Privacy Policy

Will It Fit

3D & AI model viewer for Android · com.gorisse.thomas.arcamera

Last updated: September 2, 2026

The short version

This Privacy Policy explains what information the Will It Fit (formerly AR Model Viewer — 3D & AI) mobile application (the "App") handles, why, and with whom. The App is published by Thomas Gorisse ("we", "our", "us"). By using the App you agree to this policy.

1. Local-first by design, with an optional account

Models you download, files you import, photos you capture, and your settings are stored locally on your device. If you uninstall the App, that local data is removed with it. You can use every feature of the App without an account.

The App also offers an optional "Sign in with Google". Its only purpose is to attach your generation credits to an account rather than to a handset, so they survive a new phone or a reinstall. Signing in is never required, we never ask you to create a password, and we never ask for your name, phone number, or postal address. What signing in stores on our side, and how to delete it, is described in section 2 — Account and sign-in and section 5 — Your choices and data deletion.

Sign-in is offered in the Android app only. The iOS app has no sign-in and no account: it creates no account, and there is therefore nothing to delete on our side for iOS users.

2. Information handled when you use the App

Account and sign-in (optional, Android)

If — and only if — you tap Sign in with Google, Google returns a signed identity token to the App, which sends it to our endpoint. We verify it and store, in our own database, the following:

We never store the Google identity token itself, your Google password, your profile picture, your contacts, or anything else Google may hold about you. This data lives in a Cloudflare D1 database operated by us on Cloudflare's infrastructure, provisioned in Cloudflare's Western Europe (WEUR) region, reachable only by our own endpoint over HTTPS. It is not sold, not shared with advertisers, and not used for advertising or profiling.

We keep it for as long as the account exists. You can delete the account from inside the App at any time — see section 5. Signing out (without deleting) simply forgets the session on that device; your credits stay on the account and come back when you sign in again.

Camera and photos

The App uses your device camera for augmented-reality placement and to let you capture photos of models in your space. AR camera frames and photos you capture are processed on your device and are not sent anywhere — unless you explicitly use the AI "image → 3D" feature (see below).

AI 3D generation (optional)

When — and only when — you choose to generate a 3D model, the App sends your input to our generation service:

The request goes over HTTPS to our processing endpoint (a Cloudflare Worker at arcamera-api.mcp-tools-lab.workers.dev), which forwards it to our third-party AI provider, Tripo3D (tripo3d.ai/privacy), to produce the 3D model. Nothing that identifies you is ever forwarded to Tripo3D — it receives only the prompt or the image needed to create the model, never your account, your email or a device identifier. Our own endpoint does not store your prompts, your photos, or the generated models; when credits are counted on our side, a generation request additionally carries your session credential and/or a random per-install identifier so the credit is debited from the right account, and what we keep of it is a ledger line (a date, a cost, the generation's reference), not your content. Tripo3D processes the input to return your model; its handling of that input is governed by Tripo3D's own privacy policy, linked above. Do not include personal or sensitive content in prompts or photos you submit for generation.

3D model catalog (Sketchfab)

Browsing and downloading catalog models sends your search terms and the public model identifier through the same HTTPS endpoint to the Sketchfab community API. No personal data is sent — this is an anonymous catalog request.

Crash reports and analytics (Firebase)

The App uses Google Firebase Crashlytics and Firebase Analytics to understand stability and general usage. These collect:

This data is collected via Google acting as our data processor and is used only to operate and improve the App. It is not sold and not used for advertising. See Firebase's privacy information.

Purchases (Google Play Billing)

Subscriptions and one-time purchases are handled entirely by Google Play's billing system (and by Apple's App Store on iOS). We never see your card or payment details. The App unlocks features by checking your purchase on your device. When credits are counted on our side, the App additionally sends the purchase token issued by the store to our endpoint, which asks Google (or Apple) to confirm it and then credits the corresponding account; we keep a record of that verified purchase — the product, the store's transaction identifier, the dates and the status — as an accounting record. Google's handling of the transaction is governed by Google's Privacy Policy.

3. Data we collect and share — at a glance

DataWhyLeaves device?Shared with
Google user IDIdentify your optional account so credits follow youOnly if you sign in— (stored by us)
Email address (from Google)Recognise the account, answer your requestsOnly if you sign in— (stored by us)
Hashed session credentialKeep you signed in securely for up to 90 daysOnly if you sign in— (stored by us)
Credit balance, credit history, verified purchasesRun the credit system, accountingOnly if credits are counted server-side— (stored by us)
Photo (for image → 3D)Generate a 3D model you asked forOnly on that actionTripo3D (AI provider)
Text prompt (for text → 3D)Generate a 3D model you asked forOnly on that actionTripo3D (AI provider)
Crash logs & diagnosticsKeep the App stableYesGoogle Firebase (processor)
Anonymous usage eventsUnderstand feature usageYesGoogle Firebase (processor)
Firebase installation IDGroup analytics/crashes per installYesGoogle Firebase (processor)
Downloaded / imported models, captures, settingsCore app featuresNo — stays on device

We do not collect location, contacts, calendar, messages, microphone/audio, health, or web-browsing data. We show no advertising.

4. Children

The App is not directed to children under 13 and does not knowingly collect personal data from them. Signing in requires an existing Google account, which Google itself gates by age. If you believe a child has signed in, email us and we will delete the account.

5. Your choices and data deletion

Deleting your account and the data attached to it

If you signed in, you can delete your account from inside the App, with no need to write to anyone:

Deleting the account is immediate and cannot be undone. It erases the personal data we hold about you: your Google user ID and your email address are deleted from our database, every session is revoked (you are signed out on every device), and the link between the account and your installs is removed.

What we keep, and why: the credit history, the credit balances and the record of verified purchases attached to that account are retained as financial and accounting records, which we are required to keep for tax and audit purposes and to handle refunds and chargebacks. Once your identity is deleted they no longer point at a person — they are kept against an anonymous account identifier that we can no longer connect back to you or to any Google account. Any credits left on the account stay with it: they are not refunded and do not return to your phone. The App tells you this before you confirm.

Deletion by request. If you cannot use the in-app path — for example you have lost access to the phone or to the Google account — email thomas.gorisse@gmail.com from the address attached to the account and we will delete it for you. We answer deletion requests within 30 days.

Your other choices

6. Changes to this policy

We may update this policy as the App evolves (for example, if the AI generation feature changes). Material changes will be reflected here with a new "Last updated" date.

Contact

Questions or requests about this policy or your data:
Email: thomas.gorisse@gmail.com