View.gs / Legal
Privacy Policy
Effective date:
Last updated:
View.gs provides Gaussian-splat viewing and temporary cloud sharing. This policy explains what information is processed, why, and the choices available to you.
1. Who is responsible
L2labs OÜ operates View.gs and is responsible for personal information used to operate the website and sharing service. Where someone uploads personal data on behalf of an organization, their responsibilities and our role for that content depend on the circumstances; this policy does not replace a required data-processing agreement.
L2labs OÜ. Registry code: 16476064. Postal address: Ruunaoja tn 3, Lasnamäe linnaosa, Tallinn, Harju maakond, 11415, Estonia. Contact: alexsoroka@l2labs.dev.
2. At a glance
No registration is required for ordinary browser uploads. Selecting or dropping a file on the website starts a cloud upload. After validation, you can name the scene, choose its opening camera and publish a viewer link and embed code.
A published link is a capability link: anyone who has it can access, copy, download, record, embed or forward the scene. It is not an authenticated private workspace. We do not provide a public scene directory, and our pages ask search engines not to index shared scenes; this cannot prevent discovery or redistribution.
Free files normally expire 48 hours after the upload finishes validation, including time spent preparing an unpublished draft. Keep your own original file. Do not upload secrets, confidential material or personal data unless you are authorized and this public-link service is appropriate.
3. Website and macOS application
This policy covers the View.gs website, cloud upload, viewer and embed service, programmatic uploads, inquiries, and the optional cloud-sharing part of the View.gs macOS application.
When you choose Share & Embed in the macOS application, the selected file and associated metadata are transmitted to View.gs for cloud sharing. The web upload flow also transmits the file; browser rendering does not mean local-only storage.
4. Information we process
Information depends on the features you use. Uploaded scenes and even filenames or camera views can reveal people, locations, private premises or other personal information.
- Scene content: the compatible Gaussian PLY or common 32-byte SPLAT file you upload, currently up to 500 MB (500,000,000 bytes).
- Scene details: original filename, optional display name, camera position/direction/up vector, size, format and validation details, random share identifier, owner identifier, status, and upload/creation/expiration times. Link recipients can receive the original filename as well as the display name.
- Upload and usage records: upload-session and multipart identifiers, part-completion information, ownership, transfer state, upload count, rate-limit window and retry/verification information.
- Identifiers: a random signed browser-session identifier used to recognize ownership, or an assigned service-account identifier and optional label for programmatic access. These are pseudonymous, not necessarily anonymous: records can be associated using the identifier or identifying content.
- Network information: IP address and request headers such as user agent, requested address, origin/referrer and cookies are processed when infrastructure receives requests. Application database code does not explicitly store IP addresses or user agents. Providers may process technical/security records separately.
- Operational information: API failure type, cleanup counts and infrastructure runtime diagnostics. Application logging avoids deliberately recording uploaded content, filenames, signed file URLs or authorization headers.
- Inquiries: name, email, selected plan and optional company/comment submitted in a request form, plus messages and reasonable verification information you send to us.
- Optional website analytics: when accepted, Google Analytics receives browser/cookie identifiers, permitted public-page views, selected upload interaction events and technical browser/device information. The viewer, embeds and privacy/deletion pages are excluded from the website analytics loader.
5. Why we use information
For individuals requesting the service, we use information necessary to receive, validate, host and display uploads, save names and camera settings, generate links, apply expiry, identify upload ownership and process requested scene removal to perform the requested service (GDPR Article 6(1)(b)). Required file and technical information cannot be omitted if you want the associated feature to work.
For security, abuse prevention, proportionate usage limits, troubleshooting and reliability, we rely on legitimate interests where those interests are not overridden by your rights (Article 6(1)(f)). These interests include protecting the service and its users and investigating failures. We also use this basis to respond to business representatives and ordinary support inquiries when contract necessity does not apply.
For an individual’s plan inquiry we use necessary information to take steps at their request before a contract. An inquiry does not subscribe you to a newsletter or authorize unrelated marketing. Optional analytics relies on your affirmative consent (Article 6(1)(a)); refusing it does not block uploads or viewing.
When a specific law requires retention, disclosure or a rights response, processing may be necessary to meet that legal obligation (Article 6(1)(c)). Not every security or government request is automatically a legal obligation. We assess the applicable grounds.
Your contract does not, by itself, authorize processing personal data about other people in a scene. Uploaders must have the necessary authority and information for those people.
7. Recipients and service providers
Amazon Web Services (AWS) provides object storage, web delivery through CloudFront, API processing, server functions, secret storage, operational logs and scheduled cleanup. File uploads and downloads go directly between the client and AWS object storage using temporary authorized URLs.
Google Firebase/Google Cloud provides Firestore for scene metadata, ownership and upload/rate-limit records. Database access is handled by the server. Google Analytics processes optional website measurement when you consent.
Resend delivers the acknowledgement of a Pro or Business request and a separate message to our configured business mailbox. It processes email addresses, request content and delivery information. Your and our email providers also process correspondence.
Anyone receiving a published viewer or embed link can obtain scene data. An embedding website may independently collect its visitors’ information; its privacy notice governs that separate activity. Downloaded or recorded copies are outside our control.
