Legal
Privacy Policy
X3JS is operated by Miramtech, a company based in Türkiye. This policy explains, in line with Türkiye's Personal Data Protection Law (KVKK) and the GDPR, what personal data we process when you use X3JS, why, and the rights you have. Miramtech is the data controller.
Last updated September 26, 2026
Who We Are
X3JS ("X3JS", "we", "us" or "our") is an online platform for creating, publishing, playing and sharing interactive 3D creations, games and experiences. It is operated by Miramtech, established in Türkiye, which is the data controller (veri sorumlusu) responsible for your personal data.
This policy applies to the X3JS website, editor and related services (the "Service"). It is written to meet Türkiye's Personal Data Protection Law No. 6698 ("KVKK") and, for users in the European Economic Area and the UK, the General Data Protection Regulation ("GDPR"). If you do not agree with it, please do not use the Service. You can reach us about privacy at contact@miramtech.com.
Personal Data We Process
We process the following categories of personal data:
- Account data — your email address, username and a securely hashed password.
- Profile data — optional details you add, such as display name, avatar, bio, links, company and country.
- Content you create — your creations, projects, kits, posts and comments, and the 3D models, textures, animations and other assets you upload, with related metadata such as titles, descriptions and tags.
- Social data — who you follow and who follows you, and interactions such as likes and shares.
- Messages — direct messages you exchange with other users, and messages you send us for support.
- Connection data — if you connect a third-party AI assistant (see "AI Features and Your Data"), we store, in hashed form, the access token needed to maintain that connection.
- Usage and device data — how you interact with the Service, your IP address and approximate location derived from it, browser type, device, operating system and timestamps.
- Cookies and local storage — see "Cookies and Local Storage" below.
Why We Process It and Our Legal Grounds
We process your data to provide and secure the Service, relying on the following legal grounds under KVKK Article 5 and GDPR Article 6:
- Performance of a contract — to create and operate your account, host your content and deliver the features you use.
- Legitimate interests — to keep the Service secure, prevent fraud and abuse, understand how it is used and improve it, where your fundamental rights do not override those interests.
- Legal obligation — to comply with applicable law and respond to lawful requests.
- Explicit consent — where required, for example for certain cross-border transfers or optional features; you may withdraw consent at any time.
In practice we use your data to authenticate you, personalise your feed and recommendations, enable social features such as following and messaging, communicate with you about your account and security, and detect and address violations of our Terms of Service.
AI Features and Your Data
X3JS offers optional AI features, and how your data is handled depends on which you use:
- Connecting your own AI assistant. If you connect your own AI account (for example Claude) to build in X3JS, your prompts and the content you act on are sent to that provider under your account and their terms and privacy policy. We do not run that inference and do not pay for it; we only store the connection token needed to maintain the link.
- Server-side AI features. For some features we may send content from our servers to an AI provider to generate things like descriptions, tags or search indexing. Where we do, that provider acts as our sub-processor and processes the data on our behalf. See our sub-processor list.
Cookies and Local Storage
We use cookies and browser local storage to make the Service work:
- Authentication — to keep you signed in, your session token is stored in your browser.
- Preferences — for example a cookie that remembers your language.
- Security — Google reCAPTCHA, which we use on sign-up and sign-in to prevent automated abuse, sets its own cookies (see "Third-Party Services").
Essential cookies and storage are required for the Service to function. You can control or delete cookies in your browser settings, but disabling essential ones may break parts of the Service.
Third-Party Services
The Service relies on and links to third parties whose own terms and privacy policies apply:
- Google reCAPTCHA — used to protect sign-up and sign-in from abuse. Its use is subject to Google's Privacy Policy and Terms of Service, and reCAPTCHA collects hardware and software information for its analysis.
- AI providers — see "AI Features and Your Data".
- Embedded creations and links — creations may be embedded on, or link to, third-party sites we do not control.
International Data Transfers
Some of our sub-processors are located outside Türkiye and the EEA (for example in the United States). When we transfer your personal data abroad, we do so on a lawful basis under KVKK Article 9 and Chapter V of the GDPR — such as appropriate safeguards (including standard contractual clauses or equivalent undertakings) or, where required, your explicit consent.
Data Retention
We keep your personal data for as long as your account is active or as needed to provide the Service. After your account is closed we may retain certain data where necessary to meet legal obligations, resolve disputes, prevent abuse and enforce our agreements; otherwise we delete or anonymise it.
Your Rights
Under KVKK Article 11 you have the right to learn whether your personal data is processed, request information about the processing, learn its purpose, know the third parties (including those abroad) to whom it is transferred, request correction or deletion, object to outcomes produced solely by automated analysis, and claim compensation for damage caused by unlawful processing.
If you are in the EEA or UK, you also have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR. If you are in California, you have rights to know, delete and opt out of any "sale" of personal data (we do not sell it), without discrimination.
You can exercise most of these in your account settings or by contacting contact@miramtech.com. You also have the right to complain to a supervisory authority — in Türkiye, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).
Security
We use technical and organisational measures designed to protect your data, including encryption in transit, hashed passwords, session-token rotation on sign-in, hashed connection tokens, and a tiered storage architecture. No system is perfectly secure, so we cannot guarantee absolute security — please use a strong, unique password and keep your credentials confidential.
Children's Privacy
The Service is intended for users aged 13 and over, and we do not knowingly collect personal data from children under 13. Where local law sets a higher age of digital consent, that age applies. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after the changes take effect means you accept the revised policy.
Contact and Data Controller
The data controller is Miramtech (Türkiye). For any privacy question, or to exercise your rights, contact us at contact@miramtech.com.
