Privacy Policy
This Privacy Policy explains how personal data is processed when you visit the Metropolygonia website, use the browser application, create an account, save projects, export assets, submit product feedback, contact support, choose marketing communications, consent to analytics or allow advertising measurement.
1. Controller
The controller is KUNZ STANISLAW, trading as Metropolygonia, P.IVA 02894360995, registered at Via Camillo Benso Conte di Cavour 42/1, Bogliasco (GE), Italy.
Privacy contact: kunzdesign2017@gmail.com
Application and website: https://metropolygonia.com
2. Scope and principles
Metropolygonia processes personal data only for specified purposes and seeks to limit processing to data that is adequate, relevant and necessary. Data is not sold.
The service is not designed to receive special-category data, government identifiers, financial data, medical information or confidential third-party information. Do not place such information in project names, feedback or support messages, or user-supplied files.
3. Data collected
3.1 Website and technical data
When you visit the website or application, hosting and security systems may receive IP address, date and time, requested URL, response status, referrer, browser and device information, network metadata, security events and error data.
3.2 Account and authentication data
Account data may include email address, internal user ID, display name, avatar, locale, account role, sign-in provider, authentication events, session data and security metadata.
If you choose Google sign-in, Google authenticates you under Google's own terms. Metropolygonia receives the basic account data included in the authorised sign-in scope, such as a Google subject identifier, email address, name and avatar where available.
3.3 Project data
Cloud project records may include project name, project type, procedural parameters, seed, metadata, size, ownership, created and updated timestamps, and the saved-building or city information needed to restore the project.
Some drafts, material preferences and language choices may remain only in your browser through local storage or session storage.
Exported model and texture files are currently prepared in the browser and are not automatically stored by Metropolygonia in the cloud unless a feature expressly states otherwise.
3.4 Export, allowance and licence data
Export records may include user ID, project ID, export format, status, reservation or idempotency identifier, completion or failure time, plan code, starter and monthly allowance use, allowance-period dates, licence type, licence version and acceptance evidence.
3.5 Legal acceptance data
Metropolygonia may record the accepted document type and version, acceptance time, language, source and, where relevant, the export to which the acceptance applies.
3.6 Communication and consent data
Marketing records may include the selected channel, the version of the consent wording, pending, confirmed or withdrawn status, source, timestamps and a securely hashed double-opt-in token with its expiry.
Notification records may include whether an eligible system or promotional message was shown, read or dismissed.
3.7 Support data
When you contact support, Metropolygonia processes the information you provide, your contact details and the technical or account context reasonably needed to answer the request.
3.8 Product feedback
When you voluntarily use the feedback panel, Metropolygonia stores the selected category, your free-text message, a rating from 1 to 5 only for General feedback, interface language, whether the panel was opened on the public site or in the application, submission time and administrative review status.
The application does not attach an account ID, email address, project ID, page URL, model file, export file or device identifier to a feedback record. Hosting and Supabase infrastructure may nevertheless process ordinary IP, network and security-log data when the request is delivered. Free text may identify you if you include identifying details, so do not include personal, confidential or third-party information.
3.9 Consent-based analytics and advertising measurement
After Statistics consent, Microsoft Clarity may process page and interaction events, technical device and browser information, approximate location derived from IP address, heatmap data and session-playback data. Authentication credentials, full email addresses, private project names, model files and texture files must not be intentionally sent to Clarity.
After Marketing consent, Reddit Pixel may process a PageVisit event, current page URL and referrer, event time, IP and network information, browser, device and screen information, Reddit click or campaign identifiers when present, and a pixel/browser identifier. The base integration does not intentionally send account email addresses, credentials, private project names, project geometry, model files, texture files or form contents to Reddit.
4. Purposes and legal bases
Metropolygonia processes data for the following purposes:
- Public website delivery, account creation, authentication, cloud projects, generation, exports, allowances, licence administration and necessary system messages: performance of a contract or steps requested before entering a contract.
- Website and application security, export idempotency, abuse and fraud prevention, service stability, error diagnosis and defence of legal claims: legitimate interests in operating and protecting the service and its users.
