Phone3D 隐私政策
本政策说明 Phone3D 收集哪些信息、如何使用、会发送给哪些第三方,以及你可以如何查看、删除或提出请求。
1. 运营者与联系方式
Phone3D(包括 iOS 应用、phone3d.funcd.org 网站与网页版应用,以及 Blender 插件的设备配对功能)由 Hao Zhu 以个人身份独立运营,并对本政策所述个人信息的处理负责。本政策中的「我们」指 Hao Zhu 本人。
- 联系邮箱:support@funcd.org。隐私问题、支持请求、账户删除和关于你数据的其他请求都通过这个邮箱提出。
- 版权:© 2026 Hao Zhu。版权持有人与运营者是同一人。
2. 我们收集的信息
账户与登录
- 邮箱验证码登录。我们记录你输入的邮箱地址。每次申请验证码时,服务器还会记录申请时间和来源 IP 地址,用于限制请求频率和防止滥用。验证码本身以不可逆的散列形式保存,只能使用一次,10 分钟后失效。
- 验证码邮件由第三方邮件发送服务 Resend 投递,发件地址为 noreply@one-shot.funcd.org。
- 通过 Google 登录。如果应用显示并且你选择这一方式,Google 会处理账号选择和身份验证,并向应用提供身份令牌。我们的服务器验证该令牌后,记录你的 Google 账号稳定标识符及已验证的邮箱地址,用于识别账号;服务器不持久保存该身份令牌,也不会获取你的 Google 密码。为限制验证尝试,服务器暂存来源 IP 的哈希及尝试时间,并清理过期记录。已使用邮箱验证码注册的账号可在登录后主动绑定 Google;仅凭邮箱相同不会自动合并账号。
- Google 登录 SDK 的隐私清单。iOS App 使用的 GoogleSignIn 9.2.0 随附清单,将姓名、邮箱、电话号码、粗略位置、用户 ID、设备 ID、其他使用数据及「其他数据」列为可能处理且与用户关联的类别。清单把用户 ID 和「其他数据」标为应用功能及分析用途,设备 ID 和其他使用数据标为分析用途,其余类别标为应用功能用途;所有类别均标为不用于追踪。这是 SDK 的声明范围,不表示每次登录都会处理每个类别,也不表示 Phone3D 服务器会收到或保存所有这些字段。我们的服务器用于 Google 身份验证的资料如上一项所述。
- 登录会话。登录成功后,服务器保存一条会话记录,包含应用提供的客户端类型或设备名称,以及创建和最近使用时间。会话最长 30 天,退出登录会立即结束。会话令牌在你的设备上保存于钥匙串,服务器只保存它的散列值。
- 通过 Apple 登录(iOS App)。如果登录页提供该选项且你选择使用,Apple 会完成身份验证,并向 App 提供身份令牌、授权码,以及你选择共享的邮箱地址(也可能是 Apple 私密转发地址;Apple 不一定每次都提供邮箱)。我们的服务器验证身份令牌,并向 Apple 交换授权码;我们保存 Apple 提供的稳定账号标识符、可用的邮箱地址和加密后的刷新令牌,用于识别账号,并在删除账号时尝试撤销 Apple 授权。我们不会收到你的 Apple ID 密码。Apple 登录创建独立的 Phone3D 账号;即使邮箱与现有邮箱验证码或 Google 账号相同,也不会自动合并模型和积分。
照片与 3D 生成
- 只有你主动拍摄、或通过系统照片选择器主动选出并提交的照片才会上传。应用不会读取你的整个相册。
- 上传的照片保存在我们自己的服务器存储中,并记录文件类型、大小、尺寸、内容散列和上传时间;服务器会为照片生成缩略图。
- 每个生成任务记录所用照片、状态、时间、冻结或扣减的积分、Tripo 返回的任务编号,以及失败时的错误信息。
- 生成得到的 3D 模型和预览图保存在你的模型库中。访问需要你的账户授权(包括你配对的设备);运营者出于支持和运营目的的访问方式见第 3 节。
发送给第三方 AI 服务 Tripo 的内容
Phone3D 使用第三方 AI 服务 Tripo 生成 3D 模型。当你提交生成任务时,我们的服务器会把你为该任务选择的照片和生成参数发送给 Tripo。发送给 Tripo 的照片使用统一的合成文件名,不附带你的邮箱、账户编号或其他账户信息。Tripo 按其自己的条款处理收到的内容,详见 Tripo 隐私政策。我们不对 Tripo 的内部做法(包括是否用于模型训练、保留多久)作任何保证。照片中可能包含人物或其他个人信息,请只上传你有权处理的内容。
