3D & AI model viewer for Android · com.gorisse.thomas.arcamera
Last updated: September 2, 2026
This Privacy Policy explains what information the Will It Fit (formerly AR Model Viewer — 3D & AI) mobile application (the "App") handles, why, and with whom. The App is published by Thomas Gorisse ("we", "our", "us"). By using the App you agree to this policy.
Models you download, files you import, photos you capture, and your settings are stored locally on your device. If you uninstall the App, that local data is removed with it. You can use every feature of the App without an account.
The App also offers an optional "Sign in with Google". Its only purpose is to attach your generation credits to an account rather than to a handset, so they survive a new phone or a reinstall. Signing in is never required, we never ask you to create a password, and we never ask for your name, phone number, or postal address. What signing in stores on our side, and how to delete it, is described in section 2 — Account and sign-in and section 5 — Your choices and data deletion.
Sign-in is offered in the Android app only. The iOS app has no sign-in and no account: it creates no account, and there is therefore nothing to delete on our side for iOS users.
If — and only if — you tap Sign in with Google, Google returns a signed identity token to the App, which sends it to our endpoint. We verify it and store, in our own database, the following:
sub identifier Google issues for
our app). This is the identity — nothing else identifies you to us.We never store the Google identity token itself, your Google password, your profile picture, your contacts, or anything else Google may hold about you. This data lives in a Cloudflare D1 database operated by us on Cloudflare's infrastructure, provisioned in Cloudflare's Western Europe (WEUR) region, reachable only by our own endpoint over HTTPS. It is not sold, not shared with advertisers, and not used for advertising or profiling.
We keep it for as long as the account exists. You can delete the account from inside the App at any time — see section 5. Signing out (without deleting) simply forgets the session on that device; your credits stay on the account and come back when you sign in again.
The App uses your device camera for augmented-reality placement and to let you capture photos of models in your space. AR camera frames and photos you capture are processed on your device and are not sent anywhere — unless you explicitly use the AI "image → 3D" feature (see below).
When — and only when — you choose to generate a 3D model, the App sends your input to our generation service:
The request goes over HTTPS to our processing endpoint (a Cloudflare Worker at
arcamera-api.mcp-tools-lab.workers.dev), which forwards it to our third-party AI
provider, Tripo3D (tripo3d.ai/privacy),
to produce the 3D model. Nothing that identifies you is ever forwarded to Tripo3D —
it receives only the prompt or the image needed to create the model, never your account, your email
or a device identifier. Our own endpoint does not store your prompts, your photos, or the
generated models; when credits are counted on our side, a generation request additionally
carries your session credential and/or a random per-install identifier so the credit is debited from
the right account, and what we keep of it is a ledger line (a date, a cost, the generation's
reference), not your content. Tripo3D processes the input to return your model; its handling of that input is governed by
Tripo3D's own privacy policy, linked above. Do not include personal or sensitive content in prompts
or photos you submit for generation.
Browsing and downloading catalog models sends your search terms and the public model identifier through the same HTTPS endpoint to the Sketchfab community API. No personal data is sent — this is an anonymous catalog request.
The App uses Google Firebase Crashlytics and Firebase Analytics to understand stability and general usage. These collect:
This data is collected via Google acting as our data processor and is used only to operate and improve the App. It is not sold and not used for advertising. See Firebase's privacy information.
Subscriptions and one-time purchases are handled entirely by Google Play's billing system (and by Apple's App Store on iOS). We never see your card or payment details. The App unlocks features by checking your purchase on your device. When credits are counted on our side, the App additionally sends the purchase token issued by the store to our endpoint, which asks Google (or Apple) to confirm it and then credits the corresponding account; we keep a record of that verified purchase — the product, the store's transaction identifier, the dates and the status — as an accounting record. Google's handling of the transaction is governed by Google's Privacy Policy.
| Data | Why | Leaves device? | Shared with |
|---|---|---|---|
| Google user ID | Identify your optional account so credits follow you | Only if you sign in | — (stored by us) |
| Email address (from Google) | Recognise the account, answer your requests | Only if you sign in | — (stored by us) |
| Hashed session credential | Keep you signed in securely for up to 90 days | Only if you sign in | — (stored by us) |
| Credit balance, credit history, verified purchases | Run the credit system, accounting | Only if credits are counted server-side | — (stored by us) |
| Photo (for image → 3D) | Generate a 3D model you asked for | Only on that action | Tripo3D (AI provider) |
| Text prompt (for text → 3D) | Generate a 3D model you asked for | Only on that action | Tripo3D (AI provider) |
| Crash logs & diagnostics | Keep the App stable | Yes | Google Firebase (processor) |
| Anonymous usage events | Understand feature usage | Yes | Google Firebase (processor) |
| Firebase installation ID | Group analytics/crashes per install | Yes | Google Firebase (processor) |
| Downloaded / imported models, captures, settings | Core app features | No — stays on device | — |
We do not collect location, contacts, calendar, messages, microphone/audio, health, or web-browsing data. We show no advertising.
The App is not directed to children under 13 and does not knowingly collect personal data from them. Signing in requires an existing Google account, which Google itself gates by age. If you believe a child has signed in, email us and we will delete the account.
If you signed in, you can delete your account from inside the App, with no need to write to anyone:
Deleting the account is immediate and cannot be undone. It erases the personal data we hold about you: your Google user ID and your email address are deleted from our database, every session is revoked (you are signed out on every device), and the link between the account and your installs is removed.
What we keep, and why: the credit history, the credit balances and the record of verified purchases attached to that account are retained as financial and accounting records, which we are required to keep for tax and audit purposes and to handle refunds and chargebacks. Once your identity is deleted they no longer point at a person — they are kept against an anonymous account identifier that we can no longer connect back to you or to any Google account. Any credits left on the account stay with it: they are not refunded and do not return to your phone. The App tells you this before you confirm.
Deletion by request. If you cannot use the in-app path — for example you have lost access to the phone or to the Google account — email thomas.gorisse@gmail.com from the address attached to the account and we will delete it for you. We answer deletion requests within 30 days.
We may update this policy as the App evolves (for example, if the AI generation feature changes). Material changes will be reflected here with a new "Last updated" date.
Questions or requests about this policy or your data:
Email: thomas.gorisse@gmail.com