Privacy

theprototype cloud — how your data is used.

theprototype is a peer-to-peer collaborative 3D app. The engine is open source and serverless: your scene and everything you do in a session travel directly between connected peers, not through our servers. The optional cloud tier below adds only account identity and room discovery.

Account (when you sign in)

Signing in uses GitHub or Google OAuth via our authentication backend (PocketBase). We store your email, display name and avatar URL from the provider to identify you across sessions. You can delete your account at any time by contacting us; that removes this record.

Feature-update emails (opt-in)

If — and only if — you tick "Email me about new features" in your profile, we store that preference and a consent timestamp on your account and may email you occasional product updates. Unticking it withdraws consent and stops the emails. We never sell or share your email.

Rooms

If you choose to list a room publicly, its name, description, host id and current peer count are stored so others can browse and join. Unlisting or ending the session removes it. Rooms you don't list are never recorded.

Peer-to-peer connections and your IP address

Because sessions are direct browser-to-browser (WebRTC), the peers you connect with can see each other's IP addresses — that is how the technology establishes a direct link, and it applies to any WebRTC app (RFC 8828). Only peers you approve into your session can see yours. If a direct connection cannot be made, traffic is relayed through our TURN server, which forwards encrypted media and data without storing it. Treat joining a session with strangers the way you would any direct connection.

What we do not collect

No cookies at all, no analytics or tracking scripts, no scene contents, no chat/voice on our servers (those are peer-to-peer). The app stores your settings and local library in your own browser (localStorage and IndexedDB); that never leaves your device unless you export it. Network diagnostics (latency, relay usage) stay in your browser. If you configure an AI provider, your prompts go directly from your browser to the endpoint you chose — never through us.

Privacy questions and account-deletion requests: [email protected] — or open an issue at github.com/theprototype-app. See also Terms · Content policy.