积分与购买
- 积分。服务器保存你的积分余额、每一笔积分变动(购买、赠送、任务冻结与结算、退款冲正等)以及对应的任务或订单编号。
- 网站购买(Creem 或 PayPal)。积分目前只能在网站上购买,可选择 Creem 或 PayPal。我们向所选支付服务商发送订单编号、金额和币种;使用 Creem 时还会发送不含邮箱的单笔订单标识。我们接收并保存服务商返回的订单状态、交易编号和后续通知(例如退款)。你在支付服务商的结账页面填写付款信息;Phone3D 网站不提供填写卡号或银行信息的表单。
- App Store 应用内购买目前未开通。如果将来开通,本政策会先更新。
设备配对(Blender 插件)
如果你在「设备」页生成配对码并在 Blender 插件中兑换,服务器会保存该设备的名称、设备令牌的散列值和最近使用时间。配对码本身以散列形式保存,5 分钟内有效,只能兑换一次;兑换请求的 IP 地址会被记录用于限制频率。你可以随时在应用中撤销已配对的设备。
服务器日志
我们的网页服务器记录访问日志,包括来源 IP 地址、请求路径、浏览器或应用标识(User-Agent)、响应状态和耗时;应用服务也会写运行日志,用于排错和安全防护。这些日志保存在按容量轮换的文件中(每个文件最大 10 MB,最多保留 5 个文件),写满后最旧的内容会被覆盖;它们不按天数保留。
运营通知
当有新用户注册、或网站上的 PayPal 购买完成付款时,系统会向运营者使用的内部通知渠道(飞书 / Feishu / Lark)发送一条通知。注册通知包含你的邮箱和账户编号;付款通知另包含金额、币种、积分数量和订单编号。这些通知只用于让运营者知悉服务的运行情况。
保存在你设备或浏览器中的数据
- iOS 应用会在设备上缓存草稿照片、任务列表、模型、预览图和应用设置,并把登录会话保存在钥匙串中。应用内拍摄的照片不会写入系统相册,草稿是唯一的一份;退出登录会清除本设备上的缓存和草稿。
- 网页版应用会在浏览器的本地存储中保存会话、草稿和缓存。
- 相机权限只在你拍摄时申请;相册通过系统照片选择器访问,不需要整个相册的权限。两者都可以在系统设置中撤回。
- 删除 App、清理缓存或清除浏览器数据,都不会删除你在服务器上的账户和数据。
广告、分析与位置
Phone3D 不投放广告,不使用广告标识符,也没有用于广告投放或跨 App、网站追踪的功能。iOS App 不申请系统位置权限;但 Google 登录 SDK 的隐私清单仍列有粗略位置,以及可能用于分析的用户 ID、设备 ID、其他使用数据和「其他数据」。这些是 SDK 清单声明的用途,并非我们对某次登录实际传输的观测结果;该清单将追踪用途标记为「否」。
3. 我们如何使用这些信息
- 提供服务:登录与识别你的账户、接收照片、生成并保存 3D 模型、在你的设备和配对设备之间传送模型。
- 积分与结算:核验购买、发放与扣减积分、处理支付服务商通知的退款、进行对账。
- 安全与防滥用:限制验证码请求频率、防止重复领取注册赠送积分(如有)、保护账户免受未授权访问、排查故障。
- 支持与运营:处理你的支持请求。运营者可以通过内部管理控制台查看账户、任务和订单记录,用于支持、结算和处理滥用。
4. 与我们协作的第三方
| 服务 | 用途 | 会接触到的信息 |
|---|---|---|
| Tripo | 生成 3D 模型 | 你提交的照片和生成参数;返回生成的模型 |
| Creem | 网站购买 | 订单编号、金额、币种、不含邮箱的单笔订单标识;返回订单状态、交易编号和通知 |
| PayPal | 网站购买 | 订单编号、金额、币种;返回订单状态、交易编号和通知 |
| Resend | 发送登录验证码邮件 | 你的邮箱地址和验证码邮件内容 |
| 当你选择 Google 登录或绑定时验证你的 Google 账号 | Google 处理账号选择与身份验证;Phone3D 接收身份令牌并核验稳定账号标识符和已验证的邮箱地址。iOS GoogleSignIn SDK 的清单还声明可能处理与用户关联的姓名、电话、粗略位置、设备 ID、其他使用数据等,其中部分可用于分析;见第 2 节 | |
| Apple | 当你在 iOS App 中选择 Apple 登录时验证你的 Apple 账号 | Apple 处理身份验证;Phone3D 接收身份令牌、授权码、稳定账号标识符及 Apple 提供的邮箱地址,并向 Apple 换取刷新令牌 |
