Privacy Policy

Effective as of October 22, 2025

Last updated: October 22, 2025

This Privacy Policy describes how [Mathmagic] (“Company”), and our website at hitem3d.ai (collectively, “hitem3d.ai”, “Hitem3D.ai”, “we,” “us,” or “our”) collect, use, disclose, transfer and store your Personal Data when you access our website or use the hitem3d.ai services, applications, online platforms or any other digital properties (collectively, the “Services”) as well as what choices you have about it.

hitem3d.ai’ Services allows users to convert unstructured data—such as text, images, videos, and sensor inputs from real or virtual-world objects and environments—into AI-driven 2D/3D and related content, including images, models, textures, animations, and interactive elements. Please read carefully and fully understand this Privacy Policy together with our Terms of Use Agreement to make choices that you deem appropriate before using the hitem3d.ai’ Services.

The Privacy Policy only applies to the Personal Data we collect.

The Privacy Policy will help you understand the followings:

Index

1.Definitions

2.Collecting and Using Your Personal Data

3.How We Store Your Personal Data

4.How and When We Share Your Personal Data

5.Your Rights and Choices

6.Security

7.How Your Personal Data Transferred Globally

8.Our Policy on Children’s Data

9.Other Sites and Services

10.How We Make Changes to This Policy

11.Contact Us

Supplemental U.S. State Privacy Disclosures

1. Definitions

Collect” refers to the behaviour of gaining control over Personal Data, including voluntary provision by the data subject, automatic collection by interaction with the data subject or recording the behaviour of the data subject, and indirect acquisition by sharing, transferring and collecting public information.

Controller” refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

Children” is a term defined differently under different jurisdictions, e.g., it refers to an individual who is under the age of 13 pursuant to Children’s Online Privacy Protection Act (“COPPA”), in the U.S.

Delete” refers to the behaviour of removing Personal Data from the system involved in the implementation of daily business functions, so that it cannot be retrieved and accessed.

Personal Data” refers to any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing” refers to any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Publicly disclose” refers to the behaviour of releasing information to the society or to non-specific groups of people.

Share” refers to the process of Personal Data controller providing Personal Data to other controllers, and both sides have independent control over Personal Data.

Third Parties” refer to companies or persons who do not have a related relationship arising out of joint ownership or control with hitem3d.ai (i.e., a non-Affiliated Company) or other non-related persons. Third parties can be financial or non-financial companies, or persons other than you and hitem3d.ai;

Transfer” refers to the process of transferring Personal Data control from one controller to another.

You” or “your” means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

2. Collecting and Using Your Personal Data

2.1 Personal Data that We Collect

hitem3d.ai collects information for more efficient operations and provides you with the best product experience. We collect Personal Data in a few different ways including: (1) information directly provided by you; (2) data recorded by us about how you interact with our products; (3) data from Third Parties.

2.1.1 Information you provide to us

When you use hitem3d.ai’ Services, you voluntarily share certain information.

2.1.2 Technical information when you use and interface with our Services

When you use a website or other internet service, certain internet and electronic network activity information gets created and logged automatically via event tracking and other technical methods, which is adopted for device performance detecting, user behavior analysis and subsequent product optimization. This is also true when you use hitem3d.ai. Here are some of the types of information we collect:

2.1.3 Third Parties (such as our partners and advertisers) share information with us

We also receive information about you and your activity outside hitem3d.ai from our affiliates, advertisers, partners and other third parties we work with. For example:

We may collect other third-party data, such as data from our affiliates, vendors, data brokers or public sources.

2.1.4 Information Provided by Third-Party Applications via our API

You may be using a third-party product or service that has integrated hitem3d.ai’s technology via our API. In such cases, your data, particularly the content you create (such as Prompts and generated Outputs), is sent to our Services for processing.

