Privacy Policy

We built AIV to be private by design. This policy explains what we collect, why, and the control you keep over your data.

Last updated: 31 July 2026

In short

AIV is a tool for hosting and embedding interactive 3D models. We collect the minimum we need to run your account and the service. We do not sell your personal data. Public embed analytics are privacy-friendly: visitors are counted using a keyed, rotating one-way identifier derived from the IP address, and we set no tracking cookies on the sites where your models are embedded. You can access, export, or delete your data at any time.

Please do not upload sensitive, confidential, or regulated data to AIV — no health or patient data, no payment card details, no identity documents, no special-category data. See section 12.

1. Who we are

AIV (“AIV”, the “Service”) is a product of Bot Engine LLC (“Bot Engine”, “we”, “us”, “our”), the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable laws.

Registered address: 1309 Coffeen Ave, Sheridan, Wyoming 82801, USA. For any privacy question, request, or complaint, contact us at [email protected].

Representatives in the EU and the UK. Because we are established outside the European Economic Area and the United Kingdom but offer the Service to people in them, we have designated representatives under Article 27 GDPR and Article 27 UK GDPR. Data subjects and supervisory authorities may contact them on all matters relating to our processing, in addition to or instead of contacting us:

  • EU representative: named in our contact and sub-processor register, available from [email protected].
  • UK representative: named in the same register, available from [email protected].

We have not appointed a Data Protection Officer because we do not meet the criteria in Article 37(1) GDPR. Privacy questions are handled at the address above.

2. Scope of this policy

This policy covers the AIV website, dashboard, editor, and the public 3D embeds we serve on your behalf. It does not cover third-party websites that embed your models, or third-party AI or calendar providers you connect using your own credentials, each of which is governed by its own privacy policy.

Where you are a business customer embedding models on your own website, you are the controller for your site’s visitors and we act as your processor for the embed analytics we generate for you. Contact [email protected] for our data processing agreement.

3. Data we collect

We collect the following categories of personal data:

  • Account data — your email address, and, if you sign in with Google or Microsoft, the basic profile identifiers those providers return (name, email, avatar). Passwords are handled by our authentication provider and are stored only as salted hashes; we never see your plaintext password. We also record which version of the Terms and this policy you accepted, and whether you opted in to marketing.
  • Organization & billing data — organization membership, role, plan, credit balance, invitations, and waitlist entries. Card payments (where applicable) are processed by our payment provider; we do not store full card numbers.
  • Your content— the 3D models, images, scene settings, hotspots, and interactive scripts you upload or create, together with any documents you add to the AI assistant’s knowledge base. Please keep sensitive data out of these — see section 12.
  • AI provider credentials — if you enable the voice/chat assistant with your own provider keys, those keys are encrypted at rest (AES-256-GCM) and used only to make requests to the provider you configured.
  • Usage & embed analytics — aggregate view counts, referring domains, and coarse interaction signals (rotate, zoom, AR launched, session duration). To count unique visitors without identifying them, we derive a keyed one-way identifier from the IP address, using a secret key held only by our servers and a salt that rotates daily. We do not store the raw IP address of embed visitors, and because the key is secret and the salt rotates, that identifier cannot be matched back to an IP address or correlated from one day to the next.
  • Communications — messages you send us, and your email/notification preferences.
  • Technical & security data — data needed to operate securely, including the authentication cookies described in section 5 and request metadata used for rate limiting and abuse prevention. When you are signed in, we record the IP address and browser user-agent of your active session so that you can review and revoke your sessions and so that we can detect account takeover. That record is deleted when the session ends or expires, and in any case within the period given in section 8.

4. How we use data and our legal bases

Under the GDPR we rely on the following legal bases:

  • To provide the Service (Art. 6(1)(b) — contract): create and secure your account, host and serve your models, run the editor and AI features, and process your plan and credits.
  • To keep the Service safe (Art. 6(1)(f) — legitimate interests): rate limiting, fraud and abuse prevention, debugging, session security, and aggregate analytics that help us and our customers understand how published models perform. We have weighed those interests against the rights of the people affected: the data involved is minimal, visitor identifiers are keyed and rotating rather than persistent, we set no cookies on embeds, and we serve no advertising and build no cross-site profiles. You can object at any time (section 10), and you can ask us for a summary of that assessment.
  • To communicate with you (Art. 6(1)(b) and (f)): send transactional email such as sign-in, billing, and account notices.
  • Marketing (Art. 6(1)(a) — consent): send product updates only where you have opted in. You can withdraw consent at any time via the unsubscribe link or your settings, without affecting processing carried out before you withdrew.
  • To meet legal obligations (Art. 6(1)(c)): tax, accounting, and responding to lawful requests.

