Legal
Privacy Policy
Effective August 24, 2026
The short version
TwinPoint handles two kinds of data: account data about you — your name and email — and the scan content you upload: point clouds, splats, 360 photos, and walk paths. We use both only to provide the service. We do not sell data, show ads, or use advertising trackers.
Account data
When your account is created, we store your name, your email address, and a securely hashed password. As you use TwinPoint, we also keep the records the service needs to function: your projects and settings, storage usage, and processing history. Emails you send to support stay in our support inbox.
We use your email address to operate your account: sign-in, password resets, invitations you send or receive, and important service notices.
Content you upload
Your uploads are stored privately and processed only to provide the service — conversion to streaming formats, thumbnails and floor maps, scan alignment, and the face blurring described below. No one sees your content unless you share it, through a share link you create or a project member you invite, and you can revoke either at any time.
Faces and people in scans
Real-world 360 captures sometimes include people. TwinPoint runs an automatic face-blur pass on every 360 tour before its photos are stored — there is nothing to turn on — and provides a manual blur brush for anything the automatic pass misses. The automatic pass is best-effort: the account holder who uploads a capture is responsible for reviewing it, and for any consent required by the law of the place it was captured (see the Terms of Service).
Where data is processed
TwinPoint runs on established infrastructure providers, each of which handles data under its own security terms:
- Vercel — hosts the application.
- Supabase — accounts, sign-in, and the project database.
- Cloudflare — stores uploaded files and processed outputs.
- Brevo — sends account email, such as sign-in links, password resets, and invitations.
- RunPod— provides the GPU compute used while aligning a scan's 360 tour.
- Anthropic — provides the automated image comparison used during alignment to verify station placement.
Cookies
TwinPoint sets only the cookie that keeps you signed in. There are no advertising cookies and no third-party analytics.
Retention and deletion
Deleting a scan or project permanently deletes its stored files. Revoking a share link stops it working immediately for everyone who has it. To delete your account entirely during the beta, email us and we will remove it along with your stored content.
Security
Data travels over encrypted connections, files live in access-controlled storage, and share links use signed grants that can be revoked. If you find a security problem, please email us — we take reports seriously.
Your rights
You can ask us at any time what data we hold about you, and ask us to correct or delete it. TwinPoint is not directed at children.
Changes and contact
If this policy changes materially, we will email account holders. Questions: support@geminibim.com.