Privacy Policy
This Privacy Policy explains what MessyPoly collects, why it is collected, and how it is handled when you use the service.
1. Information We Collect
- Account information, including email address, password hash, verification status, plan, quota state, and session metadata.
- Uploaded GLB files, generated outputs, render artifacts, job status, optimization metrics, and error details needed to run and debug jobs.
- Billing identifiers from Stripe, such as customer IDs, subscription IDs, price IDs, event IDs, invoice status, and subscription status.
- Operational data such as request timestamps, IP-derived rate-limit metadata, worker logs, and security events.
- Support messages you send to support@messypoly.com.
- Website usage analytics collected via Google Analytics, such as pages viewed, referring site, device/browser type, and approximate location.
2. Information We Do Not Store
MessyPoly does not store full card numbers, CVC codes, or raw payment credentials. Payment collection is handled by Stripe. Passwords are stored only as password hashes, not plaintext passwords.
3. How We Use Information
- Authenticate accounts and protect sessions.
- Process uploaded models and provide optimized downloads.
- Track quotas, subscriptions, credit packs, and billing state.
- Send verification and password reset emails.
- Detect abuse, enforce rate limits, debug failures, and improve product quality.
- Respond to support requests and account questions.
4. Service Providers
MessyPoly uses third-party providers to operate the product: Vercel for the web layer, Koyeb for backend and worker services, MongoDB for application data, Cloudflare R2 for file storage, Stripe for payments, Resend for transactional email, and Google Analytics for website usage analytics. These providers process data as needed to provide their services.
5. File Retention
Uploaded source files and generated artifacts are retained only as needed to operate the service, support account history and download windows, debug failures, and maintain analytics. Files referenced by Pro, Studio, or administrator account history are protected from automatic deletion. Free-account files may expire under the published retention windows. To avoid repeated uploads of the same model, MessyPoly may briefly use a content-addressed staging cache; accepted jobs are copied into job-owned storage before processing. Deleting a version, asset, job, or account may permanently remove its associated files.
6. Security
MessyPoly uses HTTPS, HTTP-only session cookies, server-side service tokens, password hashing, Stripe-hosted payment surfaces, signed webhooks, and access controls for account-owned jobs. No internet service can guarantee perfect security.
7. Your Choices
You may request account help, billing help, correction, export, or deletion by emailing support@messypoly.com. Some records may be retained when needed for security, legal, billing, or abuse-prevention reasons.
8. Changes
We may update this Privacy Policy as MessyPoly changes. The effective date will show when the latest version applies.
Privacy questions: support@messypoly.com