Privacy Policy

Effective date: 19 May 2026

1. Introduction

Yontari, operated by Ilter Aksoy (“we”, “us”, “our”), operates the AI 3D model generation service at yontari.com. This Privacy Policy explains what personal data we collect, how we collect it, why we are allowed to use it, how long we keep it, and what rights you have over it under applicable data protection law.

2. Data We Collect

2.1 Account data

When you create an account, we collect your email address, display name (optional), and a hashed version of your password. Your password is hashed using a strong, industry-standard algorithm (following current OWASP guidance) before storage; the plaintext is never stored or logged.

2.2 Input images

To generate a 3D model, you upload one or more images. These images are stored in our secure cloud object storage and passed to a third-party AI processing provider that generates the 3D model. Input images are retained for up to 1 year (365 days), then permanently deleted. You can also delete them yourself at any time. If an image you upload depicts a person, you confirm that you are that person or that you have their explicit consent, as required by our Acceptable Use & Likeness Policy.

2.3 Generated outputs

The 3D model files produced by the service (GLB, OBJ, FBX, USDZ, and PBR texture maps) are stored in our secure cloud object storage. Output files are associated with your account: other users cannot reach them, and the download links we issue are short-lived and expire.A small number of authorised administrators can open stored files where it is genuinely necessary to run the service — investigating a support request you raise, a security or abuse issue, or a legal obligation — and every such access is recorded in an internal audit log. Generations are retained for up to 1 year (365 days), after which they are automatically removed from your account. So you never lose something you meant to keep, we email you once a month during the final 3 months before a model is deleted — download the files you want to keep before then. You may also delete a generation at any time; deleted generations are removed from our active storage immediately, and backup copies are cleared within 30 days.

2.4 Credit ledger

We maintain an append-only record of credit transactions (purchases, debits for generations, refunds). This record is kept for billing, dispute resolution, and auditing purposes.

2.5 Analytics

We use a privacy-preserving, cookieless web analytics service to understand aggregate traffic and performance (page views, response times). It does not set cookies, build a cross-site profile of you, or fingerprint visitors, and it collects no identifiable input data (your images or prompts), so it requires no consent.

2.5a Cookies

One cookie, for one purpose: keeping you signed in. It is strictly necessary for the site to work, so it needs no consent, and it carries nothing but your session. We set no advertising, tracking, or analytics cookies of any kind. Your choice on the notice at the bottom of the page is remembered in your browser’s local storage rather than in a cookie, so it never leaves your device.

2.6 Notification / waitlist emails

If you ask us to notify you about Yontari — for example by joining a waitlist for an upcoming feature — we collect your email address and use it solely to send that notification. It does not create an account and is never used for anything else; you may ask us to remove your address at any time by contacting us at the address in Section 8.

2.7 Messages you send us

When you contact us — through the contact form, a privacy or support request, or a problem report raised from inside your account — we store the message so we can answer it and keep a record of what was asked and what we did about it. That includes the name and email address you give us, the subject and body of the message, and, for a problem report, the generation it refers to. The contact form needs no account, so these messages are not always linked to one. Please avoid putting anything sensitive in a message that we do not need in order to help you.

3. How We Use Your Data

  • Service delivery: to process generation requests, store your models, and serve download links.
  • Billing: to track credit balances, process subscriptions through our third-party Merchant of Record (identified at checkout), and issue refunds.
  • Security and abuse prevention: to detect fraud, rate-limit requests, and enforce our Terms of Service.
  • Service improvement: aggregate, cookieless analytics help us understand how the service is used and where to invest engineering effort.
  • Legal compliance: to satisfy applicable legal obligations, including responding to privacy-rights requests and keeping tax and accounting records.

3b. How We Collect Your Data, and Why We May Use It

How we collect it. Everything above reaches us in one of three ways: you give it to us directly (your email, display name, password, uploaded images and prompts, and anything you write to us in a message); it is generated automatically as you use the service (generation records, credit ledger entries, download activity, API usage, security and rate-limit logs); or it comes from our payment provider when you buy something (confirmation that a payment succeeded, and the plan or credit pack it was for). We do not buy personal data, and we do not collect it about you from third parties for marketing.

Why we may use it. Each purpose below rests on one of these grounds:

What we doWhy we are allowed to
Create your account, run your generations, store and serve your modelsTo perform the contract you entered into when you signed up — without this we cannot provide the service you paid for
Take payment, grant credits, issue refundsTo perform that same contract, and to meet our tax and accounting obligations
Prevent fraud and abuse, rate-limit requests, keep security logsOur legitimate interest in keeping the service available and protecting you and us from misuse — balanced against your privacy, which is why these logs are minimal and short-lived
Understand aggregate traffic and performance (cookieless, non-identifying)Our legitimate interest in improving the service. Because it identifies nobody and sets no cookie, it needs no consent
Send you a notification you asked for (for example a waitlist email)Your consent, which you may withdraw at any time by contacting us
Answer a message you send us — a contact, support, feedback or privacy request, or a problem reportTo perform the contract, where you are a customer asking about the service you bought; otherwise our legitimate interest in replying to people who write to us. Where the message is a privacy-rights request, we also keep a record of it to meet our legal obligations
Keep billing records, and respond to legal or tax requirementsCompliance with our legal obligations

Where we rely on your consent, you can withdraw it at any time and we will stop that use; withdrawing it does not affect anything done beforehand. Where we rely on a legitimate interest, you can object — see Section 5.

