Privacy Policy
What we collect, why, who else touches it, and how to make us stop.
[ENTITY-NAME — set LEGAL_ENTITY_NAME] — based in British Columbia, Canada, operating as 360 Hextile.
[MAILING-ADDRESS — set BUSINESS_ADDRESS]
Privacy Officer: [PRIVACY-OFFICER — set PRIVACY_OFFICER_NAME], reachable at [PRIVACY-EMAIL — set PRIVACY_EMAIL]
Privacy Policy · Version 2.0 · Effective 2026-07-31 · version history
1. The short version
In short: your images are generated on your own GPU and never leave your machine unless you publish them to the Gallery or attach them to a feedback report. We never train anything on your work.
360 Hextile is a desktop application. Every render runs locally on your own graphics card. There is no cloud render pipeline, no image upload step, and nothing to opt out of — the images simply never go anywhere.
Two things do leave your machine, and only because you tell them to: publishing an image to the Gallery, and sending a feedback report from inside the app. Both are explicit actions you take. Everything below explains the rest — accounts, payments, licences, and the website.
2. Who is responsible for your data
In short: [ENTITY-NAME — set LEGAL_ENTITY_NAME] is the controller, and a named person is accountable for privacy.
[ENTITY-NAME — set LEGAL_ENTITY_NAME], based in British Columbia, Canada, decides what personal information is collected and why. In privacy law that makes us the controller (or, under Canadian law, the organisation accountable for it).
Privacy Officer: [PRIVACY-OFFICER — set PRIVACY_OFFICER_NAME], reachable at [PRIVACY-EMAIL — set PRIVACY_EMAIL]
Post: [ENTITY-NAME — set LEGAL_ENTITY_NAME], [MAILING-ADDRESS — set BUSINESS_ADDRESS]
3. What we collect
In short: an email address, what Stripe tells us about your card, hashed machine IDs for your licence, and — only if you switch it on — anonymous usage counts.
3.1 Your account
- Email address
- Name, if you give one — it is optional
- Your password, stored only as a bcrypt hash. We cannot read it.
3.2 Payments
Stripe processes every payment. We never see or store your full card number. What we receive back from Stripe and keep against your order is the card brand, the last four digits, and the expiry date.
3.3 Your licence
- Hashed machine identifiers — a one-way digest, not a hardware fingerprint we can reverse
- Which version of the app is running
- When each activation and deactivation happened
This is what lets a licence work on your machines and not on a stranger's.
3.4 Telemetry — off unless you turn it on
Telemetry is opt-in and off by default. If you switch it on in the app, we receive counts and totals about how you use it. The full list, with nothing left out:
- Total renders and total tiles processed
- Number of sessions and total session minutes
- Your most-used workflow, and per-workflow counts
- Your primary GPU model
- The app version you are running
- Badges you have earned
- Event-level properties in the same categories — which feature fired, when, and with what counts
Telemetry carries no image content and no prompts. We never see what you made or what you typed to make it.
3.5 Website technical data
- IP address
- Browser type and version
- Operating system
- The page that referred you
3.6 The Gallery, if you publish
- The images you publish, stored on our servers
- Image metadata: title, description, slug, tags, and collection
- Your gallery profile: username, display name, bio, links, and avatar
- Resolution variants we generate server-side (8K, 4K, 2K, thumbnails)
- SHA-256 IP hashes used to deduplicate reactions and reports. Plain IP addresses are never stored.
- View counts, which are anonymous
EXIF metadata is stripped on upload. Camera data, GPS coordinates, and software tags in a file you publish do not survive the upload.
These parts of the Gallery are public and visible to everyone:
- Your profile: username, avatar, display name, bio, links, and published images
- Published images, unless you hide them or an administrator does
- Reaction counts. Who reacted is not tracked or exposed.
- IP hashes are never exposed to other users or to third parties.
3.7 Feedback you send us
When you send feedback, we receive your message. If you tick the diagnostics box, we also receive a diagnostics bundle, which can include log excerpts and file paths from your machine. That box is off unless you tick it.
One more thing worth saying plainly: when you send feedback from inside the app, we receive your licence key along with the message, so we can match the report to the right purchase.
4. Why we are allowed to use it
In short: most of it we need to deliver what you bought. Some of it protects the service. The optional parts are consent-based, and you can withdraw consent.
- To perform our contract with you — creating your account, taking payment, issuing and validating your licence, and delivering downloads.
- Legitimate interest — preventing fraud and licence abuse, keeping the service secure, and understanding which features people actually use.
- Your consent — the newsletter, website analytics, and in-app telemetry. Each is separate, each is optional, and you can withdraw any of them at any time.
- Legal obligation — tax and accounting records, and responding to lawful demands.