| 飞书(Feishu / Lark) | 运营者的内部通知渠道 | 注册邮箱和账户编号;网站 PayPal 付款的金额、币种、积分数量和订单编号 |
| Hetzner | 托管我们的服务器 | 数据库、照片、模型和日志都保存在我们在 Hetzner 托管的服务器本地存储中;该服务器位于芬兰 |
| Cloudflare(邮件路由) | 转发发到 support@funcd.org 的邮件 | 你发给支持邮箱的邮件内容和邮件元数据(发件地址、时间等)会经由 Cloudflare 的邮件路由转发给运营者 |
| 腾讯 QQ 邮箱 | 接收并存放支持邮件 | 经 Cloudflare 转发后,你发给支持邮箱的邮件内容和邮件元数据由运营者使用的腾讯 QQ 邮箱接收并保存 |
每个第三方按其自身的条款处理信息,其处理可能按各自的政策和条款跨境进行。我们不使用 Stripe;App Store 应用内购买目前未开通。
5. 照片发送给 Tripo 的前提
- 照片只会在你自己选择照片并提交生成任务之后才会发送给 Tripo。提交生成任务即表示你知悉这些照片将经由 Phone3D 发送给 Tripo 用于生成 3D 模型。
- 较新的 iOS 应用版本会在第一次上传前显示单独的确认页,列出接收方和隐私政策链接;如果你的版本有这一步,点击「取消」不会上传任何照片,也不会创建任务,已有的模型和任务不受影响。
- 无论是否显示确认页,已经发送给 Tripo 的照片都无法由 Phone3D 撤回;正在处理中的任务也无法中断。
6. 数据保存多久
我们的原则是:数据只为了向你提供服务、完成结算和保障安全而保存,不再需要时应当删除。具体情况如下:
- 照片、任务、模型和预览图为了让你的账户能查看、下载和继续使用它们而保存。目前没有自动到期删除,我们也会不定期审视是否仍有必要保存。你可以随时删除单个模型,或按第 7 节申请删除账户或指定数据。删除单个模型会移除该模型,但不一定同时删除生成它所用的源照片;如需一并删除,请在请求中说明。
- 登录验证码 10 分钟后失效,只能使用一次;申请新验证码会作废之前未使用的验证码。登录会话最长 30 天,退出登录会立即结束。
- 服务器日志按容量轮换(见第 2 节),不设固定天数。
- 备份。我们会不定期地手动备份数据库和存储,目前没有自动备份计划,也没有自动过期删除。这意味着你删除的数据可能仍以副本形式保留在此前制作的备份中,并不会立即从备份中消失。处理删除请求时,我们会评估对相关备份可行的清理范围,并向你说明;没有固定的清理期限,也没有自动清除。
- 积分和交易记录在账户删除后的处理见第 7 节。
7. 删除账户与数据
你可以在 Phone3D App 的「设置」中点按「删除账号」,再确认「永久删除账号和所有内容」。App 会显示 Phone3D 自有存储清理已完成或仍在处理中的结果,并提示第三方服务副本清理可能尚未完成。
在 App 内确认后,Phone3D 会处理以下账户和自有存储数据;此前制作的备份与第三方服务副本另行处理:
- 停用账户,并使登录会话和已配对设备失效;
- 清理你的照片、缩略图、模型、任务内容、导入记录、配对记录和会话记录,并尽可能移除或替换账户中的邮箱等身份信息。我们不保证每一项个人信息都能被完全替换;
- 评估此前制作的备份中可行的清理范围。备份可能仍保留副本,我们会向你说明能做到什么、不能做到什么;
- 审查哪些记录必须保留:为了结算、退款、防止重复处理和审计,我们会保留必要的订单、积分账本和支付服务商交易编号等记录,并以删除账户的内部编号关联;这些记录不是完全匿名的。我们会向你说明保留的范围和依据。删除账户本身不会发起退款;购买相关问题请另行联系支持;
- 若无法登录以使用 App 内删除,或需要跟进清理进度,请用你登录 Phone3D 的邮箱发邮件到 support@funcd.org,以便我们确认账户归属。
关于 Tripo 一侧的副本:发送给 Tripo 的照片和生成结果由 Tripo 按其条款保存。Phone3D 目前没有可以直接删除 Tripo 一侧副本的接口。这些副本的后续人工清理与 Phone3D 自有存储的清理分别处理。你可以通过支持邮箱要求我们协助向 Tripo 提出删除请求,我们会尽力协助,但不能保证 Tripo 一侧的副本已被删除。
