VASE 3D Open the studio
← Back to vase3d.io

Privacy Policy

Last updated 25 August 2026

This policy explains what happens to the information you give us when you use VASE 3D — the website at vase3d.io, the studio app where you design vessels, and the launch waitlist. We keep it deliberately small: we collect what we need to run the service and to tell you when new things open, and nothing more.

1.Who is responsible

The controller of your information is Afek Hershko (VASE 3D), Israel. You can reach us any time at afekhershko@vase3d.io.

2.What we collect

What we hold depends on how you use VASE 3D.

  • If you join the waitlist or ask to hear when Foundry opens: your email address, your platform preference (web, iPhone/iPad, or Android), the time you signed up, and whether you joined by email or via Google sign-in.
  • If you sign in to the studio: your email address, so we can keep your account and unlock what your plan includes. There are two ways in and neither uses a password. Google’s signed response contains your verified email address and may also contain your name and Google profile picture; we never receive your Google password. Or you can ask for a one-time sign-in link: we email you a link that works once and expires after 15 minutes, and we store only a one-way hash of it, never the link itself. There is no VASE 3D password to set, reset, leak or reuse.
  • If you use the studio while signed in: the studio keeps an account copy of its JSON records on our server. That includes saved vessel parameters (not their rendered thumbnails), saved glaze mixes, favourites, recent choices, deletion markers, your local maker name, settings and allowed records of tips, onboarding, lessons, practice and recent activity. The live vessel you are editing, browser recovery copies, rendered thumbnails and your session credential are excluded. Optional-measurement identifiers, acquisition and experiment counters, the onboarding-research marker, and the local celebration, taste and home-personalisation records are also device-only and never enter this account copy. Sync is tried after sign-in and when the studio opens or returns to the foreground, after a save, and before sign-out or a page closes when a save is waiting. Saved work and your local maker name can follow the account to another device; machine-specific preferences are kept in the account copy but are not automatically applied on the other device.
  • Our record of Terms acceptance: the account identifier, which document and version the sign-in screen presented, the version the server had at the time, and when the acceptance was recorded. A sign-in from an older client can leave the presented version blank; we keep that as unknown rather than filling in a claim the client did not send.
  • Each device you sign in from: a short record that lets us end that device’s session the moment you sign out. It holds a coarse label built from your browser’s user-agent — a browser family and a platform, such as “Chrome on Windows” — together with when that device signed in and when it was last active. The label is deliberately coarse: a full user-agent string is a fingerprint, so we never store one. This record is what makes signing out actually sign that device out, rather than only expiring its token later. You can ask us for a copy of these records, or to erase them, through the rights in section 7.
  • If you create a public maker page: the display name, biography, location, website, optional contact email, profile image, vessel images, captions, tags, and VASE 3D design links you choose to publish. Draft vessel posts remain visible only to your account. Your website or contact email is made public only when you enable the contact option.
  • If you post on the feature request board: the title and any detail you write, and which requests you have voted for. The board shows your words to other makers; it never shows your email address, and the per-post identifier it uses is different on each of your posts so your requests cannot be grouped into a profile by someone reading the board.
  • While you use your account: a short set of timestamps — when you first signed in, the last day you were active, the first time you got a vessel on screen, the first time you exported, and which of our emails have already been sent to you. We keep these so we can see where people get stuck and so we do not send you the same email twice. It is not a record of each thing you did or when; there is one row per account, with those dates in it. If we invite you to a named beta group, we also keep a keyed invite tag, the group and invite time, and at most one return timestamp if you visit in the 72–96 hour window after an earlier visit. This lets us answer the beta group’s day-three question without keeping a visit log.
  • If you allow product measurement: each event carries an event name and time, a random per-tab session identifier, the part of VASE 3D it came from, the app environment and a small, fixed set of numbers or short labels — for example which workflow or control was used, never the value of your design. For a signed-in account, a separate keyed map connects the email address to a random research identifier; the email address itself is not written to the telemetry databases. If the optional PostHog service is enabled, the signed-in browser uses a one-way account tag rather than sending the email address to that provider. Each batch also writes a separate receipt containing the measurement choice, its version and the time it was received. We do not send vessel geometry, project files, titles, filenames or free-form text as measurement.
  • If that optional measurement is on when you arrive through a public-launch asset: we can attach one first-touch record to a new signed-in account, only when the account record already exists and the attachment arrives within one hour of first sign-in. Optional measurement cannot create a signup record or relabel an older account. The record contains exactly four bounded labels: acquisition_channel (one of the named launch channels), acquisition_campaign (only vase3d_public_launch), acquisition_content (an approved asset label for that channel, or empty), and landing_via (which fixed VASE 3D button took you into the studio). It helps us compare which launch channel and asset produced accounts that later previewed, exported or returned. We also keep the server time when those labels were attached. A later link cannot replace the first touch. Your browser reduces the referring address or launch link to those approved labels; we do not store or send the raw referrer or full URL.
  • If you subscribe to a paid plan: which plan you are on, its status, price and next charge or scheduled-cancellation time, and the transaction and subscription identifiers we receive from our payment provider. We use them to unlock the right features, show your billing state, apply a refund or cancellation to the right subscription, and stop delayed provider messages from recreating a deleted billing record. We never see or store your card number (see “Who we share it with”).

