The app listens only on 127.0.0.1 with a per-session token and sends nothing over the network after setup.
If you find a security problem, please report it privately through GitHub: Security → Report a vulnerability on this repository. Please don't open a public issue for it.
Two things worth knowing: the SCAD → STEP tab runs OpenSCAD on the model you choose, and an OpenSCAD model is a program (it can include other files and import files from disk), so only convert models you trust, as you would only open them in OpenSCAD. Choosing a file by path reads that path from your own computer; the page is reachable only from this computer with the session token.
The Diagnostic panel of the preview window shows a QR code with a job's settings and result. It is a picture on the page and is sent nowhere. It holds the app version, the time, the settings and the result numbers, and which of Linux / Windows / macOS it ran on; it does not hold the file's name, any path, the log or the error text (the panel shows the file name and error text beside it in words, marked "not in the code", so crop them out of a screenshot if they are private).
This is a work-in-progress, as-is project with no warranty; fixes are best-effort.