Privacy Policy
What we collect when you use StructLib, why, who else handles it, how long we keep it, and what you can ask us to do.
Last updated: 28 September 2026
1. Who we are
StructLib is run by Moso Engineering, Rotterdam, the Netherlands (“we”). This policy covers structlib.com and the apps at app.structlib.com, including the desktop app. For anything in it, email [email protected].
2. What we collect
- Your account: your email address and name, and anything you add to your profile (such as company, profession, country or phone number). If you sign in with Google, Google gives us your name, email address and profile picture. If you set a password, we store only a salted hash of it.
- Your work: the models, projects and files you save to the cloud, and the people you share them with — including invitations: the address invited, the role, when it was sent, and whether it was accepted, declined, cancelled or expired. When you are invited, you see the name and email address of the project owner before you accept; the owner is told by email if you decline. Your settings, if you are signed in, so they follow you between devices.
- Sign-in and security records: your sessions (when they started and were last used, the IP address and the browser or app), and a log of sign-ins and account changes with the email address and IP address involved.
- Copilot and agent use: your conversations with the AI copilot, the files you give an agent job, and how much you use them (to apply the plan limits).
- Your plan: which plan your account is on and until when.
What we do not collect: a model you analyse only in your browser never reaches our servers — the solver runs on your computer. Nothing is sent to us from structlib.com itself unless you accept analytics (section 7).
3. Why we use it
- To provide the service you signed up for: your account, your saved work, analyses on the cloud engine, the copilot, and the limits of your plan (performing our agreement with you — the Terms of Service).
- To keep accounts secure and the service working: sessions, sign-in records, preventing abuse (our legitimate interest).
- To send you the emails the service needs — sign-in codes, password resets, email-address changes.
- To count visits to structlib.com, only if you accept analytics (your consent, which you can withdraw at any time).
We do not sell your data, and we do not use your models for anything except providing the service to you.
4. Who else handles it
We use these providers to run StructLib. Each gets only what its job needs:
| Provider | What for | What it sees |
|---|---|---|
| Hetzner Online GmbH (Nuremberg, Germany) | Hosts our servers | Everything our servers store or process: your account, saved work, copilot conversations, agent jobs and logs |
| Cloudflare | Delivers both sites and protects them; stores our encrypted backups (Cloudflare R2) | All traffic to structlib.com and app.structlib.com in transit, including your IP address; the backups only in encrypted form |
| “Sign in with Google”, if you choose it | That you are signing in to StructLib | |
| Resend | Sends the service’s emails | Your email address and the email’s content (for example a sign-in code) |
| OpenRouter, and the AI model providers it routes to — currently Anthropic and OpenAI | Answers the AI copilot | Your copilot message and the model open at the time |
| Anthropic | Runs agent jobs | The instructions and files you give an agent job |
Some of these providers are established in the United States, so your data may be processed outside the European Economic Area. Where it is, we rely on the safeguards the law provides for such transfers.
5. How long we keep it
- Account and saved models: until you delete them. When you delete your account (from the account page, or by emailing us), your account and saved models are deleted within 30 days.
- Backups of the database and attached files are encrypted and stored off our server, with Cloudflare R2. They roll over within 90 days; anything deleted is gone from them by then.
- Security and audit logs (sign-ins and failed sign-in attempts with how you signed in, account lockouts, files attached to or removed from a project (name and size only, never the contents), and administrator actions — with the email address and IP address involved): 12 months, then deleted automatically.
- Project invitations: kept as part of the project's history until the project is deleted (an open invitation expires after 30 days). If your account is deleted, your name is removed from them.
- Sign-in sessions (IP address and browser): deleted 30 days after the session ends. Email sign-in codes: deleted 1 day after they expire.
- Cloud analyses: the model and results are held in memory only, and forgotten once collected or 15 minutes after the run.
- Copilot conversations: a conversation you delete is erased 90 days later; the text of any message is cleared 12 months after it was written.
- Agent jobs: results are deleted after 7 days; uploaded files not used by a job after 48 hours.
More on where your model goes: Security and your data.
6. Your rights
You can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Email [email protected]. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
7. Cookies and similar storage
Needed for the service (no consent needed, cannot be switched off):
structlib_atandstructlib_refreshon app.structlib.com — keep you signed in (24 hours and 30 days). HttpOnly: page scripts cannot read them.- Your browser’s storage (local storage and IndexedDB) on app.structlib.com — your settings on this device, recent files and unsaved work that can be recovered after a crash. It stays on your device.
Analytics (only with your consent):
- Google Analytics sets cookies (
_ga,_ga_…) to count visits and see which pages are read. It loads only after you click Accept in the banner; Reject keeps it off. Your choice is kept in your browser’s local storage, and “Cookie settings” at the foot of every page lets you change it. Withdrawing consent deletes the analytics cookies. Analytics are not switched on yet, so today structlib.com sets no cookies at all.
We use no advertising cookies and no other trackers.
8. Changes
When this policy changes, the date at the top changes with it.