alphaAlpha releaseLan3D is in active development. The editor will keep changing and improving — features will move around, though your sites stay safe. Every plan, free and paid, can be started today.
Legal

Privacy Policy

Version 1.0 · Effective Sep 16, 2026

This policy explains what personal data we collect when you use Lan3D, why, on what legal basis, who we share it with, how long we keep it, and what rights you have. It is written to meet the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the Law on Legal Protection of Personal Data of the Republic of Lithuania.

1. Who is responsible for your data

1.1 The controller of the personal data described in this policy is Codesis, MB, a small partnership (mažoji bendrija) incorporated in the Republic of Lithuania, company code 305522610, VAT number LT100013080113, registered office at Biržiškų g. 1E-42, LT-51436 Kaunas, Lithuania ("Codesis", "we", "us").

1.2 We have not appointed a data protection officer, because the law does not require us to. For anything about your personal data, write to hello@lan3d.com or to the registered office above.

1.3 This policy covers the Lan3D website (lan3d.com), the Lan3D editor (app.lan3d.com), the guest editor, any other application we make available under the Lan3D name, and the emails we send in connection with them (together, the "Service").

2. When you are the controller, not us

Lan3D lets you upload photographs, plans and files, and lets you invite other people to models and projects. Where that content contains personal data about other people — a site photograph that shows a neighbour or a car, a task that names a contractor, an email address you invite — you decide why that data is there and you are its controller. We process it on your behalf, as your processor, only to provide the Service to you and as described in section 5, and we act on your instructions (which you give by using the Service). You are responsible for having a lawful basis for that data and for telling the people concerned what you need to. If you need a separate data-processing agreement, ask us.

3. What we collect, why, and on what basis

The table below lists each category of personal data we process, where it comes from, why we process it, and the legal basis under Article 6(1) GDPR.

3.1 Your account

WhatDetails
DataEmail address; display name; profile picture (if you sign in with Google); the identifier Firebase Authentication assigns to your account; whether you signed in with a password or with Google; the language you chose.
SourceYou, or Google when you sign in with a Google account.
WhyTo create and secure your account, sign you in, address you by name, show you your own content, and let other people you share with see who you are.
BasisPerformance of the contract with you (Art. 6(1)(b)).

We never see or store your password: Firebase Authentication (a Google service) holds it in hashed form. Your Google credentials are never shared with us.

3.2 Your acceptance of the Terms and this policy

WhatDetails
DataThe version of the Terms of Service and of this policy you accepted, the date and time, the IP address and browser (user-agent string) the acceptance came from.
SourceGenerated when you tick the acceptance boxes.
WhyTo be able to prove that, and when, you agreed to the contract between us.
BasisOur legitimate interest in being able to evidence the contract (Art. 6(1)(f)), and the contract itself (Art. 6(1)(b)).

3.3 Approval and administration of your account

WhatDetails
DataWhether your account has been approved; whether it has been suspended, when, and an internal note on why; the plan on your account and its status; what you have created (counts of models and projects, and their names).
SourceGenerated by the Service and by our administrators.
WhyThe Service is invitation-only while in alpha; we decide who is let in and we may suspend accounts that break the Terms.
BasisPerformance of the contract (Art. 6(1)(b)) and our legitimate interest in running a safe, fair service (Art. 6(1)(f)).

3.4 Your content

WhatDetails
DataEverything you create or upload: site plans, terrain models and their saved versions, reference photographs, site photographs, textures, custom objects, notes, projects, tasks, comments and the photos attached to them, and the renders and objects the AI features generate for you. The content may itself contain personal data (see section 2). Each item records which account created it and when.
SourceYou.
WhyTo store your work, show it back to you, sync it between your devices, share it with the people you invite, and generate renders and objects from it.
BasisPerformance of the contract (Art. 6(1)(b)).

3.5 Sharing and invitations

WhatDetails
DataThe email addresses of the people you invite to a model, workspace or project; who invited whom, when, and with what role. When a person you invited creates an account, the invitation is linked to it.
SourceYou (the inviter).
WhyTo give the invited person access and to tell them who shared with them.
BasisPerformance of the contract with the inviter (Art. 6(1)(b)); for the invited person before they have an account, our legitimate interest in delivering the invitation (Art. 6(1)(f)).

3.6 Guest sketches

WhatDetails
DataA sketch drawn in the guest editor without an account, and a random token stored in your browser that lets you reopen it. No name or email is attached unless you later create an account and claim it.
SourceYou.
WhyTo let you try the editor and keep what you drew for 30 days after your last edit, so you can claim it if you sign up.
BasisOur legitimate interest in letting you try the product before registering (Art. 6(1)(f)).

