Controller and scope
ARCY, a French SAS registered with the Paris Trade and Companies Register under number 937 957 785, 60 rue François 1er, 75008 Paris, France, is the controller for the processing described here. For privacy questions or to exercise your rights, contact contact@arcy.app.
This policy covers the Segmentit website and application: accounts, private projects, photo uploads, manual selections, a library of existing 3D models, requested AI processing and paid purchases. SAM 3 segmentation and SAM 3D generation depend on the features enabled for your account and the required credits. Uploading a photo alone does not start AI processing or send it to Modal.
Why we process your data
Data needed to create your account, authenticate you and manage your projects is processed to provide the service you request, on the legal basis of performance of a contract. Without an email address and a verified account identity, you cannot access the private workspace. Uploading a photo is optional and is only necessary if you want to work on that photo.
Preventing unauthorised access, limiting abuse, diagnosing incidents and handling support requests rely on ARCY’s legitimate interest in keeping the service secure and operational. Information you send to support is used to understand and answer your request.
Segmentit does not sell your data or use your uploads for advertising or model training. Your projects are not published in a gallery. Viewing existing models does not run AI processing on your photo.
Accounts and authentication
WorkOS provides identity management and authentication. For email-code sign-in, the Segmentit server sends your email address, IP address and browser information to WorkOS. WorkOS sends and verifies the one-time code, which expires within 10 minutes. An account may be created as part of this sign-in.
If you choose Google, WorkOS receives the necessary identity details, including your email address and the profile information shared. This flow does not request access to Gmail, Drive or Calendar. Google access tokens are not sent to the Segmentit interface. WorkOS’s hosted AuthKit page may also be used, including when additional verification is needed. If that page asks for a password, the Segmentit server does not receive it.
Cloudflare D1 databases retain internal and WorkOS identifiers, the application profile’s email address, creation and update dates, and the identifiers and expiry information needed to track sessions and sign-in transactions. They do not store passwords, email codes, access tokens or refresh tokens.
To limit code requests and verification attempts, the server stores fingerprints of the email address, IP address and transaction, calculated with a secret key (HMAC), together with counters and their expiry times. The relevant protection tables do not store those addresses in plain text. These fingerprints are pseudonymised data, not anonymous data.
Photos, projects and files
Uploaded JPEG, PNG and WebP photos, limited to 5 MiB per file, are stored in private Cloudflare R2 storage. Cloudflare D1 retains associated information: owner, project, filename, type, size, dimensions, dates and selection or mask data. The APIs verify your session and access to the project before serving its private files.
For an account with access to the feature, an explicit segmentation request sends Modal the photo and the text describing the object to select so that it can run SAM 3. An explicit generation request sends the prepared photo and validated mask so that it can run SAM 3D. Identifiers and technical information needed to track the processing are also sent. The resulting masks and models are retrieved into private Cloudflare R2 storage and linked to the project; access remains subject to account checks.
Files can contain people, locations and metadata, including EXIF data. Segmentit does not automatically remove that metadata: remove information you do not want to share before uploading. Only upload content you are authorised to entrust to the service.
Library models are existing resources, separate from your private photos. Their sources and licences appear in the viewer. Editing a selection does not generate a new 3D model.
Cookies and local preferences
Production authentication and security cookies are sent over HTTPS and protected by the HttpOnly attribute, which makes them inaccessible to page JavaScript.
__Host-segmentit-oauthsecures the sign-in callback and is valid for 10 minutes.__Host-segmentit-emaillinks a code request to its verification. It is encrypted and valid for no more than 10 minutes. It does not contain the code you receive and is cleared after successful verification or invalidation of the flow.__Host-segmentit-sessionis the encrypted session cookie. The session lasts no more than 7 days after sign-in, even if its cookie is renewed during that period. Signing out revokes the session and clears authentication cookies.
The application’s language preference is saved in your browser’s local storage under segmentit.app.locale. It stays on your device until replaced or until you clear that storage. Your browser may also cache website resources.
