Account data
Supabase handles email-and-password accounts. Google sign-in shares only basic identity data.
Legal / privacy
Your browser is the working room. An account is the doorway to private cloud storage. Molstudio uploads a Studio project only when you deliberately save it, and creates a public snapshot only when you deliberately share it.
Supabase handles email-and-password accounts. Google sign-in shares only basic identity data.
Studio autosave and recovery remain on your device and do not upload by themselves.
Save new project and Save current project are the explicit cloud-write actions.
A link exposes one immutable saved version until it is revoked or expires.
This policy explains how the operator of Molstudio handles personal data when you use molstudio.app, including the public website, Account, Studio, Lab and project-sharing features. Molstudio is responsible for deciding why and how the personal data described here is used.
Questions, access requests and deletion requests can be sent to [email protected].
If you create an email-and-password account, Supabase Auth receives your email address and password to authenticate you. It stores your email address, a one-way password verifier, account identifier, verification state and authentication timestamps. Molstudio’s operator does not receive or store a readable copy of your password.
If you choose Google sign-in, Molstudio requests only the OpenID Connect scopes openid, email and profile. That can provide a stable Google account identifier, email address and verification state, plus basic profile information such as name, locale or profile image when Google supplies it. Molstudio does not request access to your contacts, files, calendar or other Google services.
The site and its service providers may process limited technical information needed to deliver and protect the service, such as IP address, request time, browser or device information, authentication events, error details and security logs. If you contact us, we receive your address and the contents of your message.
Studio autosave, recovery revisions and working preferences are stored locally in browser storage. They stay on that device and do not upload a project by themselves. Clearing site data can remove them.
Only choosing Save new project or Save current project writes the complete portable project to private Supabase Storage. Project title, owner, format, content hash, size, version and timestamps are stored as database metadata.
A portable project can include structures or other source files you imported, scene and animation data, annotations, custom assets, audio, settings and provenance information. Do not save material you are not entitled to store.
Choosing Share current version creates an unlisted capability link to that exact saved version. The snapshot is immutable: later project edits do not rewrite it. Anyone who has the link can open or download it while it remains active.
Revocation stops future access through Molstudio. It cannot recall copies that recipients already downloaded, screenshots they made, or a link they forwarded before revocation.
We use personal data to create and secure accounts; keep you signed in across the Molstudio website; store, load, version and delete the cloud projects you ask us to manage; create and revoke share snapshots; deliver account and recovery messages; answer support or privacy requests; prevent abuse; diagnose failures; and meet legal obligations.
Where data-protection law requires a legal basis, these activities are necessary to provide the service you request, protect Molstudio and its users, comply with law, or act on a choice you make, such as Google sign-in or creating a share link.
Molstudio does not sell your personal data. We do not use account or project data for third-party behavioural advertising.
These providers process data only for the parts of the service they support. Their own policies also apply to their direct relationship with you.
openid, email and profile.These providers may process data in countries other than yours. Where required, transfers are protected by the provider’s contractual and legal safeguards.
Account data is kept while your account is active. Each cloud save creates an immutable, content-addressed object. The project record points to its current version, but previous immutable project versions are intentionally retained in private storage for the life of that cloud project so concurrent saves and shares cannot race with object deletion. Revoking a share blocks its link and retains revocation metadata, but does not itself erase the underlying snapshot bytes.
Deleting a cloud project triggers removal of its live project and share records and attempts to remove every object under its private project path. We remove owned cloud projects as part of an account-deletion request. If a write result is ambiguous or safe storage cleanup fails, residual private objects can remain until they can be safely removed.
Security logs, delivery records, support correspondence and provider backups can remain for a limited period after deletion where needed for security, dispute handling, recovery or legal compliance. Browser-local data is controlled by your browser and is not remotely cleared when a cloud account is deleted.
You can choose email-and-password or Google sign-in, decide if and when a Studio project is saved, export a portable copy, delete cloud projects, and revoke share links. You can disconnect Molstudio in your Google Account, but that does not by itself delete the corresponding Molstudio account or its saved projects.
Depending on where you live, you may have rights to access, correct, export or delete personal data, restrict or object to processing, or complain to a data-protection authority. Send a request to [email protected]. We may need to verify that the account is yours before acting.
If you request account deletion, export anything you want to keep first. Account deletion removes the account and owned cloud records from the live service, subject to the limited retention described above; it does not erase copies already downloaded by you or a share recipient, or browser data on devices we cannot control.
Molstudio uses access controls, private storage, owner-scoped database rules, content-integrity checks and high-entropy share tokens. No internet service can promise perfect security. Keep your credentials and share links private, and contact us if you suspect unauthorised access.
Molstudio is not directed to children who cannot lawfully consent to an online account. If you believe a child provided personal data without the permission required in their country, contact us so we can investigate and delete it where appropriate.
We may update this policy when the service, providers or law changes. The date at the top will change, and material changes will be presented through the website or account experience when appropriate.
For privacy questions or requests, email [email protected]. The Molstudio Terms explain the rules for using the service.