我们会按适用的法律要求处理删除请求;对于通过支持邮箱提出的请求,我们会通过邮件告知处理进度以及保留记录的依据。删除单个模型、删除 App 或清理本地缓存,都不等同于删除账户。
8. 你的选择
- 不把照片发送给 Tripo:不要提交生成任务;若应用显示确认页,点击「取消」。
- 删除单个模型:在模型详情页删除。
- 撤销配对设备:「设备」页。
- 退出登录:「设置」页;会同时清除本设备上的缓存和草稿。
- 撤回相机权限:iOS 系统设置。
- 删除账户、查看或更正你的数据、其他请求:发邮件到 support@funcd.org。
9. 本政策的变更
本政策自 2026 年 10 月 8 日起生效。当我们开通新的登录或购买方式、更换第三方服务、或改变数据处理方式时,会先更新本页并修改页首的生效日期。
Phone3D Privacy Policy
This policy explains what information Phone3D collects, how it is used, which third parties receive it, and how you can review it, delete it or make a request.
- Who operates Phone3D and how to reach us
- Information we collect
- How we use it
- Third parties we work with
- When photos are sent to Tripo
- How long data is kept
- Deleting your account and data
- Your choices
- Changes to this policy
1. Who operates Phone3D and how to reach us
Phone3D — the iOS app, the website and web app at phone3d.funcd.org, and the device-pairing feature used by the Blender add-on — is operated by Hao Zhu personally, as an individual, who is responsible for the processing of personal information described in this policy. "We" in this policy means Hao Zhu.
- Contact: support@funcd.org. Use it for privacy questions, support requests, account deletion and any other request about your data.
- Copyright: © 2026 Hao Zhu. The copyright holder and the operator are the same person.
2. Information we collect
Account and sign-in
- Email-code sign-in. We record the email address you enter. Each time you request a code, the server also records the time of the request and the IP address it came from, which are used to rate-limit requests and prevent abuse. The code itself is stored only as a one-way hash, works once, and expires after 10 minutes.
- The code email is delivered by the third-party email service Resend, from the sender address noreply@one-shot.funcd.org.
