Privacy Policy
This policy explains what information 3Dhive (“3Dhive”, “we”, “us”) collects when you use the 3Dhive website, currently at 3dhivelocal.jcjurevis.workers.dev (the “service”). It also explains how we use and share that information, how long we keep it, and how you can delete it. 3Dhive is run by its developer, who decides how your information is used and is responsible for it. Questions or requests: jcjurevis@gmail.com.
The short version
- You can browse without an account. If you sign in with Google, Apple or Facebook, we receive your email address, an account identifier and, from Google and Facebook, your name and profile picture link. We never see your password.
- When you are signed in, we save your workspace to your account so it follows you between devices. It includes your cart and uploaded models, favorites, settings, chat and Support messages, command and assistant history, and seller shop details.
- We do not sell your information, show ads or run our own analytics. Some content from other companies loads automatically, such as YouTube videos, Mapbox maps and, for terrain models, public elevation data from Amazon Web Services.
- Some features send text or images to companies that process them for us. OpenAI handles the assistant and, when enabled, upload content review. Zoo handles 3D model generation and Mapbox handles place searches on the terrain map.
- You can ask us to delete your account and data at any time. See Delete your data.
1. Information we collect
Account information
If you create an account, you sign in through one of the providers we offer: Google, Apple or Facebook, as each becomes available. Our sign-in service provider, Supabase, keeps the identity details that provider shares (see section 2). 3Dhive uses your name, email address and a 3Dhive account ID. It also uses when your account was created and last signed in, which sign-in providers are linked, and whether your email address is verified. We also store your account type (buyer or seller) and your analytics preference. If you are made an administrator, we store a record of that change and any note written with it.
Your workspace
While you are signed in, the service saves your workspace to your account so it can be restored on any device. It can include:
- your print cart and saved-for-later items, the print shop you chose, the name, file name and 3D shape of models you upload and add to the cart, and names or text you put into personalized designs;
- test checkout records (the print shop, items, quantities and estimated prices you chose, your payment-method choice and whether you asked for text updates) and the expected shipping dates on your calendar;
- favorites, display settings and other preferences;
- your workspace chat: messages you write in chat threads and channels, the names and descriptions of channels you create, names of people you add as chat contacts, and designs you share into a thread. These practice chats are not delivered to other people;
- your Support chat, including the answers you received, and assistant replies posted into your threads;
- your recent command-bar entries (up to 50), and your recent conversation with the assistant: your last 10 messages and replies, with the tools and parts each one used.
If you are not signed in, your workspace is not sent to our servers. It stays in your browser, and most of it is gone when you reload the page.
Seller shop information
If you open a seller account, we store the shop details you enter:
- your printers, their models and multi-color setups, and their settings, costs, rates and hours;
- the materials, filament spools (brand, product line and color) and filament colors you stock, and your prices;
- shop alerts;
- listing drafts, including the file name and a preview image of each uploaded model;
- ad campaign settings such as budget and placements;
- the local network addresses of printer control panels you add;
- other settings for your shop page.
Things you type into assistant and design features
When you use the command bar, the assistant, “describe it” for custom designs or the Support chat, we process the following to answer you:
- the text you type;
- your recent messages in that conversation;
- the name of the object you have selected;
- limited context about the design you are working on, including any names, dates or other text you entered into a personalized design.
This is sent to OpenAI (see Service providers). If you are signed in, your recent command-bar entries, assistant conversation and Support chat are saved to your account as part of your workspace. Recent Support messages are sent again as context with your next question. Apart from 3D model descriptions, which are kept for about an hour (see 3D model generation), we keep no other copy of these requests on our servers.
3D model generation
If you ask the service to generate a 3D model from text, OpenAI first checks that you are asking for an object. Your description is then sent to Zoo to create the model. When you edit a generated model, the design code behind it is sent too. Our server keeps your description, the generated model file and its design code for about an hour so you can load and edit the model.
We also record each generation’s type, outcome, time and duration, with your account ID (or a note that it came from a guest). The record does not include your description or the model.
Guests get two free generations per browser. A cookie holds a random guest ID, and our server records the start time of each guest generation under that ID, so the count is kept on our server rather than in the page. This record contains no description, model or account details.
Location
Some map features ask your browser for your location, for example when you open the Build view, choose “Find my location” or press “Use my location” on the terrain map. You can decline. If you allow it, your location is used in your browser to center the map and estimate distances to print shops, or on the terrain map to place the arrow (see Terrain models). The map images for that area are loaded from Mapbox.
