Privacy Policy
This Privacy Policy explains how three.ws ("we", "us", "our") collects, uses, and shares information about you when you use three.ws (the "Service"). We take your privacy seriously and collect only what we need to operate.
1. Information We Collect
| Category | Examples | Why |
|---|---|---|
| Account identifiers | Wallet address, email (optional), username, display name | Authentication & account management |
| Content you upload | 3D models (GLB/glTF), thumbnails, agent metadata | Service delivery, CDN delivery to viewers |
| On-chain data | ERC-8004 agent registrations, Metaplex NFT mints, USDC payment tx hashes | Identity verification, subscription status |
| Usage data | API calls, widget load events (no IPs, no fingerprints) | Quota enforcement, abuse prevention, aggregate analytics |
| Session data | Hashed session token, IP address (hashed), user agent | Authentication, security |
| Legal acceptance records | Terms of Service version accepted, Risk Disclosure version accepted, timestamp, IP address, user agent, which flow recorded it | Proof of agreement, legal compliance |
| Email (if provided) | Email address for transactional messages | Account notices, subscription receipts |
We do not collect advertising identifiers, use third-party tracking pixels, or sell personal data to any third party.
2. How We Use Your Information
- To authenticate you and maintain your session.
- To store and serve your 3D content via our CDN.
- To send transactional emails (welcome, subscription receipts, security alerts).
- To enforce plan quotas and rate limits.
- To detect and prevent abuse, fraud, and security incidents.
- To keep records of your acceptance of our legal agreements.
- To improve the Service using aggregate, anonymized analytics.
3. On-Chain Data
Wallet addresses and on-chain registrations are public by nature of blockchain technology. We index publicly available on-chain data (ERC-8004 events, Metaplex metadata) to power the agent directory. We do not create profiles that link on-chain identity to off-chain personal information beyond what you explicitly provide. Note that anything written to a public blockchain is permanent and outside our control; we cannot delete it.
4. Sharing & Disclosure
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share information only with:
- Infrastructure providers: Google Cloud Platform (hosting and compute), Neon (database), Cloudflare (storage and CDN), Resend (transactional email), and Privy (optional sign-in). Each processes data on our behalf under its own privacy policy and data-processing terms.
- Payment facilitators: for paid features settled on-chain (x402), payment verification runs through a facilitator such as Coinbase Developer Platform or the public x402.org facilitator. They see your public wallet address and transaction signatures, never private keys.
- AI model providers: generation features forward your prompts and asset URLs to upstream model APIs (see Section 10).
- Legal obligations: if required by law, court order, or to protect the rights and safety of three.ws or others.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to affected users.
5. Data Retention
We retain your account data for as long as your account is active. Deleted accounts are soft-deleted for 30 days (for recovery), then permanently purged. Session tokens expire after 30 days. Nonces expire after 5 minutes and are purged within 24 hours.
Usage events are retained for 90 days for quota and abuse analysis, then deleted. Widget view events (no personal data) are retained for 12 months. Security audit logs are retained for 365 days.
Legal acceptance records (your acceptance of the Terms of Service and Risk Disclosure) are retained for the life of your account and afterward for as long as needed to establish or defend legal claims. This retention is a legal obligation and survives an account-deletion request.
6. Your Rights
Depending on your jurisdiction you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these rights, email privacy@three.ws from the email address associated with your account, or sign a message with your wallet address confirming the request.
We will respond within 30 days (or sooner where the law requires). Requests to delete your account will remove all content stored on our servers, except records we must keep (Section 5); on-chain data cannot be deleted by us. We will never discriminate against you for exercising a privacy right.
7. GDPR (EEA & UK Users)
For users in the European Economic Area or United Kingdom, our legal bases for processing are: contract performance (account operation, content delivery), legitimate interests (security, abuse prevention, aggregate analytics), legal obligation (records of legal acceptance, lawful requests), and consent (optional email marketing, if you opt in).
You have the right to lodge a complaint with your local supervisory authority. You may also contact us first at privacy@three.ws; we would welcome the chance to resolve your concern directly.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident: the categories of personal information we collect are listed in Section 1, the purposes in Section 2, and the recipients in Section 4. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; browser opt-out signals such as Global Privacy Control are honored by default because there is no sale or sharing to stop. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
You have the rights to know, access, correct, delete, and port your personal information, and to not be discriminated against for exercising them. Exercise them via privacy@three.ws (Section 6). We verify requests using your signed-in session, your account email, or a message signed by your wallet. An authorized agent may act for you with written permission.
