PRIVACY & CONTROL

Your work belongs in your workspace.

This page describes the implemented data handling. Public launch requires business-approved privacy terms, contact details, and retention decisions in operator readiness.

Private originals and versions

Uploaded photos and models are private objects. Originals, conversions, repairs, and approved artifacts are recorded as separate hashed versions. Access is authorized by account and limited to the work required to process and fulfill an order.

When data leaves this application

Starting an approved photo generation shares the selected image with the configured generation provider. Requesting an external quote may share the approved model and necessary specification. Ordering shares the required shipping and fulfillment details with the selected supplier. Payment details are entered in the payment provider’s hosted checkout.

Retention and deletion

Account settings expose a retention preference and an asset deletion request. Active orders, refunds, disputes, and transaction evidence can require a file or record to remain available. The server checks those obligations before deletion.

Connected tools

OAuth connections and local handoff tokens carry limited scopes. You can revoke tool tokens in settings. The remote MCP server cannot read arbitrary files on your computer; a host-provided file or an explicit local upload is required.

Supplier information

Public supplier locations use the precision selected by the workshop. Customer delivery addresses are available only within authorized order contexts. Supplier purchasing credentials remain server-side.

Requests and questions

Use your authenticated account settings for controls, or the support form to request help. The operator readiness screen records the missing legal contact and approved policy evidence before public activation.