If you have allowed location and automatic light and dark theme is on, the service also reads your location when a page loads. It uses it to time the theme to your local sunrise and sunset, and it stays in your browser.
If you use the option to fill in your ZIP code at checkout, your coordinates, rounded to about 100 meters, are sent to Mapbox to look up the ZIP code. We do not store your location.
Terrain models (Maps & Terrain)
When you make a terrain model, the spot you choose is used in your browser to build it, whether you place the arrow on the map, search for a place, type coordinates or use your location. While a terrain model is open, your browser downloads the elevation data for the area it covers directly from Amazon Web Services’ public Terrain Tiles dataset. Amazon Web Services receives your IP address, standard browser information (including that the request comes from our website) and the tiles requested, and those tiles show the area you chose. The map itself loads from Mapbox, as described above.
Place names or addresses you type into the terrain map’s search, or ask the command bar to go to, are sent to Mapbox’s search service to find them. “Use my location” asks your browser for your location only when you press it. If you allow it, your browser places the arrow at your location, and your location is not sent to 3Dhive. As with any other spot, the map images for that area then load from Mapbox and the terrain model downloads its elevation tiles from Amazon Web Services, so those tiles show the area around you.
The location is not sent to OpenAI. When you use “describe it” on a terrain model, our server removes the model’s coordinates before contacting OpenAI, so only your description, the design’s name and its other settings, such as its size and outline, are sent. A place you name in the description yourself is sent like any other text.
If you add a terrain model to your cart, it is saved like other designs as a 3D model file. The file is named after the design, not its coordinates, but its shape is the landscape of the area you chose, so it shows that area. When you are signed in, it is saved to your account with the rest of your cart (see Your workspace).
Files and images you open
3D model files and images you open are previewed in your browser. When upload content review is enabled, supported images and a few rendered views of uploaded models are sent through our server to OpenAI for policy screening. Review does not establish legality or intellectual-property ownership. Unsupported files remain held. The review service does not write images, filenames or raw provider responses to disk; review decisions are temporary. See our content guidelines.
Models are saved to your account only when you are signed in and add an uploaded model to your cart. Photo-to-3D (“Auto segment with SAM3D”) is not available on our hosted website. In local development, using it sends the approved image to your local SAM3D service, which stores its working images, masks and model files. The server also sends the selected object image to OpenAI before releasing the result. SAM3D working files are separate from the review service and are not deleted by an account deletion request.
Connecting your printer
Printer connection works only in the 3Dhive app running on your own computer, not on our hosted website. When you choose “Connect printer to the hive”, the app on your computer looks for Klipper printers on your local network by trying ports 80 and 7125 on nearby addresses, and reads each printer’s name and whether it has a camera. You can also type your printer’s address.
After you allow it, the app reads your printer’s status: its state, the name of the file it is printing, progress, print time and temperatures. It only reads. It never starts, stops, heats or moves your printer. It stores the printer’s name and network address, your camera choices, a record of up to 25 recent prints (file name, outcome, progress and times) and a running total of print time and number of prints in a file on your computer. If the printer stops answering and you choose “Turn back online”, the app may search your local network the same way to find the same printer at a new address. If you allow the camera, snapshots go from your printer through the app on your computer to your browser and, on Windows, to the 3Dhive icon in the taskbar. They are not saved.
None of this is sent to 3Dhive’s servers or to other companies. “Disconnect printer” removes the stored printer and its print records from your computer.
Live sharing (“3Dhive together”)
If you start or join a live sharing session, your display name starts as your account name, and you can change it before inviting someone. Your display name and connection details, including your IP address, pass through our server. The server keeps them in memory only and discards the session within about an hour.
The video of your 3Dhive tab is sent over an encrypted connection to the person you invited. Your browsers use Cloudflare’s connection service to set up that link, and if a direct connection is not possible, Cloudflare may relay the encrypted video. The person you invite sees everything shown in your 3Dhive tab, including any account details on screen, and could record it. If you allow it, they can also rotate or switch your 3D view for up to 5 minutes. These control messages go directly between your browsers.
Recordings of your 3Dhive tab stay in that browser tab until you download them or share them with an app you choose. They are never uploaded to 3Dhive.
Support requests
If you contact us or submit a support ticket, we receive your name, email address, the topic you choose and your message. We keep that correspondence to answer you. Cloudflare’s email service delivers support tickets to our Gmail inbox, which Google hosts, and we keep the correspondence there. Our server keeps only each ticket’s number and delivery status, not its contents.
