Google.10 minutes
_streamlit_xsrfProtects file uploads in the tool against cross-site request forgery.Browser session

Server logs

Like any web server, the service records technical access logs: time, requested page, status code, browser type and IP address. They are used only to operate and protect the service, for example rate limiting and investigating errors. They are deleted automatically after 14 days. Application error logs contain a reference code and the type of error, but never passwords or the contents of uploaded files. To stop password guessing, failed sign-in attempts are counted per e-mail address and per network for 15 minutes to 24 hours (network addresses only as a hash).

Third parties

Pages and the tool are served entirely from this server. No external content-delivery networks, analytics services or fonts are used, so your browser makes no requests to third parties while you use LIMES. Exceptions you choose yourself: if you click Continue with Google, your browser goes to Google to sign in (Google's own privacy policy applies there); and confirmation and password-reset e-mails are delivered through the site's e-mail provider. The TLS certificate is issued by Let's Encrypt.

Security measures

AreaMeasure
TransportHTTPS only (TLS 1.2+), HTTP redirected, HSTS
Browser protectionsContent-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
UploadsType allow-list, size limit, structural check, triangle limit, coordinate sanity check, no storage by default
Input validationBounded numeric inputs in the tool; strict schemas, ranges and identifier patterns in the API
ErrorsUsers see a friendly message and a reference code; details stay in the server log
Accountsscrypt password hashes, password rules, e-mail confirmation codes that expire after 15 minutes, throttling of failed sign-ins, HttpOnly/Secure/SameSite session cookies, same-origin checks against cross-site requests, Google sign-in with state, PKCE and nonce
My filesOnly 3D models (STL, STEP, IGES) and G-code, validated by content; size and storage limits; random file names; every download checks that the file belongs to the signed-in account
Access controlAdministrative functions need a secret token and are blocked at the proxy; the statistics page is visible only to the site owner's confirmed account; the application services listen only on localhost
Abuse protectionRate limits on sign-in, uploads and API calls; request-size limits
ConfigurationSecrets only in a root-owned environment file, never in source code
Operating systemFirewall (only 22, 80, 443), unprivileged service account, systemd sandboxing, automatic security updates

Report a vulnerability

If you believe you have found a security problem, please email hakimov99h@gmail.com with a description and steps to reproduce it. Please do not test against other users' sessions, run denial-of-service tests, or disclose the issue publicly before it is fixed. The machine-readable contact is published at /.well-known/security.txt.