ThreeD.PhotoLegal
Privacy Policy
Last updated: September 11, 2026 (version 2026-09-11)
The Short Version
Your photos are uploaded only to make your wigglegram, and they belong to you.
ThreeD.Photo keeps your project (your frames, your settings, and the videos we render) on our own servers in the United States so you can come back and re-export it. You can delete it any time with one click. If you don’t, we delete it for you 24 hours after upload, whether or not you signed in. We never use your photos to train machine learning models, we never sell them, and we never show them to anyone.
The rest of what we collect is small: your email address (that is how you sign in), a record of what you bought from Stripe, and anonymous counts of which screens are used. No advertising trackers, no third-party analytics. We don’t sell your personal information. The full detail is below.
1. Who We Are
Frequincy Inc. ("we," "us," "our") operates ThreeD.Photo at https://threed.photo (the "Service"). This Privacy Policy explains what personal information we collect, why, how long we keep it, and what rights you have over it.
If you have questions or want to exercise a privacy right, contact us at hello@threed.photo or write to Frequincy Inc., 209 E 31st Street, New York, NY 10016. For people in the European Economic Area and the United Kingdom, Frequincy Inc. is the data controller.
2. Your Photos: How They Are Handled
To make a wigglegram, ThreeD.Photo uploads the three or four frames from your 3D camera to our servers, aligns them, estimates depth, and renders a short looping video. Here is exactly what that means:
- Stored as a project. Your original frames, the crop and focus you choose, and every video we render for you are kept together as a project on our servers so that you can return, adjust, and export again. Nothing about the project is public. Only the account that made it (or, if you did not sign in, the browser that made it) can open, edit, export, or delete it.
- Deleted on your command. Delete project removes the originals, the settings, and every rendered export immediately.
- Deleted automatically. Projects you do not delete are removed 24 hours after upload, whether or not you signed in. Projects uploaded before September 11, 2026 keep the 30-day window they were given when they were uploaded; that is the only exception, and it ends once those projects are gone. Server backups that may hold a copy expire within 30 days after that.
- Never used to train machine learning models. We do not train, fine-tune, or improve any AI or ML model using your photos. We do not license, sell, or share them, and we do not use them for marketing or promotion.
- Rarely seen by a person. Images are processed automatically. A member of our team may open a specific project only where strictly necessary to diagnose a technical fault you reported or to investigate a suspected violation of our Terms.
- Not recoverable after deletion. Once a project is deleted we cannot restore it. Keep your own copies.
- Encrypted in transit. Uploads and downloads travel over HTTPS.
2(a). How the conversion works. The conversion is performed by automated software running on servers we operate (hosted by DigitalOcean in the United States). It uses a machine-learning depth-estimation model (MiDaS) to judge how far away things are, and standard computer-vision software (OpenCV) to line the frames up. To suggest a focus point it runs automatic face detection, which finds where a face is in the frame. Face detection does not identify, verify, or recognize anyone, it does not produce or keep any faceprint, face geometry, or other biometric identifier, and its result is not stored; the only thing kept is the focus point you choose. No third party performs any part of the conversion, and no output is used to make any decision about you.
2(b). Metadata. An image file may carry embedded metadata such as EXIF location coordinates, camera model, or timestamps. That metadata is stored with your original frames as part of the project and is deleted with it. We do not read it for any purpose other than orienting the image, and it is not copied into the videos we render. If you would rather we never receive it at all, strip metadata from your images before uploading.
3. Information We Collect
a. Account information. To sign in you give us your email address and we send you a one-time code. We keep your email address, the time your account was created, and a short-lived record of the code (as a one-way hash) while it is valid. There is no password and we do not use Google, Apple, or any social sign-in.
b. Purchase information (via Stripe). When you buy credits or ThreeD Unlimited, Stripe processes the payment. We receive a record of the transaction: amount, date, what was purchased, and Stripe’s customer, session, and subscription identifiers. We never receive or store your full card number, expiration date, CVC, or bank credentials.
c. Images you upload. Described in full in Section 2 above.
d. Technical and usage information. Our servers keep standard access logs (IP address, browser type, the address requested, and the time) for security and debugging. To limit abuse we keep a salted one-way hash of your IP address for rate limiting; the hash cannot be turned back into your address. Our site also sends us anonymous first-party counts of which screens are viewed and whether a download, share, or error happened. Those counts contain no identifier, no address, no file, and no error text, and they are not sent at all if your browser sends the Do Not Track signal.