Technical information
When you visit the service, Cloudflare, our hosting provider, receives your IP address and standard browser information in order to deliver and protect the site. Your browser also loads the Mapbox map library, YouTube videos, in some cases jsDelivr files and, for terrain models, public elevation data from Amazon Web Services directly from those companies (see section 4). When you sign in, your browser connects directly to Supabase and to the sign-in provider you choose. They receive your IP address and browser information, and Supabase records sign-in events, including your IP address, in its security logs.
Our application server logs each request’s method, path, status and timing. It does not log your IP address or account ID. To prevent abuse and overspending, the server keeps rate-limit counters in memory. Some are keyed by your account ID when you are signed in, or by the random guest ID for free model generations. Others, whether or not you are signed in, are keyed by a code derived from your IP address. On our website, Cloudflare turns your IP address (for an IPv6 address, only its network part) into a one-way code with a secret key that our application server does not have, and sends our server only that code. The same address always gives the same code, so our server can count your requests but cannot turn the code back into your IP address. Requests that reach our server without this code are counted by the network connection it receives. Counters, including these codes, expire after a minute to an hour. They are removed on later requests or when the server restarts, and they are never written to disk or logs.
What we do not collect
- Passwords. We never receive your Google, Apple or Facebook password.
- Payment details. The hosted service does not take payments. Checkout is a test flow that places no real order.
- Checkout contact and delivery details. The name, email, address and phone number you type into the test checkout stay in your browser tab and are not sent to us or saved. Only the ZIP code is sent, through our server to USPS, to estimate shipping.
- Interaction analytics. We do not collect analytics on the hosted service. The “Share interaction analytics” switch only saves your preference.
- Camera and microphone. We do not use your computer’s camera or microphone. A printer camera you allow in the 3Dhive app on your computer is shown only on that computer (see Connecting your printer).
2. Google, Apple and Facebook sign-in
We use these providers only to let you sign in and to identify your account. We request only basic sign-in information:
- Google: your name, email address, profile picture link, whether your email is verified and your Google account ID (the “email” and “profile” permissions).
- Apple: your email address, or an Apple relay address if you choose “Hide My Email”, and an account identifier. Apple does not give us your name through this sign-in method, so we show the part of your email address before the “@” instead.
- Facebook: your name, profile picture link, email address and an app-specific account ID (the “public_profile” and “email” permissions).
We do not post on your behalf, read your contacts, friends or messages, or access any other data in those accounts. We use this information to:
- sign you in and keep your account secure;
- show your name and email in your account settings;
- suggest your display name when you start or join live sharing (you can change it before anyone sees it);
- let authorized administrators identify and support your account (see section 3);
- match privacy and deletion requests to your account.
We do not sell it or use it for advertising. We share it only with the service providers listed in section 4 and, if you keep your account name as your live sharing display name, with the person you share with.
3Dhive’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use information
| Purpose | Legal basis |
|---|---|
| Providing the service: signing you in, saving and restoring your workspace and seller shop, generating models, answering your requests and support | Providing the service you asked for (contract) |
| Keeping the service secure and reliable, preventing abuse, limiting costs and keeping request logs | Our legitimate interest in running a safe, affordable service |
| Administrator support and operation of the service (see below) | Our legitimate interest in supporting you and running the service |
| Showing YouTube videos and Mapbox maps as part of the page | Our legitimate interest in showing how objects are printed and where print shops are |
| Making terrain models: finding the places you search for with Mapbox and loading public elevation data from Amazon Web Services for the area you choose | Providing the service you asked for (contract) |
| Using your location in your browser | Your consent, given through your browser’s permission prompt |
| Responding to privacy and deletion requests and meeting other legal obligations | Legal obligation |
Where we rely on legitimate interests, you can object at any time by emailing us. You can browse without giving us personal information. Signing in requires the details your sign-in provider shares; without them we cannot create an account for you.
Administrators. To operate the service, a small number of authorized administrators can view account information. This includes:
- your email, name, sign-in providers, account type and analytics preference;
- when your account was created and last signed in, and when your workspace or seller shop was last saved;
- the names of items in your cart, saved-for-later list and favorites;
- for sellers: your printers (including costs, rates and hours), materials, filament colors and shop alerts;
- model-generation records linked to your account ID.
Administrators use this to support you, prevent abuse and run the service. Changes to administrator access are recorded.
