Back to the editor

Privacy Policy

Last updated: 2026-08-14

Who we are

VesselMaker is operated by Marco Siino (“we”, “us”). You can reach us at siino.marco@gmail.com for any privacy question or request.

Signing in is required to use VesselMaker

You need to sign in with Google to open the editor. Editing and the 3D preview never leave your browser. Signed-in usage does make a small number of further server requests: entitlement checks, premium export authorization, and — as described under What we store below — lightweight usage counters. Your actual vase design (the geometry, profile points, materials) is never part of any of those requests; a project file you save stays a local file on your device, as before.

Before launch, the tool is additionally invite-only: a signed-in account also needs an invite code or a grant from us to get in. If you sign in without one, we store your account (see below) but you won't have access to the tool until you're let in or the tool launches. The one exception is the waitlist (see below): joining it never requires signing in with Google. When we grant a signed-in account access, we send a one-time notification email to the address on that account so you know you can start using the tool — this is a transactional message about your own account's status, sent whether or not you've opted in under Occasional updates & early invite codes below, since that opt-in is about ongoing marketing/product-update email, not this single confirmation.

What we store

  • Account data — when you sign in with Google, we store your email address, display name, and profile picture URL as provided by Google. We never see or store your Google password.
  • Access & subscription records — records tied to your account that determine what it's entitled to use (your subscription tier, if any, and how it was granted) and, before launch, whether you've been let into the tool.
  • Waitlist — joining the waitlist (from the welcome page or the invite-only screen, with or without a Google account) stores just your email address, a shareable referral code we generate for you, and — if you arrived via someone else's referral link — which code referred you. On its own, we use your email only to send a single launch notification when VesselMaker opens to the public, and the referral linkage solely to prioritize invites for people who've referred others. (Receiving an invite code by email before that public launch is covered by the separate opt-in below.) Contact us to be removed from the waitlist at any time.
  • Occasional updates & early invite codes — an optional opt-in, separate from the above and always off by default, never assumed: wherever VesselMaker shows an explicit opt-in for this (for example when joining the waitlist, in account Settings, or elsewhere in the product), choosing it stores that you opted in and the date; leaving it unticked on a form that offers it records that you have not opted in, and clears any earlier opt-in from that email address. Opting in lets us (a) occasionally email you about VesselMaker in general — news, new features, progress, and similar updates — and (b) send you an invite code before the public launch, since we release pre-launch access in batches to people who've opted in. That early access is the only added benefit of opting in: declining changes nothing else — you keep your place on the waitlist and still get the one-time launch email. We never use this for anything else and never share it with third parties. You can withdraw at any time — as easily as you gave it — via an unsubscribe link in those emails (once we send them) or by contacting us.
  • Usage & product-analytics counters — tied to your account, not a new cookie: how much time you spend using the editor, and counters for saves, exports, AI renders, upgrade-page views, how many times you've hit the export paywall, and which optional premium features (if any) you've tried. We use this only to understand how VesselMaker is actually used and to gauge demand for premium features — never sold, shared with third parties, or used for advertising. An admin can view this detail for a specific account, including a day-by-day breakdown (not just totals), for support and product-understanding purposes. Day-by-day usage detail is kept for up to 24 months and then automatically deleted; account-level totals (like your export count) are kept for as long as your account exists. A small, separate count of how often each individual feature has been used overall is kept in fully aggregate form with no link to any account — not personal data. Saving or exporting a design sends only an action type and a list of which features it uses — never the design's geometry, profile points, or materials.
  • Email-send history — when we email you (a pre-launch invite code, or a notification that you've been let into the beta), we keep a record of that send tied to your account or waitlist entry: the recipient address, when it was sent, its delivery status (delivered, or bounced/blocked), and — if it failed — the error, so we can retry or troubleshoot a delivery problem. Our email provider, Brevo, embeds a standard open- and click-tracking pixel in these messages that cannot be disabled for transactional email; we run it in Brevo's anonymous tracking mode, so opens and clicks are not linked to you or your IP address, and we do not read, store, or act on open or click data — the delivery status we keep comes only from bounce/delivery reports.
  • Session cookie — a strictly-necessary cookie that keeps you signed in. It is not used for tracking or advertising.

Some data never reaches our servers in any stored form: your Gemini API key (used for AI rendering) stays in your browser's local storage — requests using it are relayed through our server without being logged or persisted — and your vase project files stay on your device as local JSON files.

Processors we use

  • Google — identity provider for sign-in (Google OAuth). See Google's Privacy Policy.
  • Our hosting and database providers — used to run the application and store the account/entitlement data described above.
  • Brevo — sends the transactional emails described above (invite codes, beta-access notifications) on our behalf; Brevo processes the recipient address and message content needed to deliver them under its own data processing agreement/standard contractual clauses. Brevo embeds a standard open- and click-tracking pixel in these emails that cannot be turned off for transactional messages; we have it set to Brevo's anonymous tracking mode, so opens and clicks are not associated with you or your IP address, and we do not use or retain that data. See Brevo's Privacy Policy.
  • If we add a payment provider in the future (for self-serve checkout), it will be a merchant of record responsible for handling payment details and applicable tax directly — we do not store card details ourselves.

Cookies

We only use a strictly-necessary session cookie to keep you signed in. We do not use any third-party analytics, tracking, or advertising cookies, so no cookie-consent banner is shown. Separately, as described under What we store above, we do keep server-side usage counters tied to your account (time spent, exports, saves, and similar) — these are not cookies and involve no tracking technology in your browser, so they don't change the answer above; they're listed there for completeness.

Your rights

You can delete your account and all associated data (profile, entitlements, redeemed-code history) at any time from Settings. You can also contact us at the email above to request access to, correction of, or deletion of your data.

Changes to this policy

If this policy changes materially (for example, if we add a new processor such as a payment provider), we will update this page and the “Last updated” date above.

Also see our Terms of Service.