Privacy Policy
Last updated August 11, 2026
This explains what RenderDay does with your personal data. We are a cloud rendering service for Blender files, run from Germany under the GDPR and the German TDDDG.
1. The short version
Three things are worth knowing before the detail.
We ask you for one thing: an email address. No name, no postal address, no phone number. A file, some settings and a way to reach you is the whole account.
Your files are rendered and then deleted. Thirty days after you last touch a project, the .blend and the frames are gone from our storage. We never show them to anyone, never publish them, and never use them to train machine-learning models.
Everything is processed in the United States. Not "possibly" and not "in some cases". Our servers, our database and our GPUs are American. Section 4 says exactly where, and what protects the transfer. If that is a problem for your project, tell us before you upload.
2. Who is responsible
The controller under Art. 4(7) GDPR is:
Sascha Schwabbauer (RenderDay), sole proprietor, Bochum, Germanyc/o POSTFLEX PFX-318-277, Emsdettener Straße 10, 48268 Greven, Germany
support@renderday.com
+49 152 079 92 398
We have not appointed a data protection officer. A sole proprietorship with nobody else permanently engaged in automated processing does not need one under Art. 37 GDPR or §38 BDSG. Writing to the address above reaches the person who makes the decisions.
3. What we collect, and why
| Data | Why we have it | Legal basis |
|---|---|---|
| Email address | To send you the price, the receipt and the notice that your frames are ready, and to let you back into a project from another device | Art. 6(1)(b) — the contract |
Uploaded files: .blend, archives, textures | To render them | Art. 6(1)(b) |
| Rendered output | To give it back to you | Art. 6(1)(b) |
| Job metadata: settings, frame timings, GPU seconds, scene complexity measurements, errors | To price and schedule your job, and afterwards to price and schedule other jobs more accurately | Art. 6(1)(b) for your job, Art. 6(1)(f) for improving pricing and capacity |
| Payment records: amount, date, Stripe identifiers, your email | To take the payment, and afterwards because German tax law requires us to keep them | Art. 6(1)(b), then Art. 6(1)(c) with §147 AO and §257 HGB |
| Consent records: what you agreed to, when, from which IP | So we can prove consent was given, which Art. 7(1) puts on us | Art. 6(1)(c) |
| Abuse-prevention signals (below) | To stop one person draining the free GPU budget under fifty identities | Art. 6(1)(f) |
| Server logs: IP address, user agent, timestamp, path, errors | To keep the service up and work out what broke | Art. 6(1)(f) |
| Analytics events | To see where people give up on the funnel | Art. 6(1)(a) — your consent |
| Ad-click attribution: the click id a Google ad appends to its link (gclid), campaign parameters, and — if you buy — the order amount | To tell Google Ads which clicks became purchases, so we stop bidding on keywords that bring nobody | Art. 6(1)(f) — see the note on ad measurement below |
| Marketing email | Only if you tick the box | Art. 6(1)(a) — your consent |
| Support correspondence | To answer you | Art. 6(1)(b) or Art. 6(1)(f) |
Abuse-prevention signals, specifically
Analysis and price calculation are free to you, and the price calculation burns real GPU time on our account. To keep that from being drained, every free calculation is counted against four budgets:
- a random id kept in your browser (
rd_anonymous_id), which you can clear whenever you like - the first 24 bits of your IP address, plus your network operator's ASN
- your email address, hashed
- the contents of your
.blendfile, hashed
The hashes are keyed and are never stored in a form we can read back. We do not fingerprint your browser: no canvas, no WebGL, no font probing. Fingerprinting would raise a §25 TDDDG consent question for a signal we do not need.
We also put Cloudflare Turnstile in front of uploads to check that a person is at the keyboard. Turnstile receives your IP address and browser characteristics and returns a pass or a fail. It sets no tracking cookie and does not follow you around the web.
Our interest here is keeping a free thing free without going broke, which we take to be legitimate under Art. 6(1)(f). You can object under Art. 21; see section 9.
Ad conversion measurement, specifically
We buy Google ads. When you arrive through one, the address bar carries a click id Google minted for that click (gclid). We keep it with the project you create, and if that project becomes a purchase we report the click, the amount and the currency back to Google Ads. That is the whole exchange: no email, no name, no file — nothing Google did not already know about its own ad.
This happens whether or not you accepted marketing cookies, and that deserves a plain sentence rather than a buried one. Knowing whether our advertising pays for itself is a legitimate interest under Art. 6(1)(f): what travels is a click identifier and a number, and without them a small advertiser is flying blind. Your banner choice still matters twice. Nothing is stored on your device without marketing consent (section 6), and every report carries your banner choice to Google, which limits what Google may do with the data on its side.
