← Adoryl

LEGAL / PRIVACY

Privacy Policy.

Last updated: 31 August 2026.

Introduction

This Privacy Policy describes how Pawan Kumar, operating under the name Adoryl (“Adoryl”, “we”, “our” or “us”), collects, uses, shares, protects and otherwise processes personal data through www.adoryl.com(the “Platform”). You can browse most of the Platform without registering. By providing information or using a product or service, you acknowledge this policy and the applicable terms.

Collection

We collect your personal data when you use the Platform, place an order, request a quote, contact us or otherwise interact with us. Depending on the service, this can include your name, email address, mobile number, delivery and billing address, order information, project instructions, uploaded files or images, transaction references and correspondence. You can choose not to provide information, but the related service may then be unavailable.

You can receive an instant STL estimate without providing a name or email address. The longer project-intake form runs locally in your browser, and Adoryl receives its contents only if you choose to send the prepared email. Standard catalogue checkout sends the stated order and delivery details to Adoryl over HTTPS.

Usage

We use personal data to provide and fulfil requested products and services, prepare quotes, process and reconcile payments, communicate order and delivery updates, provide support, resolve disputes, prevent fraud and misuse, enforce our terms, meet accounting or legal duties, improve the customer experience and conduct the limited analytics described below. We do not sell personal or project data.

Sharing

We share only the information reasonably needed with service providers involved in the requested service, such as payment providers, participating banks, couriers, hosting and infrastructure providers, email services and named AI or production providers. Those parties process data under their own terms or our instructions. We may also disclose information when required by law, legal process, regulators or law enforcement, or when reasonably necessary to protect users, Adoryl or another person's rights and safety.

STL quote files

The instant quote tool accepts STL files up to 20 MiB. Your file is sent over HTTPS and held in temporary, memory-backed working storage only while the quote request is processed. The service removes the STL as the request finishes. If normal cleanup is interrupted, an automatic cleanup sweep retries the removal.

Uploaded STL files are not added to a model library, used to train an AI system, sold, or included in Adoryl backups. The quote result may describe calculated details such as dimensions, estimated material, print time, and price, but an email address is not required to view it.

AI-assisted 3D work

The AI 3D tool is a limited private beta. When you start a generation, Adoryl sends your prompt or source image from its server to Meshy in the United States. Meshy processes that material to generate the 3D model. The browser does not receive Adoryl's Meshy API key or Meshy's private task details.

Do not use the AI tool for confidential information or a photo that identifies a person. You must own the prompt, image, and other material you submit, or have all rights needed to use it for AI generation and the intended project.

Meshy documents that assets created through its API are retained for up to three days. Its non-Enterprise terms also allow customer inputs and outputs to be used to improve and train its services. Read the Meshy Terms of Use, Meshy Privacy Policy, and Meshy API retention guidance before submitting material.

Adoryl keeps each private AI job and its downloaded results for 14 days, then deletes them. Access to the job and its files requires the secret job token issued when the job starts. Keep that token private and save any model files you need before the 14-day period ends. Transfers between your browser and Adoryl use HTTPS.

When you request a print price, your browser fetches the protected AI STL and sends a temporary copy to Adoryl's quote service. The quote service sets the requested size, creates print toolpaths, calculates the estimate, and removes that temporary copy. The job token is not sent to the quote service. The original AI job keeps its normal 14-day retention period.

Accounts, carts and order tracking

Adoryl uses Zoho's ZeptoMail service to process your email address solely for account-verification and password-reset emails. In this release, ZeptoMail does not send order confirmations or payment, fulfilment, dispatch, or delivery-status updates. Payment and fulfilment updates are handled manually. Verification and reset emails are transactional account-security messages; requesting or receiving one is not marketing consent and does not enrol you in promotional email.

You can create an account with your name, normalised email address and a password. Adoryl stores a one-way password hash rather than the readable password. A Secure, HttpOnly, SameSite session cookie keeps you signed in; browser scripts cannot read it. Session security records include bounded creation, activity and expiry times. Pre-authentication sessions expire after 24 hours. Signed-in sessions expire after seven idle days or 30 total days, whichever happens first. Expired and revoked session records are removed by scheduled bounded cleanup, ordinarily within seven days.