4. Data Retention

CategoryRetention period
Account email, display name & credentialsAnonymized immediately on account deletion
Input imagesUp to 1 year (365 days), or immediately when you delete them or your account (backups cleared within 30 days)
Generated 3D modelsUp to 1 year (365 days), then automatically removed — with monthly reminder emails during the final 3 months; or deleted immediately when you delete the generation or your account (backups cleared within 30 days)
Credit ledger7 years (tax / billing compliance)
Messages you send us (contact, support, feedback, privacy requests, problem reports)Kept while we deal with the matter, and afterwards as a record of it. Not deleted automatically, and not removed when you delete your account — ask us at Section 8 and we will delete them unless we have to keep them as a billing or legal record
Notification / waitlist email addressKept until you ask us to remove it (Section 8); not deleted automatically
Download activity & API usage records14 days (rolling)
Plan / subscription history & API key recordsKept while your account exists, and retained in anonymized form afterwards alongside your account record
Server logs30 days (rolling)

When you delete your account, your account is deactivated and all sessions are revoked immediately — you (and anyone with your former credentials) cannot sign in again. As part of the same request, your account email, display name, and credentials are anonymized (your email is replaced with an unrecoverable placeholder, and your display name and password hash are erased), and your input images, generated 3D models, and output files are deleted from active object storage immediately. Any residual copies in encrypted backups are cleared within 30 days. Your generation history records are retained in anonymized form, linked to the anonymized account rather than to you, and credit ledger entries are retained for billing compliance for the period noted above. Messages you have sent us are retained too: deleting your account does not withdraw them, because they are our record of what was asked and what we answered. Ask us at Section 8 and we will delete them separately.

5. Your Rights

Under applicable data protection law you have the following rights over your personal data. We provide them to every user, wherever you are:

  • Right of access: you may download a copy of your data from the “Your data” section of your account profile page, as a JSON file. It includes your account details, generation records, credit ledger, plan history, download activity, support messages, and API key details and usage. Sign-in credentials (password-reset and email-verification tokens, and session records) are deliberately excluded on security grounds — returning them would let anyone who obtained the file take over your account. The file itself lists what was withheld and why.
  • Right to deletion: you may permanently delete your account from the “Danger Zone” section of your profile page. This immediately deactivates your account and revokes all sessions, anonymizes your account email, display name, and credentials, and deletes your input images, generations, and output files from active object storage straight away. Residual copies in encrypted backups are cleared within 30 days. Generation history records are retained in anonymized form (see Section 4).
  • Right to correction: you may update your display name and email address from the profile page at any time.
  • Right to data portability: the data export download (JSON format) is machine-readable and may be used to port your generation history to another service.
  • Right to object or restrict: you may object to, or ask us to restrict, certain processing of your personal data. Contact us at the address in Section 8.
  • Right to complain: you may lodge a complaint with the data-protection supervisory authority for your country of residence.
  • Other requests: for any rights request not covered by the profile-page tools above — for example a question about a specific processing activity — contact us at the address in Section 8 and we will respond within 30 days.

6. Third-Party Services

We use the following third-party processors to deliver the service:

  • Cloud infrastructure provider — content delivery, serverless compute, object storage, database, and privacy-preserving, cookieless analytics for the service.
  • Third-party AI processing provider — the automated provider that produces the 3D output. Input images and text prompts are transmitted to it to generate the model.
  • Payment provider (Merchant of Record) — Our third-party Merchant of Record, identified at checkout, acts as the seller of record for subscription and credit purchases. It handles payment processing and card data and manages sales tax/VAT collection; Yontari does not handle raw card data. As an independent data controller, it keeps its own transaction, invoice, and tax records under its own privacy and retention policies and applicable law. Those records are separate from your Yontari data and may be retained by it even after you delete your Yontari account.

Some of these processors operate outside your country of residence. Where personal data is transferred internationally, we rely on appropriate safeguards — such as the processor's standard contractual clauses — so your data remains protected to the standard required by applicable law.

7. Security

We implement industry-standard security measures including TLS encryption in transit, strong password hashing, signed webhook payloads, and short-lived signed URLs for file access. We do not store plaintext passwords or payment card details.

8. Contact

For privacy-related questions or data-subject rights requests, contact us at [email protected]. We aim to respond to all requests within 30 days.

You can also reach us through our contact form — no account required.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be notified via email or a prominent in-app notice. Continued use of the service after a policy change constitutes acceptance of the updated terms.

Last updated: 21 July 2026 · Terms of Service · Acceptable Use & Likeness Policy