Skip to the policy

Privacy Policy

This policy explains what information 3Dhive (“3Dhive”, “we”, “us”) collects when you use the 3Dhive website, currently at 3dhivelocal.jcjurevis.workers.dev (the “service”). It also explains how we use and share that information, how long we keep it, and how you can delete it. 3Dhive is run by its developer, who decides how your information is used and is responsible for it. Questions or requests: jcjurevis@gmail.com.

1. Information we collect

Account information

If you create an account, you sign in through one of the providers we offer: Google, Apple or Facebook, as each becomes available. Our sign-in service provider, Supabase, keeps the identity details that provider shares (see section 2). 3Dhive uses your name, email address and a 3Dhive account ID. It also uses when your account was created and last signed in, which sign-in providers are linked, and whether your email address is verified. We also store your account type (buyer or seller) and your analytics preference. If you are made an administrator, we store a record of that change and any note written with it.

Your workspace

While you are signed in, the service saves your workspace to your account so it can be restored on any device. It can include:

If you are not signed in, your workspace is not sent to our servers. It stays in your browser, and most of it is gone when you reload the page.

Seller shop information

If you open a seller account, we store the shop details you enter:

Things you type into assistant and design features

When you use the command bar, the assistant, “describe it” for custom designs or the Support chat, we process the following to answer you:

This is sent to OpenAI (see Service providers). If you are signed in, your recent command-bar entries, assistant conversation and Support chat are saved to your account as part of your workspace. Recent Support messages are sent again as context with your next question. Apart from 3D model descriptions, which are kept for about an hour (see 3D model generation), we keep no other copy of these requests on our servers.

3D model generation

If you ask the service to generate a 3D model from text, OpenAI first checks that you are asking for an object. Your description is then sent to Zoo to create the model. When you edit a generated model, the design code behind it is sent too. Our server keeps your description, the generated model file and its design code for about an hour so you can load and edit the model.

We also record each generation’s type, outcome, time and duration, with your account ID (or a note that it came from a guest). The record does not include your description or the model.

Guests get two free generations per browser. A cookie holds a random guest ID, and our server records the start time of each guest generation under that ID, so the count is kept on our server rather than in the page. This record contains no description, model or account details.

Location

Some map features ask your browser for your location, for example when you open the Build view, choose “Find my location” or press “Use my location” on the terrain map. You can decline. If you allow it, your location is used in your browser to center the map and estimate distances to print shops, or on the terrain map to place the arrow (see Terrain models). The map images for that area are loaded from Mapbox.

If you have allowed location and automatic light and dark theme is on, the service also reads your location when a page loads. It uses it to time the theme to your local sunrise and sunset, and it stays in your browser.

If you use the option to fill in your ZIP code at checkout, your coordinates, rounded to about 100 meters, are sent to Mapbox to look up the ZIP code. We do not store your location.

Terrain models (Maps & Terrain)

When you make a terrain model, the spot you choose is used in your browser to build it, whether you place the arrow on the map, search for a place, type coordinates or use your location. While a terrain model is open, your browser downloads the elevation data for the area it covers directly from Amazon Web Services’ public Terrain Tiles dataset. Amazon Web Services receives your IP address, standard browser information (including that the request comes from our website) and the tiles requested, and those tiles show the area you chose. The map itself loads from Mapbox, as described above.

Place names or addresses you type into the terrain map’s search, or ask the command bar to go to, are sent to Mapbox’s search service to find them. “Use my location” asks your browser for your location only when you press it. If you allow it, your browser places the arrow at your location, and your location is not sent to 3Dhive. As with any other spot, the map images for that area then load from Mapbox and the terrain model downloads its elevation tiles from Amazon Web Services, so those tiles show the area around you.

The location is not sent to OpenAI. When you use “describe it” on a terrain model, our server removes the model’s coordinates before contacting OpenAI, so only your description, the design’s name and its other settings, such as its size and outline, are sent. A place you name in the description yourself is sent like any other text.

If you add a terrain model to your cart, it is saved like other designs as a 3D model file. The file is named after the design, not its coordinates, but its shape is the landscape of the area you chose, so it shows that area. When you are signed in, it is saved to your account with the rest of your cart (see Your workspace).

