Privacy Policy
This policy explains how tesseract.build handles information when you use Tesseract to create 3D models, edit and save objects, export files, and order prints for delivery. It focuses on the iOS app. Web-app sign-in and beta email signups are covered separately below.
Your descriptions and selected images are sent to our servers and AI provider to create models. Ordering a print also involves our manufacturing and payment partners. We do not sell your personal information or use it for cross-context behavioral advertising.
Information used by the app
App access and security
The iOS app creates device-linked access without requiring a Google account. We store an internal account identifier, access credentials, and verification records associated with your installation. Apple App Attest helps verify that access requests come from our app. Credentials are held in the iOS Keychain on your device.
Descriptions, images, and models
When you submit a design request, we process your description and any photo or drawing you attach. These are sent to OpenAI for content screening and model generation. Generated models may contain details from your input, such as names, lettering, or recognizable shapes.
We store generated designs, model parameters, object identifiers, generation status, a short name derived from your description, a fingerprint of the submitted request, and error information to provide your library and let the app recover results when you return. The app also saves object data and model previews on your device. Source photos are processed for the request; the native app backend does not save the uploaded image as a separate photo in your library.
Quotes, payments, and delivery
To request a print quote, you provide an email address and delivery details, including the recipient’s name and postal address. Your model file, material, quantity, and delivery information are shared with our print partner to calculate the quote. This can happen before you pay. We retain quote and order identifiers, the item ordered, price, email, payment status, and fulfillment status to manage the transaction.
Stripe collects payment details in its checkout. Our app backend does not receive or store your full card number or security code.
Notifications and diagnostics
If you enable notifications, we store an Apple push notification token and delivery records so we can tell you when a model is ready or a generation fails. Notifications can include the object’s name and identifier. You can control notification permissions and lock-screen previews in iOS Settings.
We process request metadata, generation timing, error information, and usage counts to run and protect the app. Security controls use network information, including a hashed representation of an IP address or network range. Some counters and security records are stored in our database. Hosting providers may also retain connection logs.
Your device and permissions
The app uses the camera when you choose to take a photo and request permission. You can also select an image through the system photo picker. Selected images are sent to our backend when you submit a design request; choosing a photo alone does not start generation. The camera can also support an augmented-reality preview of an object in your surroundings. That preview is processed on your device; it does not submit camera frames for model generation.
Saved objects, preview caches, preferences, and draft delivery details can be stored on your device. Exported files are saved or shared where you choose. A file you export may contain identifying text or shapes from your design. Files you share with another app or person are then subject to their handling practices.
You can change camera and notification access in iOS Settings. Removing the app does not itself delete records held on our servers or files you exported elsewhere.
How we use information
- Create and screen models from the descriptions and images you submit.
- Save your objects, support editing and export, and retrieve completed generations.
- Calculate print quotes, process payments, and arrange manufacture and delivery.
- Send requested generation notifications, beta updates, and support replies.
- Enforce usage limits, investigate failures, and prevent misuse.
- Maintain transaction records and meet legal obligations.
Where EEA or UK data protection law applies, the relevant grounds can include providing the services you request, our legitimate interests in security and reliable operation, your consent where required, and compliance with legal obligations. You can withdraw consent by changing app permissions or contacting us; this does not affect processing already carried out lawfully.
Services that receive information
- OpenAIReceives submitted descriptions and images for content screening and model generation.
- AppleProvides app and device verification and delivers optional push notifications through Apple Push Notification service.
- Slant3DReceives model files and the contact, delivery, material, and quantity details needed to quote, manufacture, and ship an order.
- StripeProcesses checkout and payment details and returns payment status and transaction identifiers to us.
- RailwayHosts our app backend, saved records, and beta signup database.
- GoogleProvides optional sign-in for the web app.
- VercelHosts the web app and landing page and routes their requests to our backend.
These services receive information needed for the functions described above and apply their own retention and security practices. Delivery carriers receive the information needed to deliver your order. We may also disclose information when legally required, to protect rights or safety, or as part of a business transfer, subject to applicable law.
Retention and deletion
We keep saved designs to provide your library until you delete them or request removal. In My Objects, you can delete an object or all saved objects. This removes the saved design from the app library and its server record; it does not erase exported files, completed orders, or every record associated with that generation. We may retain generation identifiers, status records, and usage counts for security and abuse prevention.
Access records, notification records, and diagnostic information are retained as needed to operate and protect the service. Short-lived verification challenges and rate-limit windows expire, while other records do not all have an automatic deletion date. Quote, payment, and order records may need to be retained for fulfillment, accounting, disputes, or legal obligations.
For removal beyond the app’s object-deletion controls, contact hello@tesseract.build. We may need to verify your request and identify the records associated with your installation or order. Deletion can be limited by legal requirements and legitimate security needs; information held by our providers or in backups may follow their retention schedules.
Web app and beta signups
If you choose Google sign-in in the web app, we receive your Google account identifier, email, and available profile details. Functional session cookies keep you signed in. The web app can record prompts and design activity, and its browser storage holds preferences and draft delivery details. Clearing browser storage does not delete server records.
If you join the beta email list, we store your email address, signup date, and source in our Railway-hosted database to send beta access updates. We keep the signup until you ask to leave the list or the beta signup program ends. Contact hello@tesseract.build to unsubscribe or request deletion. Joining the list does not create a paid order.
Your privacy choices
Contact hello@tesseract.build to request access to your information, correction, deletion, or limits on its use. We will respond within the time required by applicable law and may ask for information needed to verify the request. Do not send your connection token, payment card details, or other credentials in an email.
Depending on where you live, you may have rights to obtain a portable copy, object to processing, withdraw consent, or complain to a data protection authority. We do not sell or share personal information for cross-context behavioral advertising, and we do not discriminate against you for exercising applicable privacy rights.
Security and processing locations
App requests use HTTPS. Native access credentials are stored in the iOS Keychain, and backend access controls restrict access to saved objects and orders. No system can guarantee absolute security.
Our hosting and service providers may process information in the United States and other countries where they operate. Their locations and practices may differ from those in your country.
Children
Tesseract is not directed to children. We do not knowingly collect personal information from children under 13, or under 16 in the EEA and UK. Contact hello@tesseract.build if you believe a child has submitted personal information so we can investigate and remove it where appropriate.
Policy updates
We update the date above when this policy changes. We will provide additional notice of material changes where required. The policy should be read alongside the Terms of Service.
Contact
For privacy questions about Tesseract or requests about your data, contact hello@tesseract.build.