What data the Free Beta uses.
This policy describes account, project, export, consent, notification and website-tool data in the current Metropolygonia architecture.
Version 1.0.0 · Published: 26 July 2026 · Effective: 26 July 2026
Controller and contact
Controller: KUNZ STANISLAW, trading as Metropolygonia
Registered address: Via Mario Tosa 14/1, Genova (GE), Italy
Country: Italy
VAT / P.IVA: 02894360995
Privacy contact: kunzdesign2017@gmail.com
Application: Metropolygonia, https://metropolygonia.com
Data categories
- Account and sign-in: email, user ID, display name, avatar from an optional sign-in provider, locale, account role and authentication/security data.
- Projects: project name, type, parameters, metadata, size and created/updated timestamps. Exported model and texture files are currently prepared in the browser and are not automatically stored by Metropolygonia in the cloud.
- Exports and allowances: project ID, format, status, idempotency key, licence type and version, completion/failure times, plan code, starter/monthly use and period dates.
- Legal and communication choices: accepted document type/version, time, source and locale; marketing channel, pending/confirmed/withdrawn state, consent text version; secure double opt-in token hash and expiry.
- Notifications and product use: eligible messages, read/dismissed state and the limited product events listed in the tracking inventory.
- Technical and support: IP address, browser/device and network metadata, security and error logs, plus details and contact information voluntarily sent to support.
Product analytics must not contain full email addresses, private project names, model or texture files, or authentication credentials.
Purposes and legal bases
- Account, authentication, projects, generation, export, allowances, licensing and system notifications — performance of a contract or requested pre-contract steps.
- Security, export idempotency, abuse prevention, stability, error diagnosis and legal claims — the controller's legitimate interests.
- Document-acceptance evidence and legal compliance — contract, legal obligation or legitimate interest in demonstrating compliance, depending on context.
- Email marketing, in-app promotional messages and Microsoft Clarity analytics — consent specific to that channel.
- Support responses — contract performance or legitimate interest in handling the request.
Providers and transfers
The current application uses Supabase for authentication, database and identified stored assets; Hostinger for application hosting and ordinary server logs; Google only if Google sign-in is selected; Usercentrics Cookiebot for cookie consent; and Microsoft Clarity only after Statistics consent.
Resend delivers the one-time double-opt-in confirmation email. It receives the recipient address, message content, confirmation link and technical delivery data. The address is not automatically added to Resend Contacts or a newsletter list; the current consent status remains in Supabase. We do not synchronise the complete account database with Resend.
If a provider processes data outside the European Economic Area, an applicable safeguard such as an adequacy decision or Standard Contractual Clauses must be verified before launch.
Retention
Account data and projects are kept until account deletion or service termination, subject to a limited backup cycle. Export, licence, acceptance and consent history is kept while needed to run the account, prove rights or consent, calculate allowances and defend claims, and is then deleted or anonymised.
An unconfirmed double opt-in token expires after the configured technical period and is stored only as a secure hash. Security and error logs are kept for a period proportionate to diagnosis and protection. Support records remain until the issue is resolved and for a necessary follow-up period.
Before launch: approve exact periods, the backup cycle and anonymisation deadlines in the retention register. Limited records may be kept longer where law or legal claims require.
Consent and communications
Email and in-app promotional consent are separate, optional and off by default. Selecting email creates only a pending state; email marketing can begin only after the one-time double opt-in link is clicked. Either choice can be withdrawn without losing product functions.
System messages are not marketing and may be delivered where required to operate or secure the account. Analytics consent is managed separately through Cookiebot and can be changed at any time.
Your choices and rights
Depending on applicable law, you may request access, a copy, correction, deletion, restriction or portability, and may object to processing. The account panel provides a route to download available data and begin account deletion. Privacy & Communications settings allow marketing withdrawal.
Withdrawing consent does not affect earlier lawful processing. You may complain to the data-protection authority for your residence, workplace or the location of an alleged infringement. Contact kunzdesign2017@gmail.com to exercise a right or ask a privacy question.
Security and changes
Metropolygonia uses access control, Supabase Row Level Security, restricted public keys and server-side privileged operations. No online system can guarantee complete security.
Material changes receive a new version and will be communicated in-app or by email where appropriate. If a consent-based purpose changes, fresh consent will be requested before the new processing begins.