This Privacy Policy explains how three.ws ("we", "us", "our") collects, uses, and shares information about you when you use three.ws (the "Service"). We take your privacy seriously and collect only what we need to operate.
| Category | Examples | Why |
|---|---|---|
| Account identifiers | Wallet address, email (optional), display name | Authentication & account management |
| Content you upload | 3D models (GLB/glTF), thumbnails, agent metadata | Service delivery, CDN delivery to viewers |
| On-chain data | ERC-8004 agent registrations, Metaplex NFT mints, USDC payment tx hashes | Identity verification, subscription status |
| Usage data | API calls, widget load events (no IPs, no fingerprints) | Quota enforcement, abuse prevention, aggregate analytics |
| Session data | Hashed session token, IP address (hashed), user agent | Authentication, security |
| Email (if provided) | Email address for transactional messages | Account notices, subscription receipts |
We do not collect advertising identifiers, third-party tracking pixels, or sell personal data to any third party.
Wallet addresses and on-chain registrations are public by nature of blockchain technology. We index publicly available on-chain data (ERC-8004 events, Metaplex metadata) to power the agent directory. We do not create profiles that link on-chain identity to off-chain personal information beyond what you explicitly provide.
We do not sell your personal data. We share information only with:
We retain your account data for as long as your account is active. Deleted accounts are soft-deleted for 30 days (for recovery), then permanently purged. Session tokens expire after 30 days. Nonces expire after 5 minutes and are purged within 24 hours.
Usage events are retained for 90 days for quota and abuse analysis, then deleted. Widget view events (no personal data) are retained for 12 months.
Depending on your jurisdiction you may have rights to access, correct, delete, or export your personal data. To exercise any of these rights, email privacy@three.ws from the email address associated with your account, or sign a message with your wallet address confirming the request.
We will respond within 30 days. Requests to delete your account will remove all content stored on our servers; on-chain data cannot be deleted by us.
For users in the European Economic Area or United Kingdom, our legal bases for processing are: contract performance (account operation, content delivery), legitimate interests (security, abuse prevention, aggregate analytics), and consent (optional email marketing, if you opt in).
You have the right to lodge a complaint with your local supervisory authority.
We use the following browser storage:
__Host-session): HttpOnly, Secure, SameSite=Strict. Required for authentication.__Host-csrf-siwe, __Host-csrf-siws): Short-lived, for SIWE/SIWS replay protection.3dagent:auth-hint): Stores a non-sensitive login hint for faster page loads. Cleared on sign-out.We do not use third-party advertising cookies.
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.
three.ws exposes Model Context Protocol (MCP) connectors (e.g. https://three.ws/api/mcp and https://three.ws/api/mcp-3d) that AI clients such as Claude and ChatGPT can call on your behalf. This section explains how data flows through those connectors.
$THREE; USDC is used purely for settlement.We may update this Privacy Policy. We will notify you of material changes by email or a prominent notice on the Service. The "Effective" date at the top reflects the most recent revision.
Privacy questions: privacy@three.ws
three.ws · Terms of Service · Home