Private login
Your login email is separate from an optional public handle and stock avatar.
Your browser is the working room. An account enables deliberate cloud saves and account services; it does not upload an open project by itself. Profiles, gallery submissions, forum posts, AI jobs and private rooms begin only when you choose the corresponding action.
Your login email is separate from an optional public handle and stock avatar.
Studio and Lab upload only through Save new project or Save current project.
Shares, profiles, gallery submissions and forum posts each require an explicit action.
Receipts, AI jobs and private rooms store only the records described below.
This policy explains how the operator of Molstudio handles personal data when you use molstudio.app, including the public website, Account, Studio, Lab, Projects, profiles, community gallery, forum, export receipt registry, AI jobs and private collaboration rooms. Molstudio is responsible for deciding why and how the personal data described here is used.
Questions, access requests and deletion requests can be sent to [email protected].
If you create an email-and-password account, Supabase Auth receives your email address and password to authenticate you. It stores your email address, a one-way password verifier, account identifier, verification state and authentication timestamps. Molstudio’s operator does not receive or store a readable copy of your password.
If you choose Google sign-in, Molstudio requests only the OpenID Connect scopes openid, email and profile. That can provide a stable Google account identifier, email address and verification state, plus basic profile information such as name, locale or profile image when Google supplies it. Molstudio does not request access to your contacts, files, calendar or other Google services.
The site and its service providers may process limited technical information needed to deliver and protect the service, such as IP address, request time, browser or device information, authentication events, error details and security logs. If you contact us, we receive your address and the contents of your message.
Every account receives a private profile record. If you edit it, Molstudio stores the handle, display name, biography, selected bundled avatar and visibility choice. A public profile exposes those fields but not your login email or private account identifier. Gallery submissions store the submitted immutable share, title, description, status and moderation record. Forum topics, posts, reactions and reports store their content, author profile, timestamps and moderation status.
A saved AI run stores your prompt, bounded sanitized scene snapshot, mode, status, validated returned plan and any review feedback. It cannot call a model while every browser is closed. Accepted or edited results create an account-private plan-memory record; rejected results do not. An export receipt stores a SHA-256 digest and limited file metadata described below, not the file. A private room stores its title, mode, member roles and bounded sequential checkpoints; Realtime presence and presenter events are processed while members are connected.
Studio autosave, recovery revisions and working preferences, together with Lab’s local project store, are stored locally in browser storage. They stay on that device and do not upload a project by themselves. Clearing site data can remove them.
Only choosing Save new project or Save current project writes a complete portable Studio project to private Storage. Project title, owner, format, content hash, size, version and timestamps are stored as database metadata. Superseded immutable objects remain private and enter delayed cleanup when no current head, share or gallery record still references them.
The same two manual actions write a verified Lab package manifest and any content-addressed blobs that the account does not already store. Metadata records the project head, immutable revision chain, blob links, hashes, sizes and timestamps. Lab does not automatically upload local history or save while you work.
A portable project can include structures or other source files you imported, scene and animation data, annotations, custom assets, audio, settings and provenance information. Do not save material you are not entitled to store.
Choosing Share current version creates an unlisted capability link to that exact saved version. The snapshot is immutable: later project edits do not rewrite it. Anyone who has the link can open or download it while it remains active.
After a supported file downloads, the browser may calculate its SHA-256 locally. If you are signed in, it attempts to register that digest, media type, byte size, optional dimensions or duration, application version and server time. The registry does not receive the render, project bytes, local filename, email or public profile. Public verification reveals the first matching receipt metadata, not the account that registered it.
Revocation stops future access through Molstudio. It cannot recall copies that recipients already downloaded, screenshots they made, or a link they forwarded before revocation.
A receipt is not an authorship certificate. A match means a Molstudio account registered the exact digest at the shown server time. It does not prove authorship, ownership, originality, scientific validity or chain of custody. A missing result does not prove Molstudio was never used.
We use personal data to create and secure accounts; keep you signed in across the Molstudio website; store, load, version and delete the cloud projects you ask us to manage; create and revoke share snapshots; register and verify exact-file receipts; operate profiles, moderated gallery submissions and forums; queue and review AI plans; operate invitation-only rooms; deliver account and recovery messages; answer support or privacy requests; prevent abuse; diagnose failures; and meet legal obligations.
Where data-protection law requires a legal basis, these activities are necessary to provide the service you request, protect Molstudio and its users, comply with law, or act on a choice you make, such as Google sign-in or creating a share link.
Molstudio does not sell your personal data. We do not use account, project, community or AI-job data for third-party behavioural advertising.
Technical limits protect the shared service. Current new-account defaults are 100 combined Studio and Lab projects, 1 GiB of counted cloud Storage, 100 Lab revisions per project, 100 new receipt registrations per UTC day and 20 new AI jobs per UTC day. Limits may be adjusted per account. Usage records contain counters and total bytes needed to enforce them.
