Privacy and cookie policy
Last updated: 10 October 2026
This policy explains what happens to your data when you use Leviate at vladpereverzyev.github.io/leviate, Leviate for Desktop (section 6), Leviate for Blender (section 7), Leviate for Chrome (section 8) and Leviate for Dentra Viewer (section 9). It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
1. Data controller
Vladyslav Pereverzyev, Via del Macello 36/B, 39100 Bolzano (BZ), Italy, VAT IT03281410211. Email: info@vladpereverzyev.com
2. What Leviate does with your data
Leviate is a static web app. It has no accounts, no server of its own, no analytics and no advertising. Your 3D files are opened in your browser and never uploaded. The camera video is read by the hand tracking on your device, frame by frame and is never recorded or sent anywhere. The camera starts only after you allow the Camera category in the consent banner and then the permission asked by your browser.
3. Hosting
The app is served by GitHub Pages, operated by GitHub, Inc. (USA). When a page is requested GitHub records technical data such as the IP address, date and time and browser, to deliver the site and keep it secure. Legal basis: legitimate interest in a secure and reliable service (Art. 6(1)(f) GDPR). GitHub is certified under the EU-U.S. Data Privacy Framework. See the GitHub Privacy Statement. The download page also asks GitHub (api.github.com) which release is the latest, so its buttons point to the newest files; GitHub receives the same technical data.
4. Use phone
To use a phone as a webcam the computer and the phone must find each other. This is done by the public PeerJS server (0.peerjs.com), which receives the IP addresses of both devices and a random session code. To find the way between the two devices each of them also asks a STUN server of Google (stun.l.google.com) for its own public IP address. The video then goes straight between the two devices over WebRTC, encrypted. When a direct link is not possible it is relayed through a PeerJS TURN server (in the EU or in the USA), still encrypted. Neither PeerJS nor Google ever sees the video. This service runs only if you allow the External services category. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. PeerJS and Google may process the IP addresses outside the European Union, in particular in the USA. Google is certified under the EU-U.S. Data Privacy Framework; for PeerJS the transfer rests on your consent (Art. 49(1)(a) GDPR).
5. Links to other sites and the Ko-fi note
The links to GitHub, Ko-fi and vladpereverzyev.com open those sites, which process data under their own policies. Nothing from them is loaded until you click.
Ko-fi note. Two minutes after the web app, its phone camera page or Leviate for Desktop opens, a short note asks for support on Ko-fi, on every visit and every start. Remind me later hides it until the next one; Support or Don't ask again hide it for good. Nothing is counted or measured for this. Only that last answer is kept, on your device, so the note is not shown again to someone who said no (leviate.support in section 10, leviate.desktop in section 6); it is never sent anywhere. Ko-fi is contacted only if you press Support, which opens ko-fi.com in your browser.
6. Leviate for Desktop
Leviate for Desktop is a program for Windows, macOS and Linux, downloaded from the releases of the project on GitHub (see section 3 for the data GitHub records when you download it) or installed from an app store: the Mac App Store (Apple), the Microsoft Store (Microsoft) or the Snap Store (Canonical). Each store handles the installation and the updates of its copy under its own privacy policy. The macOS program from GitHub is signed by the author and notarized by Apple: when it opens for the first time macOS may check it with Apple, as it does for every notarized program. It has no accounts, no analytics and no advertising. It shows no cookie banner because it sets no cookies and keeps only its own settings on your computer.
The camera starts when you press Start, after the permission asked by your operating system. The video is read by the hand tracking on your computer, frame by frame and is never recorded or sent anywhere. The hand tracking model is part of the program.
Hand controls. In the 3D and Mouse modules the program moves the mouse pointer, presses mouse buttons and the Shift, Ctrl or Alt keys and turns the mouse wheel, on your computer only, as your hand tells it. It does not read or record what you type, what is on the screen or what other programs do: the only keys it listens for are its own shortcut, Ctrl+Alt+M (Ctrl+Option+M on macOS), which turns the hand off and on. On macOS this needs the Accessibility permission, which you grant in the system settings.
Phone. Use phone connects through the PeerJS server exactly as described in section 4: PeerJS and the STUN server of Google receive the IP addresses of both devices, never the video. Before the first pairing the program explains this and connects only if you choose Continue. Legal basis: your consent (Art. 6(1)(a) GDPR); you withdraw it by not using the phone.
