How identity, billing and native project data are handled by Rig2d.
Scope
This policy covers the hosted Rig2d service atinochi2d.blendduck.com, including account, billing, and project storage. Local files that never enter a cloud project remain under your browser and operating-system controls.
Information we process
- Account identity: name, email address, profile image and provider identifiers returned by Google sign-in.
- Billing state: Stripe Customer and Subscription identifiers, plan, status and renewal boundaries. Card numbers are collected and held by Stripe, not this application.
- Project data: project name, revision ancestry, byte length and integrity hashes in D1; native INX revision bytes in R2.
- Operational data: bounded security, error and request metadata needed to operate and protect the service. Provider secrets and model bytes are not written to application logs.
How information is used
Information is used to authenticate accounts, enforce subscription access, save and recover native project revisions, prevent stale overwrites, investigate abuse and keep the service reliable. It is not used to train generative models.
Service providers
Google provides account authentication, Stripe provides hosted billing, and Cloudflare provides the application runtime plus D1 and R2 storage. Each provider processes data under its own terms.
Retention and deletion
Native save revisions are retained for the lifetime of their project to preserve cloud integrity and conflict protection. When an owner deletes a project, its D1 metadata is removed and every immutable R2 object is queued for deletion. Failed object deletions remain in a durable queue and are retried by an hourly storage sweep. Billing and security records may be retained where required for accounting, fraud prevention or legal obligations.
Security and choices
Access is checked before storage reads and again when advancing a project head. Revision conflicts fail closed. You can export native project data, delete projects, manage billing in Stripe and revoke Google access. No system is perfectly secure; suspected account compromise should be reported through the support channel shown in the signed-in Dashboard.
Changes and contact
Material changes will update the effective date and, when appropriate, appear in the product before taking effect. Privacy questions can be submitted through the support channel in the account Dashboard. This policy remains available at this canonical URL with its effective date.