- Keeping evidence of Terms, licence and consent choices: performance of a contract, compliance with legal obligations, or legitimate interests in demonstrating compliance and protecting rights, depending on the record.
- Responding to support and privacy requests: performance of a contract, compliance with legal obligations or legitimate interests in handling the request.
- Reviewing voluntary product feedback, diagnosing reported errors and prioritising improvements: legitimate interests in understanding and improving the service. Submission is optional and the database record is not linked to an account.
- Email product news and marketing: consent for that channel, activated only after double opt-in.
- In-app promotional messages: separate consent for that channel.
- Microsoft Clarity analytics and related non-essential storage: Statistics consent managed through the consent banner.
- Reddit Pixel advertising measurement, attribution and campaign optimisation: Marketing consent managed through the consent banner.
- Necessary cookies and browser storage: providing a service requested by the user, maintaining authentication and security, and the controller's legitimate interests where applicable; terminal access is limited to what is necessary for the requested service.
You may withdraw a consent at any time. Withdrawal does not affect processing that was lawful before withdrawal and does not remove access to core product functions.
5. Whether data is required
An account requires the authentication data needed to identify and secure it. Cloud save requires project data. A new export requires the account, allowance, licence and acceptance data needed to perform and document the export.
Product feedback, marketing communications, Statistics analytics and Reddit Pixel advertising measurement are optional. Refusing them does not prevent use of generation, editing, account, cloud-project or Free Beta export functions.
6. Recipients and service providers
Personal data may be disclosed only as needed to the following categories of recipients:
- Supabase: authentication, database, identified stored assets and related platform services. For customer data, Supabase acts under its data-processing terms.
- Hostinger: website and application hosting, infrastructure and ordinary server logging.
- Resend: transactional and double-opt-in email delivery. Resend receives the recipient address, message content, confirmation link and delivery metadata required to send the message. Metropolygonia does not automatically synchronise the full account database to a Resend marketing audience.
- Usercentrics Cookiebot: consent-banner operation, storage of the consent decision and the current cookie declaration.
- Microsoft Clarity: consent-based analytics, heatmaps and session playback. Microsoft describes Clarity as processing analytics data under Microsoft's terms and privacy statement.
- Reddit: consent-based advertising measurement, attribution and campaign optimisation through Reddit Pixel. Reddit may receive the pixel event and related technical, browser and campaign-identification data under the applicable Reddit Business Tool Terms and Reddit privacy information.
- Google: authentication only when you choose Google sign-in. Google processes the sign-in interaction under Google's own terms and privacy notice; Metropolygonia controls the basic account data received into its account system.
- Professional advisers, authorities and courts: where disclosure is necessary to comply with law, establish or defend claims, or protect the service and users.
Processors are instructed to process personal data for the agreed service and are subject to applicable contractual and confidentiality obligations.
7. International transfers
Some providers or their subprocessors may process personal data outside the European Economic Area.
Where a transfer requires a safeguard, Metropolygonia relies on the mechanism applicable to the relevant recipient and processing, such as an adequacy decision, participation in the EU–US Data Privacy Framework by an eligible certified recipient, or the European Commission's Standard Contractual Clauses together with supplementary measures where required.
Information about the safeguard applicable to a particular provider and a copy or description of the relevant protection may be requested at kunzdesign2017@gmail.com. Provider privacy notices and data-processing terms may contain additional information about locations and subprocessors.
8. Retention
Personal data is retained according to the following periods or criteria:
- Account and cloud-project data: until account deletion or service termination, unless a limited record must be retained for another purpose described below.
- Browser-only data: until you clear it, the application replaces it, or the applicable session ends.
- Export, allowance, licence and legal-acceptance evidence: while needed to operate the account and licence, calculate allowances, demonstrate the rights attached to an export, resolve disputes and establish or defend legal claims; after that, it is deleted or anonymised.
- Marketing consent: while active. After withdrawal, a limited suppression and evidence record may be retained for as long as necessary to honour the withdrawal and demonstrate compliance.
- Unconfirmed double-opt-in data: until the confirmation link expires, after which the pending record and token are deleted or anonymised according to the configured process.
