Your product photos, handled carefully
Retail teams often work with unreleased product photography, so we built VMrender to treat every upload as sensitive. This page describes exactly how your images are protected, where they travel, and how long anything is kept. If your security team needs more, we are happy to walk them through the pipeline directly.
Encrypted everywhere
TLS in transit on every request; AES-256 encryption at rest for all stored photos and models.
You own your content
Your photos and generated models are yours. We never train AI models on your images, and our AI provider's licence to your content is limited to providing the service.
AI copies self-destruct
Files created during AI processing auto-delete from the provider within one hour of generation.
Bounded retention
Generated models are kept 12 months, then deleted. Source photos can be deleted by you at any time.
The pipeline
How your photo travels
You upload
TLS-encrypted transfer into your private, access-controlled workspace.
Encrypted storage
AES-256 at rest. Row-level security scopes every file to your account.
AI processing
Passed by expiring reference link. Provider-side copies auto-delete within 1 hour.
Your 3D model
Delivered over signed, expiring links. Retained 12 months, then deleted.
Encryption and access
Every connection to VMrender uses TLS, and all stored content, source photos, styled previews and 3D models, is encrypted at rest with AES-256. Files live in private storage buckets that are never publicly listable. Access is scoped per account with database-level row security, and file downloads use short-lived signed URLs (24 hours for previews, 7 days for model downloads) so a shared or leaked link stops working on its own.
How AI processing works with your images
Generation runs on a specialist AI infrastructure provider. Three things keep that step tight. First, your photos are passed to the AI models by reference through expiring links, not uploaded into the provider's storage. Second, we opt out of the provider's request-history storage, so our requests' contents are not kept in its dashboard records. Third, every file the AI generates on the provider's side is set to delete itself within one hour; the copy you keep lives only in your encrypted VMrender storage.
On training: we never use your images to train AI models. Under our AI provider's terms, you retain ownership of everything you submit, and the provider's licence to your content is limited to providing the service. Like most infrastructure vendors, the provider may use anonymised, aggregated usage data to improve its services; your actual images are not part of that.
Retention and deletion
- Generated models and previews are retained for 12 months from generation, then automatically deleted from storage.
- Source photos in your asset library can be deleted by you at any time, immediately, from the dashboard.
- On request, we delete your account and all associated content. Email us and it is handled.
- Custom retention windows (including immediate post-generation purge of source photos) are available for enterprise agreements.
Payments, monitoring and analytics
Payments run entirely through Stripe; card details never touch our servers. Error monitoring uses Sentry and captures stack traces and job identifiers, never image content. Site analytics use Plausible, a cookie-less, privacy-first service that collects no personal data.
Subprocessors
The services that may process customer data on our behalf. Enterprise customers receive the complete named list as part of our data processing agreement:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and encrypted file storage | USA |
| AI inference provider | AI image styling and 3D model generation. Named on request under our DPA. | USA |
| Railway | Application hosting | USA |
| Cloudflare | DNS, TLS and content delivery | USA |
| Stripe | Payment processing (card data never touches our servers) | USA |
| Resend | Transactional email (account confirmations, receipts) | USA |
| Sentry | Error monitoring (no image content in reports) | USA |
| Plausible | Cookie-less, privacy-first web analytics | EU |
For enterprise and security teams
Evaluating VMrender for a team that works with unreleased product lines? We support that directly: a data processing agreement for your pilot, security questionnaire responses, custom retention configuration, and a walkthrough of the pipeline with your security reviewers. Single sign-on and audit logging are on our enterprise roadmap; tell us your requirements and we will be straight with you about timelines. VMrender is operated by Satellite Design Studio (James Montgomery Design Inc., British Columbia, Canada).
Contact us about enterpriseEvaluate it without uploading anything.
Download a finished sample model from the homepage and test it in your own software first. No signup, no photos required.