When you submit a form or use the service your IP address is processed momentarily, in memory, to rate-limit abuse. We do not store it with your record; our security log keeps only a one-way hashed tag, never the address itself. We do not collect your card details or build an advertising profile.

3.Why we use it, and our legal basis

We use your details to run VASE 3D and to tell you about it:

  • to notify you about availability and closely related launch updates — legal basis: your consent, given when you sign up, which you can withdraw at any time (see “Your choices” below);
  • to provide your account and the studio, and to deliver and support any paid plan you buy — legal basis: performance of our contract with you;
  • to keep the factual record of which Terms version a sign-in flow presented and when an acceptance was recorded;
  • to measure how the product is used only when you turn measurement on, including the bounded first-touch launch labels described above for a signed-in account — legal basis: your consent, which you can withdraw through Privacy choices (and, in the Studio, through Settings);
  • to send you a short series of emails about parts of the studio people do not find on their own, and to check in once if you signed up and never made anything — every one of them carries a one-click unsubscribe that needs no sign-in, and stopping them stops all of them; and, if we invite you to a named beta group, to measure the group’s activation and exact day-three return distribution without a general visit history;
  • to keep the service secure and prevent abuse — legal basis: our legitimate interest in protecting VASE 3D and its users.

4.Who we share it with

We do not sell your data or share it for advertising. Below is every service provider that can be in the loop, including the ones that are switched off or not built yet, each only for the job named. The same list is on the trust page.

These two are in the loop whenever you use VASE 3D:

  • Hosting — our site, the studio servers and your waitlist entry are hosted on Fly.io.
  • Email delivery — waitlist confirmations, one-time sign-in links and the account or product emails we send are carried by Resend. To deliver one, Resend receives the recipient and sender addresses, subject and full message text. For a sign-in email that text includes the one-time link, which expires after 15 minutes and works once. There is no password email, because there is no password.

These two come into play only if you use the relevant feature:

  • Google sign-in — used when you choose Google as your way in. The alternative, a one-time sign-in link we email you, involves no third party beyond the mail provider that carries it. The waitlist form also has a Google button you may use instead of typing your address. Google gives us a signed response containing your verified email address and may include your name and Google profile picture. We never receive your Google password.
  • Payments — if you subscribe, Paddle acts as the merchant of record: Paddle (not us) collects and holds your payment and billing details and the associated tax records. We receive your email address, selected plan, processor transaction/subscription identifiers, and subscription status and timing needed to unlock, display, cancel or refund the right plan.

