Privacy Policy
How Hello 3D collects, uses, shares, retains, and protects account, payment, analytics, uploaded image, and generated 3D asset data.
Last updated: 2026-07-16
Version 1.0 · Effective July 16, 2026
This Privacy Policy explains how Hello 3D, the independently operated online business that provides hello3d.ai, collects, uses, shares, stores, and protects personal information when you use our website, AI 3D studio, APIs, account areas, and support services (collectively, the “Service”).
Please read this Policy together with our Terms of Service. If you do not agree with this Policy, do not use the Service.
1. Data controller and contact
Hello 3D is the controller of personal information processed for its own business purposes.
- Controller and service operator: Hello 3D
- Website: https://hello3d.ai
- Privacy and support contact: support@hello3d.ai
- Online contact: Registered users may open a ticket under Settings → Support Tickets
- Typical support hours: Monday–Friday, 09:00–18:00 (UTC+8), excluding public holidays
Hello 3D has not appointed a data protection officer because its present processing activities do not require one. Privacy and legal notices may be sent to the email address above.
2. Scope and roles
This Policy applies to information we process about website visitors, registered users, credit purchasers, API users, and people who contact support.
If an organization uses the Service to process personal information in its own images, models, prompts, or other content, that organization is responsible for deciding whether it has a lawful basis to submit the information. In that context, the organization may be the controller and Hello 3D may act as its service provider or processor for the requested task.
3. Information we collect
3.1 Information you provide
We collect information you choose to provide, including:
- Account and profile information: name, email address, password hash, profile image, language, and account preferences.
- Third-party sign-in information: when you use Google sign-in, the account identifier, name, email, profile image, and authorization information Google makes available to us. We do not receive your Google password.
- AI task and content data: prompts, reference images, multi-view images, uploaded model files, selected settings, task instructions, and other Input Content; generated models, textures, previews, exports, and other Output Content.
- Payment and order information: selected credit pack, amount, currency, transaction and order identifiers, payment status, payer email or name, invoice information, discount information, and refund or dispute records. We do not store full card numbers or card security codes.
- Support communications: ticket titles and messages, email correspondence, attachments, feedback, and information you provide to investigate an account, billing, technical, legal, or safety issue.
- API information: API-key title and prefix. The full API key is shown once when created; we store a SHA-256 hash rather than the plaintext key.
Please do not submit sensitive personal information or confidential information belonging to another person unless you have a lawful basis and the Service has expressly agreed to process it.
3.2 Information collected automatically
When you use the Service, we may automatically collect:
- IP address, approximate country or region derived from IP, browser type, operating system, device type, language, time zone, user-agent string, and referring page;
- authentication session identifiers, sign-in times, session expiry, security events, and verification records;
- pages viewed, buttons or features used, traffic source and campaign parameters, task status, selected models and settings, API requests, processing time, errors, and diagnostic logs;
- credit balance and ledger activity, including credits granted, purchased, consumed, refunded, or expired; and
- cookie and similar-technology identifiers described below.
3.3 Information from other sources
We may receive information from Google when you sign in, from Waffo Pancake or another checkout provider when a transaction is processed, from fraud-prevention or security providers, and from service providers that return status or output information for an AI task.
4. How and why we use information
We use personal information for the following purposes and legal bases:
- Provide the Service and perform our contract: create and secure accounts; authenticate users; receive, process, and return AI tasks; store and display assets; provide exports and APIs; manage credits; process purchases and refunds; and provide support.
- Our legitimate interests: maintain reliability; diagnose errors; understand feature usage; improve workflows and user experience; prevent fraud, abuse, unauthorized access, and chargeback misuse; enforce our Terms; and protect users, the public, and our business.
- Your consent: provide optional third-party sign-in, non-essential analytics or advertising where consent is legally required, send optional marketing messages, or use content for a separately disclosed purpose. You may withdraw consent at any time without affecting earlier lawful processing.
- Legal obligations: maintain transaction and tax records, respond to valid legal requests, protect legal rights, and meet regulatory, accounting, sanctions, and fraud-prevention obligations.
- Protect vital interests or public safety: address credible threats of serious harm where permitted by law.
We may aggregate or de-identify information for statistics, service planning, security, and research. We do not attempt to re-identify information that has been properly de-identified.