3.7 AI features

WhatDetails
DataThe inputs you give an AI feature — a prompt, a photograph, a plan, a selection — and the output it produces.
SourceYou.
WhyTo generate the render, object or text you asked for. The inputs are sent to the third-party AI provider that powers the feature (section 5).
BasisPerformance of the contract (Art. 6(1)(b)).

3.8 Billing

WhatDetails
DataYour Stripe customer identifier, your subscription and its status, plan, billing interval, renewal date and any discount code you used; and, on Stripe's side, your name, billing address, payment method and payment history. We do not receive or store your full card number.
SourceYou, and Stripe.
WhyTo charge you for a paid plan, manage renewals and cancellations, and comply with accounting and tax law.
BasisPerformance of the contract (Art. 6(1)(b)); compliance with our legal obligations under Lithuanian accounting and tax law (Art. 6(1)(c)).

3.9 Emails we send you

WhatDetails
DataYour email address, the messages we send (welcome, approval, invitations, notifications about work on your projects, billing and service notices), and whether they were delivered.
SourceGenerated by the Service.
WhyTo run your account and tell you things you need to know about it.
BasisPerformance of the contract (Art. 6(1)(b)). We do not currently send marketing emails; if we start, we will ask for your consent first (Art. 6(1)(a)) and every such email will have an unsubscribe link.

3.10 Push notifications

WhatDetails
DataIf you turn notifications on: a device token issued by Firebase Cloud Messaging, the device's language, and when it was last seen.
SourceYour browser, when you switch notifications on.
WhyTo notify you about work on your projects on the device you chose.
BasisYour consent (Art. 6(1)(a)), given when you enable notifications and withdrawn by switching them off.

3.11 Product analytics and session recording

WhatDetails
DataPage views and the route you were on; clicks, taps and form submissions (the element's text and position, never what you typed); "stuck" signals such as rage-clicks, dead clicks, uncaught errors and page-performance timings; referrer and campaign parameters; device, browser and operating system; your IP address and the approximate location (country and city) derived from it; a pseudonymous visitor identifier held in a cookie; and — when you are signed in — your account identifier, email address and display name, so a session can be tied to an account. We also record session replays: a reconstruction of what was on your screen as you used the Service, with everything you type masked and with the option of masking any other element. Replays are used to see how people use the editor and where they get stuck.
SourceYour browser, through PostHog.
WhyTo understand which parts of the Service are used, where people struggle, and what to fix.
BasisYour consent (Art. 6(1)(a) GDPR and Article 96 of the Law on Electronic Communications of the Republic of Lithuania), given through the cookie banner described in section 7. Nothing in this row is collected, and no analytics cookie is set, until you have accepted; you can withdraw your consent at any time, with effect for the future, as section 7 explains. Withdrawing it does not affect your use of the Service.

3.12 Improving the Service and the models behind it

WhatDetails
DataYour content (section 3.5) and data derived from it — the shapes, altitudes and structures of a plan, the corrections you make to an AI-generated result, the inputs and outputs of the AI features — together with the usage data in section 3.11. Wherever practicable we first remove what identifies you (your account identifier, name, email address and the metadata of uploaded files) and work with the de-identified content. Content that contains personal data about other people (section 2) is used for this purpose only after it has been de-identified.
SourceYour use of the Service.
WhyTo develop, test and improve the Service and the automated and machine-learning features behind it — for example, to make terrain generation, plan recognition or the AI features produce better results.
BasisOur legitimate interest in improving a product in active development (Art. 6(1)(f)), balanced by de-identification, by the fact that the data is used for the Service you are already using and not for advertising or for sale, and by your right to object at any time (section 10). This purpose is told to you here, at the time the data is collected, as Article 13 GDPR requires; we will not use the data for a purpose incompatible with this one without telling you first.

3.13 Technical logs and security

WhatDetails
DataThe IP address, request path, timestamp, response code and user-agent string of requests to our servers; error reports; and the account the request was made from.
SourceYour browser, automatically.
WhyTo keep the Service running, diagnose faults, detect and prevent abuse and attacks, and investigate incidents.
BasisOur legitimate interest in the security and reliability of the Service (Art. 6(1)(f)).

3.14 Support and correspondence

WhatDetails
DataWhat you write to us, your email address, and our replies.
SourceYou.
WhyTo answer you, and to keep a record of what was said.
BasisPerformance of the contract, or steps before entering into one (Art. 6(1)(b)); our legitimate interest in keeping records of complaints and disputes (Art. 6(1)(f)).

We do not process special categories of personal data (health, biometric, political, religious and similar) and ask you not to put such data into the Service. We do not make decisions about you by automated means that have legal or similarly significant effects.