These five are switched off unless we turn them on. We name them now rather than after the fact, so this page stays true either way:

  • Payments, the second optionPolar is a second merchant of record we have built support for and have not switched on. It has received nothing. If we ever move billing to it, it would hold your payment and billing details in place of Paddle, on the same terms, and we would say so here first.
  • Launch mailing list — if we switch it on, Loops holds the launch list and receives the email address you gave us for exactly that purpose, and nothing else about you.
  • Optional product measurement — if we switch it on, PostHog (EU region) counts how the product is used. It is configured cookieless, with no session replay and no advertising profile, and the page address is withheld from it so that a shared design and the name you gave it cannot travel inside it.
  • Optional product measurement — if we switch it on, Plausible receives the same bounded interaction events named above. VASE sends no automatic pageview, raw page address or raw referrer. It is cookieless and does not follow you to other sites.
  • Ask, the studio teacher — if we switch it on, your question, a summary of the piece you are working on and, when you attach one, your reference photograph are sent to DeepInfra to be answered. Your photograph is re-encoded here first, which removes every piece of hidden metadata a camera adds — including the location a phone records in it. Your email address is never sent. Ask is off unless we switch it on, and no part of the studio calls it today.

And one that receives nothing at all today:

  • Print fulfilmentFacFox is our intended print bureau. Ordering a print through us is not built yet, so no model and no order has ever been sent to them. If you use their quote page from the studio today, you upload your file to them yourself. When we do connect it, your model and order details would go to FacFox to make and ship the piece, and we will update this page before that starts.

Your information may be processed on servers outside your country (for example Resend and Google operate in the United States). We rely on these providers’ own transfer safeguards for any such transfer.

5.How long we keep it

We keep each kind of data only as long as we need it:

  • Your waitlist or notify-me entry — until we have finished telling people about the launch, or until you ask us to remove it, whichever comes first. In any case no longer than 12 months, after which it is deleted automatically.
  • Your account and subscription record (your email and which plan you are on) — for as long as you keep your account. To avoid hiding a recurring charge, account deletion does not complete while a paid subscription can still renew or while we cannot verify its state; you must first cancel it or schedule its cancellation with the merchant of record. Once deletion is safe, we remove our raw-email billing rows and keep only the provider’s opaque transaction and subscription references needed to stop a delayed provider message from recreating the deleted record. Those reference-only safeguards currently have no automatic expiry. The merchant of record separately keeps the billing and tax records it is legally required to keep.
  • Your synced studio state — for the life of the account, with no scheduled expiry. The optional-measurement and local-personalisation records named in sections 2 and 6 are not part of it. The live account database logically deletes any historical rows for those excluded records when it opens; this is ordinary database-row deletion, and an older backup can still hold a pre-deletion copy. The configured backup set includes the account database and does not currently declare a separate automatic expiry for retained off-box copies. If a backup is restored, later deletion requests and the exclusion migration have to be applied again.
  • Your Terms-acceptance record — the readable account address is replaced with a one-way keyed tag when the account is erased, while the document, presented version, server version and time are retained. There is currently no automatic expiry for that tagged record.
  • Optional product measurement — raw event rows are pruned after 180 days. The separate account-to-research-identifier map lasts for the account and is removed with a behavioural-data erasure. Consent receipts are kept in a separate database, are not removed by that erasure, and currently have no automatic expiry. The event, identity and consent stores are included in the off-box backup set.
  • Optional account-linked launch attribution — the four bounded first-touch labels and their server receipt time last until you withdraw optional measurement or delete your account; they have no separate automatic expiry. Withdrawal clears those fields without deleting the service timestamps needed to operate your account. The account download includes those labels and their receipt time; they are removed with account erasure.
  • Your maker page, vessel posts, and uploaded images — until you delete an individual post or close your public maker page. Unused image uploads are deleted after 24 hours. Safety reports are retained for no longer than 90 days.
  • Your feature requests and votes — until you delete the post, or until you close your account, at which point your posts and your votes are removed with it.
  • Your account timestamps and beta-cohort tag (section 2) — for as long as you keep your account, and removed when you delete it. An invite-only keyed tag is removed by the same erasure even if you never created an account. If you unsubscribe from our emails we keep a keyed suppression marker, rather than your readable address or account-activity row, so erasure and an old unsubscribe link cannot silently re-enable those messages. It has no automatic expiry today.
  • A design you publish via a scan-to-remix link — until you ask us to remove it, or the project is discontinued.
  • Your signed-in devices, and any sign-in link you request — an active device record is deleted after 90 days without use; signing out marks it revoked, and that revoked row is deleted after 30 days. A one-time sign-in link works once and authorizes sign-in for 15 minutes. Its hashed database row remains briefly so a repeated click can receive a useful “used” or “expired” answer: a used row is deleted 24 hours after use, and an unused row 24 hours after expiry. Normal identity operations run this deletion sweep, and an idle session cannot be revived. These records are deliberately excluded from our backups — restoring an old copy could bring back a device you had signed out.
  • Our security audit log — this holds only one-way hashed tags, never a readable email or IP address. It is tamper-evident evidence kept for security and compliance, so it is rotated rather than mined for personal data.