5. AI content processing
To perform a task, we may send the prompt, reference image, model file, selected settings, task identifier, and necessary technical metadata to AI providers such as Tripo AI and WaveSpeed AI. They process that data to generate or transform the requested asset and return task status and output locations.
We do not use private Input Content or Output Content to train a generalized Hello 3D model without separate notice or consent. AI providers process task content under their applicable service arrangements and may temporarily retain copies for delivery, security, abuse prevention, or legal compliance. Do not upload content that you are not authorized to send to these providers.
If the Service identifies a project or output as public, or you choose a public or sharing option, the relevant content and associated profile information may be visible to other people. Otherwise, we treat workspace content as account-associated content and do not intentionally publish it.
6. Cookies, analytics, and advertising
We use cookies, local storage, pixels, and similar technologies for:
- Strictly necessary functions: authentication, session security, checkout flow, fraud prevention, and core Service operation. These cannot be disabled through the Service without making essential functions unavailable.
- Functional preferences: language, interface, and similar settings.
- Analytics: Google Analytics helps us understand visits, traffic sources, devices, and feature use. See Google's Privacy Policy.
- Advertising measurement: Google Ads may measure whether an advertisement led to a visit or purchase. Google may use cookies or similar identifiers for this purpose. You can review ad controls in Google My Ad Center.
Depending on configuration, analytics or advertising providers may receive identifiers, IP-derived location, device/browser information, page URLs, referrers, campaign parameters, and conversion information such as transaction value and currency. We do not intentionally send uploaded images, prompts, full payment-card details, or generated 3D files to analytics or advertising providers.
You can restrict cookies through your browser, use provider opt-out controls, or contact us. Blocking strictly necessary storage may prevent sign-in or checkout. Where local law requires prior consent for non-essential technologies, we will request it before activating those technologies for that user.
7. How we share information
We do not sell personal information for money. We disclose only the information reasonably necessary for the following purposes:
- Payments: Waffo Pancake and, where displayed at checkout, Stripe or another enabled checkout provider process payments, fraud checks, refunds, and tax or invoice information. Full card data is submitted directly to the provider and is not stored on Hello 3D servers. See Stripe's Privacy Policy when Stripe is used.
- AI processing: Tripo AI, WaveSpeed AI, and any replacement provider disclosed in the Service process task inputs, settings, and outputs needed to provide AI 3D functions.
- Identity: Google processes information when you choose Google sign-in. See Google's Privacy Policy.
- Hosting and storage: cloud hosting, database, content-delivery, and object-storage providers, including Cloudflare R2 or compatible S3 storage where configured, store or transmit account records, uploaded files, and generated assets.
- Email and support: email-delivery and customer-support providers transmit service notices, verification or recovery messages, and support communications where those features are enabled.
- Analytics and advertising: Google Analytics and Google Ads process the limited website and conversion data described in Section 6.
- Professional advisers and authorities: lawyers, accountants, auditors, insurers, regulators, courts, law enforcement, or other authorities may receive information when reasonably necessary or legally required.
- Business transfers: information may transfer as part of a merger, financing, reorganization, sale of assets, acquisition, or insolvency process, subject to notice and continued protection required by law.
- With your direction or consent: we share information when you ask us to, publish content, connect a third-party service, or otherwise consent.
Some privacy laws define certain advertising disclosures as a “sale,” “sharing,” or use for targeted advertising even when no money is paid for the data. You may opt out of such processing by using the controls described in Section 6 or emailing us.
8. Data retention
We use the following retention schedule unless a longer period is required for legal claims, fraud prevention, tax, accounting, or regulatory obligations:
- Account and profile records: while the account is active, then up to 90 days after a verified deletion request before deletion or de-identification from active systems.
- Uploaded inputs and generated assets: while needed for the account workspace, then up to 90 days after verified account deletion. Provider-side temporary copies and disaster-recovery backups may remain for a limited additional period under the provider's retention cycle.
- AI task and usage records: up to 24 months after the task, after which they are deleted or de-identified unless needed to resolve a dispute or protect the Service.
- Support tickets and communications: up to 24 months after the ticket is closed.
- Authentication, security, and diagnostic logs: up to 12 months, unless a security investigation requires longer retention.
- Payment, order, invoice, tax, refund, and dispute records: up to 7 years after the transaction, or the longer period required by applicable financial law. Full card data is not held by Hello 3D.
