This Privacy Policy explains how Thrine ("Thrine", "we", "us") collects, uses and protects your information when you use the Thrine website at thrine.app, its editor, templates, exports and embeds (together, the "Service").
We keep this short and specific on purpose. If something here is unclear, write to hello@thrine.app.
1. Our approach
Thrine is a web app for making 3D scenes for websites: you bring a 3D model, a line of text or an SVG logo, style it with materials, lighting and animation, and export it as an image, a video or an embed code for your own site. We collect what we need to run it: your account, the work you save, and enough about how the Service is used to make it better. We do not sell your personal information, we do not share it with advertisers, and we do not show ads.
2. Information we collect
Information you give us
- Account information: your email address, and your name and profile picture if you sign in with Google or add them yourself. Thrine has no passwords: you sign in with Google or with a link we email you
- Waitlist: your email address, if you join the waitlist
- Content you create or upload: projects and their settings, 3D models, SVG drawings, text, background images and videos, and the pictures of your projects we draw for your project list
- Embeds: when you create an embed, a copy of the scene and the files it uses at that moment
- Communications: messages you send us by email or through the Service
Information collected automatically
- Usage data: pages viewed, templates previewed or opened, features used (for example, the look, material or animation you choose), and your favorites and history
- Device and technical data: browser type, operating system, screen size, language, and approximate location derived from your IP address
- Log data: IP address, request timestamps, and error information
- Email data: whether the emails we send you were delivered and opened
- Local storage: see Section 7
Information from third parties
If you sign in with Google, we receive basic profile information from Google: your name, email address and profile picture. We do not receive your Google password, and we do not ask for access to your Google Drive, contacts, calendar or any other Google data.
3. How we use your information
We use information to:
- Provide, operate and maintain the Service
- Create and manage your account, and sign you in
- Save your projects and files, and give them back to you on any device you sign in on
- Serve the embeds you create on the websites where you place them
- Send sign-in links, early-access invitations and service announcements
- Understand which templates and features are used, so we can improve the Service
- Detect, prevent and investigate abuse, fraud and security incidents
- Enforce our Terms of Service
- Comply with legal obligations
We do not use your personal information or your content to train AI models.
4. Google user data
When you choose Continue with Google, Thrine asks Google for three things only: your name, your email address and your profile picture (the openid, email and profile permissions). We use them only to:
- Create your Thrine account, or find it if you already have one
- Sign you in, so your projects are saved to your account
- Show your name and picture in the app's account menu, so you can see who is signed in
We store them with your account in our authentication provider (Supabase) and our database. We do not sell this information, do not use it for advertising, do not use it to train AI models, and do not transfer it to anyone except as needed to provide the Service, to comply with the law, or as part of a business transfer described in Section 8. No person at Thrine reads it except to support you, investigate abuse or comply with the law.
Thrine's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove Thrine's access at any time from your Google Account settings, and ask us to delete everything we hold about you by writing to hello@thrine.app.
5. Your content and embeds
- Projects are private: your projects and uploads are visible only to you, and to our team where needed to operate the Service, support you or investigate abuse
- Embeds are public: an embed is made to be seen. Anyone with its code, and every visitor to a page it is placed on, can view the scene, and their browsers download the files it uses. The embed code carries an id, not your name or email. Do not put anything in an embed that you would not want public
- Embeds do not track visitors: an embed sets no cookies and uses no storage on the websites where it appears. When it loads, our servers receive the standard data of any web request (IP address, browser, the page that loaded it)
6. Legal bases for processing (EEA/UK users)
Where GDPR applies, we process personal data on these bases:
- Contract: to provide the Service you've asked for
- Legitimate interests: to secure, improve and analyse the Service
- Consent: for optional communications
- Legal obligation: where the law requires it
You may withdraw consent at any time; this does not affect processing already carried out.
9. Retention and deletion
We keep your account and content for as long as your account is open. When you delete a project, an embed or a file, we delete it, along with any file nothing else of yours still uses. To delete your account and everything in it, write to hello@thrine.app from the address you sign in with; we delete it within 30 days. Logs and analytics are kept for a limited period, and backups may hold deleted data for a short time before they expire.
10. International transfers
Our providers operate globally, and your information may be processed in countries other than your own (including the United States and India), where data protection laws may differ. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
11. Security
We protect your information with encryption in transit (HTTPS/TLS), access controls, and regular review of our infrastructure. Thrine stores no passwords: sign-in is through Google or a one-time email link.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
12. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your personal information and your account
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent for consent-based processing
- Opt out of non-essential emails at any time
- Not be discriminated against for exercising these rights
To exercise any of these, email hello@thrine.app. We'll respond within the time required by applicable law, typically 30 days. We may need to verify your identity first.
Indian users: under the Digital Personal Data Protection Act, 2023, you may also nominate another individual to exercise your rights in the event of death or incapacity, and you may raise grievances with us at the contact below before approaching the Data Protection Board.
EEA/UK users: you have the right to lodge a complaint with your local supervisory authority.
13. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with information, contact hello@thrine.app and we will delete it.
14. Do Not Track
We do not currently respond to browser Do Not Track signals, as no common standard has been established.
15. Changes to this policy
We may update this Privacy Policy. Material changes will be reflected in the "Last updated" date above and, where appropriate, announced in the Service or by email. Continued use after changes take effect constitutes acceptance.
16. Contact
For privacy questions, requests or grievances:
Thrine
Bengaluru, Karnataka, India
hello@thrine.app