Review or change optional analytics and advertising permissions.
Modelcore Privacy Policy
Effective and last updated: August 2, 2026
Version: 2026-08-02
This Privacy Policy explains how True Level LLC, a Vermont limited liability company (Modelcore, we, us, or our), handles personal information through modelcore.app, create.modelcore.app, the Modelcore beta, and related services (the Service).
Contact support@modelcore.app with privacy questions or requests.
1. Scope
This policy applies when Modelcore decides why and how personal information is processed. It does not govern information another organization controls independently, including a customer's separate systems or a third-party site you visit from Modelcore.
The beta is for adults. You must be at least 18 to create an account.
2. Information we collect
Account and authentication
We receive your email address, name, profile image, verified-email status, identity-provider identifier, authentication method, and limited organization claims from WorkOS AuthKit and providers you choose, such as Google or Microsoft. We store session and security records needed to keep you signed in and protect the account.
For new accounts, we record the Terms and Privacy Policy versions accepted, acceptance time, adult confirmation, and source flow as contract evidence.
Projects, files, and collaboration
We process models, geometry, project names, snapshots, thumbnails, imported files, materials, site context, exports, commands, comments, membership, presence, locks, edit history, and other content you choose to create or share. Collaborators may see your identity, presence, edits, comments, and content according to project roles.
Site-context features may process a location, address, coordinates, map bounds, or related geographic data you request. A project can reveal precise or sensitive locations, so only add location data you are authorized to use.
Beta, support, feedback, and email
We collect beta-role and use-case answers, waitlist status, feedback posts and votes, support messages, and related context. The public website may send an email address and source label to Resend for waitlist or product email. You can unsubscribe from marketing email at any time.
Usage, device, and security information
We and our providers may process IP address, user agent, browser and device attributes, timestamps, route, referrer or campaign parameters, cookie or session identifiers, coarse location derived from IP, performance measurements, errors, crash traces, and interaction events. Feedback abuse controls may retain salted hashes of IP address and user agent rather than the raw values.
We configure Sentry not to send default personal information from API requests. Error reports can still contain information present in an error, filename, or application state, so do not place secrets in names or free-text fields.
AI-assisted features
When you invoke an AI-assisted feature, we process the prompt and the model or project context selected for that request and send the necessary content to OpenAI's API. OpenAI states that API inputs and outputs are not used to train its models by default. Depending on the endpoint and account configuration, OpenAI may retain abuse-monitoring logs for up to 30 days unless a different eligible retention control applies. Do not submit sensitive information that is unnecessary for the request.
3. How we use information
We use personal information to:
- provide authentication, projects, storage, collaboration, imports, exports, mapping, AI-assisted actions, support, and email you request;
- operate the beta, manage access, and understand product use;
- secure accounts, prevent fraud and abuse, debug failures, and maintain reliability;
- send service notices and, with the required choice, product or marketing communications;
- measure optional analytics and advertising conversions when you allow those categories;
- comply with law, enforce agreements, and establish or defend legal claims; and
- improve Service features using operational and usage evidence. We do not use private project content to train a general-purpose AI model.
Where law requires a legal basis, we rely on performance of our contract, legitimate interests in operating and securing the Service, consent for optional tracking or communications, and legal obligations. You may withdraw consent without affecting earlier lawful processing.
4. When we disclose information
We disclose information only as reasonably needed:
- Service providers. WorkOS/AuthKit; Vercel; Railway; managed PostgreSQL and object-storage providers; Cloudflare R2; PostHog; Sentry; Resend; Google advertising measurement; OpenAI; Mapbox; and providers or public data services used for OpenStreetMap, Overpass, and Overture Maps workflows. See Service Providers.
- Collaborators and organizations. Project members and organization administrators receive information allowed by project roles and settings.
- Legal and safety. We may disclose information when we reasonably believe law requires it or it is necessary to protect people, rights, security, or the Service. We evaluate government and private demands for validity and scope.
- Business transactions. Information may transfer in a financing, merger, reorganization, acquisition, insolvency, or sale, subject to appropriate confidentiality and notice where required.
- At your direction. We disclose content when you invoke an integration, share a project, export a file, or otherwise direct us.
We do not sell personal information for money. Optional Google advertising measurement may be treated as sharing, targeted advertising, or a similar regulated activity in some U.S. states. It remains off until you allow optional categories, and you can turn it off through Privacy choices on the Privacy page. We honor a recognized Global Privacy Control signal by keeping optional tracking off while that signal is active.
5. Cookies and privacy choices
We use essential cookies or similar storage for sessions, authentication state, security, load balancing, and your privacy choice. These are required to provide the Service.
PostHog, Vercel Analytics, Vercel Speed Insights, and Google Ads measurement are optional. The public site and web app do not load them until the optional category is allowed, except for strictly necessary security processing. Your choice is stored for up to one year and can be changed at any time through Privacy choices on the Privacy page. Browser controls can also delete stored choices.
6. Retention
We retain information only as long as reasonably necessary for the purposes above:
- account and current acceptance records while the account is active and afterward as needed for contract, security, tax, or legal claims;
- projects and collaboration records until deletion, account closure, or the end of applicable backup and recovery cycles;
- session cookies for up to 30 days, while short-lived authorization state normally expires within minutes;
- waitlist and marketing contacts until unsubscribe, deletion request, or the list is no longer used;
- feedback and audit records for product operations, moderation, abuse prevention, and accountability; and
- provider-held analytics, logs, errors, email, mapping, and AI records under our configured retention and the provider's service terms.
Deletion from active systems may not immediately remove encrypted backups. We isolate backups from ordinary use and delete or overwrite them on the normal recovery cycle unless a legal hold applies.
7. Security
We use access controls, encrypted transport, secure session cookies, CSRF defenses, rate limits, provider controls, audit records, and other safeguards appropriate to an early beta. No system is perfectly secure. Use a unique account, control collaborators carefully, and keep independent exports of important work.
Report security concerns to support@modelcore.app. Do not include exploit details in public feedback.
8. International transfers
Modelcore and many providers operate in the United States. If personal information is transferred from another country, we and our providers use transfer mechanisms required by applicable law, such as standard contractual clauses where available. Contact us for information relevant to your location.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; opt out of targeted advertising or regulated sharing; and appeal a denied request.
Email support@modelcore.app with the subject Privacy request. State the account email and request. We may verify identity and authority before acting. Authorized agents must provide proof of authority. We will respond within the period required by applicable law and explain any lawful exception.
You may complain to your local privacy or data-protection authority. We will not discriminate against you for exercising a privacy right.
10. Minors
The Service is not directed to people under 18, and we do not knowingly permit them to create accounts. We have removed student- and classroom-directed beta acquisition pages while we evaluate a separate minors program. If you believe a minor provided personal information, contact support@modelcore.app so we can investigate and delete it where required.
11. Changes
We may update this policy as the Service or law changes. We will post the effective date and provide reasonable notice of material changes. If a change requires consent, we will ask before applying it as required by law.
12. Contact
True Level LLC
Vermont, United States