A guest cart stays in your browser and contains only a random cart identifier, model identifiers, offer versions and quantities. It does not contain your name, email, address, price or session token. When you sign in, Adoryl merges that cart into your server-side account cart only after the authenticated merge succeeds.

Signed-in carts, account profile details, checkout contact and delivery details, immutable order lines, payment state, production events and shipment tracking records are used to provide checkout, fulfilment, support and delivery tracking. Specified account, order and delivery fields are encrypted at rest and access is restricted to the customer's account and authorised operations.

A cart quote expires after 10 minutes. When checkout succeeds, Adoryl immediately redacts the quote's delivery PIN code and active quote token while retaining the minimum amount, cart and order evidence needed to reconcile that checkout. Expired unconsumed quotes are removed by the scheduled cleanup. Guest-cart merge receipts are retained for no more than 90 days so a retried merge cannot add the same items twice.

You may delete your account from the account page. Active legal, accounting, tax, refund, delivery, fraud, complaint or dispute records are retained for their required period and de-identified where possible. Account deletion revokes sessions and removes active cart items, merge receipts and unconsumed quotes from the live database; the account profile becomes an irreversible tombstone needed to preserve authorised order links. You may also contact Adoryl for access, correction or deletion support.

SQLite secure deletion and a write-ahead-log checkpoint are used as best-effort cleanup for the live database. Access-restricted local backups contain those encrypted database fields, are retained for 30 days and then expire under the backup policy. Information removed from the live database may therefore remain in a protected backup until that backup expires.

Domestic catalogue orders and UPI

The current domestic checkout policy bundle is adoryl-policy-2026-08-31-r20. At account registration, Adoryl records that server-owned version, the acceptance time and your Terms and Privacy acknowledgements. At order creation, Adoryl records the applicable bundle, acceptance time and one acceptance of the current Terms and incorporated policies, including the rules for authorised order instructions and non-safety-critical use. The browser cannot choose or replace the version.

For an India order, Adoryl keeps the order reference, selected product and offer version, quantity, production details needed to fulfil it, item and delivery amounts, payment status, expiry and timestamps. Your name, email address, 10-digit mobile number, address lines, city, state or union territory, and delivery PIN code are encrypted at rest. The private checkout capability is stored as a one-way hash rather than in readable form.

The public UPI checkout capability expires 30 days after order creation and is revoked sooner when an order is cancelled, a durable fulfilment handoff is acknowledged, or a completed refund or verified bank reversal is recorded. Revoking that link does not erase the order and payment evidence needed for fulfilment, refunds, accounting, disputes and audits.

Complete delivery details are collected before payment so Adoryl can prepare a bank-confirmed order for dispatch. They are released to the operator only through the restricted fulfilment export after the exact bank credit has been confirmed; payment status and operator attention views do not show them.

If you report a UPI transaction reference, Adoryl stores an encrypted copy and a hashed copy used to prevent duplicate claims. The transaction reference is a payment report, not proof of bank credit. Adoryl checks it against the exact credit in the receiving account before marking the order paid or starting production.

Adoryl also records independent evidence from the receiving account: the bank transaction reference, exact credited amount, credit time, and the time the evidence was checked. Bank references are encrypted and hashed for duplicate detection. This evidence is available only through restricted operator tools and is used to reconcile orders, prevent the same credit from paying two orders, handle reversals and refunds, and maintain accounting and dispute records.

If an order is cancelled, Adoryl records the bounded cancellation reason and recording time. A completed full refund or verified full bank reversal records its encrypted and hashed transaction reference, exact amount, provider or bank event time, and operator recording time. If either event arrives after a fulfilment handoff, the ledger also records the stop cause, the bounded operational outcome, and the time that outcome was acknowledged. These fields keep money and production decisions auditable without exposing them on the public payment page.

A receiving-account credit that cannot be matched safely to one order is quarantined in an encrypted exception register. The register keeps its bank reference, amount, credit time, reason, any customer-reported reference, and independently verified refund, reversal, or control-transfer evidence. An open exception never marks an order paid or releases a print. Public status and alert notifications show only a redacted case count; private evidence is limited to the restricted reconciliation session.

Your chosen UPI app, its payment-service provider and the participating banks process the transfer under their own terms. Adoryl never asks for or stores your UPI PIN, OTP, bank login or full bank credentials. Do not send any of them by email or message.