- Google sign-in. When the app offers this option and you choose it, Google handles account selection and authentication and gives the app an identity token for that sign-in. Our server verifies the token and stores your stable Google account identifier and verified email address to recognise your account. The server does not persist that identity token or receive your Google password. To limit verification attempts, the server temporarily stores a hash of the source IP address and the attempt time, and clears expired records. Existing email-code accounts can explicitly link Google after signing in; matching email addresses alone do not merge accounts.
- Google sign-in SDK privacy manifest. The GoogleSignIn 9.2.0 SDK included in the iOS App declares name, email address, phone number, coarse location, user ID, device ID, other usage data and “other data types” as categories it may process, all marked as linked to the user. Its manifest marks user ID and other data types for app functionality and analytics, device ID and other usage data for analytics, and the remaining categories for app functionality. It marks none of these categories for tracking. This describes the SDK's declared scope; it does not mean every category is processed on every sign-in or that Phone3D's server receives or stores all of them. The account data our server uses for Google verification is described above.
- Sign-in sessions. After you sign in, the server keeps a session record that includes the client type or device name provided by the app and the time it was created and last used. A session lasts at most 30 days and ends immediately when you sign out. The session token is stored in the Keychain on your device; the server keeps only a hash of it.
- Sign in with Apple (iOS App). If the sign-in screen offers this option and you choose it, Apple authenticates you and gives the App an identity token, authorization code and, when shared, an email address (which may be an Apple private relay address; Apple may not provide the email on every sign-in). Our server verifies the identity token and exchanges the authorization code with Apple. We store Apple's stable account identifier, any email provided and an encrypted refresh token to recognize your account and attempt to revoke Apple authorization when you delete it. We do not receive your Apple ID password. Apple sign-in creates a separate Phone3D account; matching email addresses alone do not merge its models or credits with an existing email-code or Google account.
Photos and 3D generation
- Only photos you deliberately take in the app, or deliberately pick through the system photo picker and submit, are uploaded. The app does not read your whole photo library.
- Uploaded photos are stored on our own server storage, together with their file type, size, dimensions, a content hash and the upload time. The server generates thumbnails of them.
- Each generation task records the photos used, its status and timestamps, the credits held or charged for it, the task identifier returned by Tripo, and an error message if it failed.
- The resulting 3D models and preview images are kept in your library. Access requires authorization from your account (including the devices you have paired); the operator's access for support and operational purposes is described in section 3.
What is sent to the third-party AI service Tripo
Phone3D generates 3D models with the third-party AI service Tripo. When you submit a generation task, our server sends the photos you selected for that task, plus the generation parameters, to Tripo. Photos are sent under a generic synthetic file name; your email address, account identifier and other account details are not attached. Tripo processes what it receives under its own terms — see Tripo's privacy policy. We make no guarantee about Tripo's internal practices, including whether content is used for model training or how long it is kept. Photos may contain people or other personal information — please upload only content you are entitled to process.
Credits and purchases
- Credits. The server keeps your credit balance, every credit movement (purchases, grants, task holds and settlements, refund reversals and so on) and the task or order each movement belongs to.
- Website purchases (Creem or PayPal). Credits can currently be bought only on the website, with a choice of Creem or PayPal. We send the chosen payment provider an order reference, amount and currency; for Creem we also send an opaque per-order reference that contains no email address. We receive and retain order status, transaction identifiers and later notifications (for example refunds) from the provider. You enter payment details on the provider's checkout page; the Phone3D website has no form for entering card or bank details.
- App Store in-app purchases are not currently enabled. If they are enabled in the future, this policy will be updated first.
Device pairing (Blender add-on)
If you generate a pairing code on the Devices screen and redeem it in the Blender add-on, the server stores that device's name, a hash of its device token and when it was last seen. The pairing code itself is stored only as a hash, is valid for 5 minutes and can be redeemed once; the IP address of the redemption request is recorded for rate limiting. You can revoke a paired device in the app at any time.
Server logs
Our web server keeps access logs containing the client IP address, the request path, the browser or app identifier (User-Agent), the response status and timing; the application service also writes operational logs used for troubleshooting and security. These logs are kept in size-rotated files (at most 10 MB per file and at most 5 files); once full, the oldest content is overwritten. They are not retained for a fixed number of days.
