Back to home

Privacy Policy

Learn how img2threejs handles uploaded reference images, AI processing, generated Three.js output, technical data, retention, and your choices.

Last updated: 2026-07-25

1. Scope

This Privacy Policy explains how the img2threejs image-to-Three.js converter processes information. The current converter can be used without creating an account or making a payment. If account, payment, analytics, or cloud-storage features are introduced, this policy will be updated before those features are made available.

2. Information We Process

Depending on how you use the service, we may process:

  • Uploaded content: one primary PNG or JPEG image and, if you choose, up to two additional reference images.
  • Generation data: instructions created by the service, AI model responses, generated model specifications, TypeScript output, and quality or validation results.
  • Agent mode waitlist: the email address and language preference you submit when you ask to be notified about Agent mode availability.
  • Technical data: IP address, request time, browser and device information, requested URL, response status, rate-limit data, security events, and limited error diagnostics.
  • Communications: information you include when contacting the public support address.

Do not upload confidential information, government identifiers, financial or health records, biometric data, private images of another person, or other content that would cause harm if disclosed.

3. Agent Mode Waitlist

If you voluntarily join the Agent mode waitlist, we store the email address and language preference you submit. We use that information only to manage the waitlist and notify you when Agent mode is available. Submitting the form does not create an account or subscribe you to unrelated marketing.

To ask us to remove your waitlist record, contact support@img2threejs.com from the same email address. We retain the record until Agent mode notifications are complete, you request deletion, or the waitlist is discontinued.

4. How Image Generation Works

When you select Generate, your uploaded images are sent to the img2threejs server and then to OpenRouter. OpenRouter may route the request to a configured downstream AI model provider. The configured model and provider can change for availability, quality, or safety reasons.

The images and generation data are processed to analyze visible structure, produce a procedural model specification, validate the result, and return a browser preview and downloadable code. The browser renders the returned specification; the AI provider does not receive code from your local projects unless you upload it as part of an image.

5. Purposes of Processing

We process information as needed to:

  • Provide, validate, secure, and troubleshoot the requested conversion.
  • Prevent abuse, enforce rate limits, and maintain service reliability.
  • Respond to support, privacy, or legal requests.
  • Comply with law and protect users, the service, and the public.

Where applicable law requires a legal basis, the basis may be performance of the service you request, our legitimate interests in operating and securing the service, compliance with legal obligations, or consent where specifically requested.

6. Storage and Retention

The current converter does not provide an account-linked upload library or a product feature for retrieving past uploads. This is not a promise of zero storage or immediate deletion.

Uploaded images and generation data may exist in request bodies, server memory, temporary processing systems, backups, security logs, or AI-provider systems. Hosting, security, OpenRouter, and downstream model providers may retain data under their own settings, contracts, and policies. Operational logs may also be retained for security, reliability, abuse prevention, and legal compliance.

We will update this policy with specific retention periods when the production hosting and provider configuration is finalized. Until then, do not upload material that requires a guaranteed deletion schedule.

7. Service Providers and Disclosure

Information may be disclosed only as needed to:

  • OpenRouter and the downstream AI model provider selected for the request.
  • Hosting, content-delivery, security, logging, and monitoring providers.
  • Professional advisers, authorities, or other parties when required by law or reasonably necessary to address fraud, abuse, security, or legal claims.
  • A successor in a merger, acquisition, financing, reorganization, or sale, subject to appropriate notice and legal safeguards.

We do not sell uploaded images or personal information. We do not use uploaded images for advertising. Third-party providers process data under their own terms and privacy policies; review OpenRouter's privacy policy before generating.

8. Cookies and Local Storage

The site may use essential cookies or browser storage for language, theme, security, and interface preferences. The current public converter does not require an advertising profile, payment cookie, or account session for ordinary generation. If optional analytics or marketing technologies are enabled, this policy and any required consent controls will be updated first.

9. International Transfers

OpenRouter, downstream AI providers, and infrastructure providers may process information in countries other than yours. Where required, transfers will rely on an appropriate legal mechanism. Do not use the service if your content cannot lawfully be transferred to the providers needed to process it.

10. Security

We use measures such as HTTPS transport, server-side credential handling, file-type and size validation, structured-output validation, and rate limiting. No internet service or AI provider can guarantee absolute security. You remain responsible for removing sensitive information before uploading.

11. Your Choices and Rights

You may decide not to generate, remove a selected image before submission, or stop using the service. Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to complain to a data-protection authority.

Send a request to the contact address below with enough detail to identify the relevant request, such as the approximate date, time, and technical context. Because the converter does not currently associate uploads with an account, we may be unable to locate or verify a particular request. We may ask for reasonable identity verification and may retain information when legally required.

12. Children

The service is not directed to children under 13 or under the minimum digital-consent age in their jurisdiction. A person under the age of legal majority should use the service only with permission and supervision from a parent or legal guardian. Do not upload images of children unless you have a lawful basis and all required permissions.

13. Changes

We may update this policy when the product, providers, retention configuration, or legal requirements change. The updated date identifies the current version. Material changes will be presented through the site or another reasonable notice method before they take effect where required.

14. Contact

Privacy and data-rights questions may be sent to support@img2threejs.com.

The address is published for support use, but production email routing has not yet been confirmed. Until setup is completed, delivery and response cannot be guaranteed. See the Support page for the current contact status.