Files and images you open

3D model files and images you open are previewed in your browser. When upload content review is enabled, supported images and a few rendered views of uploaded models are sent through our server to OpenAI for policy screening. Review does not establish legality or intellectual-property ownership. Unsupported files remain held. The review service does not write images, filenames or raw provider responses to disk; review decisions are temporary. See our content guidelines.

Models are saved to your account only when you are signed in and add an uploaded model to your cart. Photo-to-3D (“Auto segment with SAM3D”) is not available on our hosted website. In local development, using it sends the approved image to your local SAM3D service, which stores its working images, masks and model files. The server also sends the selected object image to OpenAI before releasing the result. SAM3D working files are separate from the review service and are not deleted by an account deletion request.

Connecting your printer

Printer connection works only in the 3Dhive app running on your own computer, not on our hosted website. When you choose “Connect printer to the hive”, the app on your computer looks for Klipper printers on your local network by trying ports 80 and 7125 on nearby addresses, and reads each printer’s name and whether it has a camera. You can also type your printer’s address.

After you allow it, the app reads your printer’s status: its state, the name of the file it is printing, progress, print time and temperatures. It only reads. It never starts, stops, heats or moves your printer. It stores the printer’s name and network address, your camera choices, a record of up to 25 recent prints (file name, outcome, progress and times) and a running total of print time and number of prints in a file on your computer. If the printer stops answering and you choose “Turn back online”, the app may search your local network the same way to find the same printer at a new address. If you allow the camera, snapshots go from your printer through the app on your computer to your browser and, on Windows, to the 3Dhive icon in the taskbar. They are not saved.

None of this is sent to 3Dhive’s servers or to other companies. “Disconnect printer” removes the stored printer and its print records from your computer.

Live sharing (“3Dhive together”)

If you start or join a live sharing session, your display name starts as your account name, and you can change it before inviting someone. Your display name and connection details, including your IP address, pass through our server. The server keeps them in memory only and discards the session within about an hour.

The video of your 3Dhive tab is sent over an encrypted connection to the person you invited. Your browsers use Cloudflare’s connection service to set up that link, and if a direct connection is not possible, Cloudflare may relay the encrypted video. The person you invite sees everything shown in your 3Dhive tab, including any account details on screen, and could record it. If you allow it, they can also rotate or switch your 3D view for up to 5 minutes. These control messages go directly between your browsers.

Recordings of your 3Dhive tab stay in that browser tab until you download them or share them with an app you choose. They are never uploaded to 3Dhive.

Support requests

If you contact us or submit a support ticket, we receive your name, email address, the topic you choose and your message. We keep that correspondence to answer you. Cloudflare’s email service delivers support tickets to our Gmail inbox, which Google hosts, and we keep the correspondence there. Our server keeps only each ticket’s number and delivery status, not its contents.

Technical information

When you visit the service, Cloudflare, our hosting provider, receives your IP address and standard browser information in order to deliver and protect the site. Your browser also loads the Mapbox map library, YouTube videos, in some cases jsDelivr files and, for terrain models, public elevation data from Amazon Web Services directly from those companies (see section 4). When you sign in, your browser connects directly to Supabase and to the sign-in provider you choose. They receive your IP address and browser information, and Supabase records sign-in events, including your IP address, in its security logs.

Our application server logs each request’s method, path, status and timing. It does not log your IP address or account ID. To prevent abuse and overspending, the server keeps rate-limit counters in memory. Some are keyed by your account ID when you are signed in, or by the random guest ID for free model generations. Others, whether or not you are signed in, are keyed by a code derived from your IP address. On our website, Cloudflare turns your IP address (for an IPv6 address, only its network part) into a one-way code with a secret key that our application server does not have, and sends our server only that code. The same address always gives the same code, so our server can count your requests but cannot turn the code back into your IP address. Requests that reach our server without this code are counted by the network connection it receives. Counters, including these codes, expire after a minute to an hour. They are removed on later requests or when the server restarts, and they are never written to disk or logs.

What we do not collect

2. Google, Apple and Facebook sign-in

We use these providers only to let you sign in and to identify your account. We request only basic sign-in information:

We do not post on your behalf, read your contacts, friends or messages, or access any other data in those accounts. We use this information to:

We do not sell it or use it for advertising. We share it only with the service providers listed in section 4 and, if you keep your account name as your live sharing display name, with the person you share with.