5. Who else touches your data
In short: five service providers, each doing one job. We do not sell personal information — to anyone, ever.
| Provider | What they do for us | Where |
|---|---|---|
| Stripe | Payments, receipts, refunds, and disputes | US / global |
| Brevo | Transactional email and the newsletter | EU |
| DigitalOcean | Hosting, the managed PostgreSQL database, and Spaces object storage for Gallery images | US / Canada region |
| Sign-in with Google, and GA4 website analytics (only after you consent) | US | |
| Anthropic | Writes the automated first reply to a feedback submission, and powers the documentation and support assistant | US |
Each one only receives what it needs to do its job, and none of them may use it for anything else.
We do not sell personal information. We have never done it and we do not intend to.
We will disclose information if the law compels us — a court order, a valid legal demand — or where we need to in order to establish or defend a legal claim.
6. We never train on your work
In short: no model of ours is trained on your images, your prompts, or your settings. Not now, not later, not anonymised.
Every image is generated on your own GPU by models that were already trained before you downloaded them. Nothing you create is used to train, fine-tune, or evaluate any model — ours or anyone else's.
This is not a preference we could quietly change; it is how the product is built. Your images never reach us in the first place unless you publish them.
7. Your rights
In short: email us and we will send you a copy of your data, correct it, or delete it, within 30 days.
Wherever you live, you can ask us to:
- Give you a copy of the personal information we hold about you
- Correct anything that is wrong
- Delete your data
- Send you a portable copy
- Withdraw a consent you previously gave (newsletter, analytics, telemetry)
- Stop marketing emails — every one of them has an unsubscribe link
How: email [PRIVACY-EMAIL — set PRIVACY_EMAIL] and we will send you a copy of your data, or delete it, within 30 days. There is no self-serve export button today — this is a person doing it, and we would rather say so than imply a feature that does not exist.
For Gallery content specifically:
- You can delete individual images at any time from the Gallery interface or the API
- You can ask us to delete all of your Gallery data — images, profile, collections, and reactions — by emailing [PRIVACY-EMAIL — set PRIVACY_EMAIL]
- Deleting your account permanently removes all associated Gallery content
If you think we have got something wrong, you can complain to the Office of the Privacy Commissioner of Canada, or to the supervisory authority where you live if you are in the EU or the UK. We would rather you told us first, but that right is yours either way.
8. Security
In short: HTTPS everywhere, bcrypt password hashing, and as few people with access as possible.
- All traffic is encrypted in transit with HTTPS
- Passwords are stored as bcrypt hashes and are never recoverable
- Licence keys are signed with Ed25519; the signing key never leaves our server
- Access to personal data is limited to the people who need it to run the service
9. Cookies
In short: essential cookies keep you logged in. Analytics cookies are only set if you say yes, and you can change your mind.
We use essential cookies for:
- Session management — keeping you logged in
- Security — CSRF protection
We also use Google Analytics (GA4) cookies (_ga, _ga_*) to understand how visitors use the site. These are only set after you explicitly consent via the cookie banner. If you decline, or ignore the banner, no analytics cookies are set. Google may still collect anonymised, cookieless measurement signals such as aggregate page-view counts, but those cannot identify you.
You can withdraw consent at any time by clicking "Manage Cookies" in the site footer. That removes the analytics cookies and brings the banner back.
10. How long we keep things
In short: account data while your account is open, then only what tax and legal rules require.
We keep your account data for as long as your account is active. After you delete it, we retain purchase and tax records for as long as the law requires — up to seven years — and delete the rest.
For the Gallery:
- Images stay until you delete them or an administrator removes them
- Deleting an image permanently removes the original, every resolution variant, and every thumbnail from disk
- Images belonging to banned accounts are hidden from public view but not automatically deleted; administrators may delete them
- Moderation audit entries are kept indefinitely so appeals can be reviewed fairly
11. Data leaving your country
In short: we are in Canada, which the EU recognises as offering adequate protection. Some providers are in the US.
We are based in Canada, which holds an adequacy decision from the European Commission. The service providers listed in section 5 may process your data outside your own country — most commonly in the United States or the European Union. We use providers that offer appropriate contractual safeguards for those transfers.
12. Children
In short: 360 Hextile is for adults. You must be 18 or older.
Our services are not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal information, email [PRIVACY-EMAIL — set PRIVACY_EMAIL] and we will delete it.
13. Changes, and how to reach us
In short: material changes get emailed to you at least 14 days before they take effect.
We may update this policy. If a change is material, we will email account holders at least 14 days before the new version takes effect. Every version is listed on the Policy Changelog.
Privacy Officer: [PRIVACY-OFFICER — set PRIVACY_OFFICER_NAME] — [PRIVACY-EMAIL — set PRIVACY_EMAIL]
Post: [ENTITY-NAME — set LEGAL_ENTITY_NAME], [MAILING-ADDRESS — set BUSINESS_ADDRESS]