A backup created before an account or behavioural-data erasure can still contain the older record. We do not currently have a proven external deletion journal that could safely replay every later erasure into an older restore. Until that control is proven, recovery must use a backup made after the later erasure; otherwise the restore remains stopped rather than resurrecting deleted data.

If the project is discontinued, we delete the waitlist and account data.

6.Cookies, analytics & your designs

We run no advertising trackers, and nothing on VASE 3D follows you across other sites. Product measurement is off unless you allow it through Privacy choices. In the Studio, the same choice is shown as “Share product usage” in Settings, and no Studio usage event or account-linked launch attribution is sent until it is on there. When you allow measurement, VASE 3D sends the bounded events described in section 2 to our own telemetry endpoint. If a cookieless service named in section 4 is switched on, the same permitted events can also go to PostHog or Plausible. They set no cookies, record no session replay, and build no advertising profile. PostHog is configured so the page address is withheld from it, because in the studio that address can carry your design and the title you gave it. Until you make that choice, optional measurement stays off.

Storage on your device is a bigger part of VASE 3D than it is on most sites. The live studio works from that local copy; when you are signed in, the bounded account copy described in section 2 is also kept on our server. Here is the device storage, by purpose:

  • Your work — your library of saved vessels, the piece you have open, your glaze recipes and your maker-page profile as you edit it are held in your browser’s local storage, with their rendered thumbnails in a browser database on the same device. While signed in, saved vessel parameters, glaze mixes, favourites, deletion markers and the local maker name are part of account sync. Rendered thumbnails and the live vessel on screen stay on this device unless you separately publish or export them.
  • Keeping you signed in and respecting privacy choices — one session cookie holds only your signed-in session, is never used for tracking, is cleared when you sign out, and otherwise lasts 30 days. Two additional parent-domain cookies hold only a boolean 1: one keeps an optional-attribution withdrawal active and retryable, and one prevents a first touch already attached to one account from being reused for another account on a shared browser. They contain no channel or account value, can only suppress optional measurement, and last up to one year (the withdrawal one is cleared by a later explicit “Allow”). In the iPhone, iPad and Android app there is no session cookie, so the same session is held in local storage instead.
  • Your settings, and what you have already seen — your preferences, which tips and lessons have been shown, your favourite and recent patterns, and a local record of the styles you tend to pick so the studio can suggest more of them. These shape the app on this device. Allowed JSON entries whose names begin with vs_ are copied to the signed-in account, but the live draft, local admin flag, browser recovery copies, optional-measurement state, onboarding-research marker, celebration ledger, taste profile and home behaviour/activity records are excluded. The latter records remain on this device. Device preferences that are allowed into the server copy are backup-only and are not applied automatically elsewhere.
  • Keeping the app working — a few technical entries: the one that clears a stale cached page, a one-shot retry if the app fails to start, a recovery copy if one of your records is ever found damaged, and the display setting the app falls back to on a device that struggled.
  • An offline copy of the app — so the studio opens without a network, a service worker keeps the app’s own files and the pattern images you have already loaded. That cache is bounded: at most 60 files, and nothing older than 7 days. Your designs and your account never go into it.
  • Measurement, only if you allow it — after you turn measurement on, the studio creates a random identifier for the current tab. It closes with the tab and is removed immediately if you withdraw that choice. We also keep a random browser identifier and a few local counters, so the same browser is not counted twice, and one short word for the kind of place you arrived from the first time: a search engine, an AI assistant, a social platform, a community, a link we sent, a scanned maker mark, our own site, some other link, or nothing to go on. The address you came from is read on your device and is not kept or sent; only that one word is. It tells us whether people are finding VASE 3D on their own or because we put it in front of them, so we can tell real interest from our own advertising. Choosing “Necessary only” stops events and deletes the per-tab identifier, the longer-lived browser identifier and that word rather than merely stopping their use. Public launch links use a separate first-touch browser record containing only the four approved labels described in section 2. It is never part of general account sync; after sign-in, those labels can be attached separately to the account while measurement is allowed. Choosing “Necessary only” deletes that local launch record and removes the four account labels without deleting the service lifecycle timestamps. If that attachment succeeds, a no-detail boolean consumes the browser touch so it cannot be reused for a second account. A second no-detail boolean keeps a withdrawal active and retries the authenticated deletion after a temporary failure. Both are excluded from account sync and can only turn optional measurement off. The raw referrer and full URL are never stored in either record.