We do not use your information for advertising, we do not sell it, and we do not train AI models on it. OpenAI does not use API requests to train its models by default. Zoo’s terms allow it to use the model descriptions and model files it receives to train and improve its AI models.
4. Service providers and sharing
We share information with the service providers below, only what each one needs, and in the limited cases described after the table.
| Provider and what it does | Information involved |
|---|---|
| SupabaseSign-in and account database | Account identity, sign-in times, workspace and seller shop data; your IP address and browser information when you sign in |
| CloudflareWebsite hosting and delivery, support email, live sharing connections | IP address and request details; support tickets on their way to our inbox; connection details for live sharing, and the encrypted video if it must be relayed |
| RenderApplication server | Everything you send to the service (including text it forwards to OpenAI or Zoo), request logs, generated models and descriptions (about 1 hour), generation records and short-lived in-memory data |
| Google, Apple, Meta (Facebook)Sign-in, when you choose them | Your sign-in with that provider |
| Google (Gmail)Our support and privacy inbox | Your name, email address and the messages you send us, including support tickets and deletion requests |
| OpenAIAssistant, command understanding, design suggestions, support answers, checking 3D model requests and upload content review | What you type, your recent messages and limited design context; when content review is enabled, uploaded images, model previews and selected object images. We turn off Responses API storage. API data is not used for training by default. Abuse-monitoring retention is generally up to 30 days, with legal and safety exceptions; images flagged for potential child sexual abuse may be retained for manual review. See OpenAI’s data controls. |
| ZooText-to-3D model generation | Your model description and the model being edited. Zoo keeps these in its records under 3Dhive’s account, not linked to your name or email, and its terms allow it to use them to improve its AI models. |
| MapboxMap library, map images, place search and ZIP code lookup | Your IP address and browser information on every visit (the map library loads with the page), the map area you view, and a map-load event with an anonymous ID (see section 5); the place names or addresses you type into the terrain map’s search (see Terrain models); your rounded coordinates if you use ZIP lookup |
| Google (YouTube)Print videos shown next to objects, which load automatically | Your IP address and browser information when the video player and thumbnails load, and how you use the player |
| jsDelivrDelivers the charting library and, if our own copy cannot load, the 3D graphics library | Your IP address and browser information when a library loads |
| Amazon Web ServicesPublic elevation data (the Terrain Tiles open dataset) for terrain models | Your IP address and browser information, and which elevation tiles your browser downloads, which show the area of the terrain model you open |
| USPSShipping estimates | The destination ZIP code and package size you check, sent through our server |
These providers handle information under their own privacy terms. YouTube and Mapbox may collect information such as your IP address, device identifiers and how you use their content, and may use it across other websites under their own policies. 3Dhive does not track you across other websites. We do not respond to browser “Do Not Track” signals, because we have no cross-site tracking to turn off.
People you choose to share with. When you host a live sharing session, your guest receives your display name, your connection details (including your IP address) and, once you choose Share this page, the video of your 3Dhive tab. When you join someone else’s session, the host receives your display name and your connection details (including your IP address); your own tab is not shared.
Other disclosures. We may also disclose information:
- if the law requires it;
- to protect the rights and safety of our users or the service;
- as part of a transfer of the service to a new owner, who would have to honor this policy.
5. Cookies and browser storage
We use only cookies that the service needs to work. We do not use advertising or analytics cookies.
| Cookie | Purpose | Lasts |
|---|---|---|
__Host-hive_auth (may be split into several cookies) | Keeps you signed in. Encrypted, and not readable by page scripts. | Up to 90 days after you last use 3Dhive and at most 365 days after you sign in, or until you sign out |
__Host-hive_oauth | Protects the sign-in redirect | 10 minutes |
hive_zoo_guest | A random, signed ID for your browser’s guest trial. It lets our server count your two free model generations and lets you open the models you generated. Sent only to our model generation service. | 1 year |
Google, Apple, Facebook, Supabase, YouTube and Mapbox may set their own cookies or use browser storage when you sign in with them or when their content loads. Their policies apply. When a map loads, Mapbox’s map software stores an anonymous ID in this site’s browser storage and sends Mapbox a map-load event, which Mapbox uses for billing. We turn off its extra performance reporting.
The service keeps a few things in your browser’s own storage:
- your header banner choice;
- Seller page view options and changes you make to the example seller shop;
- random IDs that keep a browser tab’s state together.
When you are signed in, your other settings and favorites are saved to your account (see Your workspace). You can remove everything the service stores in your browser by clearing this site’s data in your browser settings.
