Privacy Policy

Last updated: 15 July 2026

AR Works (ar.works) is operated by Qode LTD, a company registered in England and Wales (company number 17259547) with its registered office at Liberty House, 30 Whitchurch Lane, Edgware, England, HA8 6LE. AR Works is a Qode LTD product. For the personal data described in this policy, Qode LTD is the data controller - except for school-managed student accounts, where the school is the controller and we process data on its behalf (see section 8).

Questions, requests, or complaints: privacy@ar.works.

1. What we collect

  • Account data. Your email address, a password (stored only as a bcrypt hash - never in plain text), an optional display name, and your role, plan, and account status. We also record when your account last signed in and when it was last active, so that unused or unexpectedly active accounts are visible to our administrators. These are timestamps only - we do not store your IP address or device details against your account.
  • Your content. The AR projects you build (scenes, objects, animations, logic) and the media you upload (images, video, audio, 3D models), plus share links for projects you publish.
  • Enquiries and support. If you use a contact form ("For schools" or "Contact us"): your name, email address, your message, and - for school enquiries - the school name. If you open a support ticket while signed in: the subject you choose, your messages, and our replies.
  • Billing data. Payments are processed by Stripe. We store only Stripe customer and subscription identifiers and your subscription status. Your full card details never touch our servers.
  • Technical data. IP addresses and request metadata are used transiently for security and rate limiting, and appear in short-lived infrastructure logs at our hosting providers. We run no analytics, tracking, or advertising tools.
  • Security tokens. Sign-in refresh tokens and password-reset tokens are stored only as cryptographic hashes. Reset links expire after 1 hour and are single-use.

2. Your camera

The AR viewer asks for camera access so it can track your target image and render the AR scene. Camera frames are processed entirely on your device by the in-browser AR engine. They are never recorded, stored, or transmitted to us or anyone else. Denying camera access stops the AR experience but has no other effect.

3. How we use your data

PurposeLegal basis (UK/EU GDPR)
Providing the service - accounts, projects, publishing, the AR viewerPerformance of a contract
Processing subscription payments and keeping billing recordsPerformance of a contract; legal obligation
Responding to enquiries, contact messages, and support ticketsSteps prior to a contract; legitimate interests
Transactional email (e.g. password resets)Performance of a contract; legitimate interests
Security, abuse prevention, rate limitingLegitimate interests

We do not send marketing email, show ads, profile you, or sell or rent personal data to anyone.

4. Where your data lives

We use a small number of hosting and infrastructure providers (processors) to run AR Works:

ProviderWhat they doLocation
Neon (PostgreSQL)Database - accounts, projects, enquiriesLondon, UK (AWS eu-west-2)
Cloudflare R2Uploaded media filesWestern Europe
RenderAPI hostingFrankfurt, EU
VercelWebsite delivery (global edge network)Global (edge caching)
StripePayment processingPer Stripe's own policies
ResendTransactional email deliveryPer Resend's own policies
jsDelivr (CDN)Serves the AR viewer's open-source librariesGlobal CDN

Application data is stored in the UK/EU. Where a provider (such as Vercel's edge network, Stripe, Resend, or jsDelivr when its CDN serves a request) processes data outside the UK/EEA, transfers rely on recognised safeguards such as the UK Addendum, Standard Contractual Clauses, or an adequacy framework. When your browser loads the AR viewer, the jsDelivr CDN receives standard request data (your IP address and browser details) in order to serve the files.

5. Published projects are public

Publishing a project creates a share link and QR code. Anyone with the link can view the project - its name, content, and media - until you unpublish it. Uploaded media is served from unguessable public URLs from the moment it is uploaded; those URLs are not listed anywhere, but anyone who has a URL can open the file. Please don't upload media containing confidential information or other people's personal data without their agreement.

6. Retention and deletion

  • Account data is kept for as long as your account exists.
  • Deleting a project or account removes the database records immediately (projects, assets, share links). Copies of media files in object storage are removed on a best-effort basis and may persist for a short period afterwards.
  • Password-reset links expire after 1 hour and can be used once.
  • Contact-form messages and support tickets are kept for as long as needed to respond and follow up.
  • Stripe retains transaction records in line with its own legal obligations (e.g. tax and anti-fraud rules).

There is currently no self-service account deletion - email privacy@ar.works from your account email address and we will delete your account and content. Students on school-managed accounts should ask their teacher or school.

7. Your rights

Under the UK GDPR and EU GDPR you can ask to access, correct, delete, restrict, or receive a copy of your personal data, and object to certain processing. Contact privacy@ar.works and we will respond within one month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.

8. Children and school accounts

Self-service registration is for users aged 13 or over. Student accounts are different: they are created and managed by a teacher at the student's school, and the school is the data controller for them - we process student data only on the school's instructions. Student accounts need only a login identifier (which can be a school-controlled alias rather than a personal email), a password, and a display name (which can be a non-identifying label such as a class alias); we encourage schools to use non-identifying values for both. Schools can ask us to delete student accounts and content at any time.

9. Security

All traffic is encrypted in transit (TLS). Passwords are stored as bcrypt hashes; session and reset tokens are stored only as hashes; sign-in state uses an httpOnly cookie that JavaScript cannot read. Access to accounts and projects is role-based, and the API is rate-limited. No system is perfectly secure - if a breach affects your data we will notify you and the regulator as required by law.

10. Changes to this policy

We will post any changes here and update the date at the top. If a change materially affects how we handle your data, we will tell you through the site or by email before it takes effect.

11. Contact

Qode LTD (company number 17259547), Liberty House, 30 Whitchurch Lane, Edgware, England, HA8 6LE. Email: privacy@ar.works. See also our Terms & Conditions and Cookie Policy.