3Dhive’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use information

Where we rely on legitimate interests, you can object at any time by emailing us. You can browse without giving us personal information. Signing in requires the details your sign-in provider shares; without them we cannot create an account for you.

Administrators. To operate the service, a small number of authorized administrators can view account information. This includes:

Administrators use this to support you, prevent abuse and run the service. Changes to administrator access are recorded.

We do not use your information for advertising, we do not sell it, and we do not train AI models on it. OpenAI does not use API requests to train its models by default. Zoo’s terms allow it to use the model descriptions and model files it receives to train and improve its AI models.

4. Service providers and sharing

We share information with the service providers below, only what each one needs, and in the limited cases described after the table.

These providers handle information under their own privacy terms. YouTube and Mapbox may collect information such as your IP address, device identifiers and how you use their content, and may use it across other websites under their own policies. 3Dhive does not track you across other websites. We do not respond to browser “Do Not Track” signals, because we have no cross-site tracking to turn off.

People you choose to share with. When you host a live sharing session, your guest receives your display name, your connection details (including your IP address) and, once you choose Share this page, the video of your 3Dhive tab. When you join someone else’s session, the host receives your display name and your connection details (including your IP address); your own tab is not shared.

Other disclosures. We may also disclose information:

5. Cookies and browser storage

We use only cookies that the service needs to work. We do not use advertising or analytics cookies.

Google, Apple, Facebook, Supabase, YouTube and Mapbox may set their own cookies or use browser storage when you sign in with them or when their content loads. Their policies apply. When a map loads, Mapbox’s map software stores an anonymous ID in this site’s browser storage and sends Mapbox a map-load event, which Mapbox uses for billing. We turn off its extra performance reporting.

The service keeps a few things in your browser’s own storage:

When you are signed in, your other settings and favorites are saved to your account (see Your workspace). You can remove everything the service stores in your browser by clearing this site’s data in your browser settings.

6. How long we keep information

7. Your choices and rights

Depending on where you live, you may have rights to:

To use any of these rights, email jcjurevis@gmail.com. We will not treat you differently for doing so. We may ask you to confirm that the request comes from the account holder. You may use an authorized agent; we will ask the agent for your signed permission and may confirm the request with you directly. You may also complain to your local data protection authority.

California residents. Section 1 describes the categories of personal information we collect: identifiers such as your name, email and account ID; internet activity such as requests and your saved workspace; location used in your browser; and content you create. We collect it from you and from your sign-in provider. We use it for the purposes in section 3, disclose it to the recipients in section 4, and keep it for the periods in section 6. We do not sell your personal information or share it for advertising based on your activity on other sites (“cross-context behavioral advertising”).

8. Deleting your data

You can ask us to delete your account and the information connected to it at any time, whichever provider you signed in with. Email jcjurevis@gmail.com, ideally from the email address on your account. If you can’t, for example because you use Apple’s Hide My Email, tell us which provider you sign in with and the address it uses. If your request does not come from your account’s address, we write to that address and delete the account only after you confirm from it. We complete deletion within 30 days. Full instructions are on Delete your data. They include what is deleted and how to remove 3Dhive from your Google, Apple or Facebook account.

9. Security

We use HTTPS for all traffic. Sign-in sends you to Google, Apple or Facebook and back with a one-time code, which stops anyone else from finishing your sign-in. Your session is kept in an encrypted cookie that page scripts cannot read. Database rules let each account reach only its own records. The exception is a small number of authorized administrators, who can view the account information described in section 3 through read-only functions, with changes to their access recorded. Our servers never receive your passwords. No method of storage or transmission is completely secure, but we work to protect your information and to limit who can access it.

10. International processing

We and our service providers process information in the United States and other countries, where data protection laws may differ from those where you live. When we transfer personal information from the EEA, the UK or Switzerland, we rely on the safeguards in our providers’ data processing terms. These are the European Commission’s Standard Contractual Clauses, or the EU-US Data Privacy Framework where a provider is certified. Email us for more information about these safeguards.

11. Children

The service is not directed to children under 13, or under the minimum age for online services where you live (such as 16 in parts of Europe), and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the service changes, for example before adding payments or new features. We will change the date at the top. If a change is significant, we will also tell you in the service before it takes effect.

13. Contact us

For questions, requests or complaints about privacy, email jcjurevis@gmail.com.