e. Communications. If you email us or use Help & Feedback, we keep your message, your account email, our reply, and the ticket number so we can help you and keep a record of the exchange.
f. Consent record. When you first sign in and accept our Terms, we record the date, time, IP address, and the version of the Terms and this Policy in effect at that moment. When you buy ThreeD Unlimited we record your renewal consent the same way.
g. Email preferences. Whether you have opted in to optional product emails, and the unsubscribe tokens we generate for them.
h. Cookies and similar technologies. See Section 7.
Categories at a glance (California terms):
| Category | Examples | Source | Why we collect it | Disclosed to | Kept for |
|---|---|---|---|---|---|
| Identifiers | Email address, IP address, hashed IP | You; automatic | Sign-in, security, abuse limits | Resend (to deliver codes and receipts), DigitalOcean (hosting) | Email: life of account; logs: up to 90 days |
| Commercial information | Purchase records, Stripe identifiers | Stripe | Deliver what you bought, receipts, tax and accounting | Stripe | 7 years |
| Internet or network activity | Access logs, anonymous screen counts | Automatic | Security, debugging, reliability | DigitalOcean (hosting) | Logs up to 90 days; counts are aggregate |
| Visual information | Photos you upload, settings, rendered videos, embedded metadata | You | Make the wigglegram you asked for | DigitalOcean (hosting) | Until you delete, or 24 hours (Section 2) |
| Geolocation (precise) | EXIF coordinates, if present in your file | You | Not used; stored with the file | DigitalOcean (hosting) | With the project |
| Communications | Feedback tickets and emails | You | Support | Resend (email delivery) | 2 years |
| Consent records | Acceptance of Terms, renewal consent | You | Prove what was agreed | Stripe (renewal consent only) | Life of account + 6 years |
We do not collect the following categories at all: government identifiers, financial account numbers, biometric information, education records, professional or employment information, or inferences drawn to create a profile.
3A. Sensitive Information and Biometrics
We do not intentionally collect sensitive personal information as that term is defined under California law, and we do not ask you to provide it.
An image you upload may happen to depict a person, including their face. We do not use any image to identify, verify, or recognize any individual. Our automatic face detection only locates where a face is so we can suggest a focus point; it does not extract, generate, capture, or store faceprints, face geometry, voiceprints, fingerprints, or any other biometric identifier or biometric information as those terms are defined under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, or comparable law, and the detection result is discarded as soon as the suggestion is made. We do not sell, lease, trade, or otherwise profit from biometric data, because we do not collect it.
Written retention and destruction schedule. This paragraph is our publicly available written policy for the purposes of 740 ILCS 14/15(a) and comparable state law. Because we do not collect or possess biometric identifiers or biometric information, we hold none and there is nothing to retain. In the event we were ever to come into possession of a biometric identifier or biometric information, whether intentionally or otherwise, our policy is to permanently destroy it as soon as reasonably practicable and in no event later than thirty (30) days from the date it came into our possession, or upon satisfaction of the purpose for which it was obtained, whichever occurs first. We will not sell, lease, trade, or otherwise profit from any such data, and will not disclose it except with written consent, as required to complete a transaction you requested, or as required by law or valid legal process.
If you upload an image depicting another identifiable person, you are responsible for having that person’s permission. See Section 5 of our Terms and Conditions.
4. Third Parties Who Process Data For Us
We share personal information only with service providers who need it to run the Service, and only for that purpose:
| Provider | What it handles | Location | Their policy |
|---|---|---|---|
| Stripe, Inc. | Payment processing, subscription billing, and the billing portal | United States | stripe.com/privacy |
| Resend, Inc. | Sending sign-in codes, receipts, and (only if you opt in) product emails | United States | resend.com/legal/privacy-policy |
| DigitalOcean, LLC | Hosting our servers, storing projects, and server backups | United States | digitalocean.com/legal/privacy-policy |
Each of these providers acts as our service provider or processor. Each is bound by a written data processing agreement to process personal information only on our instructions, only for the purposes described here, and to maintain appropriate security. None of them is permitted to use your information for their own purposes, and none of them is permitted to use uploaded images to train, fine-tune, or evaluate any model. We use no advertising network, no third-party analytics service, and no third-party error-reporting service.
