Privacy Policy
Effective and last updated: August 20, 2026
Modern DRO LLC (“ModernDRO,” “we,” “us,” or “our”) is responsible for the personal information described in this policy. This policy applies to moderndro.com, beta.moderndro.com, app.moderndro.com, api.moderndro.com, the ModernDRO application, reDRO devices, and related support services (collectively, the “Service”).
In short: we use information to provide, secure, support, analyze, improve, and market our products and services. We do not sell personal information, share it for cross-context behavioral advertising, or run third-party advertising in the Service. We may contact you about Modern DRO products and services, subject to your choices and applicable law.
1. Information we collect
Account and organization information. Clerk handles sign-in. We receive or maintain user and organization IDs, email address, name, organization name, membership, role, and account status. We do not receive your Clerk password.
Customer Content and workshop information. We process information you create, sync, upload, import, or otherwise provide, including machine configurations, tool libraries, offsets, part programs, drawings and CAD files, file names and metadata, measurements, reports, and related organization data (“Customer Content”). Some features store data only in your browser or device. In the hosted account Service, machine profiles and related Customer Content sync automatically after you accept the beta terms and enter an organization. On a reDRO or standalone device, cloud synchronization begins when you link the device to an organization; you can disable linked-device Auto-sync in device settings. Other information reaches our hosted systems when you upload or share it, request support, or use another cloud feature. Inspection reports currently remain local unless you export, upload, or send them.
Device, usage, and technical information. We may collect device identifiers and names, link and entitlement status, last-contact times, feature interactions, configuration and sync events, diagnostics, error reports, and performance information. Our servers and providers also process standard request data such as IP address, browser or device type, timestamps, paths, referring origin, and security events. Raw machine readings and local diagnostic logs remain local unless a feature or support action sends them to us.
Communications. If you contact us, we collect the message, contact details, attachments and diagnostics you provide, and our response. If you call a published support number, we may receive call metadata and a voicemail recording after the call announces that recording may occur.
We collect information directly from you and your devices, automatically when the Service is used, from organization administrators or users who invite you or share Customer Content, and from service providers such as Clerk.
2. How and why we use information
We use information to:
- provide accounts, organization access, sync, storage, device linking, files, calculations, reports, and other requested features;
- authenticate users, enforce entitlements, prevent abuse, protect users and the Service, investigate incidents, and maintain reliability;
- provide support and communicate service, security, policy, and account information;
- send product news, surveys, offers, and other marketing about Modern DRO products and services by email or within the Service, and measure the effectiveness of those communications, subject to your choices and applicable law;
- measure use, troubleshoot, test, research, and develop, maintain, and improve ModernDRO and our other products and services;
- create and use aggregated or deidentified information for analytics, research, product planning, and other lawful business purposes; and
- comply with law, enforce agreements, establish or defend claims, and complete a corporate transaction.
Where applicable law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating, securing, supporting, improving, and marketing the Service and our other products and services, compliance with legal obligations, and consent where required. Where applicable law requires consent for marketing, we will request it separately. We do not use solely automated decisions that produce legal or similarly significant effects about individuals.
Product improvement may include analyzing Customer Content and usage information, and limited human review when reasonably necessary for support, safety, security, testing, or improvement. We apply access controls and use aggregated or deidentified information where reasonably practicable. We will seek additional permission when law requires it.
3. How we disclose information
We may disclose information to:
- service providers for authentication, hosting, databases, storage, content delivery, security, support, email delivery, customer-relationship management, marketing automation, campaign measurement, and professional services, including Clerk, Neon, Amazon Web Services, and security providers used in the sign-in flow such as Cloudflare;
- your organization, including its owners and administrators, and users with whom you choose to collaborate;
- professional advisers and transaction parties, such as lawyers, accountants, insurers, auditors, financing sources, and actual or prospective acquirers under appropriate restrictions;
- authorities or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, users, or the Service; and
- others at your direction or with your consent.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you. We may use and disclose aggregated or deidentified information for lawful purposes and will not attempt to reidentify it except to test our measures or as law permits.
We may provide account, contact, preference, and engagement information to service providers that process it only on our behalf to manage, deliver, personalize, or measure Modern DRO's own marketing. We require those providers to use the information only for the contracted services and not for their own independent marketing, resale, data brokerage, or cross-context behavioral advertising.
4. Storage, cookies, and local data
The hosted Service uses local browser storage, service-worker caches, and the cookies or similar technologies Clerk needs for authentication, security, and session continuity. We do not currently use advertising or third-party analytics cookies. A reDRO device may set an essential local session cookie on a phone or computer used for file transfer; it stays on the local network. If we add non-essential tracking where consent is required, we will provide a choice before using it.
Because we do not sell personal information or use it for cross-context behavioral advertising, Global Privacy Control and “Do Not Track” signals do not change our current practices. First-party communications about Modern DRO products remain subject to your marketing preferences. The Service does not otherwise respond differently to browser “Do Not Track” settings. If our practices change, we will honor legally required opt-out signals. Clerk and its security providers may collect information across sites as needed to authenticate users, prevent fraud, and protect accounts; we do not permit them to use Service data for our advertising.
5. Retention
We retain account information and Customer Content while the account or organization is active and as reasonably needed to provide the Service. We retain security, diagnostic, support, transaction, and legal records for as long as reasonably necessary for their purpose, our legitimate business needs, dispute resolution, and legal obligations. Retention depends on the data’s nature, sensitivity, volume, risk, and purpose. Deletion from active systems may not immediately remove information from backups, legal holds, or deidentified datasets. Closing an account or organization does not itself immediately delete organization-owned Customer Content; an authorized organization administrator may request deletion, which can require verification and cleanup across providers.
6. International processing
The Service's primary hosted product-data stores are in the United States. ModernDRO personnel and providers may process information from other countries, whose laws may differ from those where you live. Where required, we use a lawful transfer mechanism, which may include adequacy decisions, contractual safeguards, or another mechanism permitted by law. Contact us to request information about safeguards applicable to your data.
7. Security
We use reasonable administrative, technical, and organizational safeguards designed for the information we process. No transmission or storage system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials, devices, local networks, and exported files.
8. Your privacy choices and rights
You can manage organization membership, unlink devices, export supported data, and change certain account information in the Service or through Clerk. Depending on where you live, you may also have rights to access, know about, correct, delete, or obtain a portable copy of personal information; restrict or object to processing; withdraw consent; appeal a denied request; and lodge a complaint with a data-protection authority. We will not discriminate against you for exercising an applicable right.
You may opt out of marketing email at any time using the unsubscribe method in the message or by emailing support@moderndro.com. We may still send non-marketing messages needed to provide, secure, or administer your account and the Service.
To submit a request, appeal, or authorized-agent request, email support@moderndro.com. Describe the request and account or organization involved. We may verify identity and authority before acting and retain a record of the request. Rights are subject to applicable exceptions, including other people’s rights, security, legal obligations, and information we cannot reasonably link to you.
9. Children
The Service is intended for adults and is not directed to children. You must be at least 18, or the age of legal majority where you live, to create an account. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information so we can investigate and delete it as appropriate.
10. Changes to this policy
We may update this policy as the Service and legal obligations change. We will post the revised policy with a new effective date and provide additional notice or obtain consent when required. We will not apply a materially more permissive use of previously collected personal information retroactively without notice and any consent required by law.
11. Contact us
Modern DRO LLC
Privacy and account requests:
support@moderndro.com
Product issues:
support@moderndro.com