We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we do not use your uploaded content or documents to train our own models. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

5. Cookies and similar technologies

On the AIV app (dashboard, editor) we set a small number of strictly-necessary cookies to keep you signed in and to protect your session. These are essential to the Service, are not used for advertising, and are exempt from consent under Article 5(3) of the ePrivacy Directive:

CookiePurpose and lifetime
Authentication cookies (set by our authentication provider)Keep you signed in and protect the session. Cleared when you sign out or the session expires.
aiv_consentCarries the Terms version you accepted and your marketing choice from the signup form through the sign-in redirect, so we can record them. Expires after 10 minutes.
Trusted-device cookie (optional)Only if you choose to remember a browser for two-factor authentication. Holds a random token; only its keyed hash reaches our database.

The editor and dashboard also keep interface preferences (such as panel sizes and collapsed sections) in your browser’s local storage. These never leave your device and contain no personal data.

On the public embeds served on third-party websites we set no cookies, write nothing to the visitor’s device, and use no cross-site trackers or fingerprinting. Everything an embed needs — including the 3D viewer library and the model decoder — is served from our own domain, so loading an embed does not disclose the visitor’s IP address to any third-party content delivery network. Visit counting relies on the keyed, rotating identifier described in section 3.

6. Sharing and sub-processors

We share personal data only with service providers who process it on our behalf under contract (“sub-processors”), and only as needed to run the Service:

  • Supabase — authentication, database, and file storage (hosting infrastructure).
  • Cloudflare — object storage (R2) and delivery of models and assets.
  • Email delivery — our transactional and marketing email provider (Resend, or the SMTP relay configured for your deployment).
  • Application hosting — the platform on which the AIV application runs.
  • Payment provider — to take and process payments where you buy a paid plan or credits.
  • AI providers you enable— where you turn on assistant features, requests (and the content you send them) are transmitted to the provider you selected, such as OpenAI, Anthropic, Google (Gemini), Deepgram, ElevenLabs, or Cartesia, using your own API keys and subject to that provider’s terms.
  • Calendar integrations — only if you connect Google Calendar or Calendly to an assistant.

Every sub-processor is bound by a written contract containing the terms required by Article 28(3) GDPR. An up-to-date register naming each provider, what it processes, and where it operates is available from [email protected], and we will tell business customers before we add or replace a sub-processor that handles their data.

We may also disclose data where required by law, to protect our rights and users, or as part of a merger, acquisition, or sale of assets — in which case we will notify you before your personal data becomes subject to a different privacy policy, and any acquirer will be bound by commitments at least as protective as these.

7. International data transfers

Some of our providers operate outside the European Economic Area (EEA) and the UK. Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards — the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant), an adequacy decision, or certification under the EU–US Data Privacy Framework — together with a transfer risk assessment and, where appropriate, supplementary technical measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards using the contact details above.

8. How long we keep data

We keep personal data only as long as necessary for the purposes above. In practice:

DataRetention
Account, organization, and content dataWhile your account is active. Deleted within 30 days of you deleting your account or asking us to erase it, except where the law requires us to keep it.
Backups containing deleted dataRolling backups are overwritten within 35 days, after which deleted data is gone from them too.
Session records (including session IP and user-agent)Deleted when the session ends or expires, and in any case within 90 days.
Embed analytics (keyed visitor identifier, referrer, coarse interaction signals)26 months, after which events are reduced to aggregate counts. Daily key rotation means identifiers stop being linkable long before that.
Invoices, tax, and accounting recordsAs required by applicable tax law, typically 7–10 years.
Support and other correspondenceUp to 24 months after the matter is closed.

Aggregate, non-identifying statistics may be kept for longer because they can no longer be linked to any individual.

9. How we protect your data

Security and privacy are core to how AIV is built. Our measures include encryption in transit (TLS/HSTS), encryption of sensitive secrets at rest (AES-256-GCM), row-level access controls so users can only reach their own data, keyed and rotating visitor identifiers instead of stored IP addresses, server-side input validation across our API, rate limiting, optional two-factor authentication, and least-privilege access for our team.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where Article 33 requires it and, where Article 34 requires it, inform you without undue delay. Where we act as a processor for a business customer, we will notify that customer without undue delay after becoming aware of a breach affecting their data.

To report a suspected vulnerability, email [email protected]. Note that we do not operate a bug bounty and do not pay for vulnerability reports — see section 11 of the Terms.

10. Your rights

If you are in the EEA, the UK, or a similar jurisdiction, you have the right to: access your data; correct inaccurate data; erase data; restrict or object to processing (including processing based on legitimate interests); data portability; and to withdraw consent at any time without affecting prior processing.

You can exercise the main ones yourself, immediately: your dashboard settings let you export all of your data in a machine-readable format and delete your account together with its content. For anything else, email [email protected]. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. We do not charge for these requests and we will not treat you differently for making one.

