Model Explorer Privacy Policy
Model Explorer is provided by Ngô Đình Dũ (“we”, “us”). This policy explains how the web app and its Meta Horizon Store package handle information.
Information stored on your device
Models you import, previews, inspection state, settings, workflows, personal memory, a selected knowledge folder, and other app state are stored in browser or app storage on your device. A Gemini API key is stored locally only if you choose to add one. You can remove this information by deleting models in the app, clearing Model Explorer site data, or uninstalling the app.
Optional model sharing
Imported model files remain on your device by default. When you explicitly choose Share inspection, Model Explorer uploads the selected model files and a sanitized inspection manifest to the Model Explorer service at 0xr.space. The manifest can include display metadata, scale, render style, open or selected parts, explosion settings, and section or clipping settings. It excludes local file-system paths, device anchors, physical placement matrices, analytics data, and previous share identifiers.
Anyone with the public-by-link URL can download that shared inspection. Ordinary unlisted links and uploaded copies expire automatically 30 days after creation.
Optional Nearby models
Model Explorer requests device location permission only when you open Nearby or explicitly confirm a share that is set to appear in Nearby. After Home finishes loading, it may use an approximate network region derived by our hosting provider from the request IP to prepare Nearby results in temporary page memory; this does not display kilometer distance or trigger a device-location prompt. Nearby attempts device location at most once per browser session after you open it. Before transmission, latitude and longitude are rounded to three decimal places, approximately neighborhood or 100-meter precision. We use that coarsened location to calculate approximate distance and do not return stored coordinates in Nearby results. If device location is unavailable or not allowed, Nearby uses the prepared network-region results. Model Explorer does not store the raw IP in model discovery metadata.
For a location-listed share, hosting-provider city, region, and country labels may be attached only when its coarse network coordinates are reasonably consistent with the device location. VPN or mobile-network mismatches are discarded. Public results may show these approximate labels but never expose the underlying stored coordinates.
Location-listed models, their coarsened location, and their public links expire automatically 30 days after creation. You can turn off “List in Nearby” before creating a share to create an unlisted 30-day link without a location request. After you enable Nearby, the coarsened search location is stored on your device until you revoke location permission or clear Model Explorer site data. While Model Explorer is open, it checks about every 15 seconds for newly listed models, prefers models within 100 km, and may fall back to the nearest worldwide location-listed share. It asks before downloading or displaying a suggestion. These checks stop when the page is closed; Model Explorer does not track movement in the background or require you to travel to a model.
Analytics
We use Google Analytics and Cloudflare Web Analytics to measure page use, reliability, and feature performance. This may include device and browser information, approximate location derived from network information, online identifiers, release version, import method, model format, file-count and size ranges, XR session state, supported model features, duration, and generalized error codes.
Our app analytics do not intentionally send model filenames, file paths, model contents, model identifiers, email addresses, GPS coordinates, free-form model metadata, or free-form error messages. Google and Cloudflare process analytics information under their own terms and privacy policies.
Mixed reality, camera, hands, and microphone
Horizon OS and the browser provide head tracking, hand or controller tracking, spatial information, and passthrough needed to present mixed reality. Model Explorer uses these signals during the active experience and does not retain passthrough camera frames.
Camera access is requested only when you start something that needs it, and what happens to an image depends on which. Scanning a QR code processes frames on your device to find the code; those frames are not retained or uploaded. The shutter in the dock, and asking Zero to look at something, take a single still and send it to Google Gemini to answer that request. Photo → 3D sends one photo to Model Explorer’s server, which passes it to the service that builds the model — currently a public Hugging Face Space — and deletes that job’s files when the job ends. The photo itself is not added to your library; the model it produces, and the small preview image shown on its card, are stored on your device like any other import.
Microphone access is optional and requested only for voice features. When voice or assistant features are active, audio, prompts, and the app or model context needed to answer the request are sent directly from your device to Google Gemini. Do not use these features with information you do not want Google to process.
There are two ways those requests are authorized. If you have entered your own Gemini API key, the request uses your key and nothing about the assistant session reaches Model Explorer’s servers. During the free launch preview, if you have not entered a key, Model Explorer’s server issues a short-lived access token for a single assistant session instead. Issuing that token records your IP address, the time of the request, and an anonymous per-installation identifier, kept for 30 days and used only to prevent abuse and to limit how many free sessions are granted. Those sessions are billed to the developer’s own Google account and are subject to Google’s terms for that account. Your audio and prompts still travel directly to Google and are not routed through, recorded by, or readable by Model Explorer’s servers.
How we use and share information
We use information to provide model import, storage, rendering, sharing, mixed-reality interaction, optional assistant features, reliability measurement, and support. We do not sell personal information or show advertising. Information is shared only with service providers described above, at your direction, or when required for legal or security reasons.
Children
Model Explorer is intended for teens and adults aged 13 and older. It is not directed to children under 13, and we do not knowingly collect their personal information.
Security, international processing, and changes
We use reasonable safeguards, but no storage or transmission system is completely secure. Google, Cloudflare, and our hosting providers may process information in countries other than yours. We may update this policy as the app or its providers change; the effective date above identifies the current version.
Application settings, connection information, and user-created application data are stored locally on the user’s device. Except for inspection files that you explicitly share for 30 days, and a photo you send for Photo → 3D, which is processed only for that one job, we do not operate an application backend for collecting or centrally storing this information. We use reasonable technical measures available on the device to protect locally stored information. However, no storage or transmission method can be guaranteed to be completely secure. Users are responsible for protecting access to their device and for keeping their third-party API keys and account credentials secure.
Google Gemini Integration
The application provides an optional AI-assisted feature powered by Google Gemini, a third-party large language model service. The Gemini feature is disabled by default and is activated only when the user explicitly chooses to enable it and provides their own Gemini API key. When the user submits a request through this feature, only the text or other content selected and submitted by the user is transmitted directly from the user’s device to Google Gemini for the purpose of generating the requested response. The application developer does not operate an intermediary server for Gemini requests. The user’s Gemini API key, prompts, submitted content, and generated responses are not transmitted to or stored on servers operated by the application developer. The Gemini API key and related configuration may be stored locally on the user’s device. The user can remove this locally stored information through the application’s settings or by clearing the application’s local data. We do not use Meta platform data, Meta account information, device data, user prompts, submitted content, or generated responses to train any artificial intelligence or machine-learning model. We do not sell this data or use it for advertising, profiling, or purposes unrelated to the user’s request. Data submitted to Google Gemini is processed by Google under Google’s applicable terms, privacy policy, and Gemini API data-use terms. Users should review those terms before enabling the feature. Users are not required to enable Google Gemini to use the application’s core features.
Data Deletion
Removing an API key or disconnecting an integration from the application’s settings;
Using the application’s clear-data or reset function;
Clearing the application’s storage through the device settings; or
Uninstalling the application.
Requests concerning data retained by a third-party provider (such as Google for the Gemini API) must be submitted directly to that provider under its applicable privacy policy.
Contact
Ngô Đình Dũ
dinhdu12@gmail.com
https://0xr.space/