In this scenario, the third-party application provider is responsible for managing your data, including obtaining your consent for data collection and processing. You should carefully review the privacy policy of that provider to understand their data practices. If you wish to access, correct, or delete your data, please direct your request to the provider of the third-party application you are using.

2.2 How We Use your Personal Data

We process your Personal Data for purposes described in the Privacy Policy based on your prior consent and our legitimate interests. We also process your Personal Data pursuant to legal obligations imposed on us or to perform contracts between hitem3d.ai and you (such as the Terms of Use Agreement). hitem3d.ai will strictly comply with the Privacy Policy and its updates to use your Personal Data. If your Personal Data is used for other purposes that is not stipulated in the Privacy Policy, we will additionally obtain your specific consent or other legal basis. Examples of our processing activities are as follows:

2.2.1 Service Delivery and Maintenance

We’re committed to providing you with a powerful and intuitive AI driven 2D/3D modeling tool. To do that, we may use your Personal Data to:

2.2.2 Product & Services Improvement and Analytics

As part of our efforts to improve Services provided by hitem3d.ai, we may use your Personal Data to analyze product usage condition so as to constantly create, develop, and analyze business operation efficiency, and include new features and functions. Specifically, we use the information we collect to:

2.2.3 Compliance and protection

We use your information in our efforts to keep our users and the public safe, and to protect legal interests. To do so, we may use your personal information to:

2.2.4 Limits on Use of Your Google User Data

Notwithstanding anything else in this Privacy Policy, if you provide hitem3d.ai access to your Google data, our use of that data will adhere to the Google API Services User Data Policy andLimited Use Policy and will be subject to these restrictions, as required by Google:

2.3 How We Use Cookies and Similar Technologies

Using cookies can help you personalize your online experience. You can accept or reject cookies. Most web browsers automatically accept cookies, but you can usually modify your browser's settings to reject cookies if you want. Cookies do not track personal data. We may use the Cookies and similar technologies described above for the following purposes:

You can choose to enable or disable cookies in your Internet browser. Most Internet browsers also allow you to choose whether you want to disable all cookies or only third-party cookies. By default, most Internet browsers accept cookies, but this can be changed. For more information, please see the help menu in your Internet browser or the documentation that came with your device.

The following link provides instructions on how to manage cookies in the relevant browser:

If you use other browsers, please refer to the documentation provided by the browser manufacturer.

Please note that if you refuse to use, or clear existing cookies, you may need to change your user settings personally for each visit, and we may not be able to provide a better and quality experience to you or parts of our services may not function correctly.

3. How We Store Your Personal Data (Data Retention)

We will strictly abide by our internal retention policy to store your Personal Data. We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, except a longer period required by applicable laws and regulations or your explicit consent.

We will retain and use your Personal Data to the extent necessary to:

When assessing how long your Personal Data is retained, we consider criteria such as:

If you deactivate your account, or upon the expiration of the necessary retention period, we will take steps to delete or anonymize your Personal Data from our active systems in accordance with our internal data retention policies and applicable law. Anonymized data, which can no longer be used to identify you, may be retained for analytical and service improvement purposes. Please note that some data may persist in backup or archival media for a limited period as required by law or for legitimate business purposes before being securely deleted.

4. How and When We Share Your Personal Data

We do not sell your Personal Data. We may share your Personal Data with the following categories of parties and as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection:

These service providers are contractually obligated to protect your Personal Data and are restricted from using it for any other purpose than to provide the services we have engaged them for.

We make commercially reasonable efforts to verify that the parties with whom our mobile application shares personal information provide a level of protection of personal information consistent with the practices described in this Privacy Policy, except that all such parties described above other than service providers and affiliates may, to the extent permitted by law, use personal information as described in their own privacy policies.

Unlike platforms with community features, your User-Generated Content Data (Prompts and Outputs) created within hitem3d.ai is not made public or visible to other users of the Services by default. You control whether to share your content outside of the Services through export functionalities or integrations you may choose to use.

