AI3DLogo Privacy Policy
Pre-launch draft — not yet effective. AI3DLogo has not launched. The operator's legal name, postal address, governing law, dispute forum, and effective date must be completed and reviewed by qualified counsel before production release.
Last updated: August 28, 2026
This Policy explains how AI3DLogo handles personal data when you use ai3dlogo.com, its related API, support channels, and billing flows. The data controller is Operator identity and postal address: to be completed before launch.
1. Data we collect
- Account and authentication data: Google subject identifier, verified email address, display name, avatar URL, sign-in timestamps, authentication sessions, and account status. AI3DLogo does not receive or store your Google password or Google access and refresh tokens.
- Creative content: brand name, slogan, industry, prompt, style, material, color, background, composition, transparency request, uploaded logo, generated raster outputs, thumbnails, selected model and aspect ratio, output count, and task events.
- Payment and entitlement data: Stripe customer, checkout, subscription, invoice, payment, refund, and dispute identifiers; plan or Credit Pack; amounts, currency, tax status, credit grants, spends, refunds, balances, and retention tier. Complete payment-card numbers are entered into Stripe, not AI3DLogo.
- Browser and device data: pseudonymous visitor and guest-device identifiers, local or session storage, IndexedDB task cache, browser characteristics, coarse request metadata, security cookies, and authentication or preference events.
- Network, security, and operations data: IP addresses necessarily processed in transit by network and hosting systems; HMAC-protected or hashed device, fingerprint, and network identifiers stored by the application for guest-credit and abuse controls; rate-limit, risk, audit, worker, deletion, and error events. Routine application audit records are designed not to store raw IP addresses, prompts, credentials, cookies, or private media URLs.
- Analytics data: Google Analytics may process page route and title, permitted campaign parameters, referral information, browser and device characteristics, approximate location derived by Google, pseudonymous Google Analytics client and session identifiers, and selected product events such as tool choice, input count and size, model, output count, credit cost, checkout, and download. We do not intentionally send prompts, brand names, slogans, uploaded or generated images, email addresses, account IDs, task IDs, or private media URLs to Google Analytics.
- Support data: your email address, message, task or order identifiers, timestamps, and any material you choose to include.
Your browser may keep recent generation metadata, including prompts and temporary media links, in AI3DLogo-namespaced local storage or IndexedDB. That browser-side copy remains on your device until it is replaced, you delete it, or you clear site data.
2. Why we use data and our legal bases
We process data as needed to:
- provide the contract you request, including sign-in, generation, private storage, downloads, purchases, subscriptions, support, and account deletion;
- protect legitimate interests in service security, fraud and free-credit abuse prevention, reliability, bookkeeping, enforcing policies, and establishing or defending legal claims;
- comply with tax, accounting, payment, consumer-protection, sanctions, court, regulatory, and other legal obligations;
- measure product usage through Google Analytics when it is configured for the Service; and
- use data for another purpose when we give appropriate notice and obtain consent where required.
We do not sell personal data. AI3DLogo does not operate or train its own foundation image model. How generation providers handle inputs and outputs is described below and may include safety review under their terms.
3. Generation data flow
For Text to Logo, AI3DLogo constructs a generation prompt from the brand fields and settings you submit. For 2D to 3D, it sends that constructed prompt plus a time-limited link to the one source 2D logo. The request also includes generation settings such as the selected model, aspect ratio, and requested output count from one through four.
The API sends this information to third-party AI generation service providers. Those providers return task status and result locations; AI3DLogo downloads each requested result, validates it as an image, and stores it in private Cloudflare R2 storage. Generation providers necessarily process prompt text, the source 2D logo image for 2D to 3D, generation settings, outputs, and technical task identifiers.
Generation providers apply their own processing, safety-review, and retention practices under their then-current terms. The provider and underlying model may change as the Service evolves. Do not submit confidential, regulated, or sensitive personal information. Contact support@ai3dlogo.com if you need the current generation-provider information before submitting content.
