Privacy
We keep as little about you as the product can work with, and we sell none of it. This page says exactly what we hold, why we hold it, and how to make us delete it.
Last updated 4 October 2026. Polygonjs is run by Guillaume Fradin, who is the data controller. Write to gui@polygonjs.com about anything on this page.
What we hold, and why
Your account
Your email address, your username, and your password stored as a hash we cannot reverse. This is what an account is. We need it to sign you in, to send you a password reset, and to tell you about your licence.
Signing in
Each time you sign in we record the IP address and the browser you signed in from, attached to that one session. It is there so we can answer you if you ever ask whether somebody else has been in your account. Only we can see it. Signing out deletes the record.
Your licence and the machines you activate it on
Your licence keys, and for every machine you activate, an identifier derived from that machine plus the name the operating system gives it. A licence has a fixed number of seats, and this is how we count them. It is also how you can move a seat off a machine you no longer own.
Your scenes
Scenes you save are yours. They are public by default, and you can mark any of them private from its edit page. A private scene is visible to you and to site administrators, and to nobody else. We read the contents of a private scene only if you ask us to, for support.
Paying
Payments run through Stripe. Your card details are entered on Stripe's own form and never reach our servers. We store the customer identifier Stripe gives us, so a payment can be matched to your account, and any note we write while helping you with an order.
Subscriptions and payments
Polygon Web is a subscription, and Stripe is the payment processor for it too, so card details still never reach our servers. What we store is the identifier Stripe gives your customer record, the identifier of the subscription itself, which plan and billing period you are on, whether it is active, and the dates it started, renews, was cancelled or ended. That is what lets us tell you what you are paying for and switch the paid features on. Stripe holds the card and the invoices, and you reach them through the billing portal linked from your account page.
The AI agent
When you use the agent in the web editor, the content of the scene you are working on is sent to Anthropic, which runs the model that answers. That means the node graph, its parameter values, the names you gave things, and screenshots of the viewport taken so the model can see what you see. Your message goes with it. The model is Claude Opus 5, reached through Anthropic's API. Anthropic processes it to produce the answer and under its own terms does not train on it. Its published policy says it deletes what is sent within thirty days, keeping it longer only where it has to, for instance while looking into a suspected breach of its usage policy. That is their policy and we are repeating it, not promising it on their behalf. Do not put anything in a scene or a message that you would not send to a third party. We keep a record of each exchange so we can count what you used and investigate a failure.
You have to be signed in to use the agent. A subscription includes an allowance of turns each month, an account without one gets a few turns a month, and site administrators can run it on the scenes they can already open. Nobody who is not signed in can start it, and nothing reaches Anthropic unless a person typed a message and sent it.
The generative nodes
A generative node makes a 3D model from a prompt or from reference images, or a picture from a prompt or from one or two images it edits. The prompt and the images are sent to the generation vendor that produces the result. We only use vendors whose terms forbid training on what you send. If you upload a photograph of a person, treat it as sensitive: we keep it for as long as the generation needs it and delete it afterwards, and we ask you not to upload a photograph of somebody who has not agreed to it. The model that comes back is stored with your scene so the scene still loads later.
That vendor is Hyper3D, whose Rodin service does the generating. We send it nothing about you: not your name, not your email address, not your account. It holds what we send for up to seven days. On our side a reference image is deleted the moment the generation finishes, whether it worked or not, and what stays is the model, what you asked for, what it cost and whether it succeeded, because that is what your credits were spent on.
Pictures are made by OpenAI, through its image API. We send it the prompt and the images, and nothing about you: not your name, not your email address, not your account. On our side the images you sent are deleted the moment the picture comes back, and what stays is the picture, what you asked for and what it cost.
The newsletter
Your email address, the date you confirmed it, and, if you arrived through a campaign link, which link that was. You are only added after you confirm by email. Every letter carries an unsubscribe link, and using it stops the mail immediately.
Crash reports
When the desktop app crashes, if you restart it you have the opportunity to send us a crash report. It carries no IP address and no account identifier, and it reaches an email address only if you type one in so we can reply. Reports are deleted after six months.
Measuring the site
We use Plausible, which sets no cookies and builds no profile of you. Your IP address is sent to it so it can work out a country and count you once for the day. Plausible discards the address rather than storing it, and we never see it in our analytics. Errors in the web editor are reported to Sentry from your browser so we can fix them.
Keeping the service up and unabused
Requests to our servers are logged, including the IP address they came from. We use those addresses to rate-limit, to block spam and automated signups, and to investigate abuse of the service, which includes copies of our software redistributed without a licence. Cloudflare Turnstile receives the address of anyone submitting a form so it can tell a person from a bot. We do not use any of this to build a profile of you or to advertise.
Why we are allowed to
Your account, your licence, your scenes, your subscription and your payments are the contract between us. We cannot run any of it without them. The agent and the generative nodes are part of that contract too: you ask for the thing, and sending what you asked about to the vendor is how it gets made. The newsletter runs on your consent, which you can withdraw at any time. Sign-in records, logging, rate limiting and abuse investigation rest on our legitimate interest in keeping the service working and paid for, balanced against how little each one reveals.
Who else touches it
Each of these gets only what its job needs, and none of them may use it for anything else: Hetzner hosts our servers and database, in Falkenstein in Germany, Resend sends our email, Stripe takes payments and runs the subscriptions, Cloudflare sits in front of the site and screens forms, Plausible measures traffic, Sentry receives editor errors, Anthropic runs the AI agent, Hyper3D is the generation vendor behind the generative nodes and produces the models, OpenAI produces the pictures, and Basecamp carries our internal notifications. Your account, your scenes and your licence therefore live in the European Union. Some of the processors above are outside it and operate under the standard contractual clauses.
How long we keep it
Account, licence, subscription and scene data lives for as long as your account does, and goes when you ask us to close it, except the payment records that tax law requires us to keep for six years. The record of what you used the agent and the generative nodes for lives for as long as your account does, because it is what your monthly credit balance is counted from. A photograph you upload to a generative node is deleted once the generation it was for has finished. Crash reports go after six months. Newsletter records go when you unsubscribe, except a note that the address unsubscribed, which we keep so we do not mail you again by accident. Server logs are capped in size and rotate away on their own. We keep no archive of them and we ship them nowhere else.
Cookies
We keep two cookies. One keeps you signed in. One lets the web editor fetch the engine it runs on. There is no advertising cookie and no tracking cookie on this site, which is why you are not reading this through a consent banner.
What you can ask for
You can ask for a copy of everything we hold about you, ask us to correct it, ask us to delete it, or object to a use of it. Write to gui@polygonjs.com and we will answer within a month. If you are in the European Union or the United Kingdom and you think we have handled this badly, you can complain to your national data protection authority.
Children
Polygonjs is made to be learned from, and children are welcome to use it. You do not need an account to open the web editor, build a scene and run it, so a child can use the tool without giving us anything at all.
An account and the newsletter are different, because both mean handing us an email address. If you are under sixteen, ask a parent or guardian before you create an account or subscribe, and let them do it for you if they would rather. We do not knowingly hold data about a child who has not asked. Write to gui@polygonjs.com if we have, and we will delete it.
Changes
This page carries the date it last changed, at the top. We add to it when something new starts collecting data. We do not quietly take things away.