Sloyd logo

Sloyd

sloyd.ai
Moderate Risk
Updated August 13, 2026

Sloyd is an AI 3D asset generation tool that lets users create 3D models from text, images, and parametric templates. The consumer-facing documents grant users a favorable perpetual worldwide license to generated models and describe a GDPR-oriented privacy posture with clear data-subject rights, but they are notably thin on AI-specific concerns: there is no statement on whether user prompts or uploaded reference images are used to train models, no security controls disclosed, no certifications, and no explicit deletion SLA. A material discrepancy exists between the two document types: the Terms name the US entity 'Sloyd Inc.' while the Privacy Policy names the Norwegian entity 'Sloyd AS,' with conflicting governing-law implications. Combined with silence on training-data use and the absence of any enterprise/DPA document, the tool warrants moderate caution before use with proprietary or sensitive input data.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The Terms address uploaded reference images only to prohibit third-party copyrighted content, and the Privacy Policy covers personal/contact data, but neither document explicitly states who owns the prompts, images, or files a user submits. This silence on input ownership leaves the user without a clear contractual assurance that their submitted content remains theirs.

Confidence
45%

Output Data Ownership

Low Risk

Users receive a broad, non-exclusive, perpetual, worldwide license to use generated 3D models for personal and commercial purposes, including alterations. Reselling/redistribution is permitted under the Pro plan, and freelancers may sell models to clients directly, giving users favorable rights over generated output.

Confidence
80%

Training Data Usage

Moderate Risk

Neither the Terms nor the Privacy Policy state whether user prompts, uploaded reference images, or generated models are used to train or improve Sloyd's AI models. Given the product is explicitly AI-first (including a 'Custom AI Training' feature), this silence is a meaningful gap and users cannot confirm their inputs are excluded from model training.

Confidence
40%

Data Retention & Deletion

Moderate Risk

The Privacy Policy commits to deleting or anonymizing personal data when no longer necessary and grants an erasure right, which is favorable, but provides no specific retention schedule or deletion SLA. The Terms are weaker on stored content, reserving broad discretion to delete projects and models for inactivity or capacity reasons with only reasonable-effort email notice.

Confidence
60%

Third-Party Data Sharing

Moderate Risk

Sloyd uses data processors under data processing agreements for IT and administrative services, and shares payment data with an authorized third-party processor, all of which is disclosed and purpose-limited. However, it may also pass information to third parties for marketing on other platforms, which — although consent-gated — broadens sharing beyond core service delivery.

Confidence
68%

Opt-Out Rights

Low Risk

The Privacy Policy provides meaningful opt-out mechanisms: consent for non-essential cookies and marketing sharing can be withdrawn at any time, and users have GDPR rights to object to processing and direct marketing. These are explicit and user-favorable controls.

Confidence
75%

Compliance & Certifications

Moderate Risk

The Privacy Policy is clearly aligned to GDPR and Norwegian data protection law and describes SCCs for international transfers, and the Terms reference CCPA compliance by its payment processor. However, no framework relevant to a developer-infra/consumer tool (SOC 2, ISO 27001/27017/27018, ISO 42001, EU AI Act) is certified or even claimed for Sloyd itself, and the 'PII compliant' claim is not a recognized standard.

Confidence
62%

Model Explainability & Auditability

High Risk

Neither document offers any transparency into how the AI models behave, nor any enterprise auditing capability, audit logs, or explainability commitments. For an AI-first product this complete silence is a high-risk gap.

Confidence
55%

Security Practices & Breach History

High Risk

The documents assert account security is taken seriously and rely on third-party payment/authentication providers, but disclose no concrete security controls — no encryption at rest/in transit, access controls, penetration testing, bug bounty, or incident response. There is no security page or trust center and no breach history disclosure.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The Terms distinguish Free/Starter, Plus, and Pro tiers primarily on features (e.g., reselling rights require Pro; support is self-service on Plus), but describe no differences in data handling, privacy, or security between tiers. No enterprise agreement was provided, so no enhanced data protections for business users can be confirmed.

Confidence
50%

Human Review of User Inputs

Moderate Risk

The documents are silent on whether Sloyd staff may access, read, or review user prompts, uploaded images, or generated outputs. There is no explicit reservation of a human review right, but also no assurance against it, leaving the question unanswered.

Confidence
40%

Regulatory & Litigation Exposure

Moderate Risk

The Privacy Policy notes data may be disclosed to comply with applicable law or to pursue Sloyd's own legal claims, and the Terms specify US governing law and US courts for disputes. There are no disclosed active disputes or specific law-enforcement request procedures.

Confidence
58%

PII & SPI Data Inventory

Low Risk

Sloyd collects a limited set of PII — name, username, email, IP address (anonymised), browser/device info, approximate location, and a visitor UUID — with clear purpose limitation. While the policy defines special-category data conceptually, it does not indicate that Sloyd actively collects SPI from users, keeping the inventory relatively minimal and well-disclosed.

Confidence
65%

Policy–Product Currency

Moderate Risk

The Terms were last updated 16 February 2026 (recent relative to the August 2026 analysis date), while the Privacy Policy dates to 23 April 2025 (over a year old). Although the product is heavily AI-first — text-to-3D, image-to-3D, AI rigging, custom AI training — neither policy substantively addresses AI/ML processing, model training on user inputs, or third-party model providers, leaving material coverage gaps despite reasonably current dates.

Confidence
60%

Cross-Document Consistency

High Risk

Two document types were supplied (Terms and Privacy Policy) and they materially conflict on the identity of the contracting/controlling entity and the applicable legal regime: the Terms name US-registered 'Sloyd Inc.' governed by US law, while the Privacy Policy names Norwegian 'Sloyd AS' as data controller under GDPR/Norwegian law. A user would reach different conclusions about which entity is responsible and which jurisdiction applies depending on which document they read.

Confidence
70%

You've read all 15 risk ratings for Sloyd. Create a free account to see the exact policy wording behind each rating.