You also have the right to lodge a complaint with your local data protection supervisory authority, or with the Information Commissioner’s Office in the UK. You may contact our EU or UK representative (section 1) instead of us if you prefer.

11. AI assistant features

When you enable the optional AI voice/chat assistant, you connect your own third-party provider keys. Content you or your end-users send to the assistant (including documents you add to its knowledge base and spoken input for speech-to-text) is transmitted to the provider you chose to generate a response. Those providers process that data under their own terms and privacy policies, and you are responsible for checking that those terms suit your use. We encrypt your provider keys at rest and do not use assistant content to train our own models.

If your assistant is reachable by the public, you are responsible for telling your end-users that their input is sent to that provider, and for keeping the categories listed in section 12 out of its knowledge base.

12. Data you must not upload to AIV

Please keep sensitive, confidential, and regulated data off the platform

AIV is a general-purpose 3D viewer, including for anatomical and educational models. It is not designed, certified, or offered as a system of record for sensitive, confidential, or regulated information, and it is not a medical device and not intended for diagnosis, treatment, or any clinical use.

You must not upload, store, or transmit through the Service — in a model, texture, filename, hotspot, script, assistant knowledge-base document, support message, or anywhere else:

  • Special-category personal data under Article 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric identifiers, health data, or data about a person's sex life or sexual orientation;
  • Protected health information (PHI), medical or patient records, or scans and imaging relating to an identifiable patient;
  • Full payment card numbers, CVV/CVC codes, or bank account details;
  • Passport, national identity, social security, tax, or driving licence numbers, or scans of identity documents;
  • Passwords, private keys, or access tokens for any system other than the AI provider keys the Service is designed to hold;
  • Personal data of anyone under 16, or under the age of digital consent where they live;
  • Trade secrets or confidential information you are not free to disclose, government-classified material, or export-controlled technical data.

If you upload any of this you do so in breach of our Terms of Service and entirely at your own risk. You are solely responsible for having a lawful basis and any required agreements, notices, or consents in place. We do not act as a HIPAA business associate, a PCI service provider, or a processor of Article 9 data, and we do not offer a business associate agreement or any equivalent. We may remove such content and suspend the account.

If your source material is sensitive, anonymise or de-identify it before uploading, so that no individual can be identified from what reaches the Service.

13. Children

AIV is not directed to children and is not intended for anyone under 16 (or the minimum age of digital consent in your country). We ask you to confirm your age when you create an account, and we do not knowingly collect data from children. If you believe a child has provided us data, contact [email protected] and we will delete it promptly.

14. If you visited an embedded model

This section is for people who did not sign up for AIV but loaded a 3D model embedded on someone else’s website.

When an AIV embed loads, our servers receive your IP address (as with any web request), the address of the page the embed appears on, and your browser’s user-agent string. We do not store your IP address. We store the referring page, the user-agent, coarse interaction signals, and the keyed rotating identifier described in section 3, so the owner of the model can see how many people viewed it. We set no cookies and store nothing on your device, and the embed loads all of its code from our own domain, so no third-party content network sees your request.

The legal basis is our and the model owner’s legitimate interest in understanding how published content performs (Art. 6(1)(f)). You can object to this processing, or ask what is held about a visit, by emailing [email protected] — bearing in mind that because we deliberately keep no identifier that can be traced back to you, we may be unable to locate records relating to you specifically (Art. 11 GDPR).

15. Notice for United States residents

If you live in California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, the following applies in addition to the rest of this policy.

We collect the categories of personal information described in section 3 — identifiers, commercial information, internet activity information, and the content you choose to upload — for the business purposes described in section 4, and we keep it for the periods in section 8. We disclose personal information only to the service providers listed in section 6, under contracts that prohibit them from using it for their own purposes.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. We therefore do not publish a “Do Not Sell or Share My Personal Information” link, because there is nothing to opt out of. We do not use or disclose sensitive personal information beyond the purposes for which a right to limit does not apply.

You may request access to, correction of, deletion of, or a portable copy of your personal information, and you may appeal a refusal. Use the export and delete controls in your dashboard settings, or email [email protected]. We verify requests against your account credentials or email address. An authorised agent may act for you with your written permission. We will not discriminate against you for exercising any of these rights, and we offer no financial incentives in exchange for personal information.

16. Changes to this policy

We may update this policy from time to time. When we make a material change we will update the “last updated” date and notify registered users by email or an in-app notice at least 30 days before it takes effect, so that you can review it and, if you disagree, export your data and close your account. Where a change requires your consent we will ask for it separately, and we will not treat your continued use of the Service as agreement. Previous versions are available on request.

17. Contact us

Bot Engine LLC — 1309 Coffeen Ave, Sheridan, Wyoming 82801, USA.
Privacy enquiries and data rights: [email protected].
EU and UK Article 27 representatives: see section 1.

See also our Terms of Service.