Privacy Policy
This policy explains what 2dto3D collects, why, who else sees it, and how to get it deleted. The short version: we collect the minimum needed to run your account and generate your models, your uploaded images are sent to the AI providers listed below to produce a 3D model, and we do not sell your data or train models on your content.
1. What we collect
Account data
Your email address, and, if you sign in with Google, the name and profile picture Google returns. We also store which sign in method you used. We do not receive or store your Google password.
Content you upload
The images you upload, the intermediate images the pipeline generates from them, and the resulting 3D model files and their exports.
Usage and billing data
Your credit balance and transaction history, your generation history and its status, API keys you create, and team membership if you are part of an organisation.
Technical data
Standard server request data, and aggregated product events (for example that a generation completed) written to Cloudflare Analytics Engine. Our marketing pages use Cloudflare Web Analytics, which is cookie free and does not fingerprint or track individuals across sites.
2. Where your images go
This is the part most people want to know, so it is spelled out in full. To turn a photo into a 3D model, we send your image to third-party AI providers. Each one receives your image or a derivative of it:
- OpenAI receives your uploaded image to identify what the subject is.
- fal.ai receives your uploaded image to generate additional camera angles of the same subject.
- Tripo3D receives those generated angles to build the 3D geometry and texture, and to convert the model into other export formats.
Each provider processes the image under its own terms and privacy policy, and each may be located outside your country. If that matters for your business, review their policies before uploading anything sensitive. Uploading a product photo is fine. Uploading confidential or personal material to any AI service, ours included, deserves more thought.
3. Other services we use
- Cloudflare hosts the entire product. Your account records live in Cloudflare D1, your images and models in Cloudflare R2, sessions in Cloudflare KV, and our emails are sent through Cloudflare Email Workers.
- Polar handles payments as merchant of record. They receive your email address and payment details directly. We receive a record that an order completed and for how much. We never see your card number.
- Google receives an authentication request if you choose to sign in with Google.
4. Cookies
We set one cookie: a session cookie that keeps you signed in. It is strictly necessary, so there is no consent banner to click. We do not run advertising cookies, and we do not embed third-party tracking pixels on the marketing site.
5. Email you receive from us
Transactional email is part of the service: magic link sign in, generation complete or failed, purchase receipts, low credit warnings, export ready, and team invitations. You cannot opt out of these while you hold an account, because they are how the product tells you what happened.
We also send a small number of lifecycle emails, such as a welcome note and an occasional check in. Every one carries an unsubscribe link, and clicking it stops that category of email for good without affecting transactional messages.
6. Who can see your models
Your models are private to your account. They become visible to other people only when you make them so: creating a share link or using the embed snippet makes that model viewable by anyone holding the link, with no sign in required.
The examples in our public gallery are produced by us specifically for that purpose. We never publish, feature, or reuse customer models in our marketing.
7. How long we keep things
- Account data for as long as your account is open.
- Images and models for as long as your account is open, so you can go back to them. There is no automatic expiry.
- Billing records for as long as tax and accounting law requires us to keep them, which can outlast your account.
- Sessions until they expire or you sign out.
- Analytics events in aggregated form, not tied to your identity.
We do not control how long our AI providers retain the images we send them. That is set by their own policies.
8. Your rights
You can ask us to give you a copy of your data, correct it, or delete it. If you are in the UK, EU, or California, you have these rights under law, and we apply the same process to everyone regardless of where you live.
Account deletion is handled manually right now. Email support@2dto3d.app from the address on the account and we will delete your account, your images, and your models, and confirm when it is done. We aim to complete requests within 30 days and usually much sooner. Billing records we are legally required to retain are the one exception.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
9. Security
Sessions are held in signed cookies and API keys are stored hashed. All traffic runs over HTTPS. No system is perfectly secure, so if you believe your account has been accessed by someone else, email support@2dto3d.app and we will invalidate your sessions.
10. Children
2dto3D is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
11. Changes to this policy
We may update this policy. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will email account holders before it takes effect.
12. Contact
Privacy questions, data requests, and complaints go to support@2dto3d.app. If you are in the UK or EU and are not satisfied with our response, you have the right to complain to your local data protection authority. See also our terms of service.