VisibleIO

Legal

Privacy Policy

Effective date: July 24, 2026

This Privacy Policy describes how VisibleIO Limited handles personal information when you use visibleio.com and the VisibleIO platform—including our CMS, Viewer, Blender plugin, embeds, and related services. Privacy requests: [email protected]. It applies to individual creators and business customers in the United States, EEA/UK, Asia-Pacific, and other regions.

01Who we are (data controller)

VisibleIO Limited (“VisibleIO,” “we,” “us,” or “our”) is a limited company incorporated in Hong Kong Special Administrative Region. Our official website is https://visibleio.com. Privacy contact: [email protected].

VisibleIO provides a platform for creators, brands, and teams to design interactive, photoreal 3D product experiences—from Blender scenes and material logic to browser-ready viewers, embeds, and shared links. Our product applications (including the VisibleIO CMS and Viewer) form part of the Services.

For personal information we collect about visitors to visibleio.com and about VisibleIO account holders, VisibleIO Limited is the data controller (or equivalent under applicable law). Privacy requests: [email protected].

02Scope and roles

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our websites, CMS, Viewer, Blender plugin, APIs, and related services (the “Services”), whether you are an individual creator or a business customer. If paid billing is enabled for your account, it also covers subscription and payment-related data.

Controller vs processor for project embeds: when you publish a share link or embed a Viewer on your own site, you typically decide why and how end-user interaction data is collected in that experience. In those cases, you are generally the controller (or “business”) and VisibleIO acts as a processor / service provider, processing data on your instructions to deliver the Viewer, security, and related hosting. Your own privacy notice should cover your end users. This Policy describes VisibleIO’s own practices and, where we act as processor, the categories of processing we perform.

Business customers who need a Data Processing Addendum (DPA), including EU Standard Contractual Clauses where required, may request one at [email protected]. We respond to privacy requests sent to that address.

03Information we collect

Depending on how you use the Services, we may collect:

  • Account information: name, email address, password (hashed), language preference, and profile or workspace settings.
  • Authentication data: if you sign in with Google or another identity provider, we receive identifiers and profile details you authorize (for example email and display name).
  • Billing and subscription data (when paid plans are enabled): plan tier or entitlements, billing status, invoices, tax-related details you provide, and payment-related identifiers processed by our payment providers. We do not store full payment card numbers on VisibleIO servers.
  • Project and content data: project metadata, materials, cameras, visibility rules, render outputs, thumbnails, configuration logic, share/embed settings, and other assets you upload, sync via the Blender plugin, or generate in the CMS. This may include personal data if you choose to put it in your content.
  • Usage, device, and log data: IP address (which may be hashed or truncated), browser and device/OS information, feature usage, approximate location derived from IP, timestamps, referrers, performance metrics, and diagnostics/error logs.
  • Viewer / analytics events: when a project is viewed or embedded, we may process interaction and delivery events (for example loads, configuration changes, device class) to provide analytics to the project owner, operate the service, and improve reliability.
  • Communications: messages and attachments sent to [email protected], [email protected], or in-product feedback.
  • Cookies and similar technologies: cookies, local storage, and similar technologies for authentication, security, preferences, and (where used) analytics. See Cookies below.

04How we use information

We use personal information to:

  • Provide, operate, secure, and improve the Services (accounts, hosting, rendering workflows, viewer delivery, embeds, sharing, and analytics dashboards).
  • Authenticate users, prevent abuse, detect fraud, and maintain platform integrity.
  • Process plan entitlements (for example storage, project limits, watermark removal, iframe embedding, multi-render) and, when paid billing is enabled, subscriptions, invoices, and billing notices.
  • Provide support, onboarding, and service-related communications.
  • Send product or marketing communications where permitted by law (you may unsubscribe at any time).
  • Comply with legal obligations, enforce our Terms, and protect rights, safety, and property.

We do not sell your personal information for money. We do not use your Blender scenes or commercial project assets to train public generative AI models.

06How we share information

We may disclose personal information to:

  • Service providers / subprocessors that host infrastructure, store files, deliver email, process payments, provide security or analytics tooling, and support operations—bound by confidentiality and data-protection terms. Typical categories include cloud hosting and object storage (for example Cloudflare), identity providers (for example Google), payment processors, and transactional email providers.
  • Collaborators or organization members you invite, according to roles you configure.
  • The public or your customers when you intentionally publish a share link, gallery listing, or website embed.
  • Authorities or other parties when required by law, to protect rights and safety, or in a merger, acquisition, financing, or asset transfer (with appropriate safeguards).

A current list of material subprocessors is available on request at [email protected]. We will update customers of material subprocessor changes as required by our DPA or applicable law.

