Sloyd
sloyd.aiSloyd is an AI 3D asset generation tool that lets users create 3D models from text, images, and parametric templates. The consumer-facing documents grant users a favorable perpetual worldwide license to generated models and describe a GDPR-oriented privacy posture with clear data-subject rights, but they are notably thin on AI-specific concerns: there is no statement on whether user prompts or uploaded reference images are used to train models, no security controls disclosed, no certifications, and no explicit deletion SLA. A material discrepancy exists between the two document types: the Terms name the US entity 'Sloyd Inc.' while the Privacy Policy names the Norwegian entity 'Sloyd AS,' with conflicting governing-law implications. Combined with silence on training-data use and the absence of any enterprise/DPA document, the tool warrants moderate caution before use with proprietary or sensitive input data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The Terms address uploaded reference images only to prohibit third-party copyrighted content, and the Privacy Policy covers personal/contact data, but neither document explicitly states who owns the prompts, images, or files a user submits. This silence on input ownership leaves the user without a clear contractual assurance that their submitted content remains theirs.
Output Data Ownership
Users receive a broad, non-exclusive, perpetual, worldwide license to use generated 3D models for personal and commercial purposes, including alterations. Reselling/redistribution is permitted under the Pro plan, and freelancers may sell models to clients directly, giving users favorable rights over generated output.
Training Data Usage
Neither the Terms nor the Privacy Policy state whether user prompts, uploaded reference images, or generated models are used to train or improve Sloyd's AI models. Given the product is explicitly AI-first (including a 'Custom AI Training' feature), this silence is a meaningful gap and users cannot confirm their inputs are excluded from model training.
Data Retention & Deletion
The Privacy Policy commits to deleting or anonymizing personal data when no longer necessary and grants an erasure right, which is favorable, but provides no specific retention schedule or deletion SLA. The Terms are weaker on stored content, reserving broad discretion to delete projects and models for inactivity or capacity reasons with only reasonable-effort email notice.
Third-Party Data Sharing
Sloyd uses data processors under data processing agreements for IT and administrative services, and shares payment data with an authorized third-party processor, all of which is disclosed and purpose-limited. However, it may also pass information to third parties for marketing on other platforms, which — although consent-gated — broadens sharing beyond core service delivery.
Opt-Out Rights
The Privacy Policy provides meaningful opt-out mechanisms: consent for non-essential cookies and marketing sharing can be withdrawn at any time, and users have GDPR rights to object to processing and direct marketing. These are explicit and user-favorable controls.
Compliance & Certifications
The Privacy Policy is clearly aligned to GDPR and Norwegian data protection law and describes SCCs for international transfers, and the Terms reference CCPA compliance by its payment processor. However, no framework relevant to a developer-infra/consumer tool (SOC 2, ISO 27001/27017/27018, ISO 42001, EU AI Act) is certified or even claimed for Sloyd itself, and the 'PII compliant' claim is not a recognized standard.
Model Explainability & Auditability
Neither document offers any transparency into how the AI models behave, nor any enterprise auditing capability, audit logs, or explainability commitments. For an AI-first product this complete silence is a high-risk gap.
Security Practices & Breach History
The documents assert account security is taken seriously and rely on third-party payment/authentication providers, but disclose no concrete security controls — no encryption at rest/in transit, access controls, penetration testing, bug bounty, or incident response. There is no security page or trust center and no breach history disclosure.
Enterprise vs. Consumer Risk Delta
The Terms distinguish Free/Starter, Plus, and Pro tiers primarily on features (e.g., reselling rights require Pro; support is self-service on Plus), but describe no differences in data handling, privacy, or security between tiers. No enterprise agreement was provided, so no enhanced data protections for business users can be confirmed.
Human Review of User Inputs
The documents are silent on whether Sloyd staff may access, read, or review user prompts, uploaded images, or generated outputs. There is no explicit reservation of a human review right, but also no assurance against it, leaving the question unanswered.
Regulatory & Litigation Exposure
The Privacy Policy notes data may be disclosed to comply with applicable law or to pursue Sloyd's own legal claims, and the Terms specify US governing law and US courts for disputes. There are no disclosed active disputes or specific law-enforcement request procedures.
PII & SPI Data Inventory
Sloyd collects a limited set of PII — name, username, email, IP address (anonymised), browser/device info, approximate location, and a visitor UUID — with clear purpose limitation. While the policy defines special-category data conceptually, it does not indicate that Sloyd actively collects SPI from users, keeping the inventory relatively minimal and well-disclosed.
Policy–Product Currency
The Terms were last updated 16 February 2026 (recent relative to the August 2026 analysis date), while the Privacy Policy dates to 23 April 2025 (over a year old). Although the product is heavily AI-first — text-to-3D, image-to-3D, AI rigging, custom AI training — neither policy substantively addresses AI/ML processing, model training on user inputs, or third-party model providers, leaving material coverage gaps despite reasonably current dates.
Cross-Document Consistency
Two document types were supplied (Terms and Privacy Policy) and they materially conflict on the identity of the contracting/controlling entity and the applicable legal regime: the Terms name US-registered 'Sloyd Inc.' governed by US law, while the Privacy Policy names Norwegian 'Sloyd AS' as data controller under GDPR/Norwegian law. A user would reach different conclusions about which entity is responsible and which jurisdiction applies depending on which document they read.
You've read all 15 risk ratings for Sloyd. Create a free account to see the exact policy wording behind each rating.