Privacy Policy

Last updated: August 11, 2026

1. About this policy

This Privacy Policy explains how CAD Scene ("we," "us," or "our") collects, uses, and shares personal information when you use cadscene.com and the CAD Scene service (the "Service"). CAD Scene is an AI architectural rendering web app.

2. Information we collect

Account and authentication

We collect account details such as your email address, account identifier, display name, avatar, authentication records, and account settings. Authentication credentials are handled through Supabase. If you sign in with Google, Google provides your basic profile information, including your name, email address, and profile picture.

Projects and render content

We collect the content needed to provide your workspace. This can include prompts, uploaded source and reference images, masks and region selections, project settings, study messages, 3D model files and source packages, conversion manifests and derivatives, previews, generated renders, and related file and job metadata. We store this content so you can generate, revisit, edit, and download your work.

Billing

Stripe processes subscriptions and top-up purchases. We receive billing records such as your Stripe customer reference, subscription status, plan, transaction status, amounts, currency, invoices, and credit grants. We do not receive or store full payment card numbers.

Support and communications

We collect messages, attachments, and contact details you send when requesting support or otherwise communicating with us. Signed-in support chat can send Heyo your account identifier, name, and email so we can identify and answer you.

Technical, device, and security data

We collect data used to deliver and protect the Service, such as IP address, browser and device details, operating system, pages and app routes, timestamps, request and response metadata, security events, diagnostics, and logs. Production platform logs can include prompt text or project details connected to a request or error.

3. Product analytics and advertising measurement

PostHog

We use an EU-hosted PostHog project for curated product analytics. We send explicit events about sanitized page navigation, acquisition, onboarding, activation, feature use, paywalls, checkout, and subscription lifecycle. For signed-in users, the profile can include the CAD Scene account identifier and, when available, email and name.

PostHog autocapture, session recording, surveys, heatmaps, and automatic pageview capture are disabled. This means we select the product events sent to PostHog rather than broadly recording page interactions.

Meta

We use Meta Pixel in the browser and Meta Conversions API on the server for a narrow set of standard advertising and conversion events: PageView, ViewContent, Lead, CompleteRegistration, InitiateCheckout, and Purchase. Event details can include the viewed offer, value, currency, source page, campaign parameters, a deduplication identifier, and Meta browser or click attribution identifiers such as _fbp and _fbc.

Where used for server-side conversion matching, we send a one-way hashed email address and CAD Scene account identifier. Hashing reduces direct readability but does not make the data anonymous.

4. Error monitoring and diagnostics

We use Sentry in production to collect errors, performance traces, and application logs. These records can include account or user identifiers, IP address, device, browser, operating system, network and request details, app route, timestamps, stack traces, and information connected to the error.

Sampled Sentry Session Replay runs inside authenticated app areas. Some sessions are sampled generally, and error sessions can be sampled at a higher rate. A diagnostic capture can include interactions or on-screen content relevant to an error. We apply credential-focused scrubbing, but no automated scrub can guarantee that every item of personal or project content is removed.

5. How we use information

  • create, authenticate, and secure accounts;
  • provide projects, studies, image uploads, rendering, editing, storage, and downloads;
  • process payments and administer plans and credits;
  • answer support requests and service communications;
  • diagnose failures, prevent fraud and abuse, and maintain reliability and security;
  • understand product use, improve features, and measure acquisition and advertising conversions; and
  • comply with legal obligations and enforce our terms.

6. Providers and other disclosures

We disclose information to providers that help operate requested features and business systems:

  • Supabase for authentication, databases, and file storage;
  • Vercel for hosting, delivery, and 3D model conversion;
  • Upstash for render-job streams and rate controls;
  • Stripe for subscriptions, payments, and billing records;
  • Google for OAuth sign-in and AI features;
  • OpenAI for AI features;
  • Heyo for signed-in customer support;
  • PostHog for curated product analytics;
  • Meta for advertising and conversion measurement; and
  • Sentry for errors, traces, logs, and sampled Session Replay.

Google and OpenAI process relevant prompts, images, settings, and instructions to provide requested features under the applicable provider terms. We may also disclose information when reasonably necessary to comply with law, protect rights or safety, prevent abuse, enforce our terms, or complete a business transaction such as a merger, financing, or sale.

7. Google sign-in data

Google OAuth provides basic profile information so we can authenticate you, create or access your account, display your profile, and send account-related communications. We do not request access to Gmail, Drive, Contacts, Calendar, or permission to post to your Google account.

CAD Scene's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can revoke access in your Google Account permissions.

8. Cookies and browser storage

The Service uses cookies and browser storage for authentication, security, session continuity, and preferences. PostHog can use browser storage to maintain analytics identity and session context. Meta Pixel can set or read advertising attribution identifiers, including _fbp and _fbc. Browser settings may let you block or clear storage, but doing so can affect sign-in, preferences, attribution, or other Service functions.

9. Retention and security

We retain information for as long as needed to provide the Service, keep required business and billing records, resolve disputes, enforce agreements, maintain security, and meet legal obligations. Retention varies by data type, account status, and provider settings. Deleted data may remain temporarily in backups or records that we must retain.

We use reasonable technical and organizational safeguards, including access controls and encryption in transit. No system is completely secure. Keep your credentials confidential and contact us if you suspect unauthorized account access.

10. Your rights

Depending on where you live, you may have rights to request access, correction, deletion, or export of personal information, or to object to or restrict certain processing. You can update some account information and delete some project content in the Service. Contact us for other requests. We may verify your identity and retain information where permitted or required by law.

11. Children and international transfers

The Service is not intended for children under 16, and we do not knowingly collect their personal information. Contact us if you believe a child under 16 has provided information.

We and our providers may process information in countries other than where you live. Those countries may have different data protection rules. Contact us if you have questions about where your information is processed.

12. Changes and contact

We may update this policy as our practices or the Service change. We will revise the date above and provide additional notice when appropriate.

For privacy questions or requests, contact [email protected]. See also our Terms of Service.