Privacy Policy
Last updated: September 19, 2026
What we store
Account data: email address, username, display name, optional avatar and banner, profile visibility, membership tier, and the time you joined and last signed in. Sign-in data: your password as a salted hash (we cannot read it), and, if you connect Google or Discord, that provider's account ID, email, username and avatar link. Activity: orders, purchases, download history, favorites, wallet transactions, support tickets and notification preferences. Security data: active sessions (a hashed token, IP address and browser type) and an audit log of security-relevant events.
Cookies and local storage
We set one essential, HttpOnly session cookie to keep you signed in, and a short-lived cookie while a Google or Discord sign-in is in progress. Your language choice is kept in your browser's local storage. We do not use advertising or tracking cookies.
Who processes data for us
Stripe (card payments and subscriptions — we never see card numbers), Google and Discord (only if you choose to sign in with them; we read your ID, email, name and avatar, and for Discord our bot checks your role in our server), our email delivery provider (verification, password reset and support emails), and, when you use the AI tools, Anthropic (Verse AI Lab) and Meshy (AI 3D generation), which receive the text or images you submit.
How long we keep it
Account data is kept while your account exists. Sessions expire automatically. If you delete your account, we remove your profile, images, connected accounts, favorites, notifications and saved AI work and replace your name and email with placeholders. Order, payment and audit records are retained, without personal details, because we need them for accounting and fraud prevention.
Your choices
You can edit your profile, choose who sees it, disconnect Google or Discord, sign out other devices, manage email notifications, and deactivate or delete your account from Settings. For anything else — including a copy of your data — open a support ticket.
Security
Passwords are hashed with bcrypt, sessions are revocable, sign-in attempts are rate-limited, and files are released only to the account that bought them. No system is perfectly secure; if you think your account is compromised, change your password and sign out other devices immediately.