If you do not want your purchases reported at all, object under Art. 21 by emailing us. For this we treat a plain "stop" as enough — no balancing test, no questions. Section 9 has the address.
What we do not do
We do not sell your data. We do not use your uploaded files or your rendered frames to train machine-learning models, and we do not put them in marketing without asking you first. The statistical models we do fit are built on job metadata, which describes the work rather than the artwork: timings, settings and complexity measurements, never image data, geometry or textures.
4. Where your data is processed
In the United States. All of it. This section exists because the honest answer is uncomfortable and burying it would be worse.
| What | Where |
|---|---|
| Preprocessing, price calculation, orchestration, packaging, outbound email | Amazon Web Services, us-east-1 (Northern Virginia) |
| The database: your email address and every job record | Neon, us-east-2 (Ohio) |
| Uploaded files and rendered frames | Cloudflare R2, distributed globally |
| The website itself | Vercel, global edge network |
| GPU rendering | RunPod and Vast.ai, wherever capacity is available |
| Payments | Stripe: Ireland for European customers, United States for the group |
| Business email and documents | Google Workspace, EU storage with US access |
| Error monitoring | Sentry, United States |
| Lifecycle email | Loops, United States |
What protects it. Each provider is certified under the EU-US Data Privacy Framework, which the European Commission found adequate in July 2023, or is bound by the Commission's Standard Contractual Clauses, or both. All of them are under an Art. 28 data processing agreement with us, and each receives only what it needs for its part of the job.
What that does not do. No contract stops a US authority making a lawful demand of a US company. That is the known limit of any transfer to a third country and we are not going to pretend otherwise. What we can tell you is how little travels: an email address, a record of a render, and a file that is deleted after thirty days.
If your project genuinely cannot leave the EU, email us before you upload. There may be something we can arrange, and if there is not we will say so rather than take the job.
5. Who else handles your data
| Provider | Role | What it receives |
|---|---|---|
| Amazon Web Services, Inc. | Compute, storage, queues, outbound email through SES | Files during processing, job records, your email address |
| Neon, Inc. | Managed PostgreSQL | Your email address, job records, settings, consent timestamps |
| Cloudflare, Inc. | R2 object storage, CDN, Zaraz tag management, Turnstile | Uploaded files, rendered frames, your IP address and browser details |
| Vercel Inc. | Website hosting, plus Vercel Analytics and Speed Insights | Requests to the site, IP address, page performance measurements |
| RunPod, Inc. | GPU rendering | Your scene file and the frames it produces |
| Vast.ai Inc. | GPU rendering | Your scene file and the frames it produces |
| Stripe Payments Europe, Ltd. and Stripe, Inc. | Payment processing, invoicing, tax calculation | Card details, taken directly and never through us, plus amount, email and billing country |
| Google Ireland Ltd. and Google LLC | Workspace email; with your consent, Google Analytics 4 and Google Ads tags; ad conversion measurement per section 3 | Your support emails; with consent, page views and campaign data; for ad-attributed purchases, the click id, amount and currency |
| Functional Software, Inc. (Sentry) | Error monitoring | Stack traces, browser details, sometimes an IP address |
| Loops, Inc. | Lifecycle and marketing email | Your email address and a few job counts, if you consented to marketing |
Beyond this list we pass your data on only where performing the contract requires it, where you have consented, where the law compels us, or to protect somebody's vital interests.
Stripe is worth a note of its own. For fraud prevention and its own regulatory obligations Stripe acts as an independent controller, not merely as our processor, so its own privacy policy applies to the payment alongside this one. Your card number never touches our systems; we receive a confirmation, the last four digits and a transaction id.
6. Cookies, local storage and analytics
We use very few cookies. Most of what we keep on your device is browser local storage, which does the same job and which §25 TDDDG treats the same way.
Always present
cookieConsentin local storage: the choice you made in the banner, so we stop asking- session and CSRF tokens: so you stay signed in to your project and nobody else can act as you
rd_anonymous_idandrd_attributionin local storage: the random id from section 3, used for the free-tier budgets and, if you consent, to join analytics events across a visit
These are strictly necessary for a service you asked for, so §25(2) Nr. 2 TDDDG lets us store them without consent. You cannot switch them off and keep using the site, though your browser can block them.
Only with your consent
Analytics and advertising tags run through Cloudflare Zaraz. Given consent it loads Google Analytics 4 and Google Ads conversion and remarketing tags, which set their own cookies (_ga, _gcl_aw and similar) and send data to Google in the United States. Without consent it loads none of them.