We may disclose necessary information to professional advisers, authorities or other recipients for a specific legal obligation, a lawful request or a proportionate protection of rights or safety. Any preservation or disclosure remains subject to applicable law.
The implementation does not contain data-sale, data-broker or advertising integrations. Optional analytics measures website use.
8. Where processing takes place
The AWS application storage and compute configuration uses the United States (Northern Virginia). Firestore database settings identify nam5, a United States multi-region location. CloudFront processes requests at worldwide edge locations. This is not an EU-only hosting service.
Google Analytics, Resend, mailbox providers and their support/subprocessors may process information in other countries. A mail-sending region or a server region alone does not establish all processing locations.
Contact alexsoroka@l2labs.dev for information about processing locations and international-transfer safeguards relevant to your personal data.
9. Retention and deletion
Scene files: the ordinary free access period is 48 hours from completion and validation, not from publication. The viewer and embed deny new access after expiry. Scheduled cleanup normally runs hourly to remove expired source files; failed operations are retried. A storage lifecycle provides an additional 32-day orphan-cleanup safety net. These schedules do not promise physical deletion or availability at an exact moment.
Unfinished uploads: upload authorizations normally expire after two hours. Scheduled cleanup aborts stale uploads and removes associated objects. A separate storage rule targets incomplete multipart transfers after one day. Delays and retries can affect physical cleanup.
Owner-requested scene removal: the removal action disables the scene before attempting file deletion. If file deletion is pending, the service retains that state for cleanup retries. Previously authorized file requests may continue briefly until the file is deleted (file authorizations ordinarily last at most 15 minutes); a file already loaded, downloaded or copied cannot be recalled.
Metadata and identifiers: scene, upload-session and upload-count records currently have no automatic database purge. Expiry or scene-file removal does not by itself erase the original filename, optional name/camera, ownership and other associated records.
Cookies and local storage: the ownership cookie and saved privacy preference last up to 180 days; Analytics cookies are configured up to 180 days when accepted; pending-completion storage follows the tab/recovery rules above. Removing browser data is different from deleting server records.
Logs and queues: application log groups are configured for about 30 days. Failed scheduled-cleanup events can remain in a retry/dead-letter queue for up to 14 days. Provider security logs may follow separate retention schedules.
The 48-hour scene access period does not apply to analytics, correspondence, provider logs or any backup copies. Deleting a scene does not recall copies already held by recipients or automatically erase all associated records. Contact us about a request concerning your personal data.
Files may become unavailable or be removed sooner for security, abuse, legal, capacity or operational reasons, subject to applicable law. We cannot remove copies independently retained by recipients.
10. Your rights and requests
Where the GDPR applies, you may request access to and correction of your personal data, erasure, restriction of processing and portability where its conditions apply. You may object to processing based on legitimate interests on grounds relating to your situation, and withdraw consent for processing that relies on it. These rights have legal conditions and exceptions; this policy does not waive them.
Privacy choices provides owner-authenticated scene-file removal and explains how to contact us for broader data requests. Provide the viewer URL or upload identifier if available, describe what you want, and give a way to reply. Do not send passwords, API keys or unnecessary identity documents.
A browser’s signed ownership cookie or the uploading service account can verify control of an upload. A public share link alone cannot. If that proof is lost, we may need other proportionate evidence. We do not have to collect extra identifying information just to identify previously anonymous records, but will consider additional information you provide to exercise your rights.
We will handle rights requests within applicable legal time limits. Under the GDPR this is ordinarily without undue delay and within one month of receiving the request; where legally justified by complexity or number of requests, the period may be extended by up to two further months, with reasons communicated within the initial month. Requests are normally free, subject to the limited exceptions allowed by law.
You can complain to a competent data-protection authority, including where you live, work or believe an infringement occurred. You can also contact Estonia’s Data Protection Inspectorate (Andmekaitse Inspektsioon). You need not contact us first to exercise your right to complain.
11. Security and responsibility
Technical safeguards include encrypted network connections, server-controlled storage access, signed upload/file authorizations, ownership checks and scheduled cleanup.
No internet transmission or storage system can be guaranteed completely secure. Capability links are intended to be shared and are not a confidentiality control. Uploaders must consider whether people, premises or other sensitive details should be removed from their scene before uploading it. This does not limit our non-waivable security or privacy obligations.
12. Children
If you believe a child’s information has been uploaded or collected improperly, contact the business mailbox with the relevant link and concern. Do not send additional sensitive information about the child unless necessary for the response.
13. Automated controls
Automated format/size checks and rate limits may reject an upload or temporarily restrict requests. They do not evaluate people for credit, employment or comparable decisions. No automated decision process intended to produce legal or similarly significant effects is implemented. Contact us if a restriction appears incorrect.
14. Changes and contact
We will show the updated version and date here. Material changes will be highlighted on the website and, where required and contact details are available, communicated directly. If a change requires fresh consent, it will be requested; continued use alone is not consent to optional analytics or another new consent-based purpose.
Business contact: alexsoroka@l2labs.dev. Registry code: 16476064. Postal address: Ruunaoja tn 3, Lasnamäe linnaosa, Tallinn, Harju maakond, 11415, Estonia.