Privacy Policy
This explains what Tesseract collects, why, and who else sees it. It covers tesseract.build and the Tesseract design app.
The short version: we collect what's needed to generate your designs and ship your orders. We don't sell your data, we don't run advertising trackers, and there is no analytics script on this site.
What we collect
When you sign in
Sign-in is handled by Google. We receive your Google account ID, email address, name and profile picture. We never receive your Google password.
When you design
We store the text of your prompts, along with the effort level you asked for, whether the request refined an earlier design, whether it succeeded, and the name of the part produced. That's what makes your design history work and how we see what people actually ask for.
Photographs you attach to a prompt are forwarded to our model provider for that single request and are not stored by us — not in the database, not on disk.
When you order
We collect the email address and shipping address you enter (name, street, city, state, postal code, country) and record the part, material, quantity, price and status of the order.
Payment
Card payments go directly to Stripe, on Stripe's own checkout page. We never receive your card number, CVC or expiry date — only confirmation that a payment succeeded, and an identifier for it.
Technical data
Our server holds your IP address briefly, in memory, to enforce rate limits on the design endpoint. It isn't written to the database and it's gone when the window closes or the server restarts. Ordinary server logs may record request metadata for a short period.
On your device
The app saves your shipping address and last-used filament in your browser's local storage so you don't retype them. That stays on your device; clearing your browser data removes it.
Cookies
We set two, and both are strictly functional:
ts_session— your signed-in session. HttpOnly, so scripts can't read it, and valid for 30 days.ts_auth— a readable companion holding your name, email and picture so the site can show you're signed in without a round trip. It expires with the session and never decides what you're allowed to do.
No advertising, analytics or third-party tracking cookies are set on this site.
Why we use it
- To run the Service — generate designs, keep your history, quote and place orders.
- To fulfil orders — pass what's needed to our manufacturing and payment partners, and email you about your order.
- To prevent abuse — rate limits, and automated screening of prompts.
- To improve the product — understanding what people ask for, and where generation fails.
- To meet legal obligations — tax and accounting records, and lawful requests.
If you're in the EEA or UK, our legal bases are performance of a contract (designing and shipping what you ordered), legitimate interests (security, abuse prevention, improving the product), and legal obligation.
Who else sees your data
We use a small number of processors, each for one job:
- GoogleSign-in and identity.
- OpenAIGenerates designs from your prompts and screens them for prohibited content. Receives prompt text and any photographs you attach.
- Slant3DManufacturing and shipping. Receives your name, shipping address, email address and the model file.
- StripePayment processing.
- VercelHosting for this site and the app.
- RailwayHosting for the backend and its database.
OpenAI states that data submitted through its API is not used to train its models by default. We send your data nowhere else. We don't sell it, and we don't share it for cross-context behavioural advertising.
We may disclose data where legally required, to protect our rights or someone's safety, or to a successor if the business is acquired — in which case this policy keeps applying until you're told otherwise.
How long we keep it
- Your account record — until you ask us to delete it.
- Design history — until you ask us to delete it.
- Orders — seven years, because tax and accounting rules require it. While that obligation stands, order records can't be deleted on request.
- Rate-limit IP data — minutes to hours, in memory only.
Your rights
Wherever you are, email hello@tesseract.build and we'll act on any of these: send you a copy of what we hold, correct it, delete your account and design history, or stop a particular use. We'll respond within 30 days.
California. We don't sell or share personal information as the CCPA/CPRA define those terms, and we won't discriminate against you for exercising your rights.
EEA and UK. You also have the right to data portability and to complain to your local supervisory authority.
Security
Traffic is encrypted in transit. Sessions are signed, HttpOnly cookies rather than something your browser can read back. Card data never reaches our servers. No system is perfectly secure and we won't pretend otherwise — but if there's a breach that affects you, we'll tell you.
Children
Tesseract isn't for children. We don't knowingly collect data from anyone under 13, or under 16 in the EEA and UK. If you think a child has given us data, email hello@tesseract.build and we'll delete it.
Where your data lives
We're based in the United States and our providers process data there. If you use Tesseract from elsewhere, you're sending your data to the US.
Changes
We'll update this page and the date at the top when the policy changes, and tell you directly if a change is material.
Contact
Questions, or a request about your data: hello@tesseract.build.