Operational notifications
When a new user registers, or a PayPal purchase on the website is paid, the system sends a notification to the internal channel the operator uses (Feishu / Lark). The registration notification contains your email address and account identifier; the payment notification additionally contains the amount, currency, number of credits and order reference. These notifications exist only so that the operator is aware of activity on the service.
Data kept on your device or in your browser
- The iOS app caches draft photos, the task list, models, preview images and app settings on your device, and keeps your sign-in session in the Keychain. Photos taken inside the app are not written to the system photo library, so the draft is the only copy. Signing out clears the cache and drafts on that device.
- The web app keeps its session, drafts and cache in your browser's local storage.
- Camera permission is requested only when you take a photo. Existing photos are accessed through the system photo picker, which does not require access to your whole library. Both can be revoked in iOS Settings.
- Deleting the app, clearing its cache or clearing browser data does not delete your account or data on the server.
Advertising, analytics and location
Phone3D does not serve ads, use advertising identifiers, or provide ad-targeting or cross-app and cross-site tracking features. The iOS App does not request system location permission. However, the Google sign-in SDK's privacy manifest still lists coarse location and user ID, device ID, other usage data and other data types that may be used for analytics. These are the SDK manifest's declared purposes, not our observation of what a particular sign-in transmitted. The SDK manifest marks tracking as false.
3. How we use it
- Providing the service: signing you in and recognising your account, receiving your photos, generating and storing 3D models, and moving models between your devices and paired devices.
- Credits and settlement: verifying purchases, granting and charging credits, handling refunds reported by payment providers, and reconciliation.
- Security and abuse prevention: rate-limiting sign-in code requests, preventing sign-up bonus credits (where offered) from being claimed twice, protecting accounts from unauthorised access, and troubleshooting.
- Support and operations: handling your support requests. The operator can look up account, task and order records through an internal administration console for support, settlement and abuse handling.
4. Third parties we work with
| Service | Purpose | Information it handles |
|---|---|---|
| Tripo | 3D model generation | The photos and generation parameters you submit; returns the generated model |
| Creem | Website purchases | Order reference, amount, currency and an opaque per-order reference with no email address; returns order status, transaction identifiers and notifications |
| PayPal | Website purchases | Order reference, amount, currency; returns order status, transaction identifiers and notifications |
| Resend | Delivering sign-in code emails | Your email address and the content of the code email |
| Verifying your Google account when you choose to sign in or link it | Google handles account selection and authentication; Phone3D receives an identity token and verifies the stable account identifier and verified email address. The iOS GoogleSignIn SDK manifest also declares possible processing of user-linked name, phone number, coarse location, device ID, other usage data and more, some for analytics; see section 2 | |
| Apple | Verifying your Apple account when you choose Apple sign-in in the iOS App | Apple handles authentication; Phone3D receives an identity token, authorization code, stable account identifier and any email Apple provides, and exchanges the code with Apple for a refresh token |
| Feishu (Lark) | The operator's internal notification channel | Registration email and account identifier; amount, currency, credits and order reference of website PayPal payments |
| Hetzner | Hosting our server | The database, photos, models and logs are all stored on the local storage of our server hosted at Hetzner; the server is located in Finland |
| Cloudflare (email routing) | Forwarding mail sent to support@funcd.org | The content of your support emails and their metadata (sender address, time, etc.) are forwarded to the operator through Cloudflare's email routing |
| Tencent QQ Mail | Receiving and storing support emails | After Cloudflare forwarding, the content and metadata of your support emails are received and stored in the Tencent QQ Mail mailbox used by the operator |
Each third party handles information under its own terms, and its processing may take place across borders according to its own policies and terms. We do not use Stripe; App Store in-app purchases are not currently enabled.
5. When photos are sent to Tripo
- Photos are sent to Tripo only after you yourself have selected them and submitted a generation task. By submitting a task you acknowledge that those photos will be sent through Phone3D to Tripo to generate a 3D model.
