Legal

Privacy & Cookie Policy

Last Updated: July 14, 2026

1. Scope & Contact

This policy explains how UForge3D (“we”, “us”) handles personal data when you visit our website, apply for the closed beta, use the UForge3D application (the “Service”), or contact us.

The data controller for the Service is Filippo Tedeschi, operating UForge3D, at Via Terradura 15, 35020 Maserà di Padova (PD), Italy.

For privacy questions or requests, contact us at hello@uforge3d.com.

2. Information We Collect

The information we handle depends on how you use the Service:

  • Account and access data: Email address, display name, optional profile photo, user identifier, authentication and session data handled through Supabase, beta status, credit balance, and credit expiry.
  • Beta application data: Name, email, role, audience range, social profile URLs, proposed use case, sharing plan, beta agreements, application status, and internal review information.
  • Project and AI content: Project titles and descriptions, prompts, reference images, uploaded photos, masks, isolated parts, generation settings, generated images, 3D meshes, thumbnails, and related project metadata.
  • Feedback and communications: Feedback messages, category, the page from which feedback was sent, optional shared URLs, support correspondence, and email delivery information.
  • Operational data: Credit spend and refund records, operation and idempotency identifiers, selected models or providers, request status, timestamps, processing duration, and error information.
  • Credit-purchase and checkout data: Beta purchase eligibility, historical purchase-access review records where applicable, selected credit package, amount, currency, order and Stripe transaction identifiers, payment status, checkout timestamps, the versioned purchase-consent snapshot, verified confirmation-email recipient, and delivery status. Stripe collects payment credentials and billing details directly through its hosted checkout; UForge3D does not receive your full card number. Sandbox checkouts use simulated payments but may still involve the billing and technical information you enter.
  • Technical and anti-abuse data: Our hosting, authentication, and security providers may process IP address, browser or device information, request metadata, security events, and Cloudflare Turnstile challenge results when you connect to the Service.

3. How We Use Information

  • Review beta applications, create approved accounts, and manage access to the closed beta;
  • Authenticate users and maintain account sessions;
  • Save projects and perform the image, prompt, decomposition, and 3D-generation operations you request;
  • Manage beta credits, prevent duplicate paid operations, reconcile ambiguous outcomes, and process eligible credit refunds;
  • Provide beta credit purchases, create and reconcile secure checkouts, prevent duplicate fulfillment, and maintain payment, refund, dispute, tax, and accounting records;
  • Send account, password-recovery, beta-status, feedback, and other transactional emails;
  • Provide support, review feedback, diagnose failures, and improve the reliability and usability of the Service;
  • Prevent abuse, protect accounts and infrastructure, enforce our terms, and comply with applicable legal obligations.

We do not sell or rent your personal data or use your project content for third-party advertising.

4. Legal Bases

Where data-protection law requires a legal basis, we process information as needed to provide the Service or take steps you request before using it; for our legitimate interests in operating, securing, supporting, and improving the closed beta; to comply with legal obligations; and, where we specifically ask for it, on the basis of your consent. If processing is based on consent, you may withdraw it for future processing by contacting us.

5. AI Processing Providers

Core Service features require us to send the content needed for a requested operation—such as prompts, instructions, reference images, masks, or generation settings—to external AI providers. The provider used depends on the tool and model you select and may include:

  • Tripo AI: Image-to-3D reconstruction and mesh generation.
  • fal.ai and models made available through fal.ai: Background removal, image generation and editing, and subject isolation. Depending on your selection, a model may originate from providers such as Google, xAI, ByteDance, or Black Forest Labs.
  • OpenRouter and the selected downstream model provider: Text, prompt, and vision analysis. The current configuration can route these requests to Google Gemini models.
  • OpenAI: Optional direct image isolation and editing operations.
  • Google Cloud Vertex AI or Google AI: Configured fallback processing for certain Gemini text, vision, or image operations.

These providers may temporarily host inputs or outputs and may perform abuse monitoring. Their handling and retention of data are also governed by the applicable provider configuration, contract, and privacy terms. Do not include confidential or highly sensitive personal information that is not necessary for the operation you request.

