Kerf Privacy Policy
Last updated: 22 August 2026
Kerf is an Autodesk Fusion add-in that builds cabinets from your sketches. This document describes exactly what data Kerf handles and, specifically, what an optional crash report contains.
TL;DR
- Kerf works fully offline. The only things it ever sends over the network are (a) an update check and (b) — only if you opt in — an anonymous crash report.
- Crash reporting is off by default. On first run Kerf asks once; your choice is saved and you can change it at any time.
- A crash report contains no geometry, dimensions, model data, file names, file paths, account/email, IP-identifying content, or any personal data.
Local logging (always on, never transmitted)
Kerf writes a rotating log to Documents/Kerf_Logs/kerf.log (up to ~0.5 MB × 5 files). It stays on your machine — Kerf never uploads it. When an error occurs, the log records the error code and a Python traceback so you can troubleshoot or attach it to a bug report yourself. You can delete the folder any time.
The friendly error dialog's “copy details” puts that same technical text on your clipboard (via the OS clip/pbcopy) so you can paste it into a report — that is a local action; nothing is sent.
Opt-in anonymous crash reporting
When enabled and a reporting endpoint is configured, an uncaught error sends a single small JSON document. The payload contains only these fields:
What the stack_hash is (and isn't)
It is the SHA-256 of a signature built from, per stack frame, the module file basename + line number + function name, plus the exception type — e.g. cabinet.py:412:_build_cabinet_interior;ValueError. It lets identical crashes be grouped together. It is a one-way hash: the payload carries the hash, not the signature, and it never includes absolute paths or your home directory.
What is deliberately never sent
- Your model, sketches, geometry, dimensions, or any cabinet parameters.
- The exception message (it could contain a file path or a value) — only the exception type name is sent.
- File names, folder paths, or your Documents/home directory.
- Your name, email, Autodesk account, license, or machine name/serial.
- Any persistent device identifier or advertising ID.
(Your IP address is inherently visible to any HTTPS server you connect to, as with any web request; the payload itself adds no identifier.)
Consent & control
- First run: Kerf shows a one-time dialog explaining the above and asks whether to enable anonymous crash reporting. Declining is the default if you dismiss it.
- Persisted: your choice is stored in Documents/Kerf_Logs/settings.json ("crash_reporting": true|false).
- Change your mind: set "crash_reporting" to false (or true) in that file, or call kerf.log.set_crash_reporting(False). With it off, Kerf makes zero network calls for crash reporting — verified by an automated test.
- Endpoint: reporting only happens when an endpoint is configured ("endpoint" in settings.json or the KERF_CRASH_ENDPOINT env var). With no endpoint, nothing is sent even if reporting is enabled.
Update check
App Store builds are updated through the Autodesk App Store; the built-in update check ships disabled. In builds where it is enabled, Kerf fetches a small JSON manifest on startup to see whether a newer version exists (see docs/release.md). This is a normal download and sends no personal data beyond what any HTTPS request implies. Updates are verified with an Ed25519 signature before install.
Other data Kerf stores (locally only)
Your preferences and work products are plain files on your machine, never uploaded by Kerf: settings and profiles under Documents/Kerf_Settings/ (units, price book, shop standards, saved themes, saved camera points, supplier catalog), cut lists / PDFs under Documents/Kerf_CutLists/, rendered images under Documents/Kerf_PhotoShoots/, and logs under Documents/Kerf_Logs/. Kerf reads and writes them solely to provide its features.
Third parties
Kerf contains no analytics tools, no advertising networks, and no third-party SDKs. Kerf does not sell, rent, or share any data with third parties. The crash-report endpoint, when one is configured, is operated by the publisher for the sole purpose of fixing defects. Should the publisher ever engage a third party to process crash-report data (e.g. a hosting provider), that third party is required to protect the data to at least the same standard as this policy, and this policy will be updated to name the category of processor. (Autodesk processes your App Store purchase and installation under Autodesk's own privacy policy; Kerf receives none of that data.)
Data retention and deletion
- Local files (logs, settings, cut lists, photos — everything listed above): stored on your machine and retained until you delete them. Deleting the folders removes the data completely; Kerf recreates empty ones as needed.
- Crash reports (only if you opted in and an endpoint is configured): retained for at most 12 months, used only to group and fix defects, then deleted. Reports are anonymous by construction (see above) and are never merged with any other data source. In the current release no endpoint is configured by default, so no crash data is collected at all.
Revoking consent and requesting deletion
- Revoke consent at any time: set "crash_reporting": false in Documents/Kerf_Logs/settings.json (or decline/accept again via the consent dialog). With consent off, Kerf makes zero crash-reporting network calls — verified by an automated test.
- Request deletion: email support@kerf360.com with the approximate date and the KERF-… error code(s) from your dialog or kerf.log. Because reports are anonymous, they cannot be looked up by name or account — the error code and date are what allow the matching records to be found and deleted. Deletion requests are honored within 30 days.
Questions
Email support@kerf360.com. This policy is also published at https://kerf360.com/privacy — the two are kept identical.
This page is the published copy of PRIVACY.md, the same text that ships inside the add-in. If the two ever differ, the file in the release you installed governs.