4. Other service providers
We disclose only data reasonably needed for each role:
| Provider | Purpose and data involved |
|---|---|
| Cloudflare | Website delivery, network security, and private R2 object storage; request/network metadata and stored source or result images. See Cloudflare Privacy Policy. |
| Google Identity Services | Google sign-in and account verification; Google credential and the account profile fields described above. See Google Privacy Policy. |
| Google Analytics | Audience and product measurement when configured; the limited analytics fields described above. See Google's Analytics data safeguards. |
| AI generation service providers | Producing requested outputs; prompt text, generation settings, technical task identifiers, generated outputs, and the time-limited source-2D-logo link used for 2D to 3D. The provider and underlying model may change. |
| Stripe | Checkout, payment processing, taxes when enabled, subscriptions, customer portal, refunds, disputes, and fraud controls; contact, transaction, billing, and payment-method data. See Stripe Privacy Center. |
| Resend | Transactional account and billing email; recipient email address and message content. See Resend Privacy Policy. |
| Sentry | Error and performance monitoring when configured; redacted exception and technical context. Request bodies, query strings, cookies, request URLs, user objects, prompts, tokens, and credentials are removed by application controls before sending. See Sentry Privacy Policy. |
| Email and infrastructure providers | Receiving support email and hosting the API and database. The exact production vendors and regions must be recorded in the pre-launch vendor register before the Service goes live. |
Providers may process data in the United States and other countries. Before launch, the operator must identify its establishment, production hosting regions, processor agreements, and any transfer safeguards required for the intended markets. We will not claim a transfer mechanism that has not actually been put in place.
5. AI3DLogo retention
| Data | Current application retention |
|---|---|
| Pending or source logo upload | Up to 24 hours, then queued for asynchronous deletion. |
| Guest result or signed-in result not saved to My Creations | Up to 24 hours. |
| Saved Free-account creation | Up to 60 creations, each for up to 7 days. |
| Saved creation after a Credit Pack purchase | Up to 300 creations, each for up to 30 days. |
| Saved creation for an active subscriber | Up to 1,000 creations, each for up to 90 days. |
| Authentication session | Access session up to 30 minutes; refresh session up to 7 days unless revoked sooner. |
| Account profile after verified deletion request | Access disabled immediately; profile scheduled for anonymization after 30 days. |
| Browser-side recent-task cache | Until replaced by application limits or removed through browser/site-data controls. |
Upgrading an account may extend still-active saved creations to the new tier's retention window. Reaching a creation limit may queue the oldest saved creation for deletion. A manual delete hides the creation immediately and queues physical object deletion; signed media URLs are temporary and do not extend the underlying retention.
Payment, tax, invoice, credit-ledger, security, fraud, dispute, notification, deletion, and immutable operator-audit records may be kept longer when reasonably necessary for legal obligations, accounting, chargebacks, security, or claims. Exact production schedules for those record classes, backups, support email, database snapshots, Sentry, and Google Analytics are pre-launch governance items and must be completed before those systems are enabled in production.
Third-party generation and infrastructure providers apply their own retention under their then-current terms, independently of AI3DLogo's application retention.
6. Account deletion and privacy requests
You can request account deletion in Account Settings after recent Google verification. The request disables login and new generation immediately, revokes active sessions, queues media deletion, requests subscription cancellation, and schedules profile anonymization after 30 days. Login identity records are removed during anonymization. Because subscription cancellation is performed through Stripe, check the displayed deletion status or contact support if it reports a failure.
Depending on where you live, you may have rights to access, correct, delete, restrict, object, receive a portable copy, withdraw consent, appeal a decision, or complain to a data-protection authority. Email support@ai3dlogo.com from the account email and describe the request. We may verify your identity and authority. Some data cannot be deleted immediately where law, payment, security, fraud-prevention, or legal-claims needs require retention.
7. Cookies and browser storage
Strictly necessary storage includes the a3dl_access, a3dl_refresh, and a3dl_csrf authentication/security cookies; the a3dl_guest_device guest-credit cookie; the a3dl_visitor_id visitor cookie and local-storage value; short-lived OAuth state; account and redirect preferences; and the recent-task cache. Blocking this storage may prevent authentication, generation, credit enforcement, or task recovery from working.
Google Analytics normally uses _ga and _ga_<measurement-id> first-party cookies to distinguish a browser and session. You can block or remove these cookies through your browser or site-data controls. See Google's GA4 cookie documentation.
Google Identity Services may load when Google sign-in is available and may use Google-controlled browser mechanisms for authentication. That authentication processing is separate from Google Analytics.
8. Security
Application controls include encrypted transport, private object storage, short-lived signed URLs, ownership checks, Secure and HttpOnly authentication cookies, CSRF protection, restricted administrator allowlists, rate limits, HMAC-protected abuse identifiers, append-only credit and operator audit records, idempotent charging and refunds, secrets management, and routine log/error redaction. These measures reduce risk but no Internet service is completely secure.
9. Children and sensitive data
The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. Contact us if you believe a minor has used the Service.
Do not submit health, biometric, government identifier, financial-account, precise-location, confidential employment, or other sensitive personal data. Do not submit another person's personal data unless you have a valid legal basis and required permission.
10. Changes and contact
We may update this Policy for product, provider, security, or legal changes. We will update the date above and provide additional notice when required.
Controller: Operator identity and postal address: to be completed before launch.
Privacy requests and questions: support@ai3dlogo.com.