International orders and PayPal

A private payment request is created only after Adoryl has reviewed and approved a final international order. Adoryl keeps the approved order reference, item summary, amount, currency, destination country, payment status, and PayPal order and capture identifiers. The destination postal code is encrypted at rest. These records are used to prevent duplicate payment, match payment to the order, handle refunds or disputes, and keep business and tax records.

PayPal processes the payment under its own terms and privacy notice. Adoryl receives confirmation and limited transaction details from PayPal, but does not receive or store your card details. PayPal may separately collect identity, account, payment, device, and delivery information needed to provide its service.

Anyone with the complete private payment link can view its limited order summary and, while eligible, start UPI or PayPal payment. Treat it like a password: do not forward that link or post it publicly. Ask Adoryl to replace it if it is shared by mistake.

An unclaimed direct-UPI order that expires or is cancelled is deleted after seven terminal days. An unclaimed and unsettled PhonePe order is instead de-identified after the same period as described below. Claimed, reviewed, paid, cancellation-marked review, refunded, reversed and fulfilment-handoff order evidence—and unmatched-credit and resolution evidence—is retained for seven years after the end of the Indian financial year in which the order or exception closes, and longer only while a tax, refund, reversal, consumer complaint, dispute or legal hold remains open. Adoryl then deletes or de-identifies it through a reviewed records process. Other order and payment records are kept only as long as needed for the stated fulfilment, refund, dispute, security, accounting and tax purposes.

Privacy-conscious analytics

Adoryl uses a self-hosted GoatCounter instance to measure aggregate page visits, referring sites, and fixed conversion events such as starting a print-quote request or opening a prepared email. The analytics service does not receive form-field contents, STL files, source images, prompts, quote measurements, names, email addresses, or project descriptions.

GoatCounter records aggregate browser, operating-system, screen-width, country, page, and referrer statistics. It does not retain raw IP addresses or create a cross-site advertising profile.

Adoryl runs Google Analytics 4 automatically on ordinary public storefront pages. It is configured without a consent banner: analytics storage is granted automatically when a public page loads. Google Analytics creates host-only, Secure, SameSite=Lax, session-only first-party cookies containing pseudonymous client and session identifiers. The cookies distinguish a browser and its current session, and expire when the browser session ends. Advertising storage, advertising-user-data collection, ad personalisation, Google Signals, URL passthrough and Enhanced Measurement remain disabled.

Neither analytics service receives form-field contents, delivery or payment details, STL files, source images, prompts, quote measurements, names, email addresses, mobile numbers, street addresses, or customer notes. The GoatCounter analytics payload Adoryl constructs contains only the public pathname, a bounded page title, a sanitised referrer, screen width, and fixed event names. Its self-hosted endpoint also receives ordinary connection metadata, including the IP address and User-Agent, when accepting the web request and deriving the aggregate statistics described above; it does not retain the raw IP address. GoatCounter never receives URL query strings or fragments. For Google Analytics, Adoryl supplies a sanitised public page path, bounded title, origin-only external referrer and fixed storefront events, with query parameters and fragments removed. The Google tag also sends its pseudonymous client and session identifiers, session and engagement measurements, and browser-provided details such as language, screen size, device and User-Agent information. Its request carries the IP address as ordinary connection metadata. Google states that GA4 uses the IP address at collection time to derive approximate location and discards it before the address is logged. This is not a transfer of names, email addresses, card or UPI credentials, but privacy laws may still treat identifiers, connection and device metadata as personal data.

Neither analytics service runs on private account, cart, checkout, PayPal /pay, UPI /upi or PhonePe /phonepe pages. Account profiles, cart contents, order references, delivery data and URL query values are therefore excluded from analytics. The secret part of a payment link is placed after the URL hash so it is not included in ordinary page requests or referrer information, and the page removes it from the address bar before lookup. Read Google's Analytics data safeguards for more information about Google's processing.

Advertising measurement

Adoryl advertises on Google, and may in future advertise on Meta. No advertising or remarketing pixel runs on this website, and no advertising cookie is set. Advertising storage, advertising-user-data collection, ad personalisation and Google Signals all remain denied in the analytics configuration described above. On the site's public pages the content-security policy allows scripts only from Adoryl's own origin and from www.googletagmanager.com, which here serves only the Google Analytics tag described above, and no advertising platform's own script, frame or pixel host is permitted anywhere on the site. The account, cart, checkout, order, UPI and PhonePe pages permit no external script host at all; the PayPal checkout page additionally permits PayPal's and Venmo's own scripts, which are payment hosts rather than advertising ones.