4. What we do not do

  • We do not sell personal data.
  • We contract with our AI providers on terms under which they do not train their general models on your inputs.
  • We do not use analytics data for advertising, and we do not run advertising on the Service.
  • We do not send marketing email without asking you first.

5. Who we share personal data with

We share personal data only with the service providers below, who process it on our behalf under written contracts that meet Article 28 GDPR (or, where the provider acts as an independent controller, under their own published terms), and with authorities where we are legally required to.

ProviderWhat they do for usData involvedWhere
Google Cloud (Google Ireland Ltd / Google LLC) — Cloud Run, Cloud Storage, Cloud Logging, Secret ManagerRuns our servers, stores tutorial media and rendered images, keeps server logsAll data our servers handleServers in Frankfurt, Germany (europe-west3); logs and some services may be processed in other Google regions
Firebase (Google) — Authentication, Hosting, Cloud MessagingSigns you in and holds your credentials; serves the web apps; delivers push notificationsEmail, name, picture, password hash, sign-in events, push tokensFirebase Authentication is a global service and stores data in the United States
MongoDB, Inc. — MongoDB AtlasHosts our databaseAccount data, content, consent records, subscription recordsEuropean Union
PostHog, Inc. — PostHog Cloud EUProduct analytics and session replay (section 3.11)Usage data, session replays, account identifier, email and nameEuropean Union (eu.posthog.com)
Stripe (Stripe Payments Europe Ltd / Stripe, Inc.)Payment processing, invoices, subscription billingBilling data (section 3.8)European Union and United States
Postmark (ActiveCampaign, LLC)Sends the emails the Service generatesEmail address, message content, delivery statusUnited States
Google — Gemini APIAI generation (renders, objects, assistants)The inputs you give an AI featureUnited States / global
OpenAI, LLCAI generationThe inputs you give an AI featureUnited States
Anthropic, PBCAI generationThe inputs you give an AI featureUnited States

Which AI provider powers a given feature is our operational choice and can change; the list above is kept current here. We may also disclose personal data to a buyer or successor in a merger, acquisition or sale of assets, on notice to you and subject to this policy; and to courts, regulators or law enforcement where the law requires it or where necessary to establish, exercise or defend legal claims.

6. Transfers outside the European Economic Area

Several of the providers above process data in the United States. Where personal data leaves the EEA we rely on: (a) the European Commission's adequacy decision for the EU–US Data Privacy Framework, for providers certified under it (Google, Stripe, ActiveCampaign, OpenAI and Anthropic are, at the date of this policy); and (b) the European Commission's Standard Contractual Clauses incorporated into our contracts with those providers, together with supplementary measures where needed. You can ask us for a copy of the relevant clauses at the address in section 1.

7. Cookies and similar technologies

We keep client-side storage to a minimum. What the Service sets:

NameSet byPurposeTypeLifetime
Firebase Authentication session (IndexedDB / local storage)Lan3D applicationsKeeps you signed inStrictly necessaryUntil you sign out
lan3d.locale (local storage)all Lan3D sitesRemembers the language you choseFunctionalUntil cleared
Guest sketch token (local storage)lan3d.com, app.lan3d.comLets you reopen a sketch drawn without an accountFunctional30 days after the last edit
lan3d.analytics.config (local storage)all Lan3D sitesCaches whether analytics is switched on by us, so the page does not have to wait to find outFunctionalUntil cleared
lan3d.cookie_consent (cookie, shared across lan3d.com and app.lan3d.com)lan3d.com, app.lan3d.comRemembers your answer to the cookie banner — accepted or rejected — and when you gave it, so you are not asked on every pageStrictly necessary6 months
ph_* (cookie, shared across lan3d.com and app.lan3d.com) and PostHog session storagePostHogPseudonymous visitor identifier, session identifier, and the queue of events and replay data awaiting uploadAnalytics — only with your consentCookie: 1 year; session storage: until the tab closes

Strictly necessary and functional items are needed to provide what you asked for (staying signed in, keeping your language, reopening your sketch, remembering your cookie choice) and do not need your consent (Article 96(3) of the Law on Electronic Communications). They contain no analytics and are not shared with anyone.

The analytics cookie needs your consent. When you first visit lan3d.com or app.lan3d.com you are shown a banner with two equal choices, Accept analytics and Reject. Until you choose, nothing in section 3.11 is collected and no PostHog cookie is set. If you reject, nothing is collected and the banner does not appear again for six months. If you accept, your choice is recorded in lan3d.cookie_consent and PostHog is loaded. Your choice applies to both lan3d.com and app.lan3d.com, including the editor embedded on the lan3d.com home page.