We may also disclose information: (a) to comply with law, legal process, or a valid government request; (b) to enforce our Terms or investigate suspected fraud or abuse; (c) to protect the rights, safety, or property of Frequincy Inc., our users, or the public; or (d) in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify you of any change in how your information is handled.
5. Why We Use Your Information, and Our Legal Bases
- To create, authenticate, and maintain your account, and to keep your project available to you
- To make the wigglegram you asked for
- To process payments and deliver the credits or Unlimited access you purchased
- To send transactional messages such as sign-in codes, receipts, renewal reminders, and security notices
- To provide customer support and respond to your requests
- To monitor, secure, and debug the Service
- To detect and prevent fraud, abuse, and violations of our Terms
- To comply with legal, tax, and accounting obligations
- With your separate opt-in only, to send optional product emails, which you can stop at any time
We do not use your personal information for automated decision-making that produces legal or similarly significant effects, and we do not engage in profiling.
If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases are: performance of a contract (creating your account, processing the images you submit, keeping your project available, delivering what you bought); legitimate interests (security, fraud prevention, abuse limits, debugging, and aggregate usage counts, none of which override your rights); legal obligation (tax and accounting records, responding to lawful requests); and consent (optional product emails), which you can withdraw at any time without affecting your use of the Service.
If you upload an image depicting another person, you are responsible for having their permission, and we handle the image solely on your instruction and in the manner described in this Policy.
6. We Do Not Sell Your Data
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months. We do not sell or share the personal information of anyone under 18.
7. Cookies
We use only strictly necessary cookies:
- A session cookie that keeps you signed in.
- A guest cookie that ties a project to your browser when you use the Service without signing in.
- Browser storage that remembers your in-progress edit so you can return from checkout without losing your crop and focus. This stays on your device.
We set no analytics, advertising, or third-party cookies, so there is no cookie banner and nothing to consent to. You can block or delete cookies through your browser settings, though doing so will prevent sign-in, guest projects, or checkout from working.
8. How Long We Keep Information
| Category | Retention period | Business reason |
|---|---|---|
| Projects (your frames, settings, rendered videos, embedded metadata) | Until you delete them, or 24 hours after upload. Backups expire within 30 days after that. | Letting you return to and re-export your work |
| Account information (email, balances) | Life of the account, plus up to 30 days in backups after deletion | Sign-in and delivering what you bought |
| Transaction records | Seven (7) years | Tax and accounting obligations |
| Feedback tickets and support emails | Two (2) years | Support history and dispute records |
| Server access logs and hashed IP rate-limit records | Up to ninety (90) days | Security, fraud prevention, debugging |
| Consent records (Terms acceptance, renewal consent) | Life of the account plus six (6) years | Demonstrating what was agreed |
| Email preferences and unsubscribe tokens | Life of the account; suppression of an unsubscribed address is kept so we never email it again | Honoring your choice |
| Information of a user later identified as under 18 | Deleted promptly on discovery, and in no event more than thirty (30) days after we become aware | The Service is for adults only |
| Biometric identifiers, if ever received | Thirty (30) days maximum; see Section 3A | We do not collect these; the schedule exists as a safeguard |
At the end of each period, data is deleted or irreversibly anonymized. Where a legal hold, open dispute, or statutory obligation requires longer retention, we keep only what that obligation requires and delete the rest.
9. Security
We use commercially reasonable safeguards including encryption in transit (HTTPS), secure cookies, one-time sign-in codes instead of passwords, access controls, and established providers such as Stripe and DigitalOcean for payment and infrastructure. Every project is private to the account or browser that created it, and we verify that on every request. We review our security practices, vendors, and incident response at least annually.
In the event of a personal data breach affecting your information, we will notify you and the relevant supervisory or state authorities where and within the timeframes required by applicable law, including the GDPR, the UK GDPR, and U.S. state breach notification statutes.
That said, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights
Everyone. You may request access to the personal information we hold about you, correction of inaccurate information, or deletion of your account and associated data. You can delete any project yourself from inside the app. For anything else, use Help & Feedback (choose "Privacy or deletion request") or email hello@threed.photo.