5. Your Rights and Choices

We offer you certain choices to control your data. Depending on your location and applicable local data protection laws, you may have the following rights concerning your Personal Data that we process. You can typically exercise many of these rights and choices through your account settings or by contacting us as described at the end of this section..

This means we can store your Personal Data but cannot process it.

6. Security

The security of your Personal Data is a priority for hitem3d.ai. We implement and maintain appropriate technical and organizational security measures designed to protect your Personal Data from accidental or unlawful destruction, loss, damage, alteration, unauthorized access, disclosure, or use. These measures are in accordance with industry standards and applicable laws and include, but are not limited to:

Your account is protected by a password for your privacy and security. You are responsible for maintaining the confidentiality of your password and for any activities that occur under your account. You must prevent unauthorized access to your account and Personal Data by selecting and protecting your password appropriately and limiting access to your computer or device by signing off after you have finished accessing your account. If you believe the security of your account or Personal Data has been compromised, please contact us immediately at [legal@mathmagical.com].

However, please be attention, even if we undertake reasonable measures to protect your data, there is no website, internet transmission, computer system or wireless connection that are definitely safe. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

In case of Personal Data security incident where it is likely to result in a high risk to the rights and freedoms of you, we shall communicate the Personal Data breach to you in accordance with the requirements of laws and regulations such as basic situations and possible influence of the security incident, response measures we have taken or will take, suggestions for you regarding self-prevention and risk reduction, remedial measures for you, etc.

We will inform you in a timely manner by email, mail, telephone, push notification, etc., regarding the relevant situations of the incident. When it is difficult to notify each Personal Data subject individually, we will issue a notice in a reasonable and effective manner. In the meantime, we will take the initiative to report on the handling of Personal Data security incident in accordance with regulatory department’s requirements.

7. How Your Personal Data Transferred Globally

hitem3d.ai operates as a global service. As such, your Personal Data may be transferred to, stored, and processed in countries other than your own state, province, or country of residence, where data protection laws may differ from those in your jurisdiction.

By agreeing to the Privacy Policy and using our Services, you acknowledge that your Personal Data may be transferred to and processed in these locations for the purposes described in this Privacy Policy.

The Company will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and applicable data protection laws, and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your Personal Data.

8. Our Policy on Children’s Data

Our services are not designed to target children, and therefore, we do not intentionally collect any data pertaining to children. We do not knowingly gather personally identifiable information from any children as defined by applicable laws.

We encourage parents and legal guardians to monitor their children's internet usage and to help enforce this Privacy Policy by instructing their children never to provide Personal Data through our Services without their permission.

If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us immediately at [legal@mathmagical.com]. We take the privacy and protection of children's data very seriously. Should we become aware that we have inadvertently collected Personal Data from any child without obtaining verifiable parental consent, we will promptly take all necessary steps to remove such information from our servers.

If we need to rely on consent as a legal basis for processing your information and your country requires consent from a parent, we may require your parent's consent before we collect and use that information.

9. Other Sites and Services

The Services may contain links to websites, mobile applications, and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites, mobile applications and online services you use.

10. How We Make Changes to This Policy

We may change this Privacy Policy from time to time and if we do, we’ll post any changes on this page and update the “Last updated” date at the top of this Privacy Policy. If the changes are significant, we may provide a more prominent notice, such as by sending you an email.

You are advised to review this Privacy Policy periodically for any changes. If you continue to use hitem3d.ai after those changes are in effect, the new policy applies to you.

11. Contact Us

If you have any concerns or doubt over our Privacy Policy or our practices, please contact us via following channels:

Any review and processing will normally be completed within thirty (30) days after verifying your user identity. If it takes more time to respond to your request or if weage are unable to respond to your request, we will send you a notice and explain the reasons within the maximum timeframe required by law.


