Privacy Policy
This Privacy Policy explains how AXIS ("we", "us", "our") collects, uses, and shares information about you when you use AXIS (the "Service"). We take your privacy seriously and collect only what we need to operate.
1. Information We Collect
| Category | Examples | Why |
|---|---|---|
| Account identifiers | Wallet address, email (optional), username, display name | Authentication & account management |
| Content you upload | 3D models (GLB/glTF), thumbnails, agent metadata | Service delivery, CDN delivery to viewers |
| Photos you capture or upload | One frontal photo and up to two optional side angles, if you use the selfie flow | Building your 3D avatar, and reproducing, re-rigging or re-scoring that result |
| On-chain data | ERC-8004 agent registrations, Metaplex NFT mints, USDC payment tx hashes | Identity verification, subscription status |
| Usage data | API calls, widget load events (no IPs, no fingerprints) | Quota enforcement, abuse prevention, aggregate analytics |
| Session data | Hashed session token, IP address (hashed), user agent | Authentication, security |
| Legal acceptance records | Terms of Service version accepted, Risk Disclosure version accepted, timestamp, IP address, user agent, which flow recorded it | Proof of agreement, legal compliance |
| Connected home data | The address and label of a Home Assistant instance you connect, its encrypted access token, entity and area counts, standing per-entity permissions you grant, household members and invitations, and a log of every action the agent takes in that home | Operating the AXIS Home features you enabled, and giving you an audit trail of them |
| Email (if provided) | Email address for transactional messages | Account notices, subscription receipts |
We do not collect advertising identifiers, use third-party tracking pixels, or sell personal data to any third party.
1a. Photos You Capture or Upload
If you use the selfie flow, the photos you capture (one frontal image and up to two optional side angles) are uploaded to our reconstruction service and used to build your 3D avatar. They are stored with the generation record so the result can be reproduced, re-rigged and re-scored for quality, and they are visible only to your account. They are deleted when you delete the generation or your account, subject to the retention windows in Section 5. We do not use them to train models, we do not share them with advertisers, and we do not derive or store a face template or any other biometric identifier from them. Using the selfie flow is optional: you can upload a photo from your gallery instead, or describe a character in words and never provide a photo at all.
2. How We Use Your Information
- To authenticate you and maintain your session.
- To store and serve your 3D content via our CDN.
- To send transactional emails (welcome, subscription receipts, security alerts).
- To enforce plan quotas and rate limits.
- To detect and prevent abuse, fraud, and security incidents.
- To keep records of your acceptance of our legal agreements.
- To improve the Service using aggregate, anonymized analytics.
3. On-Chain Data
Wallet addresses and on-chain registrations are public by nature of blockchain technology. We index publicly available on-chain data (ERC-8004 events, Metaplex metadata) to power the agent directory. We do not create profiles that link on-chain identity to off-chain personal information beyond what you explicitly provide. Note that anything written to a public blockchain is permanent and outside our control; we cannot delete it.
4. Sharing & Disclosure
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share information only with:
- Infrastructure providers: Google Cloud Platform (hosting and compute), Neon (database), Cloudflare (storage and CDN), Resend (transactional email), and Privy (optional sign-in). Each processes data on our behalf under its own privacy policy and data-processing terms.
- Payment facilitators: for paid features settled on-chain (x402), payment verification runs through a facilitator such as Coinbase Developer Platform or the public x402.org facilitator. They see your public wallet address and transaction signatures, never private keys.
- AI model providers: generation features forward your prompts and asset URLs to upstream model APIs (see Section 10).
- Legal obligations: if required by law, court order, or to protect the rights and safety of AXIS or others.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to affected users.
5. Data Retention
We retain your account data for as long as your account is active. Deleted accounts are soft-deleted for 30 days (for recovery), then permanently purged. Session tokens expire after 30 days. Nonces expire after 5 minutes and are purged within 24 hours.
Usage events are retained for 90 days for quota and abuse analysis, then deleted. Widget view events (no personal data) are retained for 12 months. Security audit logs are retained for 365 days.
Connected home data is kept while the home is connected and is deleted when you delete the home or your account. The home action log has its own window, 90 days by default, which you control per home and can shorten to a single day. We never store the names of your rooms or devices, their states, or any audio from voice control. The full inventory is in Home privacy and retention.
Legal acceptance records (your acceptance of the Terms of Service and Risk Disclosure) are retained for the life of your account and afterward for as long as needed to establish or defend legal claims. This retention is a legal obligation and survives an account-deletion request.
6. Your Rights
Depending on your jurisdiction you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these rights, email privacy@AXIS from the email address associated with your account, or sign a message with your wallet address confirming the request.
We will respond within 30 days (or sooner where the law requires). Requests to delete your account will remove all content stored on our servers, except records we must keep (Section 5); on-chain data cannot be deleted by us. We will never discriminate against you for exercising a privacy right.
7. GDPR (EEA & UK Users)
For users in the European Economic Area or United Kingdom, our legal bases for processing are: contract performance (account operation, content delivery), legitimate interests (security, abuse prevention, aggregate analytics), legal obligation (records of legal acceptance, lawful requests), and consent (optional email marketing, if you opt in).
