Privacy Policy
Last updated: June 10, 2026
1. What we collect
- Account data — email address and authentication identifiers (managed by Supabase Auth).
- Content — 3D models, designs, thumbnails and configurations you upload or create.
- Usage & billing — credit spend, plan, and payment status. Card details are processed by Stripe and never touch our servers.
- Technical logs — request metadata used for security, rate limiting and debugging.
2. Camera & AR try-on
The AR try-on processes your camera feed entirely in your browser. Frames are analyzed on your device for hand tracking and lighting estimation and are never uploaded, stored or shared. Photos you explicitly capture stay on your device unless you choose to save or share them.
3. How we use data
To operate the Service: render and store your designs, serve your embeds, meter credits, prevent abuse and provide support. We do not sell personal data, and we do not use your designs to train models.
4. Sharing
Data is shared only with the processors that run the Service — Supabase (database & auth), Stripe (payments) and our hosting provider — each bound by their own data protection agreements. 3D assets are stored on our own NAS. Content you publish as an embed or share link is visible to anyone with access to that page or link.
5. Retention & deletion
Your content stays until you delete it or close your account. Deleting a project removes it from the dashboard immediately and from backups on their rotation schedule. You can request a full export or deletion of your account data at any time.
6. Security
All traffic is encrypted in transit (TLS, HSTS). Tenant data is isolated with row-level security at the database layer. API keys are stored only as salted hashes. Access to production systems is restricted and audited.
7. Contact
For privacy requests (access, export, deletion), contact us through your dashboard or the email on our website.