Privacy Policy
Version 2026-08-22 · Last updated 22 August 2026
MeshCrunch stores 3D models you upload so you can process them more than once. This page describes what is collected, why, how long it is kept, and who else sees it.
Who controls your data
The controller is Puneet Mishra, trading as MeshCrunch. MeshCrunch is a trading name; the person named above is the controller. For any question about this policy, or to exercise a right described below, email support@meshcrunch.com— that address reaches the controller directly, and we do not publish a postal address.
Your 3D models
- Models you upload are stored, so you can return and re-process them. They are not deleted after a single job. See Data Retention for how long they are kept.
- We store the file itself, its name, format, size, and geometry counts, plus the settings and results of every job run against it.
- Model data goes directly from your browser or API client to object storage, using a short-lived signed URL, and is read from there by our processing workers. It never passes through our API or our website.
- We use your models to provide the processing you asked for, and for nothing else. We do not use uploaded models to train machine-learning models. This is a term of the Terms of Service, not just a policy statement. If it ever changes it will be opt-in, and this page will say so before it happens.
- Drawn entirely by your own browser — no server renders anything and it costs no processing credits. The model itself is uploaded and stored as an asset, under the retention window for your plan or session.
Account information
- If you sign in, we store an internal account identifier, the identifier your sign-in provider gives us, your verified email address if the provider reports one, a display name if you set one, and a random seed used to generate your avatar.
- Passwords are handled entirely by our authentication provider. MeshCrunch never receives or stores one.
- If you use the service without signing in, we create an anonymous session identified by a token we sign. It holds no personal information — it exists so your uploads belong to you. Signing in later transfers them to your account.
- When you accept these policies we record which versions you accepted, when, and through which action. That record exists only to evidence the agreement.
Why we are allowed to process it
Where GDPR or UK GDPR applies: uploaded models, account details, and job records are processed to perform the contract you entered into by using the service. Operational logs, abuse prevention, and rate limiting rest on our legitimate interest in keeping a shared service available and secure. Page-view measurement rests on your consent, asked for separately and withdrawable at any time on the Cookies page. We do not process special-category data.
Technical and diagnostic data
- Our servers write structured operational logs: request and job identifiers, timings, error messages, file sizes, storage keys, and rate-limit events. They never contain model contents, credentials, access tokens, or signed download URLs.
- Those logs are collected centrally, so that one request can be followed across the services that handled it. They are deleted automatically 30 days after they are written. Both the collector and the store run on our own infrastructure: application logs are not sent to a third-party logging provider.
- Our hosting and storage providers keep their own access logs, which will include IP addresses. Those are subject to their retention policies, not ours.
- To stop one person taking an unlimited number of anonymous sessions by clearing cookies, we store a one-way scrambled fingerprint of the network an anonymous session was started from, and of the network a contact form was submitted from. We do not store the IP address itself, and the fingerprint cannot be turned back into one. It is used only to apply the limits described on this site, never to identify you, build a profile, or track you between visits.
- The public website can count page views through Vercel Web Analytics (cookieless, and not loaded at all until measurement is allowed) and Google Analytics (sets a cookie; its tag is present on every page but stores nothing until allowed). In the EEA, the UK and Switzerland measurement is off until you choose; elsewhere continuing to use the site is taken as agreement. Either way you can turn it off — see Cookies.
Billing and payment information
- Paid plans are sold and paid for through Paddle, which acts as the Merchant of Record. You enter your name, billing address, tax location, and payment details into Paddle's own checkout. MeshCrunch never receives or stores your card or bank details, and no payment credential passes through our servers.
- From Paddle we receive and store: the Paddle customer identifier, the Paddle subscription identifier, the price and product purchased, the subscription status, trial and billing period dates, any scheduled cancellation, and the billing email Paddle holds for you. That is what decides which plan your account is on.
- We store a trimmed snapshot of each billing event we receive — identifiers, status, and the price — so a billing question can be answered later. Billing addresses, tax identifiers, and partial card numbers present in Paddle's notification are discarded rather than saved.
- Your account is linked to a Paddle customer only through a checkout we started for you while you were signed in. We never match a Paddle customer to an account by email address.
- Invoices, receipts, refunds, and payment-method changes are handled by Paddle. See Refunds.
Who else processes your data
Object storage, website hosting, authentication, and payment processing are provided by third parties, listed individually with their purpose and data category on the Subprocessors page. We do not sell personal data and we do not share it for advertising.
Where data is processed
Our subprocessors are global providers, and your data may be processed outside your own country — including in the United States. MeshCrunch offers no data-residency guarantee, and none should be inferred. Where a transfer out of the UK or EEA occurs, it relies on the providers' own transfer mechanisms, which are linked from the Subprocessors page. If regional storage is a requirement for you, MeshCrunch is not currently able to meet it.
How long we keep it
- Uploaded models and everything generated from them: 24 hours for an anonymous session, 7 days on a free account, 30 days on Starter and 90 days on Pro, then deleted automatically.
- Account records: for as long as the account exists.
- Job records: deleted with the asset they belong to.
- Policy-acceptance records: retained while the account exists, because they evidence an agreement.
- Subscription records: kept after a subscription ends, including cancelled ones. They are the evidence of what you were charged and what access you had, and deleting them would leave a billing dispute unanswerable. Paddle keeps its own transaction records under its retention policy.
Your rights
Depending on where you live you may have the right to access, correct, export, delete, or restrict processing of your personal data, to object to processing based on legitimate interest, and to complain to your data protection authority. Californian residents have equivalent rights under the CCPA; we do not sell or share personal information as those terms are defined there.
You can exercise the most common ones directly: any asset can be deleted from your library at once, and that removes the source file, every output generated from it, and the job records. For anything else, email support@meshcrunch.com. We respond within 30 days.
Deleting every asset removes all uploaded content; removing the account record itself is handled by support on request.
Security
Storage is private with no public URLs, downloads are signed per request and expire in five minutes, and every request for an asset is checked against the caller's verified identity. The Security page describes the controls in detail, and equally clearly lists the ones we do not have.
Children
MeshCrunch is a professional tool and is not directed at children. You must be at least 18 years old to hold an account, matching the Terms of Service. If we learn we hold data from a child below that age we will delete it.
Changes
Each version of this policy carries a version identifier and date at the top of the page, and the version you acknowledged is recorded against your account or session. For a material change we will ask you to acknowledge the new version, and notify accounts with a verified email address at least 14 days in advance.
Questions about this page? Email support@meshcrunch.com. Security reports go to the same address.