Privacy Policy
Last updated: 2026-06-04 · Applies to the 3dimages.ai app at https://app.3dimages.ai
3D IMAGES LIMITED (“we”, “us”, “Controller” where GDPR applies) operates the 3dimages.ai application at https://app.3dimages.ai.
What this covers
This policy describes how we handle personal data when you use the 3dimages web app (account, dashboard, editor, settings, and sign-in). It does not describe your own store or sites where you embed our viewer. Our marketing site (https://3dimages.ai) may use separate practices.
Roles (B2B)
If you are a business customer using 3dimages for your store, you are typically the controller for personal data about your shoppers. We act as your processor when we host embed analytics and your product content on your instruction. For your own 3dimages account data, we are the controller. See our Terms for processing terms.
Lawful bases (EEA/UK GDPR)
We rely on the following bases for app users (not an exhaustive list):
- Contract — account, hosting your projects, billing, delivering features you sign up for.
- Legitimate interests — security, abuse prevention, rate limiting, error monitoring (Sentry), and improving the service in ways that do not override your rights. You may object where applicable.
- Consent — optional PostHog analytics cookies (withdraw anytime via ).
- Legal obligation — where we must retain or disclose data to comply with law.
Data we collect
- Account — email and password, or Google sign-in via Supabase Auth. The sign-up form asks for a username, but we do not currently save it to your profile. We store email, display name (when you set it in Settings), and plan tier.
- Settings — theme preference in Settings → General. Notification columns exist in our database but are not yet available in the product UI.
- Product content — project names, 3D models, thumbnails, editor configuration, and AI generation inputs/outputs you upload or create (including prompts and image inputs where you provide them).
- Billing — we store a Stripe customer ID and plan tier; payment card details are handled by Stripe, not stored in our database.
- Usage & quotas — counts tied to your user ID (e.g. generations per billing cycle, project limits).
- Embed analytics — when a published viewer loads, we may record event type (view, hotspot click, variant select) and small optional metadata (e.g. hotspot or variant IDs). These events are linked to a project, not to a shopper account in our app. Merchants should inform shoppers where required by law.
- Technical — IP address may be used transiently for rate limiting (Upstash Redis). Error reports may be sent to Sentry (see below).
- Analytics (optional) — if you accept analytics cookies, PostHog may receive page views, interactions, session replay (with inputs masked), and when signed in your user ID and email. If you decline, we do not run PostHog in the app; embed routes use separate cookieless event beacons only.
Sentry (error monitoring)
We use Sentry on app and embed routes to diagnose crashes. Our code sets sendDefaultPii to off unless you explicitly enable it in deployment. We rely on legitimate interests for this processing. Maintain an internal Legitimate Interests Assessment (LIA) and keep session replay disabled in Sentry unless you reassess risk.
Processors & international transfers
We use providers that may process data outside your country, including:
- Supabase (auth, database, file storage)
- Google (OAuth sign-in, when you choose it)
- Stripe (payments and subscriptions)
- Fal.ai (AI 3D generation when you use those features)
- PostHog (product analytics, only with consent; US host by default)
- Sentry (error monitoring)
- Cloudflare Turnstile and R2 (when enabled)
- Resend (email delivery)
- Upstash (rate limiting)
- Hosting (e.g. Vercel)
Where GDPR requires safeguards for transfers (e.g. to the United States), we rely on appropriate mechanisms such as the provider's Standard Contractual Clauses (SCCs) and/or UK International Data Transfer Addendum where applicable. Request copies or details via the contact below.
Retention & deletion
We keep account and project data while your account is active. You can delete your account under Settings → Account; that triggers deletion of your auth user and related rows in our database (profile, projects, generations, embed events, etc.) via database rules tied to your user ID.
Deletion in our app may not automatically cancel a Stripe subscription or erase copies held by subprocessors (e.g. backups, logs, Fal temporary files, or storage objects). Contact us if you need help with a deletion request.
Analytics consent records include a timestamp and policy version; we may ask you to confirm again after 12 months or when the policy version changes (see Cookie Policy).
Your choices & rights
- — control optional analytics cookies.
- Update profile and email in Settings.
- Delete your account under Settings → Account (Danger zone).
- Depending on where you live, you may have rights to access, correct, delete, object, restrict, or port data — contact us below.
EEA/UK representatives
If you are in the EEA or UK and we are required to appoint a local representative, contact us at hello@3dimages.ai for current details.
Children
The service is not directed at children under 16, and we do not knowingly collect their personal data.
Changes
We may update this policy; the “Last updated” date at the top will change when we do. Material changes may require renewed consent for analytics cookies.
Contact
Email: hello@3dimages.ai