6. How long we keep information
| Information | How long |
|---|---|
| Account, workspace and seller shop data | Until you delete your account or ask us to delete it |
| Model descriptions, generated models and their design code | About 1 hour, so you can load and edit the model. They are deleted within a few minutes after that, or when the server restarts. |
| Model generation records (no descriptions or models) | On our application server’s temporary storage, which is erased whenever the server restarts or is updated. If any remain when you delete your account, we remove yours. |
| Guest generation allowance (a random browser ID and the start time of each free generation) | On the same temporary storage, erased whenever the server restarts or is updated |
| Rate-limit counters, including the one-way code derived from your IP address | In memory only; they expire after a minute to an hour |
| Live sharing sessions | In memory only; discarded within about an hour |
| Support correspondence | Until your request is resolved, then for up to 2 years as a record of it, unless you ask us to delete it sooner |
| Request logs | Kept by Cloudflare and Render for a limited period, currently no more than 30 days |
| Sign-in security logs | Kept by Supabase for its log retention period. Any copy in our account database is deleted with your account. |
| Administrator access records | While 3Dhive operates, as a security record of who had administrator access. When we delete your account, we remove your name or email from any note in these records. |
7. Your choices and rights
- Access and correction. You can see and change your workspace and seller shop in the service. Your name and email come from your sign-in provider, and changes made there may not reach 3Dhive. Email us to correct them. Ask us for a copy of your data at any time.
- Deletion. You can remove items from your cart, favorites and seller shop yourself, and you can ask us to delete your whole account. See Delete your data.
- Location. You can decline or revoke location permission in your browser at any time.
- Browser data and sign-in. You can clear this site’s cookies and storage in your browser. Signing out removes the sign-in cookie, and Sign out everywhere in Account & settings also signs you out on your other devices.
- Connected apps. You can remove 3Dhive from your Google, Apple or Facebook account settings (see how to remove 3Dhive from your sign-in provider).
Depending on where you live, you may have rights to:
- access, correct or delete your information;
- restrict or object to our use of it;
- receive a copy of it;
- withdraw consent.
To use any of these rights, email jcjurevis@gmail.com. We will not treat you differently for doing so. We may ask you to confirm that the request comes from the account holder. You may use an authorized agent; we will ask the agent for your signed permission and may confirm the request with you directly. You may also complain to your local data protection authority.
California residents. Section 1 describes the categories of personal information we collect: identifiers such as your name, email and account ID; internet activity such as requests and your saved workspace; location used in your browser; and content you create. We collect it from you and from your sign-in provider. We use it for the purposes in section 3, disclose it to the recipients in section 4, and keep it for the periods in section 6. We do not sell your personal information or share it for advertising based on your activity on other sites (“cross-context behavioral advertising”).
8. Deleting your data
You can ask us to delete your account and the information connected to it at any time, whichever provider you signed in with. Email jcjurevis@gmail.com, ideally from the email address on your account. If you can’t, for example because you use Apple’s Hide My Email, tell us which provider you sign in with and the address it uses. If your request does not come from your account’s address, we write to that address and delete the account only after you confirm from it. We complete deletion within 30 days. Full instructions are on Delete your data. They include what is deleted and how to remove 3Dhive from your Google, Apple or Facebook account.
9. Security
We use HTTPS for all traffic. Sign-in sends you to Google, Apple or Facebook and back with a one-time code, which stops anyone else from finishing your sign-in. Your session is kept in an encrypted cookie that page scripts cannot read. Database rules let each account reach only its own records. The exception is a small number of authorized administrators, who can view the account information described in section 3 through read-only functions, with changes to their access recorded. Our servers never receive your passwords. No method of storage or transmission is completely secure, but we work to protect your information and to limit who can access it.
10. International processing
We and our service providers process information in the United States and other countries, where data protection laws may differ from those where you live. When we transfer personal information from the EEA, the UK or Switzerland, we rely on the safeguards in our providers’ data processing terms. These are the European Commission’s Standard Contractual Clauses, or the EU-US Data Privacy Framework where a provider is certified. Email us for more information about these safeguards.
11. Children
The service is not directed to children under 13, or under the minimum age for online services where you live (such as 16 in parts of Europe), and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the service changes, for example before adding payments or new features. We will change the date at the top. If a change is significant, we will also tell you in the service before it takes effect.
13. Contact us
For questions, requests or complaints about privacy, email jcjurevis@gmail.com.