6. Infrastructure & Communications Providers

We also use service providers to host and operate the Service:

  • Supabase: Authentication, PostgreSQL database, and file storage.
  • Vercel: Website hosting and server-side frontend functions.
  • Hetzner: Backend hosting and processing infrastructure.
  • Cloudflare: Turnstile anti-bot verification and email-routing or related network services.
  • Resend: Transactional email delivery, including beta, account, feedback, and password-related messages.
  • Stripe: Hosted checkout, live payment processing, fraud prevention, billing, tax-related processing, refunds, and disputes. Sandbox mode is also used for pre-production payment testing. Payment credentials and billing details entered in checkout are provided directly to Stripe.

Each provider receives only the information needed for its role, but may also create its own service, delivery, access, or security logs.

7. Storage, Access & Public Projects

Account and project records are stored in Supabase. Project files, including reference images and generated meshes, are stored in Supabase Storage. Projects are private by default. Access controls include authenticated sessions, database Row-Level Security, server-side authorization, and time-limited signed URLs for private files. Authorized administrators and server processes may access data when necessary to operate, secure, or support the Service.

If you make a project public, anyone who can access the public project may view its project information, visual assets, generated meshes, your display name and avatar, and related community activity. You can make the project private again from its visibility control. Profile photos are stored using a public URL so they can appear in the community showcase; anyone who has that URL may be able to retrieve the photo until you remove or replace it.

We use reasonable technical and organizational safeguards, including HTTPS and restricted server credentials. No online service or storage system can be guaranteed completely secure.

8. Retention & Account Deletion

We retain account, project, application, feedback, communication, and operational records for as long as reasonably necessary to provide and secure the Service, administer the closed beta, resolve disputes, enforce our terms, and meet legal obligations. Retention periods can differ by category and by service provider.

Non-admin users can start account deletion from the Account Settings page. The automated flow deletes the authentication account and associated database records and attempts to remove project images and meshes from active storage. It may not cover records not linked directly to the account, such as the original beta application or transactional email records, provider-side copies, security logs, backup copies awaiting expiry, or objects left after a storage-cleanup error.

If you purchase credits, order, credit-ledger, purchase-consent, confirmation-delivery, refund, dispute, and related accounting records may be retained after account deletion where necessary to reconcile transactions, meet legal or tax obligations, prevent fraud, or establish, exercise, or defend legal claims. We detach those records from the active profile and pseudonymize them where the retention purpose permits; limited contract evidence such as the verified confirmation recipient may remain identifiable for the applicable retention period. Project content and your active login are not required to remain linked to those records.

You can remove your avatar and make projects private before deletion. To request deletion or review of any remaining personal data, or if the in-app flow is unavailable, email hello@uforge3d.com from the address associated with your account. Some information may be retained where required by law or needed to establish, exercise, or defend legal claims.

9. Cookies & Browser Storage

We use essential authentication cookies managed through Supabase to keep you signed in and refresh your session. Cloudflare Turnstile may use technical browser data and storage necessary to verify that a request is legitimate.

When you choose to open Stripe Checkout, you leave UForge3D for a Stripe-hosted page. Stripe may use cookies or similar technologies needed to provide checkout, prevent fraud, and secure the transaction under its own privacy and cookie information.

The application also uses local storage, session storage, and IndexedDB for preferences, one-time tours, page-to-page project handoffs, temporary work-in-progress images and generated meshes, and identifiers that prevent accidental duplicate credit operations. This information remains on your device until it is removed or overwritten, the browser session ends where applicable, or you clear site data. Clearing browser storage may remove unsaved work or operation support references.

As of the date above, we do not integrate advertising pixels or third-party behavioral analytics SDKs in the Service.

10. Your Choices & Rights

Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data; receive a portable copy of certain data; withdraw consent for future processing; and lodge a complaint with your local data-protection authority.

You can update your display name, avatar, password, and project visibility in the Service. For other requests, email hello@uforge3d.com. We may need to verify your identity and may limit a request where applicable law permits or requires it.

11. International Processing

Our infrastructure and AI providers operate in multiple countries. Using the Service may therefore involve processing outside your country, including outside the European Economic Area. Contact us if you want more information about the locations and safeguards applicable to a particular processing activity.

12. Changes to This Policy

We may update this policy as the closed beta, providers, or legal requirements change. We will update the date at the top of this page and provide additional notice where appropriate for material changes.

UForge3D — Character-to-3D AI Creation Stack