Phone3D

Phone3D 隐私政策

生效日期:2026 年 10 月 8 日 · 运营者:Hao Zhu · 联系邮箱:support@funcd.org · English version

本政策说明 Phone3D 收集哪些信息、如何使用、会发送给哪些第三方,以及你可以如何查看、删除或提出请求。

  1. 运营者与联系方式
  2. 我们收集的信息
  3. 我们如何使用这些信息
  4. 与我们协作的第三方
  5. 照片发送给 Tripo 的前提
  6. 数据保存多久
  7. 删除账户与数据
  8. 你的选择
  9. 本政策的变更

1. 运营者与联系方式

Phone3D(包括 iOS 应用、phone3d.funcd.org 网站与网页版应用,以及 Blender 插件的设备配对功能)由 Hao Zhu 以个人身份独立运营,并对本政策所述个人信息的处理负责。本政策中的「我们」指 Hao Zhu 本人。

2. 我们收集的信息

账户与登录

照片与 3D 生成

发送给第三方 AI 服务 Tripo 的内容

Phone3D 使用第三方 AI 服务 Tripo 生成 3D 模型。当你提交生成任务时,我们的服务器会把你为该任务选择的照片和生成参数发送给 Tripo。发送给 Tripo 的照片使用统一的合成文件名,不附带你的邮箱、账户编号或其他账户信息。Tripo 按其自己的条款处理收到的内容,详见 Tripo 隐私政策。我们不对 Tripo 的内部做法(包括是否用于模型训练、保留多久)作任何保证。照片中可能包含人物或其他个人信息,请只上传你有权处理的内容。

积分与购买

设备配对(Blender 插件)

如果你在「设备」页生成配对码并在 Blender 插件中兑换,服务器会保存该设备的名称、设备令牌的散列值和最近使用时间。配对码本身以散列形式保存,5 分钟内有效,只能兑换一次;兑换请求的 IP 地址会被记录用于限制频率。你可以随时在应用中撤销已配对的设备。

服务器日志

我们的网页服务器记录访问日志,包括来源 IP 地址、请求路径、浏览器或应用标识(User-Agent)、响应状态和耗时;应用服务也会写运行日志,用于排错和安全防护。这些日志保存在按容量轮换的文件中(每个文件最大 10 MB,最多保留 5 个文件),写满后最旧的内容会被覆盖;它们不按天数保留。

运营通知

当有新用户注册、或网站上的 PayPal 购买完成付款时,系统会向运营者使用的内部通知渠道(飞书 / Feishu / Lark)发送一条通知。注册通知包含你的邮箱和账户编号;付款通知另包含金额、币种、积分数量和订单编号。这些通知只用于让运营者知悉服务的运行情况。

保存在你设备或浏览器中的数据

广告、分析与位置

Phone3D 不投放广告,不使用广告标识符,也没有用于广告投放或跨 App、网站追踪的功能。iOS App 不申请系统位置权限;但 Google 登录 SDK 的隐私清单仍列有粗略位置,以及可能用于分析的用户 ID、设备 ID、其他使用数据和「其他数据」。这些是 SDK 清单声明的用途,并非我们对某次登录实际传输的观测结果;该清单将追踪用途标记为「否」。

3. 我们如何使用这些信息

4. 与我们协作的第三方

服务用途会接触到的信息
Tripo生成 3D 模型你提交的照片和生成参数;返回生成的模型
Creem网站购买订单编号、金额、币种、不含邮箱的单笔订单标识;返回订单状态、交易编号和通知
PayPal网站购买订单编号、金额、币种;返回订单状态、交易编号和通知
Resend发送登录验证码邮件你的邮箱地址和验证码邮件内容
Google当你选择 Google 登录或绑定时验证你的 Google 账号Google 处理账号选择与身份验证;Phone3D 接收身份令牌并核验稳定账号标识符和已验证的邮箱地址。iOS GoogleSignIn SDK 的清单还声明可能处理与用户关联的姓名、电话、粗略位置、设备 ID、其他使用数据等,其中部分可用于分析;见第 2 节
Apple当你在 iOS App 中选择 Apple 登录时验证你的 Apple 账号Apple 处理身份验证;Phone3D 接收身份令牌、授权码、稳定账号标识符及 Apple 提供的邮箱地址,并向 Apple 换取刷新令牌
飞书(Feishu / Lark)运营者的内部通知渠道注册邮箱和账户编号;网站 PayPal 付款的金额、币种、积分数量和订单编号
Hetzner托管我们的服务器数据库、照片、模型和日志都保存在我们在 Hetzner 托管的服务器本地存储中;该服务器位于芬兰
Cloudflare(邮件路由)转发发到 support@funcd.org 的邮件你发给支持邮箱的邮件内容和邮件元数据(发件地址、时间等)会经由 Cloudflare 的邮件路由转发给运营者
腾讯 QQ 邮箱接收并存放支持邮件经 Cloudflare 转发后,你发给支持邮箱的邮件内容和邮件元数据由运营者使用的腾讯 QQ 邮箱接收并保存