How we handle requests. Send requests to hello@threed.photo with "Privacy Request" in the subject line. We will acknowledge receipt and respond within 30 days (45 days for California requests, as that law allows). Where a request is complex or we have received several from you, we may extend once by a further 30 days (45 for California) and will tell you why within the original window. There is no charge unless a request is manifestly unfounded or excessive.
Verification. Before acting on a request we will verify that you are who you say you are, normally by confirming control of the email address on your account. For deletion requests we may ask you to confirm a second time. If we cannot verify you, we will tell you and explain why rather than acting on an unverified request.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We will ask the agent for written proof of authorization signed by you, and we may still ask you to verify your own identity directly.
Appeals. If we decline your request in whole or in part, you may appeal. Reply to our decision or email hello@threed.photo with "Appeal" in the subject line, within 60 days of our response. A person who was not involved in the original decision will review it, and we will respond in writing within 45 days with our decision and the reasons for it. If your appeal is denied, we will tell you how to contact your state Attorney General or supervisory authority to submit a complaint. We extend this right to everyone, wherever you live.
California residents (CCPA/CPRA). You have the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; to opt out of sale or sharing (we do neither); to limit use of sensitive personal information (we do not use it for purposes requiring this right); and to be free from discrimination for exercising these rights. You may use an authorized agent. Submit requests to hello@threed.photo. The categories of personal information we collect, the sources, the purposes, the categories of third parties to whom we disclose it, and our retention period for each are set out in Sections 3 and 8.
EEA, UK, and Swiss residents (GDPR / UK GDPR). You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, plus the right to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). We will honor these rights directly; contact us as described above.
Other U.S. states and other countries. Where your local law gives you rights to access, correct, delete, port, or object, we honor them through the same process. If your law requires something we have not listed, tell us and we will follow it.
Opt-out preference signals. We honor the Global Privacy Control (GPC) signal where your browser transmits it. Because we do not sell or share personal information for cross-context behavioral advertising, there is nothing for such a signal to opt you out of, but we treat it as a valid request regardless. We also honor the Do Not Track signal by not sending usage counts.
Optional emails. You can turn optional product emails on or off in Help & Feedback, and every such email contains a one-click unsubscribe link. Sign-in codes, receipts, and security notices are not optional because the Service cannot work without them.
11. Where We Operate, and International Transfers
Frequincy Inc. is a United States company. The Service is offered worldwide, in English and priced in U.S. dollars, wherever an online photo tool is lawful. We are based in New York, and our servers and service providers are in the United States.
If you access the Service from outside the U.S., your information, including your photos, will be transferred to and processed in the U.S., where data protection law may differ from your own. For transfers from the European Economic Area, the United Kingdom, and Switzerland we rely on the EU-U.S. Data Privacy Framework where a provider is certified, and otherwise on Standard Contractual Clauses (and the UK Addendum) in our agreements with providers, together with the safeguards described in Section 9. You can ask us for a copy of the relevant clauses.
Regardless of where you live, you may contact us at hello@threed.photo to request access to, correction of, or deletion of the information we hold about you, and we will act on that request as described in Section 10.
12. Children
The Service is for adults. You must be 18 or older to use it, and we do not knowingly collect personal information from anyone under 18. We ask you to confirm your age when you accept our Terms. If you believe someone under 18 has an account or has uploaded photos, contact hello@threed.photo and we will delete the account and every project on it promptly, and in no event more than 30 days after we become aware.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date and version reflect the current version. If we make material changes, we will notify you through https://threed.photo or by email where we have your address, at least 10 days before they take effect where practicable, and we will keep prior versions available on request. Continued use after changes take effect constitutes acceptance.
14. Acceptance and Record of Consent
When you first sign in you are asked to check a box confirming that you are 18 or older and that you agree to our Terms and Conditions and this Privacy Policy. When you do, we record the date, time, the version of each document in effect, and the IP address from which you signed in, so that both you and we have a reliable record of what was agreed and when. We retain that record for as long as your account is active and for six years afterward.
15. Contact Us
Frequincy Inc.
209 E 31st Street, New York, NY 10016
hello@threed.photo
See also: Terms and Conditions · Privacy Policy · Help & Feedback