Legal · Last updated May 26, 2026
Privacy Policy
This Privacy Policy explains what data 3DP Ocean collects when you use the service, how we use it, and the choices you have. We try to keep it short and free of legal padding.
The AI-3D answer in one paragraph
We do not train AI models on your uploads or your generated outputs. This applies to free and paid users equally: no tier downgrade, no "free users opt in by default," no fine print. Your input photos travel from your browser to our object storage, are sent server-to-server to the AI provider you chose for that single generation only, and the result is returned to your account. We don't pass your inputs to any third party for model training, and we don't license them out. The exhaustive list of which AI providers see what is in section 4.
1. Who we are
3DP Ocean is a service of 3DP Miniatures (ABN 60 917 115 062), an Australian business, which is the controller of the personal data you give us. For privacy questions, to ask what we hold about you, or to have it deleted, contact us at /contact and a person will answer.
2. Data we collect
2.1 Account data
- Email address (required for sign-in and password resets)
- Display name and avatar (optional; from OAuth providers if you sign in with Google or Microsoft)
- Hashed password (only if you sign in with email and password; we never see your plain password)
- Sign-in and sign-out times and the IP address a request came from, kept for security and abuse prevention. We store the address; we do not look up a location from it.
2.2 Content you upload and generate
- Images you upload as input to the AI pipeline
- Enhanced images, 3D models (GLB / STL / OBJ / PLY / 3MF / VRML), texture maps, and thumbnails produced from your inputs
- Metadata you add to your models (title, description, tags, category, price, visibility)
- AI-pipeline metadata generated about your input (pose descriptor, detected orientation, subject category; used to steer the generation, not stored as a profile about you)
- Comments, votes, likes, and downloads you make on other users' models
2.3 How your uploads are checked
We want to be exact about this, because a vague answer here is worse than none.
- The AI services that process your picture apply their own safety filters. A picture that breaches them is refused before any 3D model is generated, and we are told only that it was refused.
- We do not run our own automated scanning of uploads. No hash matching, no classifier of ours. We would rather tell you that than describe a safeguard we have not built. If we build one, this page will change before it does.
- We act on reports and on review. Anything reported to us through the contact form is read by a person, and we remove content and close accounts where the Content Policy has been broken.
- Child sexual abuse material. No threshold, no warning: any account found with it is closed permanently and reported to the relevant authority. Uploading it is a criminal act, not a policy violation.
- Real-person likeness. Your picture is used only for the generation you asked for. We do not build a facial-recognition index, do not keep it to match against other uploads, and do not share it outside the provider running that one job.
2.4 Usage data
- Pages you visit, features you use, and how long generations take
- Device type, browser, operating system, and screen size
- Diagnostic data when something fails, including error messages and the last few actions you took before the failure
2.5 Payment data
Card details and bank information go straight to our payment processor (Stripe). We never see or store your full card number; we only receive a token + the last four digits for display in your billing history.
2.6 Messages you send us
The contact form is the only way to reach us, and it works signed out, so what it collects is listed here rather than assumed from your account: the email address you give us to reply to, your name if you fill it in, the title and description you write, any screenshot you attach, and the IP address the message came from.
3. How we use your data
- Run the service. Authenticate you, generate your models, deliver downloads, render thumbnails, present Community models.
- Process payments and credits. Charge subscriptions, grant credit packages, track quotas.
- Improve the service. Diagnose failures, measure performance, prioritize features. Aggregated only, never linked to your identity outside the team.
- Communicate. Transactional emails (sign-in, billing, security). Marketing emails only if you opt in.
- Safety + abuse prevention. Detect and block content that violates the Content Policy.
- Comply with the law. Respond to lawful requests, tax requirements, and legal disputes.
We do not sell your personal data. We do not use your uploads to train our own AI models or pass them to third parties for ML training. Your inputs are sent only to the AI provider that generates your model, only for that generation.
4. AI providers and AI-training stance
4.1 Our stance, in one line
We do not use your uploads, your prompts, your generation metadata, or your generated outputs to train any AI model, ours or anyone else's. This is the same for free and paid users. Some competitors in this category reserve the right to train on free-tier users' inputs and outputs. We don't, on any tier.
For each generation, your enhanced image (and, in multi-view mode, a side and back image we generate from it) travels server-to-server to the AI provider chosen for that job, only for that job. Each provider operates under its own privacy terms; we re-host the result on our own object storage immediately so the provider can't reach back into your account and so the result survives the provider's own short-lived URLs (most providers expire output links after 24 hours).
4.2 Providers and what each one sees
The list below is the complete set of AI providers in our pipeline as of the last-updated date, and the country each one processes your image in. If we add or change a provider, we update this list before the change goes live.
- OpenAI (GPT Image, GPT-4o-mini) — United States. Used for image enhancement and the left/right-side classifier, and to answer questions you ask the in-app help. Receives the input image and the generated side view. OpenAI's API terms for paid usage state inputs are not used to train OpenAI models.
- Google (Gemini family) — United States. Used for image enhancement and pose-descriptor metadata. Receives the input image (or the enhanced front view, for multi-view jobs). Google's Gemini API terms for paid usage state inputs are not used to improve Google's models. See Google's AI privacy notice for the current commitment.