With marketing consent we also keep the ad click id itself (rd_gclid) in local storage, for 90 days at most, so a purchase you come back for days later still counts against the ad that brought you. Decline marketing and it is never written; withdraw consent and it is removed.
We also record our own funnel events in our own database rather than somebody else's: which step you reached, which campaign brought you, whether a quote became a payment. They carry the anonymous id, not your name.
Your choice, and changing it
In the EU we ask before setting anything non-essential, and nothing loads until you answer. Elsewhere the tags default to on.
You can change or withdraw your choice at any time using the Cookie settings link in the footer of every page.
Do Not Track
There is still no agreed meaning for the DNT header, so we act on the choice you make in our banner rather than guessing from a header.
7. How long we keep things
| What | How long | Why that long |
|---|---|---|
| Uploaded files and rendered frames | 30 days after you last touch the project | Long enough to re-download, short enough not to be a liability |
| Job metadata: settings, timings, complexity, cost | As long as we run the service | It is what the pricing model is built on. Ask and we will detach it from your identity |
| Your email address and account record | Until you ask us to erase it | Art. 17 |
| Payment and invoice records | 10 years | §147 AO and §257 HGB. We cannot delete these sooner, even at your request |
| Consent records | While the consent is relied on, then 3 years | Art. 7(1), then the ordinary limitation period |
| Server and application logs | 90 days | Set on the log groups themselves, not swept by hand |
| Support email | While the matter is open, then as long as it is useful for follow-up | Art. 6(1)(f) |
| Analytics events | As long as we run the service | They identify a browser, not a person. On erasure we strip the user id from them |
| Ad-click attribution: click id and campaign parameters | On your device 90 days at most; in the project record, as long as job metadata | A click older than 90 days no longer counts on the Google side; the campaign fields keep telling us which ads paid off |
Backups can hold a copy for a short while after something is deleted from the live systems. They are encrypted, are used only for disaster recovery, and roll over on their own schedule.
8. Automated decisions
Two things happen without a person in the loop.
Your price is calculated automatically, from measurements of test frames of your own scene. Nobody sets it by hand and nobody adjusts it according to who you are.
Free work is metered automatically against the budgets in section 3. When a budget runs out, a free price calculation queues behind paid work, or we ask you to confirm your email address before starting it. Nothing is refused outright, and paid work is never affected.
Neither produces a legal effect on you or anything similarly significant, so Art. 22 GDPR is not engaged. Even so: if a decision looks wrong, email us and a person will look at it.
9. Your rights
Exercise any of these by emailing support@renderday.com. There is no form and no fee, and we answer within a month as Art. 12(3) requires. If it is going to take longer, we will tell you why before the month is out.
- Access (Art. 15): a copy of what we hold and what we do with it
- Rectification (Art. 16): correct anything wrong
- Erasure (Art. 17): delete it, apart from what tax law makes us keep
- Restriction (Art. 18): freeze it while something is in dispute
- Portability (Art. 20): your data in a machine-readable file, or sent straight to another provider
- Objection (Art. 21): to anything we do on the basis of legitimate interests, on grounds relating to your situation. For direct marketing there are no grounds to give and no balance to strike, so saying stop is enough — and we treat the ad conversion measurement in section 3 the same way
- Withdrawing consent (Art. 7(3)): at any time, without affecting what we did lawfully beforehand
We may ask you to write from the address we already have on file before handing anything over. Giving your data to the wrong person would be the worse failure.
10. How we protect your data
Everything travels over TLS. Files and database contents are encrypted at rest by the providers that hold them.
There are no passwords to steal. You get into a project through a one-time link sent to your email address, so there is no password database to breach.
Rendering machines run in an isolated network, can reach only our storage and our API, and are destroyed when the job finishes. Blender's Python auto-execution is switched off on them, so an uploaded file cannot run code on our infrastructure.
Access to production data is limited to the operator named in section 2. Providers are picked partly on their security posture, and every one of them holds a data processing agreement with us.
None of that makes a system unbreakable. If a breach ever puts your rights at risk we notify the supervisory authority within 72 hours under Art. 33, and tell you directly under Art. 34 where the risk to you is high.
11. Changes to this policy
We update this page when what we do changes, and the date at the top moves when the wording does. If a change materially affects you and we have your address, we will email you rather than hope you re-read the page.
Ask and we will send you the version that was in force on a given date.
12. Complaints
Write to us first, at support@renderday.com. It is faster, and we would rather know.
If that does not settle it, you can complain to a supervisory authority: the one where you live, where you work, or where you think the problem happened. Ours is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2-4, 40213 Düsseldorf, Germany
+49 211 38424 0
poststelle@ldi.nrw.de
www.ldi.nrw.de