These providers process data only for the parts of the service they support. Their own policies also apply to their direct relationship with you.
openid, email and profile.If you run an account-backed AI request, Supabase stores the prompt and sanitized scene snapshot you explicitly saved, then returns those records and up to three of your most recent accepted examples to your signed-in Studio tab. Direct sends that material from the browser to the endpoint you configured; Copy / paste lets you send it to a destination you choose. The Molstudio operator does not configure a model or embedding service for these runs. Your model endpoint, model name and browser token are not sent to Supabase, although any destination you choose receives the request material and applies its own terms and privacy policy.
These providers may process data in countries other than yours. Where required, transfers are protected by the provider’s contractual and legal safeguards.
Browser-local recovery and the local receipt ledger remain until browser storage is cleared, the relevant local record is removed or storage eviction occurs. The receipt ledger keeps at most 250 entries. Removing or clearing that ledger does not delete a server receipt.
Studio retains the current immutable head and any object still referenced by an active share or a submitted or published gallery snapshot. A superseded head with no remaining reference enters durable delayed cleanup even while the cloud project continues, so ordinary manual saves do not accumulate invisible versions forever. Revoking a raw share link blocks future access through that capability but does not itself erase bytes referenced elsewhere. A snapshot frozen into gallery moderation or publication is retained independently of the live project and continues counting toward Storage quota until that community record is withdrawn or otherwise removed. Lab retains immutable manifest revisions and referenced blobs until deletion, subject to the account’s revision limit; identical Lab blobs remain while any revision still references them.
Deleting a Studio project revokes its raw share capabilities and removes the live project metadata. Every object no longer referenced by a frozen gallery record enters durable delayed cleanup. Deleting a Lab project creates an owner-visible deleting record and queues its manifests; metadata is finalized after safe cleanup, and a deduplicated blob is queued only after a fresh check shows no live revision reference. Cleanup waits for outstanding signed-upload capabilities plus clock skew—normally no more than 2 hours 5 minutes from the latest reservation—then uses retry backoff, so inaccessible bytes and counted usage can remain longer without being exposed or treated as a successful immediate erasure.
Server receipt rows, AI jobs and their review/memory records remain while the account remains active unless the service provides a more specific deletion control. Profiles and community records remain until edited, withdrawn, soft-deleted or moderated. When an account is deleted, its public profile and author link are removed; forum topic titles and post text can remain anonymously so one deletion does not destroy discussions and replies written by other members. Public or recipient copies already made are outside Molstudio’s control. Closing a room stops new live updates but does not automatically purge its membership and checkpoint history.
Confirmed account deletion requires a fresh password or Google sign-in and a session-bound, one-use challenge that expires after five minutes. It then removes the Auth account and account-linked live access first. Private Studio and Lab Storage paths are entered into a durable cleanup queue and remain inaccessible while outstanding signed-upload capabilities expire and reference checks are repeated. Cleanup normally becomes eligible no later than 2 hours 5 minutes after the latest reservation and is retried after transient failures; the deletion response discloses that queued work rather than claiming immediate byte erasure.
Security logs, delivery records, moderation records where lawful, support correspondence and provider backups can remain for a limited period after deletion where needed for security, dispute handling, recovery or legal compliance. Browser-local data is controlled by your browser and is not remotely cleared when a cloud account is deleted.
You can choose email-and-password or Google sign-in; decide if and when a Studio or Lab project is saved; export portable project copies; open, rename or delete cloud projects; revoke share links; keep your profile private; withdraw a gallery submission; edit or soft-delete eligible forum content; leave a room; and clear the local receipt ledger. You can disconnect Molstudio in your Google Account, but that does not by itself delete the corresponding Molstudio account or its saved records.
Account provides self-service Export my account data and confirmed account deletion. The browser follows signed, account-bound pages until the service confirms the database record set is complete, then downloads one JSON document containing identity metadata, profile, quotas and usage, project metadata, server receipts, community records, AI jobs and room memberships. It deliberately excludes authentication credentials and Studio/Lab project file bytes; export those portable project files separately before deletion.
Depending on where you live, you may have rights to access, correct, export or delete personal data, restrict or object to processing, or complain to a data-protection authority. Send a request to [email protected]. We may need to verify that the account is yours before acting.
If you delete the account, export anything you want to keep first. Successful account deletion removes the account and account-linked live access, queues inaccessible private files for the delayed cleanup described above, and can retain forum text anonymously; it does not erase copies already downloaded by you or a share recipient, public caches, or browser data on devices we cannot control.
Molstudio uses access controls, private storage, owner-scoped database rules, content-integrity checks, high-entropy share and room-invitation tokens, private Realtime topics and staff authorization stored separately from public profiles. No internet service can promise perfect security. Keep credentials, share links and room invitations private, and contact us if you suspect unauthorised access.
Live rooms transmit only allowlisted presence and presenter state—such as playhead, playback, selection and document revision—and bounded checkpoints. They are not a confidential file-transfer system and do not synchronize project, structure, audio or credential bytes.
Molstudio is not directed to children who cannot lawfully consent to an online account. If you believe a child provided personal data without the permission required in their country, contact us so we can investigate and delete it where appropriate.
We may update this policy when the service, providers or law changes. The date at the top will change, and material changes will be presented through the website or account experience when appropriate.
For privacy questions or requests, email [email protected]. The Molstudio Terms explain the rules for using the service.