Back to 3D Thunder
Legal information

Privacy Policy

Effective 2026-09-19. This notice explains the personal data used to provide and protect 3D Thunder and the rights available to you.


1. Controller and contact

The controller is Enes K., the private individual operating 3D Thunder. For privacy questions or requests, use the feedback function on the Home page.

2. Data and purposes

We process your email address, optional display name, password hash, verification and account status, usage allowance, token purchase and fulfillment records, and account timestamps to create, authenticate, secure, and operate your account. Passwords are never stored in plain text. Verification codes are short-lived and stored only as hashes.

We process saved models, collections, dimensions, prompts, assistant conversations, generation status, and timestamps to provide the Studio and preserve your work. Limited account, security, and technical data may be processed for authentication, rate limiting, abuse prevention, service reliability, and support. Feedback or privacy requests include the message and the account or contact email needed to respond.

Your email address is used only to operate your account: as your sign-in identifier, for verification, security and abuse prevention, essential account messages, and replies to requests you initiate. It is never used for newsletters, advertising, profiling, or sale to third parties.

Admins may opt in to device push notifications about new user and guest accounts. We store the device subscription endpoint, encryption keys, timestamps, and associated admin account to deliver these notifications. Notification messages do not include the new account's name or email address. Admins can disable notifications for each device in the Admin Panel.

3. Legal bases

Account and model processing is necessary to provide the service you request under Article 6(1)(b) GDPR. Security, abuse prevention, rate limiting, service reliability, and limited audit records rely on legitimate interests under Article 6(1)(f) GDPR. Any mandatory retention relies on Article 6(1)(c) GDPR. Required account data must be provided to use authenticated features.

Limited first-party audience measurement supports our legitimate interest in understanding which pages are useful and which broad sources bring traffic (Article 6(1)(f) GDPR). We store only daily totals for predefined page categories and sources such as search engines, social networks, other referrals, internal navigation, or direct/unknown. We do not store visitor identifiers, IP addresses, user agents, model IDs, full referrer URLs, or URL query parameters in these analytics totals, and use no analytics cookies or browser storage. Account settings, authentication and admin pages are excluded. Do Not Track and Global Privacy Control signals disable collection. Request metadata is used temporarily for abuse prevention; normal hosting access logs are separate from these analytics. This measurement does not identify unique visitors.

4. Service providers and transfers

Vercel hosts and delivers the app, Supabase provides the database, Resend sends transactional email, Stripe processes checkout and payment information, Cloudflare Turnstile checks registrations for abuse, and the model-generation service receives the prompt and model data needed for requested generation. Payment details are entered directly into Stripe's checkout and are not stored by 3D Thunder. Providers may process data outside the EEA. Where required, transfers use an adequacy decision, standard contractual clauses, or another lawful safeguard. Personal data is not sold.

Optional admin push notifications use the browser or operating system's push provider, such as Apple, Google, Mozilla, or Microsoft. These providers handle subscription and delivery metadata; notification payloads are encrypted for the subscribed device.

5. Retention and deletion

Account and Studio data is kept while your account is active. You can permanently delete your account in Profile settings; this removes the account, saved models, collections, prompts, conversations, verification data, and directly associated audit records from the active database. Payment records may be retained where required for accounting, tax, fraud prevention, or legal obligations. Temporary backups may remain until their normal overwrite cycle. Data required by law may be retained only for the applicable period. Verification codes expire after 15 minutes.

Admin push subscription records are removed when the device switch is turned off, the associated account is deleted, or the push provider reports that the subscription has expired. Signing out alone does not disable an existing device subscription.

Page-view totals use a 90-day retention window. Older aggregate buckets are removed on the next page-view collection or admin traffic report. No individual browsing history is stored.

6. Your rights

You may request access, correction, deletion, restriction, or portability of your data and object to processing based on legitimate interests. We may verify your identity before responding. You may also complain to your competent data protection supervisory authority. Automated abuse and generation limits do not make decisions with legal or similarly significant effects. This notice is updated when the service or legal requirements change.