Clearing browser data removes the copy on that device; it does not erase the signed-in account copy on our server, which can return after you sign in again. Settings also has a control that erases the VASE 3D records and thumbnail database from this device directly, and one that downloads a copy of the device data first. Section 7 explains how to request the server-held copy or erase it. If you choose to publish a maker-page post or share a scan-to-remix link, the material you submit is separately stored on our server so the public page or link can resolve. Uploaded maker-page images are decoded and re-encoded before storage so embedded EXIF and GPS metadata is not retained.

7.Your choices and rights

You can ask us to show you the data we hold about you, give you a copy of it to take elsewhere (portability), correct it, or delete it, and you can withdraw your consent, leave the waitlist, or close your account at any time — just email afekhershko@vase3d.io and we’ll action it. The maker-page account screen also lets you export or permanently delete your profile, posts, and uploaded images directly. An account request also covers the server-held studio state, email-to-plan record, maker profile, posts, images, feature-board posts and votes, account timestamps and beta-cohort tag, identity map, optional behavioural events, and the four optional launch-attribution labels plus their server receipt time. The account download includes those fields in its lifecycle record. Withdrawing optional measurement removes the launch-attribution labels from this browser and the signed-in account while preserving the service lifecycle timestamps. If a paid plan can still renew, deletion pauses before any account store is erased and the account screen directs you to cancel or schedule cancellation with the merchant first. After safe deletion, the opaque processor-reference safeguards and a keyed subject cutoff described in section 5 remain without your readable email or plan, so an older delayed billing event cannot recreate them. The tagged Terms-acceptance record and measurement-consent receipts described in section 5 are retained separately rather than deleted with those account and behavioural records. Every email we send you that is not a receipt or a security notice carries a one-click unsubscribe link that works without signing in, including from an address whose account has since been deleted. (Our payment provider separately retains billing and tax records it is legally required to keep.) Depending on where you live, you may also have the right to complain to your local data-protection authority.

8.Security & breach notification

We protect your information with measures matched to how sensitive it is. Traffic to the site and the studio is encrypted in transit. The studio is sign-in gated, so the design tools sit behind authentication. Our application security log stores only one-way hashed tags, never your raw email or IP address, and the application access log records request method, route, status, latency and a request identifier without the raw client address, query string or request body. We keep the data we hold deliberately small, which is the best protection of all.

If a breach ever affects your personal data, we will assess it promptly and, where the law requires, notify the relevant supervisory authority without undue delay — within 72 hours of becoming aware, where that obligation applies to us. If the breach is likely to put you at high risk, we will tell you directly and without undue delay, and explain what happened and what you can do.

9.Changes to this policy

If we change how we handle your data, we will update this page and the “Last updated” date above. For anything material, we’ll do our best to let affected users know.

10.Contact

Any privacy question or request: afekhershko@vase3d.io.