New versions. The copies from the app stores, the snap and the Flatpak do not look for new versions themselves and make no connection to GitHub: the store updates its copy, and a new Flatpak is installed by downloading its file again. The copy from the Mac App Store also shows no Ko-fi note or link. The copies downloaded from GitHub work as follows. When it opens, the program asks GitHub (api.github.com) which release is the latest, to tell you when a new version is out; GitHub receives the same technical data as in section 3. Nothing is downloaded or installed until you choose Update. Update downloads the file of the new version from the releases on GitHub, with a bar that shows the progress; GitHub again receives the same technical data. On Windows the installer is saved in the temporary folder and runs without its windows: it replaces Leviate and starts it again. Windows asks for permission when Leviate is installed for all users. On macOS the dmg is saved in the Downloads folder and opened in Finder, then you drag Leviate to Applications yourself. On Linux the new AppImage takes the place of the old one and Leviate starts again. Remind me later hides the note until the next start. You can turn the check off with Check for new versions at start, in the Settings section. Legal basis: legitimate interest in a secure and up to date program (Art. 6(1)(f) GDPR). Apart from Use phone, this check and the update you choose the program makes no connection to the internet; links open in your browser.
Settings are kept on your computer, in the data folder of the program and never leave it: leviate.desktop (camera, mode and gesture settings, which windows are closed, whether to look for new versions, whether the phone notice was shown, whether you asked not to see the Ko-fi note again) and leviate.consent (a fixed record that tells the shared phone code of the web app that no banner is needed). Uninstalling the program, or deleting its data folder, removes them.
7. Leviate for Blender
Leviate for Blender is an add-on for Blender, downloaded from the releases of the project on GitHub (see section 3) or from extensions.blender.org, which processes data under the policy of the Blender Foundation. It has no accounts, no analytics and no advertising.
The camera starts when you press Start camera in the Leviate tab. The video is read by the hand tracking on your computer, frame by frame and is never recorded or sent anywhere. The add-on moves only the 3D view or the selected objects in Blender.
Hand model. The hand tracking model comes inside the add-on. Nothing is downloaded when the camera starts.
Phone. Phone in the Leviate tab connects through PeerJS and the STUN server of Google exactly as described in section 4 and only when you choose it. Legal basis: your consent (Art. 6(1)(a) GDPR); you withdraw it by not using the phone.
The settings of the add-on are kept by Blender in its own preferences on your computer.
8. Leviate for Chrome
Leviate for Chrome is an extension for Chrome and the browsers built on it, installed from the Chrome Web Store, where Google handles the installation under its own privacy policy, or downloaded from the releases of the project on GitHub (see section 3). It has no accounts, no analytics and no advertising and it collects no data.
The camera starts when you press Start in the side panel of Leviate. The video is read by the hand tracking inside the extension, frame by frame and is never recorded or sent anywhere. The hand model comes inside the extension.
The page. While the hand is on, the extension moves the pointer, presses the mouse buttons and turns the wheel in the active tab, through the debugger permission of Chrome, and draws its cursor on top of the page. It does not read, store or send the content of the pages you visit.
Phone. Use phone connects through PeerJS and the STUN server of Google exactly as described in section 4 and only after you choose OK in the Same Wi-Fi network note, which links to this section. Legal basis: your consent (Art. 6(1)(a) GDPR); you withdraw it by not using the phone.
The settings of the extension (camera, mode, gestures) are kept in the storage of the extension on your computer and never leave it. Removing the extension removes them.
9. Leviate for Dentra Viewer
Leviate for Dentra Viewer is a plugin that runs inside Dentra Viewer, which processes data under the policy of Dentra. It has no accounts, no analytics and no advertising and it has no access to the models or to any data of Dentra.
The camera. Dentra Viewer opens the camera when you press Start in the panel of Leviate and passes its pictures to the plugin, which finds the hand on your computer and sends back to the Viewer only the moves of the view. The video is never recorded or sent anywhere. The hand model comes inside the plugin.
Phone. Use phone connects through PeerJS and the STUN server of Google exactly as described in section 4 and only after you choose Continue in the notice that explains it. This is the only use of the internet permission of the plugin. Legal basis: your consent (Art. 6(1)(a) GDPR); you withdraw it by not using the phone.
The settings of the plugin (camera quality, mirror, gesture speeds) are kept by the Viewer on your device.
10. Cookies and browser storage
Leviate sets no cookies. It keeps a few values in your browser storage, on your device only. They keep the app working and your choices remembered and never leave the device.
| Name | Purpose | Duration |
|---|---|---|
| leviate.settings | Camera and gesture settings | Until you clear it |
| leviate.windows | Position of the floating windows | Until you clear it |
| leviate.support | Remembers that you chose Support or Don't ask again, so the Ko-fi note does not come back | Until you clear it |
| leviate.consent | Your consent choice, date and a random code that identifies nobody | Six months |
The consent categories are Necessary (always active), Camera, Statistics (nothing in use today) and External services (PeerJS for Use phone). You can change your choice at any time.
11. Your rights
You have the right to access, rectify and erase your data, to restrict or object to its processing, to data portability and to withdraw consent at any time without affecting earlier processing (Articles 15 to 22 GDPR). Write to info@vladpereverzyev.com. You can also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali.
12. Changes
This policy may be updated when the app changes. The date at the top shows the last change.