Privacy Policy
Effective and last updated September 30, 2026
This policy explains how VR Build Kit (“we,” “us”) handles personal information when you use the vrbuildkit.com website, the VR Build Kit app for Meta Quest, and related services (together, the “Service”).
The short version: we collect what we need to run your projects, we do not sell your personal information or use it for targeted advertising, we do not run advertising trackers, we use website analytics only if you opt in, and you can ask us to delete your data at any time.
1. Who we are and what this covers
VR Build Kit operates the Service and is responsible for the personal information described here. This policy applies to information collected through the website, the Quest app, meeting and guest features, email, and support conversations. It does not cover third-party websites or services we link to, or Meta's own handling of data on Quest devices, which is governed by Meta's privacy policy.
If you use the Service on behalf of a company, that company may have its own policies about the projects and files you upload.
2. Information we collect
Information you give us
- Account information: email address and password (stored as a secure hash by our authentication provider). You may also try some features with a temporary guest session before creating an account.
- Project content: floor plans, drawings, photos, 3D models, textures, documents, and other files you upload; project names, spaces, variations, layouts, saved scene states, and exports.
- AI conversations: prompts, messages, attachments, and references you send to the generation assistant, plus the briefs, plans, and assets it creates.
- Payment information: plan, subscription status, generation-funds balance, automatic-reload settings, invoices, and billing name and address. Card numbers are collected and stored by Stripe, not by us.
- Feedback and support: bug reports, feature requests, contact-form messages (name, email, optional company, and message), and emails you send us.
Information collected automatically
- Device and log data: IP address, browser and operating system, pages and API endpoints requested, timestamps, and error details, recorded by our hosting provider and servers.
- Headset session data: identifiers for paired headsets, QR pairing and session tokens, app version, and headset preferences.
- 3D performance diagnostics: file structure measurements such as triangle, primitive, material, texture, and node counts; model file hashes; headset model and app version; load timing, memory samples, and whether a model loaded, remained editable, or failed. We do not upload passthrough images or tracking coordinates with these diagnostics.
- Usage and cost records: generation jobs, AI provider usage and cost, storage used, and feature activity needed for billing, spending limits, abuse prevention, and troubleshooting.
- Browser storage: sign-in tokens and settings stored in cookies or local storage. See Cookies.
Information from others
- Stripe tells us whether a payment succeeded and provides invoice and subscription details.
- People you work with may share a project or meeting invitation with you, or add content to a shared session.
We do not intentionally collect sensitive personal information such as government identification numbers, precise GPS location, health information, or biometric identifiers. Please do not upload files containing that kind of information.
3. Headset, voice, and spatial data
Mixed-reality features need information about your surroundings and movements. Here is how we handle it:
- Room and scene understanding. The Quest app uses Meta's scene and spatial anchor features to place projects in your space at real-world scale. Room scans and passthrough camera images are processed by Meta's system on the device; our app does not receive or upload camera images.
- Hand and head tracking. Tracking is used on the device to let you interact with projects. During a shared meeting, your head and hand positions may be sent in real time to other participants so they can see where you are pointing. We do not store this movement data after the session.
- Shared anchors and colocated meetings. When you host or join a meeting in the same physical room, the app shares spatial anchor information through Meta's platform so headsets can align. Meeting snapshots of the project scene are stored so guests can load them.
- Voice features. When you turn on voice controls, audio from your microphone is streamed to OpenAI for real-time transcription. We do not store audio recordings. Transcript text may be saved with the project and summarized. Raw transcript text is automatically deleted after 30 days, and the summary and action items stay with the project until you delete them.
- Streaming. If you stream your headset view to a browser, live video and audio pass through LiveKit to the viewers you invite. We do not record streams.
- Model performance. When an authenticated headset opens a 3D model, the app sends technical load and memory diagnostics tied to that model's file hash and project. We use these records to warn you about models that may load slowly, lose editing features, drop frames, or exceed headset memory, and to improve those estimates over time.
4. How we use information
- Provide the Service: store projects, convert files, generate rooms, models, and materials, sync projects to your headset, and run meetings.
- Process payments, manage subscriptions and generation funds, apply spending limits, and send receipts and required billing notices.
- Send service messages such as account confirmations, password resets, security alerts, and project notifications.
- Respond to support requests and feedback, and let you know when an issue you reported is fixed.
- Troubleshoot, secure, and improve the Service, including reviewing failed or low-quality generation jobs to fix our workflows.
- Estimate whether an uploaded 3D model is suitable for the headset and refine those estimates using de-identified, aggregated device outcomes.
- Prevent fraud and abuse, enforce our Terms, and comply with legal obligations.
We do not sell personal information, share it for cross-context behavioral advertising, or use your project files to train general-purpose AI models. If we want to use personal information for a new purpose that is not compatible with these purposes, we will ask for your consent first.
Where laws such as the EU or UK GDPR apply, we rely on these legal bases: performing our contract with you; our legitimate interests in securing and improving the Service; compliance with legal obligations; and your consent, for example for optional voice features and analytics cookies, which you can withdraw at any time.
5. AI processing
Many features use AI models provided by OpenAI through its API, including the generation assistant, floor-plan interpretation, room and object generation planning, material generation, voice transcription, and transcript and feedback summaries. To provide those features, we send the relevant prompts, files, images, and audio to OpenAI.
- We configure these requests so OpenAI does not store them for later retrieval, where OpenAI supports that option.
- Under OpenAI's API terms, API data is not used to train OpenAI's models by default. OpenAI may keep request data for a limited period, generally up to 30 days, to detect abuse.