Supplemental U.S. State Privacy Disclosures

This Addendum supplements our Privacy Policy and applies solely to residents of certain U.S. states with comprehensive privacy laws, such as California (including as applicable under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, collectively "CCPA"), Virginia, Colorado, Utah, and Connecticut, or individuals whose Personal Data has been collected in these states. Any terms defined in such applicable state privacy laws have the same meaning when used in this Addendum.

  1. INFORMATION WE COLLECT

The following table describes the categories of Personal Data (as defined by the CCPA and similar state laws) that hitem3d.ai may collect, and has collected in the preceding 12 months, and the categories of Third Parties to whom we may disclose this information for a business purpose. Please refer to Section 1 ("Personal Data We Collect") and Section 3 ("How We Share Your Personal Data") of our main Privacy Policy for more details.

Category of Personal Data (corresponds to categories listed in CCPA§1798.140(o)(1)) Collected? Categories of Third Parties to Whom Disclosed for a Business Purpose
A. Identifiers such as name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address and account name. Yes Service providers (e.g., hosting, analytics, customer support, payment processors); Affiliates; professional advisors (legal, financial); parties involved in corporate transactions (e.g., mergers); law enforcement or government authorities (as required by law); other users (if you share information publicly or with them).
B. Personal Data categories listed in the California Customer Records statute, such as name, contact information, education, occupation, employment record and financial information. Yes Service providers; Affiliates; professional advisors; parties involved in corporate transactions; law enforcement or government authorities.
C. Characteristics of protected classifications under California or federal law, such as age, race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). Yes(Currently, we only collect your age information to determine whether you meet the legal requirements to be our user) No
D. Commercial information, such as transaction information, purchase history, financial details, and payment information. Yes Service providers (e.g., payment processors, analytics); Affiliates; parties involved in corporate transactions.
E. Biometric information, such as fingerprints and voiceprints. No No
F. Internet or other electronic network activity information, such as browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements. Yes Service providers (e.g., analytics, advertising partners if applicable); Affiliates.
G. Geolocation data, such as device location. Yes Service providers (e.g., analytics, hosting)
H. Audio, electronic, visual, and similar information, such as images and audio, video or call recordings created in connection with our business activities. Yes(Includes text and image prompts you provide, AI-driven 2D/3D content you generate such as images, models, textures, and animations, your history of such Prompts and Outputs, and any other images or files you choose to upload to our Service) Service providers (e.g., essential services such as hosting, content delivery, analytics)
I. Professional or employment-related information, such as job title as well as employment record and working experience. No No
J. Education information subject to the federal Family Educational Rights and Privacy Act, such as student profiles. No No
K. Inferences drawn from any of the Personal Data listed above to create a profile or summary about, for example, an individual’s preferences and characteristics. Yes Service providers (e.g., for personalization, analytics); affiliates.
  1. YOUR ADDITIONAL U.S. STATE PRIVACY RIGHTS

Subject to certain limitations and exceptions under applicable state laws, you may have the following rights regarding your Personal Data:


Supplemental Privacy Terms for API Users

These supplemental terms apply to you if you are a developer or business that integrates our hitem3d.ai model Services into your own products, websites, or applications for use by your end-users (collectively, “API Users”). These terms supplement the other provisions of this Privacy Policy.

  1. Our Role and Your Responsibilities

When you use our API, we act as a “Data Processor” or “Service Provider” on your behalf. You, the API User, act as the “Data Controller” for any Personal Data of your end-users (“End Users”) that is processed through the Services. As the Data Controller, you have several key responsibilities:

As an API User, the processing of your own Personal Data (such as your account and payment information, if any) is governed by the applicable sections of this Privacy Policy. This subsection further clarifies how we process data on behalf of your End Users:

If you have a separate executed agreement with the Company, the terms of that agreement shall prevail over this subsection.

If you, as an API User, have specific privacy or data handling requirements related to your industry, use case, or applicable regulations, you may contact us to discuss potential customized solutions. Such solutions may be subject to a separate agreement and additional fees. Please direct all such inquiries to market@mathmagical.com.