Privacy Policy
Last updated: June 25, 2026
1. What Swap3D does
Swap3D provides 3D file conversion and preview tools. The public web conversion flow is designed to run locally in your browser whenever possible. Developer API and dashboard workflows use backend infrastructure for account management, asynchronous conversion, billing, storage, and operational security.
2. Information we collect
The information we collect depends on the features you use:
- Account information: email address, email verification status, password hash, connected OAuth provider records, and account settings.
- Authentication and security data: session token hashes, session expiry, user agent, hashed IP address, CSRF state, password reset tokens, email-change tokens, email-verification tokens, and two-factor authentication records.
- OAuth information: when GitHub sign-in is used, we receive your provider account ID, verified email address, and email verification status. Google sign-in is currently paused; if enabled, it will use the same limited basic profile and email data needed for authentication and account linking.
- Developer API data: API key name, key prefix, API key hash, last-used time, conversion job status, source and target formats, file size, output size, error messages, duration, quota usage, and download lifecycle metadata.
- Billing data: plan, subscription status, billing provider, Waffo Pancake order or subscription identifiers, buyer email where provided by Waffo, current period end, checkout and cancellation events.
- Operational records: audit log events, queue status, email delivery status, support communications, and server logs needed to operate and secure the service.
3. Files and conversion data
For browser-based local conversion, your model files are processed in your browser and are not intentionally uploaded to Swap3D servers. Browser memory, local downloads, and any files you save remain under your control.
For Developer API and backend conversion workflows, uploaded files are temporarily handled by our backend, placed into a conversion queue, processed by a worker, and written to S3-compatible object storage such as Cloudflare R2. Completed outputs are made available through short-lived download URLs and are not intended to be permanent storage.
4. How we use information
We use information to provide and secure Swap3D, authenticate users, connect OAuth sign-in methods, verify email addresses, process conversions, enforce quotas, manage API keys, process subscriptions, send account emails, detect abuse, troubleshoot reliability issues, provide support, and comply with legal or operational obligations.
5. Payments and service providers
Payments and subscription checkout are processed by Waffo Pancake. We do not store full payment card details on our servers. We also use infrastructure and service providers to operate Swap3D, including Cloudflare Pages, R2, and Queues, Render, Supabase, SMTP email service, GitHub OAuth, and Google OAuth if it is enabled in the future.
6. What we do not store
We do not store your raw password, raw session token, raw API key after creation, raw email verification token, raw password reset token, OAuth provider access token, OAuth refresh token, or full card details. API keys and session tokens are stored as hashes. Two-factor authentication secrets are encrypted before storage.
7. Retention
We keep data only for as long as needed to provide the service, maintain security, comply with obligations, resolve disputes, or enforce our terms. Current operational defaults include:
- Conversion download URLs are short-lived, typically one hour.
- Converted API outputs are temporary: Free plan outputs default to 24 hours, Pro plan outputs default to 7 days.
- Temporary uploaded source files are cleaned after processing, final failure, or scheduled cleanup, with a default cleanup window of 1 hour and a 24-hour object-storage lifecycle fallback for staged API sources.
- Usage logs default to 180 days and audit logs default to 365 days.
- Expired or revoked session metadata defaults to 30 days after expiry or revocation.
- Expired email verification, email change, password reset, and two-factor challenge records are cleaned by scheduled jobs.
8. Security
We use reasonable technical and organizational measures to protect information, including hashed credentials and tokens, encrypted two-factor secrets, HttpOnly session cookies, CSRF protection, short-lived download URLs, access checks for user-owned resources, audit logging, and backend-only database access. No internet service can be guaranteed to be completely secure.
9. Your choices and rights
You can manage many account choices in the dashboard, including changing your email, changing or setting a password, revoking API keys, signing out sessions, disconnecting OAuth accounts, and disabling two-factor authentication. You may contact us to request account deletion or correction, subject to billing, security, fraud-prevention, legal, and operational retention requirements.
10. Children
Swap3D is not directed to children. If you believe a child has provided personal information to us, contact us and we will review the request.
11. International processing
Swap3D may process information through infrastructure providers in the United States and other regions where our service providers operate. By using the service, you understand that information may be processed outside your country or region.
12. Changes
We may update this policy as the service changes. When we make material changes, we will update the date above and, when appropriate, provide additional notice.
13. Contact
Questions about privacy can be sent to support@swap3d.studio.
