Privacy Policy
Last updated: June 10, 2026
1. What we collect
- Account data — email address and authentication identifiers (managed by Supabase Auth).
- Content — 3D models, designs, thumbnails and configurations you upload or create.
- Usage & billing — credit spend, plan, and payment status. Card details are processed by Stripe and never touch our servers.
- Technical logs — request metadata used for security, rate limiting and debugging.
- Asset delivery measurements— when a 3D viewer or ring builder runs (including embedded in a merchant’s own store), the browser reports how many bytes of 3D files it downloaded, a per-tab identifier that is discarded when the tab closes, an approximate country from our CDN, and the origin of the page the viewer is embedded in. This tells merchants and us what delivering those files costs. We do not store IP addresses, finer location, or any identifier that persists across visits, and we honour Do Not Track and Global Privacy Control — with either enabled, nothing is recorded.
2. Camera & AR try-on
The AR try-on processes your camera feed entirely in your browser. Frames are analyzed on your device for hand tracking and lighting estimation and are never uploaded, stored or shared. Photos you explicitly capture stay on your device unless you choose to save or share them.
3. How we use data
To operate the Service: render and store your designs, serve your embeds, meter credits, prevent abuse and provide support. We do not sell personal data, and we do not use your designs to train models.
4. Sharing
Data is shared only with the processors that run the Service — Supabase (database & auth), Stripe (payments) and our hosting provider — each bound by their own data protection agreements. 3D assets are stored on our own NAS. Content you publish as an embed or share link is visible to anyone with access to that page or link.
5. Retention & deletion
Your content stays until you delete it or close your account. Deleting a project removes it from the dashboard immediately and from backups on their rotation schedule. You can request a full export or deletion of your account data at any time.
6. Security
All traffic is encrypted in transit (TLS, HSTS). Tenant data is isolated with row-level security at the database layer. API keys are stored only as salted hashes. Access to production systems is restricted and audited.
7. Contact
For privacy requests (access, export, deletion), contact us through your dashboard or the email on our website.