- AI output is generated automatically and can be inaccurate. It is not a decision about you that has legal or similarly significant effects.
Some generation and conversion jobs also run on computers we operate, such as 3D processing workers. Those systems only use your files to complete your jobs.
Artist Network. If you choose to request help from a human artist, we share an AI-assisted summary of your project and the files needed for the work with an artist bound by confidentiality obligations. We only do this when you ask for it.
7. Service providers
These providers process personal information for us. We may update this list as the Service changes.
| Provider | Purpose | Information involved |
|---|---|---|
| Supabase | Accounts and sign-in, database, and file storage | Account details, project data, uploaded and generated files |
| Vercel | Website hosting and server functions | IP address, request logs, data passing through our API |
| Stripe | Payments, subscriptions, invoices, and fraud prevention | Billing name, email, address, payment method (held by Stripe), purchase history |
| OpenAI | AI generation, conversation assistant, voice transcription, and summaries | Prompts, attachments, floor plans, voice audio while voice features are active, transcripts |
| LiveKit | Real-time meeting presence and headset streaming | Session identifiers, live head/hand pose, and live audio/video while a stream is active |
| Resend | Transactional email and contact-form notifications | Email address, name, and message content |
| Website analytics through Google Analytics, only if you accept analytics cookies | Pages visited (with identifiers removed from addresses), referring site, device and browser type, approximate location, and a random cookie ID | |
| Meta | Quest platform services such as app distribution, spatial anchors, and colocation | Headset and platform identifiers and shared anchor data, under Meta's own terms and privacy policy |
9. How long we keep information
| Information | How long |
|---|---|
| Account, projects, uploads, generated assets, and exports | Until you delete them or your account, then removed from active systems within 30 days and from backups on their normal cycle |
| Raw voice transcript text | Automatically deleted after 30 days; summaries stay with the project |
| Voice audio and live streams | Not stored by us |
| Headset sessions and QR pairing tokens | Until they expire or are revoked, plus a short security log period |
| 3D performance profiles and headset diagnostics | While the related project or model remains in your account; de-identified aggregate benchmarks may be kept to improve capacity estimates |
| Billing, invoices, and payment records | As long as required for tax, accounting, and legal purposes, generally up to 7 years |
| AI usage and cost records | As long as needed for billing reconciliation, disputes, and spending controls |
| Support messages and feedback | As long as needed to resolve the request and improve the Service, then deleted or de-identified |
| Server logs | According to our hosting provider's standard log retention |
| Google Analytics data (only if you opt in) | Cookies up to 2 years; event data kept 14 months |
10. Your privacy rights
Depending on where you live, you may have the right to:
- Know what personal information we have about you and get a copy in a portable format.
- Correct inaccurate information.
- Delete your personal information.
- Opt out of the sale or sharing of personal information, targeted advertising, and certain profiling. We do not do these things.
- Limit the use of sensitive personal information. We do not use it beyond what the Service requires.
- Withdraw consent you previously gave, such as for voice features.
- Appeal our decision on your request, and complain to your state attorney general or local data protection authority.
We apply these rights to all users, not only residents of states or countries that require them. To make a request, email support@vrbuildkit.com or use the contact form and choose “Privacy / data request.” We will confirm receipt, verify your identity by confirming control of your account email, and respond within 45 days (or sooner where required). An authorized agent may submit a request with proof of authorization. We will not discriminate against you for exercising your rights.
Nevada residents. We do not sell covered information as defined in Nevada Revised Statutes 603A. You may still submit a verified request directing us not to sell your covered information by emailing support@vrbuildkit.com with the subject “Nevada opt-out request.” We will respond within 60 days. You may also review and request changes to the personal information in your account by contacting us.
California residents. The rights above include those under the California Consumer Privacy Act where it applies to us. California's “Shine the Light” law lets you ask whether we disclosed personal information to third parties for their direct marketing. We do not.
To appeal a decision, reply to our response with the subject “Privacy appeal.” We will respond within the time required by applicable law.
11. Deleting your account and data
You can delete individual projects, assets, and exports from your dashboard at any time. To delete your entire account:
- Cancel any active subscription and turn off automatic reload on the Billing page.
- Email support@vrbuildkit.com from your account email with the subject “Delete my account,” or submit the contact form.
- We will confirm the request, then delete your account, projects, uploaded and generated files, transcripts, headset sessions, and meeting snapshots within 30 days.
We keep only what we must: billing and tax records, records of the request itself, and information needed to prevent fraud, resolve disputes, or comply with the law. Content already shared with others, such as an export a collaborator downloaded, cannot be recalled. Signing out of the Quest app or uninstalling it does not delete your account.
12. Security
We use encryption in transit (HTTPS), database access controls that restrict project data to authorized accounts, short-lived signed links for file access, scoped and revocable headset sessions, and limited administrative access. No system is perfectly secure. If we learn of a security incident affecting your personal information, we will notify you and regulators as required by law.
13. Children
The Service is intended for adults and is not directed to children. You must be at least 18 to create an account. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.
14. International users
We are based in Nevada, United States, and our service providers may process information in the United States and other countries. Those countries may have different data protection laws than where you live. Where required, we rely on appropriate safeguards such as standard contractual clauses offered by our providers.
15. Changes to this policy
We will update this policy when our practices change. The date at the top shows when it last changed. If we make a material change, we will notify you by email or in the Service before it takes effect.
16. Contact us
Email support@vrbuildkit.com or use our contact form.