Segmentit does not integrate audience analytics or advertising pixels. WorkOS and Google apply their own policies to their hosted sign-in pages: WorkOS privacy and Google privacy.
Recipients and processing locations
The contact form sends your name, email address, subject and message to Formspree for delivery to the ARCY team for Segmentit. You can also email contact@arcy.app directly.
Access is limited to authorised ARCY personnel and providers who need the data to deliver the service, maintain security or handle a support request. Cloudflare serves the website, runs the server and hosts D1 and R2. WorkOS manages identity, sessions and email codes. Google is involved when you choose its sign-in option. Modal receives the data needed for users’ authorised segmentation and generation requests and provides the corresponding computing resources. Information may be disclosed to an authority where legally required. Stripe handles checkout and subscription management, as described in the payment section below.
Private R2 storage and the application’s D1 database are configured in Cloudflare’s European jurisdiction. This does not locate all processing in Europe: authentication services, networks, technical teams and providers may process data outside the European Economic Area, including in the United States. Computing on Modal is not configured to be limited to the European Union.
The Cloudflare data processing documentation and WorkOS data processing documentation describe their processing frameworks and proposed transfer mechanisms, including standard contractual clauses. These links do not certify Segmentit. You can request information about recipients and safeguards applicable to your data at contact@arcy.app.
Hosting also receives technical information needed to handle requests and maintain security, such as IP address, time, URL and browser information. Cloudflare’s privacy information describes its processing. External links and the websites they lead to have their own policies.
Retention and deletion
Your profile is retained while your account is retained, and projects and files remain while you keep them in your workspace. Signing out does not delete your WorkOS account or projects. To delete your account and associated data, send a request to contact@arcy.app. This is a manual procedure; the sign-out button does not trigger it.
You can delete a project in the application. This removes its active data and files. If cleanup fails, deletion can be retried, and the interface may ask you to try again. Any backup copies follow their providers’ cycles and are not all erased instantly. Information needed to handle an incident, establish or defend a legal claim, or meet a legal obligation may be retained for that purpose with restricted access.
Modal call inputs and results, processing identifiers, tracking records and technical logs may remain according to the retention periods and mechanisms of the service used. Deleting a project in Segmentit does not immediately erase those records at Modal. Modal’s privacy and retention information explains these distinctions; stopping a compute container does not mean that all associated records have been erased.
Email transactions expire within 10 minutes. Protection counters use windows of up to one hour. Expired records are cleaned up when the server accepts new requests: a validity deadline does not guarantee physical deletion at that exact time. Sessions become invalid no later than 7 days after sign-in.
Support correspondence is retained while the request and necessary follow-up are handled. Technical log and backup retention depends on their purposes and the providers’ settings and cycles; the session durations above do not apply to them. Contact us for information relevant to your retention or deletion request.
Your rights
Subject to the conditions in applicable law, you can request access, correction, deletion, restriction or portability of your data. You can object to processing based on legitimate interests for reasons relating to your circumstances. Where processing relies on consent, you can withdraw it without affecting prior processing.
Write to contact@arcy.app, describing your request and the email address of the account concerned. We may ask only for information needed to verify your identity and protect your data. You can also complain to the French data protection authority, CNIL. CNIL explains rights over personal data.
Payments and subscriptions
When you choose a paid offer, Segmentit sends Stripe an internal account identifier, the Stripe customer identifier and the information identifying the selected offer. Stripe collects payment details on its hosted checkout page. Segmentit does not receive or store full payment-card numbers or card security codes.
To confirm the purchase, manage your subscription and allocate credits, Segmentit processes Stripe customer, checkout, payment and subscription identifiers, the selected offer, the amount and currency returned at confirmation, and payment and subscription status. Its database retains the references linking billing to your account, subscription status and periods, and the credit and billing-event records needed to manage access. See Stripe’s privacy policy for its processing of payment data.
Changes to the service
If new processing is enabled, including audience analytics, or the purposes of existing processing change, this policy and the information shown when data is collected will be updated before that processing begins.