1. Scope
This policy explains how Custom War Minis, operated by BaristaLabs, LLC ("Custom War Minis," "we," or "us"), handles information when you use the iOS, iPadOS, or Android app, this website, and the War Forge service.
2. Information we handle
- Source images, Reforge instructions, edited images, and generated model files. Photos and written edit instructions you submit, temporary edited references, GLB or OBJ output, previews, and transfer data needed to complete a Reforge or geometry forge.
- Installation and account data. A one-way hash of a random installation identifier, rank, credit balance, subscription expiration, and account timestamps. We do not persist the raw installation identifier.
- Forge metadata. While a forge is active or failed, project title, capture mode, status, timing, failure details, and provider request correlation. After a successful device transfer, the server deletes this job record.
- Purchase records. Product, App Store transaction, and Google Play order or purchase-token identifiers; purchase and expiration dates; signed-notification identifiers; event type and time; processing outcome; refund adjustments; and store environment data used to prevent duplicate grants and manage entitlements. Google Play purchase tokens are stored only as one-way hashes after verification.
- Support correspondence. Information you choose to send when you contact support.
3. How we use information
We use this information to edit reference images when you request a Reforge, generate and deliver your model, maintain credits and ranks, verify purchases, enforce service limits, diagnose failures, prevent duplicate transactions, answer support requests, and protect the service.
4. Photo, Reforge, and model retention
Our objective is zero cloud retention of your photo, edited-image, and model bytes after their successful device handoff. During a Reforge, the source views and written instruction remain in private temporary storage for up to two hours so the app can offer the included per-view Recasts. Each edited image is deleted from our transfer storage as soon as the app confirms that image is safely on the device. Starting a new Reforge, committing the selected views to geometry, discarding the Reforge, deleting the account, or reaching the session deadline triggers cleanup of the remaining source views, instruction, and edited outputs.
For geometry generation, source images are deleted after completion, failure, or project deletion. Generated model output and the server's successful job dossier are deleted after the app confirms that the files were saved locally. Deleting unfinished work or the account also requests cancellation and cleanup of correlated provider work. A one-day object-storage lifecycle is the fallback for abandoned transfers.
This does not mean we retain no data. Operational account, minimal credit-ledger references, purchase, notification, security, aggregate Reforge/forge timing and cost, and failure metadata may remain for the periods needed to operate the service, prevent duplicate grants or fraud, meet accounting obligations, and resolve disputes. Retained credit records and aggregate operations data do not contain the project title, Reforge instruction, source photos, edited images, or model files. Anti-abuse records use one-way keyed network values rather than storing the network address itself.
5. Service providers
Cloudflare provides edge compute, image safety inspection, database, queue, and temporary object storage. Fal receives a source image and your written instruction to perform each requested image edit, and later receives the selected source images to generate 3D geometry. Request-payload storage is disabled, generated provider files use a one-hour maximum lifecycle, and the service requests their deletion immediately after copying a result into private temporary handoff storage. Transient provider-cleanup failures are queued for retry. Fal still processes the submitted content and output while the requested work is active. Apple provides App Store distribution, StoreKit purchases, and transaction verification. Google provides Play distribution, Play Billing, Real-time Developer Notifications, and Play Integrity verification. These providers handle data under their own terms and privacy commitments.
6. Device-local files and exports
Final model files and reference images are stored inside the app's private sandbox on your device and excluded from app-managed cloud backup. Apple devices protect them with platform data protection; Android devices protect them with the app sandbox and device encryption where enabled. They remain until you delete the relic or app data. On Apple platforms, the random account credential may synchronize through iCloud Keychain when that feature is enabled; Android uses a device-bound encrypted installation credential. Cross-platform account linking is not currently provided. When you export a file through the system share sheet, Files, MakerWorld, a slicer, or another destination, that recipient's policies apply.
7. Tracking and advertising
Custom War Minis does not use advertising trackers and does not sell personal information. The app's privacy manifest discloses photos, generated content, service identifiers, purchase history, product interaction, and diagnostic data used for app functionality; none is declared as tracking. Operational platform logs may contain limited request and error information needed to run and secure the service.
8. Security
Traffic uses HTTPS. Model storage is private, access links are narrowly scoped, signed, and time limited, uploads and provider output are validated, and service endpoints are rate limited. Local files rely on the operating system's app sandbox and device protections. Paid Android testing controls additionally require server-verified Play Integrity evidence. No system is perfectly secure, so export important files and protect access to your device.
9. Your choices
A successfully transferred relic and its descriptive dossier live only on the device, so deleting that relic removes its local files. Deleting unfinished work also requests deletion of any remaining server record and temporary objects. The Armory provides an in-app account-deletion control that removes all relics, local model files, remaining forge records, credits, and active rank from the account. Limited one-way account and anti-abuse identifiers, per-installation deletion acknowledgements, credit-ledger entries, and store purchase records may be retained to ensure linked devices also clear local files, prevent duplicate grants and fraud, meet accounting or legal obligations, and document the deletion. A device-specific deletion acknowledgement is removed after that installation returns with a fresh originality pledge. Deleting the account does not cancel an App Store or Google Play subscription; subscriptions must be managed through the store that billed you. See Delete your account or contact us for an access, correction, deletion, or privacy request.
10. Children
The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
11. Changes
We may update this policy as the service changes. We will post the revised policy here and update the effective date.
12. Contact
Questions or requests can be sent to support@baristalabs.io.