When you arrive from an advertisement, the advertising platform puts its own click identifier in the link you follow: Google uses gclid, gbraid or wbraid, and Meta uses fbclid. Adoryl reads that identifier from the address your browser was already given and stores it on Adoryl's own server against an Adoryl session, creating that first-party session cookie if you did not already have one. That server-side record expires 90 days after the click. It is a first-party record written by this site, not a third-party advertising cookie, and it is encrypted at rest like other order information.

Adoryl also keeps that same identifier in storage inside your own browser, not a cookie, so it survives your Adoryl session expiring before you place an order—a pre-authentication session expires after 24 hours, well short of the click's 90-day window. If a new browser session then reaches Adoryl while the stored identifier is still within that 90-day window, your browser sends it to Adoryl once more and remembers, only for that browser session, that it already has, so the same identifier is not resent on every page you visit.

If you then place an order, that identifier is copied onto the order record, where it is kept for as long as that order record is kept under “Data deletion and retention” below, not the 90 days above. Once the payment is confirmed, Adoryl's server reports the sale to the advertising platform directly, server to server. Google Ads receives the click identifier, the order reference, the order value in Indian rupees and the time of the sale. Meta, if and when it is enabled, receives the order reference as an event identifier, the order value, the currency, the time of the sale, the Meta click identifier together with the time that click was recorded, and a one-way SHA-256 hash of your email address, which is used only to match the platform's own records.

Adoryl never sends an advertising platform your name, your readable email address, your mobile number, your delivery address, or what you bought. If you have never arrived from an Adoryl advertisement, no click identifier is stored and no conversion is reported.

Security precautions

We use reasonable administrative and technical safeguards to protect personal data from unauthorised access, disclosure, loss and misuse, including HTTPS in transit, restricted operator access and encryption for specified order and payment evidence. Internet transmission cannot be guaranteed completely secure, so please do not send a UPI PIN, OTP, bank password, card security code or other authentication credential to Adoryl.

Data deletion and retention

You may ask to access, correct or delete eligible personal data by emailing hello@adoryl.com. We may delay or refuse deletion where information is needed for a pending shipment, refund, complaint, fraud review, accounting, tax, dispute or legal obligation. When a retention purpose ends, data is deleted or de-identified through the applicable records process.

Unclaimed and unsettled PhonePe orders that reach a terminal state are held for seven days. Adoryl then de-identifies the customer, contact and delivery details while retaining the minimum order and provider evidence needed for payment integrity and audit.

Your rights and choices

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, or withdraw consent for processing that depends on consent. Withdrawal is not retrospective and may prevent us from supplying a service that requires the information. Use the subject “Privacy request” so we can route and verify the request safely.

What Adoryl does not do

  • We do not require an account or email address for an instant STL quote.
  • We do not sell personal or project information.
  • GoatCounter does not use analytics cookies. Google Analytics uses session-only first-party cookies on public storefront pages; advertising storage remains denied, and Adoryl does not install advertising pixels. Purchase conversions are reported from Adoryl's server, never from your browser.
  • Adoryl does not train its own AI model on your uploads. Meshy's separate non-Enterprise terms described above apply to material sent for AI generation.
  • We do not put Meshy API credentials or private task details in the browser.

Email and project information

Information you deliberately email to Adoryl is used to assess, quote, and deliver the requested work. Email and accepted-order records are separate from the temporary instant quote process. Do not email confidential designs before the applicable confidentiality terms are agreed.

Changes to this policy

We may update this Privacy Policy to reflect changes to our services, providers or legal obligations. The revised date will appear at the top of this page, and material changes will be communicated where required by law.

Privacy contact

Privacy questions, grievances and rights requests can be sent to Pawan Kumar, Proprietor and Privacy Contact, Adoryl, CD-87, Mahavir Enclave Part 1, New Delhi 110045, India, at hello@adoryl.com or +91 88820 19875, Monday to Friday, 9:00–18:00 IST.