- Deemos (Rodin) — China. Our main 3D generation provider. Receives the enhanced front image and, for multi-view jobs, the side and back images. The generated model file is downloaded by us and re-hosted on our own object storage. We also reach the same provider through fal.ai (United States) as a backup route, in which case your image passes through fal.ai as well.
- Tencent (Hunyuan 3D) — China. An alternative 3D generation provider, including for multi-view jobs. Receives the enhanced front image and, for multi-view jobs, the side and back images. Same re-host pattern as the others.
- Tripo3D — China. An alternative 3D generation provider. Receives the enhanced image. Generated model file is downloaded by us and re-hosted on our own object storage; Tripo's 24-hour result URL expires after that.
We never send any provider your email, your billing details, your community activity, or any image other than the one needed for the current generation.
4.3 If a provider changes its terms
AI provider terms evolve quickly. If a provider we use begins to train on paid-tier inputs (or otherwise materially relaxes its privacy guarantees), we will: (a) suspend sending new inputs to that provider, (b) update this page within 7 days, and (c) where applicable, give you a 30-day notice before routing any of your future generations to a replacement provider with different terms.
5. Who we share with
- Hosting + infrastructure. AWS Lightsail (servers), Cloudflare R2 (file storage).
- Payments. Stripe (subscriptions and one-time charges).
- Sign-in. Google and Microsoft (only if you choose OAuth sign-in).
- AI providers. See section 4.
- Email delivery. AWS SES (transactional email).
- Legal authorities. When required by law.
6. How long we keep your data
- Account data: until you delete your account.
- Input pictures you uploaded: kept while the creation exists. Deleting the creation puts them in the 14-day bin, after which they are destroyed.
- Enhanced and generated reference pictures: the same lifecycle as the input they came from.
- Generated 3D models and the exports made from them: kept while the model exists. A private model is visible only to you and you can delete it at any time. A model you share in Community models stays there — other people find it, download it and build on it, and it earns you rewards while they do, so it is not something you can withdraw on a whim. If you need a shared model taken down, ask us and a person will look at it.
- AI-pipeline metadata (pose descriptor, side classifier result, orientation): tied to the creation job. Deleted when the job or model is deleted.
- Messages you send us through the contact form (the address you gave, what you wrote, any screenshot attached and the IP it came from) are kept while we deal with them and for as long as we may need them to answer a follow-up.
- Models other users downloaded from you stay on their devices after they download. We can't recall those copies. A shared listing stays in Community models, so if you need new downloads stopped, contact us and we will take it down.
- A creation you delete goes to a recycle bin for 14 days. Its pictures, its 3D file and its exports stop counting against your storage straight away, and it can be brought back during that window. After 14 days a nightly job destroys it for good.
- Deleting your ACCOUNT gives you 30 days to change your mind. You are signed out immediately and cannot sign back in, but nothing is destroyed: your models, files, credits and history are held for 30 days, and we can bring the account back within that window if you write to us from the address on it. After 30 days a nightly job destroys all of it permanently.
- Server logs: 30 days, then aggregated or deleted.
- Backups. Our database is backed up so the service can be restored after a failure; those copies roll over within 30 days. Your uploaded pictures and 3D files are not in any backup. The recycle bin above, and the 30-day window on a closed account, are what protect them instead.
7. Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to erasure"), including all input images, generated 3D models, and exports. Anything private you can delete yourself; for a model you have shared in Community models, contact us and we will remove it. See section 6 for the deletion lifecycle.
- Export your data in a portable format (your account info, your uploaded inputs, your generated models, and your community activity log).
- Object to or restrict certain processing
- Withdraw consent at any time
- AI-specific: request that a specific past generation's input image be excluded from any future model-training cooperation we enter into with a third party (we don't do this today, as section 4 explains, but the right is yours regardless).
- Lodge a complaint with your local data-protection authority
Most of these you can do directly in Account settings. For anything else, email us and we'll respond within 30 days.
8. Children
3DP Ocean isn't designed for children under 13 (16 in the EEA / UK). If we learn we've collected data from a child without proper consent we'll delete it.
9. International transfers
Your pictures are processed overseas, and we want you to know exactly where. Image enhancement runs in the United States. 3D generation runs in China. Section 4.2 names every provider and the country it processes your image in. Your account details and the files you create are held on our own server and on Cloudflare's object storage, which also operate outside some customers' countries.
We rely on the data-protection terms in each provider's API agreement, and we choose providers whose published terms for paid usage state that inputs are not used to train their models. We send a provider nothing but the image needed for that job — never your email, your billing details or your account activity.
If you would rather a picture were not processed in those countries, please do not upload it. You can delete a model, or your whole account and its files, at any time from your account settings. If you have a question about a particular transfer, contact us using the details in section 12.
10. Security
We use TLS for every connection, hash passwords with bcrypt or equivalent, restrict server access to a small number of administrators with key-based authentication, and run daily encrypted backups. No system is ever 100% secure, so we also publish a coordinated disclosure process at /legal/content.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced via email or an in-app notice. The "last updated" date at the top reflects when the current version took effect.
12. Contact
Privacy questions: /contact. We are 3DP Miniatures (ABN 60 917 115 062), an Australian business, and we answer privacy requests ourselves.