How to withdraw consent. Choose Cookie settings — in the footer of lan3d.com, in your profile menu in the editor, or at the foot of the editor's sign-in page — and press Reject. From that moment nothing further is collected, PostHog's cookie and local data are deleted from your browser, and any replay in progress stops. Withdrawing consent does not affect the lawfulness of what was collected before, and does not affect your use of the Service. You can also block or delete cookies for lan3d.com in your browser's settings. Deleting your account does not delete analytics data that is not tied to your account; to have data tied to your account removed from PostHog, ask us (section 10).

8. How long we keep data

DataRetention
Account and content (sections 3.1, 3.3–3.5, 3.7, 3.10)For as long as your account exists. When you delete your account, or we delete it, your account record, your workspaces and everything in them, your invitations, your push tokens and your notifications are deleted immediately. Copies may survive in our operational backups until those expire on their ordinary cycle, and content you shared with another account's workspace stays in that workspace, because it belongs to it.
Content above a free plan's limits after a paid plan endsAt least 12 months, then deleted after 30 days' notice (Terms, clause 10.4).
Accounts with no sign-inDeleted after 24 months without a sign-in, on 30 days' notice (Terms, clause 10.4).
Guest sketches (section 3.6)30 days after the last edit, then deleted automatically.
Consent records (section 3.2)For as long as your account exists, and for 10 years afterwards — the general limitation period under the Civil Code of the Republic of Lithuania within which a dispute about the contract could be raised. Kept separately from the deleted account, with the minimum needed to identify it.
Billing records (section 3.8)10 years from the end of the financial year in which the transaction took place, as Lithuanian accounting law requires.
Emails we sent (section 3.9)12 months.
Analytics events (section 3.11)Up to 12 months from collection.
De-identified content and derived data used to improve the Service (section 3.12)Kept for as long as it is useful, including after your account is deleted, because it no longer identifies you. Data that still identifies you is deleted with your account.
Session replays (section 3.11)Up to 90 days from collection.
Server logs (section 3.13)30 days.
Support correspondence (section 3.14)3 years after the last message, or longer while a dispute is open.

Where we keep data beyond the closure of your account because the law requires it or because a claim could be raised, we restrict its use to that purpose.

9. How we protect data

Data is transmitted over TLS and stored encrypted at rest by the providers in section 5. Access to production systems is restricted to the people who need it, uses individual accounts with two-factor authentication, and is logged. Credentials the Service uses (payment and AI keys) are held encrypted with a key kept outside the database. Passwords are never held by us. We keep the amount of data we collect to what each purpose needs. No system is perfectly secure, and if a breach affects your personal data in a way that is likely to put your rights at risk we will tell you and the supervisory authority as the GDPR requires.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and to receive a copy of it;
  • rectify data that is inaccurate or incomplete — your name and picture follow your Google profile or can be changed in the editor;
  • erase your data ("right to be forgotten") — you can delete your account yourself from within the Service, which deletes everything in section 8's first row immediately, or ask us to;
  • restrict processing in the circumstances Article 18 GDPR describes;
  • data portability — to receive the data you gave us in a structured, commonly used, machine-readable format; the editor's export functions cover your models, and we will provide the rest on request;
  • object to processing based on our legitimate interests — including the use of your content and usage data to improve the Service and the models behind it (section 3.12) — on grounds relating to your situation; we will stop unless we have compelling legitimate grounds that override yours;
  • withdraw consent at any time where we rely on it — the analytics cookie (through Cookie settings, section 7), push notifications, any future marketing — without affecting the lawfulness of what was done before;
  • lodge a complaint with a supervisory authority. Ours is the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, ada@ada.lt, vdai.lrv.lt). You may also complain to the authority of the EU country where you live or work.

To exercise a right, write to hello@lan3d.com from the email address on your account, or to the registered office. We answer within one month; where a request is complex we may take up to two further months and will tell you why. We may ask you to confirm your identity first. Exercising these rights is free unless a request is manifestly unfounded or excessive.

Deleting your account is irreversible. It does not remove content you created inside a workspace, model or project that another account owns — that content belongs to the owner — and it does not remove the records in section 8 that we are required to keep.

11. Children

The Service is for adults. We do not knowingly collect personal data from anyone under 18, and we close accounts we find to belong to minors. If you believe a child has given us personal data, tell us and we will delete it.

12. Changes to this policy

We will update this policy when what we do changes — a new provider, a new feature that collects something new. The version number and effective date at the top of the page say which version you are reading. For material changes we will tell you by email or in the product before they take effect, and the Service will ask you to accept the new version before you continue. If you do not wish to accept it, you may delete your account instead.

13. Contact

Codesis, MB Biržiškų g. 1E-42, LT-51436 Kaunas, Lithuania Company code 305522610 · VAT LT100013080113 hello@lan3d.com