Privacy Policy
Last updated: 16 February 2026
Who We Are
AR Creator is a web-based platform for creating and sharing interactive augmented reality experiences, operated at artools.co.uk.
What Data We Collect
We collect the following personal data:
- Account information: Email address, display name, and a securely hashed password when you register for an account.
- Uploaded content: Images, 3D models, video, and audio files that you upload to create AR experiences.
- View analytics: When someone views an AR experience, we record the experience ID, the viewer's user agent string (browser and device information), and a timestamp. We do not record IP addresses.
- Password reset requests: If you request a password reset, we temporarily store a reset token associated with your email address.
Why We Collect It
- Account management: To create and maintain your account, authenticate your sessions, and let you manage your experiences.
- AR experience delivery: To store and serve the content you upload so it can be displayed in augmented reality when viewers scan your QR codes.
- Basic analytics: To show you how many times your experiences have been viewed. User agent data helps identify the types of devices accessing your content.
- Password resets: To verify your identity when you request a new password.
How We Store It
- Database: Account information and view analytics are stored in a MySQL database.
- File storage: Uploaded files (images, 3D models, video, audio) are stored on the server filesystem.
- Password security: Passwords are hashed using PHP's
bcryptalgorithm and are never stored in plain text.
Third-Party Services
We use the following third-party services:
- Hostinger SMTP: For sending password reset emails. Your email address is shared with Hostinger solely for email delivery.
- CDN providers: We load JavaScript libraries from Cloudflare (QR code generation), jsDelivr (MindAR), and Google (model-viewer). These CDNs serve static files and do not set tracking cookies on our site.
We do not use any third-party analytics services, advertising networks, or social media trackers.
Cookies
We use a single essential cookie (PHPSESSID) to maintain your login session. This cookie is strictly necessary for the site to function and does not track you across other websites. See our Cookie Policy for full details.
Data Retention
- Account data: Retained until you delete your account.
- Uploaded files: Retained until you delete the associated AR experience.
- View analytics: Retained for as long as the associated experience exists.
- Password reset tokens: Expire and are automatically removed after use or after a short time period.
Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct any inaccurate personal data.
- Delete your personal data (right to erasure).
- Export your data in a portable format.
- Object to processing of your personal data.
To exercise any of these rights, please contact us using the details below.
Security Measures
We take the security of your data seriously and implement the following measures:
- HTTPS encryption for all connections.
- Prepared database statements to prevent SQL injection.
- Bcrypt password hashing.
- Filename sanitisation for uploaded files.
- Security headers including content type options and frame protection.
Children
This service is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us so we can remove it.
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
Contact
If you have questions about this privacy policy or wish to exercise your data rights, please contact us at:
Email: privacy@artools.co.uk