Privacy Policy

Effective: July 16, 2026  ·  Version 2  ·  Terms of Service

This Privacy Policy explains how three.ws ("we", "us", "our") collects, uses, and shares information about you when you use three.ws (the "Service"). We take your privacy seriously and collect only what we need to operate.

1. Information We Collect

CategoryExamplesWhy
Account identifiersWallet address, email (optional), username, display nameAuthentication & account management
Content you upload3D models (GLB/glTF), thumbnails, agent metadataService delivery, CDN delivery to viewers
On-chain dataERC-8004 agent registrations, Metaplex NFT mints, USDC payment tx hashesIdentity verification, subscription status
Usage dataAPI calls, widget load events (no IPs, no fingerprints)Quota enforcement, abuse prevention, aggregate analytics
Session dataHashed session token, IP address (hashed), user agentAuthentication, security
Legal acceptance recordsTerms of Service version accepted, Risk Disclosure version accepted, timestamp, IP address, user agent, which flow recorded itProof of agreement, legal compliance
Email (if provided)Email address for transactional messagesAccount notices, subscription receipts

We do not collect advertising identifiers, use third-party tracking pixels, or sell personal data to any third party.

2. How We Use Your Information

3. On-Chain Data

Wallet addresses and on-chain registrations are public by nature of blockchain technology. We index publicly available on-chain data (ERC-8004 events, Metaplex metadata) to power the agent directory. We do not create profiles that link on-chain identity to off-chain personal information beyond what you explicitly provide. Note that anything written to a public blockchain is permanent and outside our control; we cannot delete it.

4. Sharing & Disclosure

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share information only with:

5. Data Retention

We retain your account data for as long as your account is active. Deleted accounts are soft-deleted for 30 days (for recovery), then permanently purged. Session tokens expire after 30 days. Nonces expire after 5 minutes and are purged within 24 hours.

Usage events are retained for 90 days for quota and abuse analysis, then deleted. Widget view events (no personal data) are retained for 12 months. Security audit logs are retained for 365 days.

Legal acceptance records (your acceptance of the Terms of Service and Risk Disclosure) are retained for the life of your account and afterward for as long as needed to establish or defend legal claims. This retention is a legal obligation and survives an account-deletion request.

6. Your Rights

Depending on your jurisdiction you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these rights, email privacy@three.ws from the email address associated with your account, or sign a message with your wallet address confirming the request.

We will respond within 30 days (or sooner where the law requires). Requests to delete your account will remove all content stored on our servers, except records we must keep (Section 5); on-chain data cannot be deleted by us. We will never discriminate against you for exercising a privacy right.

7. GDPR (EEA & UK Users)

For users in the European Economic Area or United Kingdom, our legal bases for processing are: contract performance (account operation, content delivery), legitimate interests (security, abuse prevention, aggregate analytics), legal obligation (records of legal acceptance, lawful requests), and consent (optional email marketing, if you opt in).

You have the right to lodge a complaint with your local supervisory authority. You may also contact us first at privacy@three.ws; we would welcome the chance to resolve your concern directly.

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident: the categories of personal information we collect are listed in Section 1, the purposes in Section 2, and the recipients in Section 4. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; browser opt-out signals such as Global Privacy Control are honored by default because there is no sale or sharing to stop. We do not use or disclose sensitive personal information for purposes requiring a right to limit.

You have the rights to know, access, correct, delete, and port your personal information, and to not be discriminated against for exercising them. Exercise them via privacy@three.ws (Section 6). We verify requests using your signed-in session, your account email, or a message signed by your wallet. An authorized agent may act for you with written permission.

9. International Transfers

The Service is operated from the United States and data is processed on infrastructure located in the United States. If you use the Service from outside the U.S., your information is transferred to and processed in the U.S. Where GDPR applies, transfers to our processors rely on their standard contractual clauses or an applicable adequacy framework.

9a. Security & Breach Notification

We protect your data with industry-standard measures: TLS in transit, encrypted storage, hashed session tokens and IP addresses, scoped credentials, and audit logging. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and, where required, regulators without undue delay and within the timelines applicable law requires (for example, 72 hours to supervisory authorities under GDPR).

9b. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly. Features that move real funds additionally require users to be at least 18 (see the Terms of Service).

Cookies & Local Storage

We use the following browser storage:

We do not use third-party advertising cookies.

10. MCP Connectors, AI Processing & Payments

three.ws exposes Model Context Protocol (MCP) connectors (e.g. https://three.ws/api/mcp and https://three.ws/api/mcp-3d) that AI clients such as Claude and ChatGPT can call on your behalf. This section explains how data flows through those connectors.

10a. Free 3D Actions (ChatGPT / GPT Store)

three.ws also exposes a free, keyless REST endpoint, https://three.ws/api/3d/studio, used by the three.ws 3D Studio custom GPT (and any OpenAPI Action client) to turn a text prompt into a downloadable 3D model. This lane involves no account, no API key, and no payment, so none of the wallet, payment, or OAuth data described in Section 10 applies to it.

11. Changes to This Policy

We may update this Privacy Policy. We will notify you of material changes by email or a prominent notice on the Service. The "Effective" date and version at the top reflect the most recent revision.

12. Contact

Privacy questions: privacy@three.ws


three.ws  ·  Terms of Service  ·  Risk Disclosure  ·  Home