Privacy Policy — CADXtend
The short version
We do not collect your data. CADXtend P3D Issues runs entirely on your computer and talks directly to the Autodesk services using your own Autodesk account. There is no CADXtend server behind the plug-in, no telemetry, no usage analytics, no crash reporting, and no advertising. Your credentials and your project data never reach us.
1. Sign-in and credentials
The plug-in signs you in to Autodesk Platform Services (APS) using the standard three-legged OAuth 2.0 flow with PKCE:
- Sign-in happens in your own web browser, on the Autodesk sign-in pages. You type your Autodesk password into the Autodesk site, never into the plug-in. The plug-in never sees your password.
-
Autodesk returns the authorization result to a temporary listener on your own machine
(
http://localhost:8989/callback). That address is local to your computer; nothing is exposed to the network. - The plug-in then exchanges that result for access and refresh tokens directly with Autodesk.
- Authentication uses an APS application registered by the publisher. Registering that application does not give the publisher access to your account, your tokens, or your project data — tokens are issued by Autodesk to the copy of the plug-in running on your machine.
2. What the plug-in stores on your computer
Everything the plug-in saves stays in your own Windows user profile, under:
%LOCALAPPDATA%\CADXtend\p3d_issues\
| File | What it holds |
|---|---|
auth.bin |
Your APS refresh token, encrypted with Windows DPAPI (current-user scope). It cannot be read by other Windows users on the machine and is not stored in plain text. |
debug.log |
A diagnostic trace of what the plug-in did, used for troubleshooting. Access tokens, refresh tokens, authorization codes, and email addresses are automatically redacted before anything is written. |
snapshots\ |
A cache of issue thumbnail images already downloaded from your Autodesk Forma project, so they don't have to be re-fetched. |
members.json |
An optional, user-editable map of Autodesk user IDs to display names, used as a fallback when the Forma members API is unavailable for your account. |
notified_issues.json |
The IDs of issues you have already been notified about, so you aren't notified twice. |
notify_settings.json |
Your notification preferences. |
The plug-in also reads the Plant 3D collaboration cache that AutoCAD maintains on your machine, in order to work out which Forma project the open drawing belongs to. It only reads it; it does not modify it and does not copy it anywhere.
None of these files are transmitted anywhere. They are yours, on your machine, and you can delete them at any time (see Section 6).
3. What the plug-in sends over the network
The plug-in communicates only with Autodesk. Specifically:
-
developer.api.autodesk.com— Autodesk Platform Services: authentication, Forma Issues, project and account/member information, and object storage for issue thumbnails. -
api.userprofile.autodesk.com— to identify which Autodesk user is signed in, so issues assigned to you can be recognized. - Short-lived signed storage URLs that Autodesk itself returns (hosted on the Autodesk cloud storage provider) when an issue thumbnail is downloaded or uploaded.
What travels over those connections is the Forma project content you are already working with: issue titles, descriptions, statuses, comments, assignees and watchers, drawing references, and issue thumbnails. If you create an issue with a snapshot, an image of your current drawing viewport is uploaded to your own Forma project.
There is no connection to any CADXtend server, because there isn't one. No usage data, no license check, no error report, and no personal information is sent to the publisher by the plug-in.
4. What we do not do
- We do not collect, receive, store, or process your personal information through the plug-in.
- We do not collect telemetry, usage statistics, or analytics of any kind.
- We do not use cookies, trackers, advertising identifiers, or profiling in the plug-in.
- We do not sell, rent, or share any user data — we do not have any to sell.
5. The role of Autodesk
Autodesk is an independent controller of the data it processes: your Autodesk account, your Forma projects, and everything the plug-in reads from or writes to them. That processing is governed by your agreements with Autodesk and by the Autodesk Privacy Statement: autodesk.com/company/legal-notices-trademarks/privacy-statement
Questions about how Autodesk handles your account or project data, and any request to access or delete data held in Forma, should be directed to Autodesk.
6. Your control over the local data
- Sign out in the plug-in — this deletes the stored refresh token
(
auth.bin). - Delete the folder %LOCALAPPDATA%\CADXtend\p3d_issues\ — this removes the token, the diagnostic log, the thumbnail cache, and your settings. The plug-in recreates what it needs the next time it runs.
- Uninstall the plug-in — after uninstalling, delete that folder to remove the leftover data.
Because the publisher holds none of this data, there is nothing for us to delete on our side.
7. If you contact support
If you email support@cadxtend.com, we receive your email address and whatever you choose to include in your message and attachments. We use it only to answer you and to fix the problem you reported. We do not add you to a mailing list and we do not pass your message to anyone else.
If you attach debug.log to a support request, note that tokens and email addresses in
it are redacted automatically — but please still review any file before sending it, and never send
us your Autodesk password or an access token.
We keep support correspondence only as long as it is useful for supporting you, and we do not use it for any other purpose.
8. The cadxtend.com website
The website is informational. It has no user accounts, no sign-up, no contact form, no analytics, and no advertising or tracking cookies.
- Like most web servers, ours may keep standard access logs (such as IP address, time, the page requested, and browser user agent) for security and troubleshooting. These logs are not used to build a profile of you and are not shared with anyone.
-
Product demo videos are embedded from YouTube in privacy-enhanced mode
(
youtube-nocookie.com) and load only after you click to play one. When you do, YouTube receives that request and applies Google's own privacy policy to it.
9. Children
The Software is a professional engineering tool. It is not directed at children and we do not knowingly collect information from anyone.
10. International users
The plug-in does not transfer any data to the publisher, in the United States or anywhere else. Any international transfer of your account or project data happens between you and Autodesk, under the Autodesk terms and privacy statement.
11. Changes to this policy
If the plug-in's data behavior changes, we will update this policy and change the effective date at the top. The current version is always published at https://cadxtend.com/privacy/.
12. Contact
Ivan Ignatenko (CADXtend)
1501 South Wolf Road, Apt 124
Prospect Heights, IL 60070, USA
support@cadxtend.com