Privacy Policy
Last updated 22 September 2026
This covers what Workshop (“the Service”) collects when you use it, what it keeps and for how long, and which outside services see any of it. It sits alongside the Terms of Service.
1. Your account
You sign in with Discord. We ask Discord for the identify
scope only, which gives us your account ID, username and avatar. We never
see your Discord password or email address.
Alongside that we keep the permissions your account has, your credit balance, any API keys you create (only a one-way hash of each key is stored, never the key itself), and any custom domains you add.
2. What we record about use
We record which tools you ran, when, and how many credits each run cost. For API keys we record how many requests each key made, to which endpoint, the result and how long it took. Changes made by administrators are written to an audit log.
We don't store IP addresses, and nothing we record says where a request came from. Visits by people who aren't signed in are counted per day as a total, with nothing that identifies anyone.
3. Files you upload to the tools
Files you give a tool are processed to produce your result and are not kept beyond that. Finished output may be stored so you can download it again from your account history, and may be removed after a while. If you give us a link instead of a file, the server downloads it for you.
4. Files you host
Images and videos uploaded through Image Hosting or the media API are stored until you delete them from the Image Hosting page. They sit in a folder whose name is derived from your account but doesn't reveal your Discord ID. Anyone who has a link to a hosted file can open it, so treat those links as public.
Every hosted upload is posted to a private Discord channel run by the site operator, for moderation. That post includes your username and account ID, the name of the API key used, the file's name, type and size, and its link.
5. Outside services
Some tools only work by handing something to another service. They receive only what that tool needs:
- Discord - signing in, and the upload notices described above.
- OpenAI - the livery and handling assistants send your artwork, reference images and the text you type.
- Meshy - the Prop Generator sends the photo you give it, to build the model.
- Sketchfab - only if you connect your Sketchfab account, to fetch models you choose. The access it grants is held in memory while the server runs and never written to disk; you can disconnect it at any time.
- Cloudflare and Google DNS - when you verify a custom domain, the domain name is looked up through their public resolvers.
Hosted files and stored output live on storage we run ourselves. We don't sell anything we hold, and we don't use your files to train anything.
6. Cookies
We set a session cookie to keep you signed in, and a short-lived cookie (ten minutes) while the Discord sign-in completes. Both are marked HttpOnly. There are no advertising or tracking cookies.
7. Deleting your data
You can delete hosted files yourself at any time, and revoke API keys or remove custom domains from their pages. To have your account and its history removed, contact us and we'll do it.
8. Changes
If this changes in a way that matters, the date at the top will change with it.
9. Contact
Questions or deletion requests: contact us through the channel you signed in or purchased through.