每个第三方按其自身的条款处理信息,其处理可能按各自的政策和条款跨境进行。我们不使用 Stripe;App Store 应用内购买目前未开通。

5. 照片发送给 Tripo 的前提

6. 数据保存多久

我们的原则是:数据只为了向你提供服务、完成结算和保障安全而保存,不再需要时应当删除。具体情况如下:

7. 删除账户与数据

你可以在 Phone3D App 的「设置」中点按「删除账号」,再确认「永久删除账号和所有内容」。App 会显示 Phone3D 自有存储清理已完成或仍在处理中的结果,并提示第三方服务副本清理可能尚未完成。

在 App 内确认后,Phone3D 会处理以下账户和自有存储数据;此前制作的备份与第三方服务副本另行处理:

关于 Tripo 一侧的副本:发送给 Tripo 的照片和生成结果由 Tripo 按其条款保存。Phone3D 目前没有可以直接删除 Tripo 一侧副本的接口。这些副本的后续人工清理与 Phone3D 自有存储的清理分别处理。你可以通过支持邮箱要求我们协助向 Tripo 提出删除请求,我们会尽力协助,但不能保证 Tripo 一侧的副本已被删除。

我们会按适用的法律要求处理删除请求;对于通过支持邮箱提出的请求,我们会通过邮件告知处理进度以及保留记录的依据。删除单个模型、删除 App 或清理本地缓存,都不等同于删除账户。

8. 你的选择

9. 本政策的变更

本政策自 2026 年 10 月 8 日起生效。当我们开通新的登录或购买方式、更换第三方服务、或改变数据处理方式时,会先更新本页并修改页首的生效日期。

Phone3D Privacy Policy

Effective date: 8 October 2026 · Operator: Hao Zhu · Contact: support@funcd.org · 中文版本

This policy explains what information Phone3D collects, how it is used, which third parties receive it, and how you can review it, delete it or make a request.

  1. Who operates Phone3D and how to reach us
  2. Information we collect
  3. How we use it
  4. Third parties we work with
  5. When photos are sent to Tripo
  6. How long data is kept
  7. Deleting your account and data
  8. Your choices
  9. Changes to this policy

1. Who operates Phone3D and how to reach us

Phone3D — the iOS app, the website and web app at phone3d.funcd.org, and the device-pairing feature used by the Blender add-on — is operated by Hao Zhu personally, as an individual, who is responsible for the processing of personal information described in this policy. "We" in this policy means Hao Zhu.

2. Information we collect

Account and sign-in

Photos and 3D generation

What is sent to the third-party AI service Tripo

Phone3D generates 3D models with the third-party AI service Tripo. When you submit a generation task, our server sends the photos you selected for that task, plus the generation parameters, to Tripo. Photos are sent under a generic synthetic file name; your email address, account identifier and other account details are not attached. Tripo processes what it receives under its own terms — see Tripo's privacy policy. We make no guarantee about Tripo's internal practices, including whether content is used for model training or how long it is kept. Photos may contain people or other personal information — please upload only content you are entitled to process.

Credits and purchases

Device pairing (Blender add-on)

If you generate a pairing code on the Devices screen and redeem it in the Blender add-on, the server stores that device's name, a hash of its device token and when it was last seen. The pairing code itself is stored only as a hash, is valid for 5 minutes and can be redeemed once; the IP address of the redemption request is recorded for rate limiting. You can revoke a paired device in the app at any time.

