Legal
Privacy Policy
Last updated: [effective date]
We collect only what we need to run the Service, we keep your designs private to your account, and we do not sell your personal data or your designs. This policy is drafted with India’s Digital Personal Data Protection Act, 2023 (DPDP Act) in mind.
1. What we collect
Account data. Your email address and authentication details, managed through our authentication provider. Passwords are stored by that provider in hashed form; we never see them in plain text.
Design data. The prompts you write, images you upload, and the 3D models, preview images and settings the Service generates or stores in your private workspace.
Payment data. When paid plans are live, payments are handled by a third-party payment processor. We receive transaction confirmations (amount, status, a transaction reference) but never collect or store your card or bank details.
Usage and technical data. Server logs and generation records (such as job status, timestamps and error details) and error telemetry from our monitoring tools, used to operate, debug and secure the Service.
2. How we use your data
We use your data to: authenticate you and maintain your session; run generations and edits; store and display your models in your private workspace; compute dimensions and weight estimates; process payments and maintain your credit balance (including automatic credit refunds for failed generations); provide support; monitor errors and keep the Service secure and reliable; and meet legal obligations such as tax and accounting records. We do not sell your personal data or your designs, and we do not use your designs to train AI models.
3. Third-party processors
To provide the Service, we share data with a small set of service providers, each processing it on our behalf and only to deliver their function:
- AI service providers — process your prompts and images to generate 3D models and images;
- Cloud hosting and storage providers — run the application, database and the private storage for your files;
- Payment processor — handles payment transactions when paid plans are live;
- Error-monitoring provider — receives technical error reports so we can fix failures.
These providers operate under their own security and confidentiality commitments. A current list of processor categories is maintained in this policy; further detail is available on request at [support email].
4. Where your data is processed
We serve users in India, but our cloud infrastructure and service providers may store or process data on servers located outside India. By using the Service you acknowledge this. We take reasonable steps to ensure your data receives adequate protection wherever it is processed, consistent with applicable law.
5. Retention
We retain your design data and account data while your account is active. When you delete an item, or your account is deleted, we remove the associated data from active systems, subject to short technical backup windows and any retention required by law (for example, tax records of transactions). Usage logs and error telemetry are retained for limited operational periods and then deleted or anonymised.
6. Your rights
Consistent with the DPDP Act, 2023, you may:
- Access — request a summary of the personal data we hold about you and how it is processed;
- Correction — request correction of inaccurate or incomplete personal data;
- Erasure — request deletion of your personal data and your account;
- Grievance redressal — raise a complaint about how your data is handled;
- Nominate — nominate a person to exercise these rights on your behalf as the law provides.
Self-serve account deletion and data export are being built into the Service. Until they ship, send any request to [support email] and we will process it within a reasonable time and any period the law prescribes, after verifying your identity.
Grievance Officer: [grievance officer name], reachable at [grievance officer email]. If you are not satisfied with our response, you may escalate to the Data Protection Board of India as provided under the DPDP Act.
7. Children
The Service is intended for users who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact [support email] and we will delete it.
8. Security
Your files live in private cloud storage accessible only through your authenticated account, served via short-lived signed links rather than public URLs. Access to production systems is restricted, and payment details never touch our servers. No system is perfectly secure, but we apply reasonable technical and organisational safeguards appropriate to the data we handle.
9. Cookies
We use essential cookies only — to keep you signed in and maintain your session. We do not use advertising or analytics cookies, and we do not track you across other websites. If that changes, we will update this policy and ask for any consent the law requires.
10. Changes to this policy
We may update this policy from time to time. For material changes we will give notice through the Service or by email before they take effect. The “Last updated” date at the top always reflects the current version.
11. Contact
Privacy questions or requests: [support email]. Grievance Officer: [grievance officer name], [grievance officer email]. Postal: [legal entity name], [registered address].