07Cookies and similar technologies

Today we primarily use strictly necessary cookies and similar technologies so you can sign in to the CMS, stay authenticated, maintain security, and remember essential preferences. The marketing website at visibleio.com does not currently set non-essential advertising or analytics cookies.

If we later introduce analytics or other non-essential technologies, we will do so in line with applicable law—including obtaining consent in the EEA/UK where required before setting those cookies, and providing a preference control where appropriate.

You can also control cookies through your browser settings. Blocking necessary cookies may prevent login or core product functions from working.

08Project content, sharing, and embeds

You control whether projects remain private, are shared via link, or are embedded on external websites. Public or embedded experiences may expose viewer assets and related metadata needed to display the experience, and may generate usage analytics for your account.

You are responsible for having a lawful basis to collect end-user data through your published experiences, for configuring share/embed settings appropriately, and for providing your own notices where required.

09Data retention

We keep personal information only as long as needed for the purposes described in this Policy, including:

  • Account and active project data: for the life of the account / project, then deletion or anonymization generally within 30–90 days after account closure or confirmed deletion, subject to backup cycles.
  • Billing and tax records: typically up to 7 years (or longer if required by law).
  • Security and server logs: typically 30–180 days, unless needed longer for investigations or legal holds.
  • Support communications: typically up to 2 years after the ticket is closed, unless a longer period is required.

Backup systems may retain residual copies for a limited period before automatic expiry. Legal holds override standard schedules.

10Security

We implement technical and organizational measures designed to protect personal information, including HTTPS encryption in transit, access controls, hashed passwords, and hardened cloud infrastructure. No method of transmission or storage is completely secure. If you believe your account has been compromised, contact [email protected] immediately.

11International transfers

VisibleIO is based in Hong Kong and uses cloud and service providers that may process data in the United States, the European Economic Area, the United Kingdom, Asia-Pacific, and other locations. When we transfer personal information from the EEA, UK, or other regions that restrict transfers, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and UK international data transfer addenda where applicable), adequacy decisions, or other lawful mechanisms.

You may request more information about transfer safeguards at [email protected].

12Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, export/port, restrict, or object to certain processing of your personal information, and to withdraw consent. We do not discriminate against you for exercising privacy rights.

To exercise rights, email [email protected]. We may verify your identity (and, for agents, your authorization). We generally respond within 30 days (EEA/UK) or within the timelines required by US state law (for example up to 45 days under California law, with a possible extension where permitted).

13EEA and UK additional information

If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority. You may object to processing based on legitimate interests, and to direct marketing at any time.

Where we act as processor for your published Viewer experiences, end users should contact you (the customer) first; we will assist you in meeting verified requests as required by our DPA and law.

14US state privacy rights (including California)

If you are a resident of California or another US state with a comprehensive privacy law (such as the CCPA/CPRA and similar statutes), you may have rights to know/access, delete, correct, and opt out of “sale” or “sharing” of personal information for cross-context behavioral advertising, and to limit use of sensitive personal information where applicable.

Categories of personal information we may collect are listed in “Information we collect” above (identifiers, commercial/subscription information, internet or electronic activity, approximate geolocation derived from IP, and audiovisual or project content you upload).

We do not sell personal information for money. If we engage in “sharing” for cross-context behavioral advertising or similar activities covered by state law, we will provide a “Do Not Sell or Share My Personal Information” mechanism and honor browser opt-out signals (such as GPC) where required. To submit a request or appeal a decision, email [email protected].

California residents may also request information about disclosures of personal information to third parties for direct marketing (Shine the Light) by contacting us at the same address.

15Asia-Pacific notice

If you are in Hong Kong, we process personal data in accordance with the Personal Data (Privacy) Ordinance (PDPO) and the principles described in this Policy. If you are in other Asia-Pacific jurisdictions (for example Singapore’s PDPA, Japan’s APPI, or similar regimes), mandatory local rights and rules apply in addition to this Policy. Contact [email protected] to exercise local rights.

16Children

The Services are not directed to children. We do not knowingly collect personal information from children under 13 in the United States (COPPA), under 16 in the EEA where required (or the lower age set by a Member State, not below 13), or under the minimum digital-consent age in your jurisdiction. If you believe a child has provided us personal information, contact [email protected] and we will take appropriate steps to delete it.

17Automated decision-making

We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about you (for example automated credit refusal). We may use automated systems for security, fraud prevention, rate limiting, and product analytics.

18Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version at visibleio.com/privacy and revise the effective date. For material changes, we will provide additional notice where appropriate (for example email or in-product notice). Where law requires consent to a change, we will obtain it before relying on the new practice.

19Contact

Privacy requests and questions: [email protected]. General support: [email protected]. Controller: VisibleIO Limited, Hong Kong Special Administrative Region. Website: https://visibleio.com.

Questions? Contact us at [email protected].

Official website: visibleio.com