- Security, access and error logs: for the shortest rolling period reasonably required for diagnosis, protection and incident investigation. Records linked to an incident or legal claim may be retained until the incident and related claims are resolved.
- Support records: until the request is resolved and for the period reasonably required for follow-up, complaint handling and legal claims.
- Product feedback: while the submission is actively reviewed and for the period reasonably required to prioritise, implement and verify an improvement, normally no longer than 12 months. Irrelevant content and content accidentally containing unnecessary personal data should be removed sooner.
- Provider backups: until overwritten or removed in the normal backup rotation applicable to the selected service plan.
- Microsoft Clarity: ordinary playback data is retained by Clarity for 30 days; labelled or favourited sessions, heatmaps and certain aggregated interaction data may be retained for up to 9 months under Clarity's current documentation.
- Reddit Pixel: pixel events and identifiers are retained according to Reddit's applicable terms, settings and retention practices. The current Cookiebot declaration lists the detected browser-storage duration; withdrawal stops new Metropolygonia pixel events and disables Reddit first-party cookies where technically supported.
- Cookiebot consent record: until it is replaced, withdrawn or renewed according to the configured consent-renewal period and any compliance-evidence retention required by the controller.
A record may be retained longer where law requires it, where it is necessary for a legal claim, or where deletion is temporarily restricted by an incident-preservation obligation.
9. Cookies and browser storage
Necessary browser technologies support authentication, security, language preferences and local project functions. Microsoft Clarity and related non-essential storage activate only after Statistics consent. Reddit Pixel activates only after Marketing consent.
Details, current storage names and consent controls are described in the Cookie and Browser Storage Policy.
10. Marketing and product communications
Email marketing and in-app promotional messages use separate, optional controls that are off by default.
The Marketing browser category used for Reddit Pixel is a separate choice and does not subscribe you to email or in-app promotional messages.
Selecting email marketing creates a pending record. Marketing may start only after you confirm the one-time double-opt-in link. Each marketing email must provide an easy way to unsubscribe.
Necessary transactional, security, legal and account-operation messages are not marketing and may be sent where needed to operate the service or comply with law.
11. Automated decisions
Metropolygonia does not currently use personal data to make solely automated decisions that produce legal effects or similarly significant effects for users.
Automated technical controls may reserve or consume an export allowance, detect repeated requests, protect authentication or block clearly abusive traffic. You may contact support if you believe such a control produced an error.
12. Children
Account, cloud-save and export functions are intended only for users aged 16 or older. Metropolygonia does not knowingly offer those functions to children under 16.
If the controller learns that an under-16 user created an account, the account and related data will be reviewed and deleted or otherwise handled as required by law. A parent or guardian may contact kunzdesign2017@gmail.com.
13. Your rights
Subject to the conditions in applicable law, you may request:
- access to your personal data and information about its processing;
- correction of inaccurate data;
- deletion of data;
- restriction of processing;
- a portable copy of data you provided where the legal requirements are met;
- objection to processing based on legitimate interests;
- withdrawal of consent; and
- information about an applicable international-transfer safeguard.
You may use available account settings to download project or account data, withdraw communication choices and start account deletion. You may also send a request to kunzdesign2017@gmail.com. Identity verification may be required before fulfilling a request.
You have the right to lodge a complaint with the Garante per la protezione dei dati personali or another competent supervisory authority in the European Union, particularly in the country of your habitual residence, workplace or the alleged infringement.
14. Security
Metropolygonia uses measures appropriate to the current service, including authenticated sessions, access controls, database row-level permissions, restricted public credentials, server-side privileged operations and transport encryption where supported by the relevant services.
No online service can guarantee absolute security. You should protect your device and credentials and promptly report suspected account compromise.
15. Changes to this Policy
A material change receives a new version number, publication date and effective date. Signed-in users will be informed in-app or by email where appropriate.
If a new purpose requires consent, processing for that purpose will not begin until the required consent has been obtained.
16. Contact
Privacy questions and rights requests: kunzdesign2017@gmail.com.
Via Camillo Benso Conte di Cavour 42/1, Bogliasco (GE), Italy · kunzdesign2017@gmail.com