- Revoked API-key hashes and audit records: up to 12 months after revocation.
- Analytics information: according to the configured provider retention setting, not exceeding 24 months for user-level analytics under our control.
Deletion may take additional time to propagate through encrypted backups. Backups are isolated from ordinary use and are deleted on a rolling schedule. We may retain a minimal suppression or transaction record where necessary to honor an opt-out, prevent fraud, prove compliance, or establish, exercise, or defend legal claims.
9. Security
We use measures appropriate to the nature of the Service, including HTTPS/TLS in transit, password hashing, hashed API keys, authentication and session controls, role-based administrative access, provider credential protection, logging, and backups. Payment-card details are handled by the checkout provider rather than stored on our servers.
No system is completely secure. You are responsible for using a strong password, protecting API keys, signing out of shared devices, and notifying us of suspected compromise.
If a personal-data breach creates a legally reportable risk, we will notify the competent authority and affected users within the time required by applicable law. Where the GDPR's 72-hour authority-notification rule applies, we will follow it.
10. International data transfers
Hello 3D and its service providers may process information in countries other than the one where you live, including locations in Asia and the United States. Those countries may have different data-protection laws.
Where required, we rely on safeguards such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, contractual confidentiality and security commitments, or another legally recognized transfer mechanism. You may contact us for information about safeguards relevant to your data.
11. Your privacy rights
Depending on where you live, you may have the right to:
- know whether we process your personal information and obtain a copy;
- correct inaccurate or incomplete information;
- request deletion;
- restrict or object to certain processing, including direct marketing and processing based on legitimate interests;
- receive certain information in a portable, machine-readable format;
- withdraw consent at any time where processing relies on consent;
- opt out of a sale, sharing, or targeted advertising as defined by applicable law; and
- complain to your local data-protection or privacy authority.
To exercise a right, email support@hello3d.ai from your account email and describe the request. We may ask for information needed to verify identity and authority. We will normally respond within 30 calendar days for GDPR-type requests or 45 calendar days for applicable California requests, subject to lawful extensions. We will explain if an exception applies.
You may use an authorized agent where local law permits. We do not discriminate against you for exercising a privacy right.
12. California privacy notice
For California residents, the categories collected in the preceding 12 months may include identifiers; customer records and commercial information; internet or electronic activity; approximate geolocation derived from IP; account credentials; and inferences about product usage. Sources, purposes, and recipient categories are described in Sections 3, 4, and 7.
We do not knowingly sell personal information for money and do not knowingly sell or share the personal information of anyone under 18. Google Ads conversion or advertising technologies may be treated as “sharing” for cross-context behavioral advertising under California law. You may request access, correction, deletion, or opt-out by emailing us and may appeal a decision by replying to our response.
13. Marketing communications
We may send service-required messages about authentication, transactions, security, support, material policy changes, and operation of your account. These are not marketing messages and may continue while you use the Service.
If we send optional marketing email, we will do so with the consent or other lawful basis required in your location. You can opt out through the unsubscribe link in the message or by contacting us. Opting out of marketing does not stop necessary service messages.
14. Children
The Service is intended only for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us. After appropriate verification, we will delete it unless law requires otherwise.
15. Third-party links and services
The Service may link to or integrate with third-party websites, payment pages, sign-in providers, or creative tools. Their privacy practices are governed by their own notices. We encourage you to review them before submitting information.
16. Automated processing
We may use automated systems to detect abuse, fraud, malicious files, account compromise, or violations of our Terms and to route AI tasks. These systems may affect whether a transaction or task is accepted or whether an account is temporarily restricted. You may contact support to request human review of a decision that significantly affects you, where required by law.
17. Changes to this Policy
We may update this Policy to reflect product, provider, legal, or security changes. For a material change, we will provide at least 15 days' advance notice by email, account notice, or a prominent website notice unless urgent legal or security circumstances require faster action. The updated version and effective date will appear at the top of this page.
18. Contact us
For privacy questions, access or deletion requests, marketing opt-outs, complaints, or security reports:
- Email: support@hello3d.ai
- Online support: Sign in and open Settings → Support Tickets
- Website: https://hello3d.ai
- Typical support hours: Monday–Friday, 09:00–18:00 (UTC+8), excluding public holidays
Please use the email associated with your account and do not send passwords, full card numbers, or card security codes.