Last updated: 15 July 2026
AR Works (ar.works) is operated by Qode LTD, a company registered in England and Wales (company number 17259547) with its registered office at Liberty House, 30 Whitchurch Lane, Edgware, England, HA8 6LE. AR Works is a Qode LTD product. For the personal data described in this policy, Qode LTD is the data controller - except for school-managed student accounts, where the school is the controller and we process data on its behalf (see section 8).
Questions, requests, or complaints: privacy@ar.works.
The AR viewer asks for camera access so it can track your target image and render the AR scene. Camera frames are processed entirely on your device by the in-browser AR engine. They are never recorded, stored, or transmitted to us or anyone else. Denying camera access stops the AR experience but has no other effect.
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the service - accounts, projects, publishing, the AR viewer | Performance of a contract |
| Processing subscription payments and keeping billing records | Performance of a contract; legal obligation |
| Responding to enquiries, contact messages, and support tickets | Steps prior to a contract; legitimate interests |
| Transactional email (e.g. password resets) | Performance of a contract; legitimate interests |
| Security, abuse prevention, rate limiting | Legitimate interests |
We do not send marketing email, show ads, profile you, or sell or rent personal data to anyone.
We use a small number of hosting and infrastructure providers (processors) to run AR Works:
| Provider | What they do | Location |
|---|---|---|
| Neon (PostgreSQL) | Database - accounts, projects, enquiries | London, UK (AWS eu-west-2) |
| Cloudflare R2 | Uploaded media files | Western Europe |
| Render | API hosting | Frankfurt, EU |
| Vercel | Website delivery (global edge network) | Global (edge caching) |
| Stripe | Payment processing | Per Stripe's own policies |
| Resend | Transactional email delivery | Per Resend's own policies |
| jsDelivr (CDN) | Serves the AR viewer's open-source libraries | Global CDN |
Application data is stored in the UK/EU. Where a provider (such as Vercel's edge network, Stripe, Resend, or jsDelivr when its CDN serves a request) processes data outside the UK/EEA, transfers rely on recognised safeguards such as the UK Addendum, Standard Contractual Clauses, or an adequacy framework. When your browser loads the AR viewer, the jsDelivr CDN receives standard request data (your IP address and browser details) in order to serve the files.
Publishing a project creates a share link and QR code. Anyone with the link can view the project - its name, content, and media - until you unpublish it. Uploaded media is served from unguessable public URLs from the moment it is uploaded; those URLs are not listed anywhere, but anyone who has a URL can open the file. Please don't upload media containing confidential information or other people's personal data without their agreement.
There is currently no self-service account deletion - email privacy@ar.works from your account email address and we will delete your account and content. Students on school-managed accounts should ask their teacher or school.
Under the UK GDPR and EU GDPR you can ask to access, correct, delete, restrict, or receive a copy of your personal data, and object to certain processing. Contact privacy@ar.works and we will respond within one month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.
Self-service registration is for users aged 13 or over. Student accounts are different: they are created and managed by a teacher at the student's school, and the school is the data controller for them - we process student data only on the school's instructions. Student accounts need only a login identifier (which can be a school-controlled alias rather than a personal email), a password, and a display name (which can be a non-identifying label such as a class alias); we encourage schools to use non-identifying values for both. Schools can ask us to delete student accounts and content at any time.
All traffic is encrypted in transit (TLS). Passwords are stored as bcrypt hashes; session and reset tokens are stored only as hashes; sign-in state uses an httpOnly cookie that JavaScript cannot read. Access to accounts and projects is role-based, and the API is rate-limited. No system is perfectly secure - if a breach affects your data we will notify you and the regulator as required by law.
We will post any changes here and update the date at the top. If a change materially affects how we handle your data, we will tell you through the site or by email before it takes effect.
Qode LTD (company number 17259547), Liberty House, 30 Whitchurch Lane, Edgware, England, HA8 6LE. Email: privacy@ar.works. See also our Terms & Conditions and Cookie Policy.