- Newer versions of the iOS app show a separate confirmation before the first upload, naming the recipient and linking to the privacy policies. If your version has this step, tapping "Cancel" (取消) uploads nothing and creates no task; your existing models and tasks are unaffected.
- Whether or not a confirmation is shown, Phone3D cannot recall photos that have already been sent to Tripo, and a task that is already being processed cannot be interrupted.
6. How long data is kept
Our principle is that data is kept only to provide the service to you, complete settlement and keep the service secure, and should be deleted when it is no longer needed. In practice:
- Photos, tasks, models and previews are stored so that your account can view, download and keep using them. There is currently no automatic expiry, and we review from time to time whether they still need to be kept. You can delete individual models at any time, or request deletion of your account or of specific data under section 7. Deleting a single model removes that model but does not necessarily delete the source photos used to generate it — if you want those deleted too, say so in your request.
- Sign-in codes expire after 10 minutes and work once; requesting a new code invalidates any unused earlier code. Sessions last at most 30 days and end immediately when you sign out.
- Server logs are size-rotated (see section 2) and have no fixed day-based retention.
- Backups. We make manual backups of the database and storage from time to time. There is currently no automatic backup schedule and no automatic expiry. This means data you delete may remain as a copy in a backup made earlier and does not disappear from backups immediately. When handling a deletion request we assess what cleanup of the relevant backups is feasible and explain the scope to you; there is no fixed cleanup deadline and no automated purge.
- What happens to credits and transaction records after account deletion is described in section 7.
7. Deleting your account and data
In the Phone3D App, open Settings (设置), tap Delete account (删除账号), then confirm Permanently delete account and all content (永久删除账号和所有内容). The App shows whether cleanup of Phone3D's own storage is complete or still being processed, and warns when cleanup of copies held by third-party services may still be pending.
After you confirm in the App, Phone3D processes the following account data and data in its own storage. Backups made earlier and copies held by third-party services are handled separately:
- disable the account and invalidate sign-in sessions and paired devices;
- clean up your photos, thumbnails, models, task content, import records, pairing records and session records, and remove or replace your email address and other identity details on the account as far as possible. We do not guarantee that every item of personal information can be fully replaced;
- assess what cleanup is feasible in the backups made earlier. Backups may still hold copies, and we will tell you what can and cannot be done;
- review which records must be kept: for settlement, refunds, preventing duplicate processing and audit, we retain the necessary order, credit-ledger and payment-provider transaction records, linked to the deleted account's internal identifier; these records are not fully anonymous. We will explain to you the scope of what is retained and the basis for it. Deleting your account does not by itself initiate a refund; for purchase issues, contact support separately;
- if you cannot sign in to use in-app deletion, or need to follow up on cleanup, email support@funcd.org from the address you use to sign in to Phone3D, so that we can confirm the account is yours.
About copies held by Tripo: photos sent to Tripo and the results it generated are kept by Tripo under its own terms. Phone3D currently has no interface that can delete Tripo's copies directly. Subsequent manual cleanup of those copies is handled separately from cleanup of Phone3D's own storage. You can contact support to ask us to assist with a deletion request to Tripo; we will do our best to help, but we cannot guarantee that Tripo's copies have been deleted.
We handle deletion requests in accordance with applicable legal requirements. For requests made through the support email, we keep you informed by email of progress and of the basis for any records retained. Deleting a single model, deleting the app or clearing the local cache is not the same as deleting your account.
8. Your choices
- Don't send photos to Tripo: do not submit a generation task; if the app shows a confirmation, tap Cancel.
- Delete a single model: from the model's detail screen.
- Revoke a paired device: Devices screen (设备).
- Sign out: Settings (设置); this also clears the cache and drafts on that device.
- Revoke camera access: iOS Settings.
- Delete your account, review or correct your data, or make any other request: email support@funcd.org.
9. Changes to this policy
This policy takes effect on 8 October 2026. When we enable a new sign-in or purchase method, change a third-party service, or change how data is processed, we will update this page first and change the effective date at the top.