9. International Transfers
The Service is operated from the United States and data is processed on infrastructure located in the United States. If you use the Service from outside the U.S., your information is transferred to and processed in the U.S. Where GDPR applies, transfers to our processors rely on their standard contractual clauses or an applicable adequacy framework.
9a. Security & Breach Notification
We protect your data with industry-standard measures: TLS in transit, encrypted storage, hashed session tokens and IP addresses, scoped credentials, and audit logging. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and, where required, regulators without undue delay and within the timelines applicable law requires (for example, 72 hours to supervisory authorities under GDPR).
9b. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly. Features that move real funds additionally require users to be at least 18 (see the Terms of Service).
Cookies & Local Storage
We use the following browser storage:
- Session cookie (
__Host-session): HttpOnly, Secure, SameSite=Strict. Required for authentication. - CSRF cookies (
__Host-csrf-siwe,__Host-csrf-siws): Short-lived, for SIWE/SIWS replay protection. - localStorage (
3dagent:auth-hint): Stores a non-sensitive login hint for faster page loads. Cleared on sign-out. - localStorage (
threews:risk-ack): Remembers which Risk Disclosure version you accepted so you are not re-prompted on every action; the durable record lives server-side.
We do not use third-party advertising cookies.
10. MCP Connectors, AI Processing & Payments
three.ws exposes Model Context Protocol (MCP) connectors (e.g. https://three.ws/api/mcp and https://three.ws/api/mcp-3d) that AI clients such as Claude and ChatGPT can call on your behalf. This section explains how data flows through those connectors.
- Tool inputs we receive: the arguments you (or your AI client) send to a tool: text prompts, reference image URLs, GLB/glTF model URLs, wallet or agent addresses, token mints, and search terms. We process these to fulfill the request and log them only as needed for quota, abuse prevention, and debugging.
- Third-party AI model providers: generation and editing tools forward your prompts and asset URLs to upstream model APIs to produce results. Depending on the tool, these may include NVIDIA NIM (Microsoft TRELLIS), Meshy, Replicate, Stability, Hugging Face, OpenAI, Anthropic, Google (Vertex AI), and IBM (Granite). Each provider processes the input under its own privacy policy. Do not submit confidential or personal data in tool prompts.
- Payment data (x402): paid tools settle in USDC via the x402 payment protocol. When you pay per call we receive your public wallet address and the payment/settlement transaction signature, verified through a payment facilitator (Coinbase CDP and/or the public x402.org facilitator). We never receive, request, or store your private keys or seed phrase. The only token three.ws itself references is
$THREE; USDC is used purely for settlement. - OAuth-scoped access: when you connect via OAuth, the connector can read and write only the three.ws account data covered by the scopes you grant (avatars, agents, memory, profile). It cannot access your AI client's chat history, memory, or local files.
- Retention of tool inputs: tool-call inputs and outputs follow the usage-data retention in Section 5 (90 days), except content you explicitly save (e.g. a saved avatar), which is retained as account content until you delete it.
10a. Free 3D Actions (ChatGPT / GPT Store)
three.ws also exposes a free, keyless REST endpoint, https://three.ws/api/3d/studio, used by the three.ws 3D Studio custom GPT (and any OpenAPI Action client) to turn a text prompt into a downloadable 3D model. This lane involves no account, no API key, and no payment, so none of the wallet, payment, or OAuth data described in Section 10 applies to it.
- What we receive: only the text prompt you send. We do not ask for, receive, or store any name, email, wallet address, or other personal information through this endpoint.
- How the prompt is used: the prompt is forwarded to our generation provider (NVIDIA NIM / Microsoft TRELLIS) solely to produce the model. Do not include personal or confidential information in the prompt.
- What we return: a public URL to the generated GLB model (hosted on our CDN) and a link to view it. The response contains no account identifiers or personal data. Generated model files are served from public URLs so you can download and share them; treat a model URL as public.
- Abuse prevention: requests are rate-limited by IP address, used only to prevent abuse of the free lane, and prompts are screened by an automated content-safety filter so the service stays appropriate for all ages.
11. Changes to This Policy
We may update this Privacy Policy. We will notify you of material changes by email or a prominent notice on the Service. The "Effective" date and version at the top reflect the most recent revision.
12. Contact
Privacy questions: privacy@three.ws
three.ws · Terms of Service · Risk Disclosure · Home