You have the right to lodge a complaint with your local supervisory authority. You may also contact us first at privacy@AXIS; we would welcome the chance to resolve your concern directly.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident: the categories of personal information we collect are listed in Section 1, the purposes in Section 2, and the recipients in Section 4. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; browser opt-out signals such as Global Privacy Control are honored by default because there is no sale or sharing to stop. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
You have the rights to know, access, correct, delete, and port your personal information, and to not be discriminated against for exercising them. Exercise them via privacy@AXIS (Section 6). We verify requests using your signed-in session, your account email, or a message signed by your wallet. An authorized agent may act for you with written permission.
9. International Transfers
The Service is operated from the United States and data is processed on infrastructure located in the United States. If you use the Service from outside the U.S., your information is transferred to and processed in the U.S. Where GDPR applies, transfers to our processors rely on their standard contractual clauses or an applicable adequacy framework.
9a. Security & Breach Notification
We protect your data with industry-standard measures: TLS in transit, encrypted storage, hashed session tokens and IP addresses, scoped credentials, and audit logging. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and, where required, regulators without undue delay and within the timelines applicable law requires (for example, 72 hours to supervisory authorities under GDPR).
9b. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly. Features that move real funds additionally require users to be at least 18 (see the Terms of Service).
Cookies & Local Storage
We use the following browser storage:
- Session cookie (
__Host-session): HttpOnly, Secure, SameSite=Strict. Required for authentication. - CSRF cookies (
__Host-csrf-siwe,__Host-csrf-siws): Short-lived, for SIWE/SIWS replay protection. - localStorage (
3dagent:auth-hint): Stores a non-sensitive login hint for faster page loads. Cleared on sign-out. - localStorage (
threews:risk-ack): Remembers which Risk Disclosure version you accepted so you are not re-prompted on every action; the durable record lives server-side.
We do not use third-party advertising cookies.
10. MCP Connectors, AI Processing & Payments
AXIS exposes Model Context Protocol (MCP) connectors (e.g. /api/mcp and /api/mcp-3d) that AI clients such as Claude and ChatGPT can call on your behalf. This section explains how data flows through those connectors.
- Tool inputs we receive: the arguments you (or your AI client) send to a tool: text prompts, reference image URLs, GLB/glTF model URLs, wallet or agent addresses, token mints, and search terms. We process these to fulfill the request and log them only as needed for quota, abuse prevention, and debugging.
- Third-party AI model providers: generation and editing tools forward your prompts and asset URLs to upstream model APIs to produce results. Depending on the tool, these may include NVIDIA NIM (Microsoft TRELLIS), Meshy, Replicate, Stability, Hugging Face, OpenAI, Anthropic, Google (Vertex AI), and IBM (Granite). Each provider processes the input under its own privacy policy. Do not submit confidential or personal data in tool prompts.
- Payment data (x402): paid tools settle in USDC via the x402 payment protocol. When you pay per call we receive your public wallet address and the payment/settlement transaction signature, verified through a payment facilitator (Coinbase CDP and/or the public x402.org facilitator). We never receive, request, or store your private keys or seed phrase. The only token AXIS itself references is
$AXIS; USDC is used purely for settlement. - OAuth-scoped access: when you connect via OAuth, the connector can read and write only the AXIS account data covered by the scopes you grant (avatars, agents, memory, profile). It cannot access your AI client's chat history, memory, or local files.
- Retention of tool inputs: tool-call inputs and outputs follow the usage-data retention in Section 5 (90 days), except content you explicitly save (e.g. a saved avatar), which is retained as account content until you delete it.
10a. Free 3D Actions (ChatGPT / GPT Store)
AXIS also exposes a free, keyless REST endpoint, /api/3d/studio, used by the AXIS 3D Studio custom GPT (and any OpenAPI Action client) to turn a text prompt into a downloadable 3D model. This lane involves no account, no API key, and no payment, so none of the wallet, payment, or OAuth data described in Section 10 applies to it.
- What we receive: only the text prompt you send. We do not ask for, receive, or store any name, email, wallet address, or other personal information through this endpoint.
- How the prompt is used: the prompt is forwarded to our generation provider (NVIDIA NIM / Microsoft TRELLIS) solely to produce the model. Do not include personal or confidential information in the prompt.
- What we return: a public URL to the generated GLB model (hosted on our CDN) and a link to view it. The response contains no account identifiers or personal data. Generated model files are served from public URLs so you can download and share them; treat a model URL as public.
- Abuse prevention: requests are rate-limited by IP address, used only to prevent abuse of the free lane, and prompts are screened by an automated content-safety filter so the service stays appropriate for all ages.
10b. Connected Homes (AXIS Home)
If you connect a Home Assistant instance, the access token you provide is a credential to a physical building. We encrypt it at rest with the same primitive we use for custodial wallet keys, never display it again, and erase it the moment you disconnect the home. Actions that open a building (unlocking, opening, disarming) always require an explicit human confirmation, which cannot be produced by an AI model, until you grant a standing allowance for one specific entity.
We do not store the names of your rooms, devices or scenes, and we do not store their states. There is no record of which lights were on, or when. The room graph is read live from your own instance and held in memory only while the connection is open. Voice audio is never stored.
You can see, export and delete everything this feature holds at any time, and set your own retention window for the action log. See Home privacy and retention for the complete inventory and the API.
11. Changes to This Policy
We may update this Privacy Policy. We will notify you of material changes by email or a prominent notice on the Service. The "Effective" date and version at the top reflect the most recent revision.
12. Contact
Privacy questions: privacy@AXIS
AXIS · Terms of Service · Risk Disclosure · Home