Server logs

Our web server keeps access logs containing the client IP address, the request path, the browser or app identifier (User-Agent), the response status and timing; the application service also writes operational logs used for troubleshooting and security. These logs are kept in size-rotated files (at most 10 MB per file and at most 5 files); once full, the oldest content is overwritten. They are not retained for a fixed number of days.

Operational notifications

When a new user registers, or a PayPal purchase on the website is paid, the system sends a notification to the internal channel the operator uses (Feishu / Lark). The registration notification contains your email address and account identifier; the payment notification additionally contains the amount, currency, number of credits and order reference. These notifications exist only so that the operator is aware of activity on the service.

Data kept on your device or in your browser

Advertising, analytics and location

Phone3D does not serve ads, use advertising identifiers, or provide ad-targeting or cross-app and cross-site tracking features. The iOS App does not request system location permission. However, the Google sign-in SDK's privacy manifest still lists coarse location and user ID, device ID, other usage data and other data types that may be used for analytics. These are the SDK manifest's declared purposes, not our observation of what a particular sign-in transmitted. The SDK manifest marks tracking as false.

3. How we use it

4. Third parties we work with

ServicePurposeInformation it handles
Tripo3D model generationThe photos and generation parameters you submit; returns the generated model
CreemWebsite purchasesOrder reference, amount, currency and an opaque per-order reference with no email address; returns order status, transaction identifiers and notifications
PayPalWebsite purchasesOrder reference, amount, currency; returns order status, transaction identifiers and notifications
ResendDelivering sign-in code emailsYour email address and the content of the code email
GoogleVerifying your Google account when you choose to sign in or link itGoogle handles account selection and authentication; Phone3D receives an identity token and verifies the stable account identifier and verified email address. The iOS GoogleSignIn SDK manifest also declares possible processing of user-linked name, phone number, coarse location, device ID, other usage data and more, some for analytics; see section 2
AppleVerifying your Apple account when you choose Apple sign-in in the iOS AppApple handles authentication; Phone3D receives an identity token, authorization code, stable account identifier and any email Apple provides, and exchanges the code with Apple for a refresh token
Feishu (Lark)The operator's internal notification channelRegistration email and account identifier; amount, currency, credits and order reference of website PayPal payments
HetznerHosting our serverThe database, photos, models and logs are all stored on the local storage of our server hosted at Hetzner; the server is located in Finland
Cloudflare (email routing)Forwarding mail sent to support@funcd.orgThe content of your support emails and their metadata (sender address, time, etc.) are forwarded to the operator through Cloudflare's email routing
Tencent QQ MailReceiving and storing support emailsAfter Cloudflare forwarding, the content and metadata of your support emails are received and stored in the Tencent QQ Mail mailbox used by the operator

Each third party handles information under its own terms, and its processing may take place across borders according to its own policies and terms. We do not use Stripe; App Store in-app purchases are not currently enabled.

5. When photos are sent to Tripo

6. How long data is kept

Our principle is that data is kept only to provide the service to you, complete settlement and keep the service secure, and should be deleted when it is no longer needed. In practice:

7. Deleting your account and data

In the Phone3D App, open Settings (设置), tap Delete account (删除账号), then confirm Permanently delete account and all content (永久删除账号和所有内容). The App shows whether cleanup of Phone3D's own storage is complete or still being processed, and warns when cleanup of copies held by third-party services may still be pending.

After you confirm in the App, Phone3D processes the following account data and data in its own storage. Backups made earlier and copies held by third-party services are handled separately:

About copies held by Tripo: photos sent to Tripo and the results it generated are kept by Tripo under its own terms. Phone3D currently has no interface that can delete Tripo's copies directly. Subsequent manual cleanup of those copies is handled separately from cleanup of Phone3D's own storage. You can contact support to ask us to assist with a deletion request to Tripo; we will do our best to help, but we cannot guarantee that Tripo's copies have been deleted.

We handle deletion requests in accordance with applicable legal requirements. For requests made through the support email, we keep you informed by email of progress and of the basis for any records retained. Deleting a single model, deleting the app or clearing the local cache is not the same as deleting your account.

8. Your choices

9. Changes to this policy

This policy takes effect on 8 October 2026. When we enable a new sign-in or purchase method, change a third-party service, or change how data is processed, we will update this page first and change the effective date at the top.