Privacy policy
This policy explains what information CraftWorld processes to run the site, workspace, 3D preview, AI director, and AI video generation, why we process it, and how to contact us. Last updated: 29 September 2026.
Scope
This policy applies to CraftWorld at craftworld.app. Using the service means you have read it. If a feature page states a more specific rule, that rule applies when you use the feature. This policy does not describe a feature as available before it is.
Accounts and sessions
You can sign in with an email verification code, Google, or GitHub. We receive and store what that sign-in requires, including a verified email address, display name, and avatar address, and record the original sign-up method and latest sign-in method. Sign-in is kept with an HttpOnly cookie used only to recognize the visit and your account, not for cross-site advertising. Some features work without an account. In that case we create a session that is not tied to an email address, and projects stay mainly in your browser.
Creative content
To perform the feature you request, and to let a signed-in account save and continue a project, we process content you submit or generate. That includes scene descriptions, chat, scene data, reference images you attach, and previews or generated videos you choose to keep. That content is not placed in the product analytics described below.
On-device work and what is sent to a model
Playing a 3D preview and exporting a preview video happen on your device. Playback or export alone does not upload the preview. When you use the AI director, that request’s description and any reference image you attach are sent to the model service you select. When you generate an AI video, the prompt, preview video, and reference material you select are submitted to the selected video model as the input for that generation.
Credit records
We record the balance and use of director credits and video credits so we can provide the features, show the remaining allowance, and limit abuse. The two balances are counted separately and are not interchangeable. Self-service purchase is available. Payment happens on the checkout page. We keep the order and credit records needed to apply credits, reconcile them, and handle follow-up.
Usage analytics
Product events are collected only on the production site craftworld.app and are relayed through this site to PostHog in the United States. They cover page views, opening the workspace, starting sign-in, selecting a pricing option, submitting or finishing an AI director request, exporting a preview, and the status of AI video generation. An event may include the feature, model name, whether a reference image was attached, duration, and failure reason. It does not include prompts, scene documents, reference images, video content, or email addresses. After sign-in, analytics uses an internal account identifier and the current plan, not your email. Session recording, automatic click capture, and performance capture are off. Events carry a CraftWorld product tag, and the analytics project may still hold older data. A browser Do Not Track or Global Privacy Control signal turns this product-event collection off. Site traffic may also be measured with Cloudflare Web Analytics.
Signed-in account acquisition and network observations
To understand how people find CraftWorld and protect the service, on signed-in visits we store the first and latest source, first referring site domain, first landing path, first UTM parameters, and the IP address, country/region/city, network number and organization provided by Cloudflare, plus browser identifier, latest path, and observation count. We do not store full referring URLs or their query strings. The admin view shows only IP observations from the past 90 days; older records are cleared on subsequent writes. Only restricted administrators can view these account records. They are not sent to PostHog. DNT/GPC disables the product events described above, not these account-access and security records.
Data stored in the browser
Language, theme, and some workspace preferences are stored locally in the browser. Projects that have not been synced are stored in the browser’s local database. Clearing this site’s data removes those local copies. It does not by itself delete projects already synced to an account.
Purposes and recipients
We process the information above to operate the service, keep you signed in, run the model generation you request, record credits, protect the service, and see whether features are used. Information required for a given action is provided to the sign-in service you choose, the model service for that request, the hosting and analytics services, and to a recipient when the law requires it. We do not sell personal information.
Retention, access, and deletion
Account and project data are kept for as long as needed to provide the service, retain credit records, and protect the service. You can delete your own projects in the workspace. There is no self-serve control to close an account. To delete an account, correct account details, or make an access request available under applicable law, email contact@craftworld.app. We handle those requests as that law requires.
Security and location of processing
We protect the service with access controls and encrypted transport. Sign-in, model, hosting, and analytics providers may process data outside your country or region, and only for the purposes in this policy. We cannot guarantee that transmission or storage will never be accessed without authorization.
Changes to this policy
We may update this policy and publish the current version on this page. The date above is the latest update. Continuing to use the service after an update means later use follows the new version. Where the law requires a separate notice, we give that notice.
Contact
For this policy or your personal information, contact contact@craftworld.app.