TONE3D
FULL PRIVACY POLICY
1. INTRODUCTION
TONE3D as a subsidiary of Aemass, Inc. and including its wholly-owned subsidiaries, collectively herein as “TONE3D” “us,” “we,” or “our”, is a leading provider of patented 3D scanning innovation, products, and technology services. At TONE3D our mission is to connect 3D data with human performance and health. We operate to provide motivational data and landmarks that work to improve and enhance your quality of life, and not invade or interfere with your needs. We take your privacy seriously and want you to understand how we use, collect, and share Personal Data and the efforts that we take to protect your Personal Data. “Personal Data” means any information that identifies you or can be reasonably linked to you, or information which is otherwise considered to be “personal information” or “personal data” under applicable laws.
We remain committed to protecting the privacy of your personal information and are providing this Privacy Policy (this “Policy”) to describe how we collect, use, and disclose personal information through our digital services either through our website at www.tone3d.com (our “Public Site”), other sites that refer to this Privacy Policy (collectively, our “Websites”), or through specific TONE3D branded technologies, products and services provided by TONE3D to its customers. This includes TONE3D specific 3D scanner applications, hosted web products, digital mobile products, server data products and general services (collectively, the “Services”). This Policy does not apply to all Aemass, Inc. products and only the TONE3D suite of application services.
2. ROLES OF PROCESSOR VS. CONTROLLER
This Privacy Policy does not cover the practices of companies or people that we do not own, control or manage. We are not responsible for the policies and practices of any third parties, and we do not control, operate, or endorse any information, products, or services that may be offered by third parties or accessible on or through the Services. For clarity, we are responsible for the data protection practices of our data processors (i.e., those processing Personal Data of which we are the controllers in relation to the Services) in accordance with the data protection laws applicable to the jurisdiction in which you reside.
We have relationships with various independent consumers, businesses, researchers, and other entities ( “Customers”) which may require us to collect and process personal information on their behalf. This may happen, for example, if a Customer licenses our technology or uses our scanners in its business, or integrates our technology into its own website or mobile app. In these cases, we will comply with the privacy-related instructions given to us by the Customer and you should review that Customer’s privacy policy to determine how it uses your information. In these situations, we consider the third-party Customer to be the “controller” of the personal information, and us to be the “processor” unless we and the Customer otherwise agree.
If you ask us to provide Personal Information to a Customer, then that Customer’s use of personal information will be governed by that Customer’s privacy policy and our use will be governed by this Policy. When this happens, then both TONE3D and the Customer will be considered to be “controllers” of the personal information.
In all other cases, such as in the direct relationship between you and the TONE3D mobile or web service applications, we are acting as the “controller” of personal information (such as when an individual sings up or in to the TONE3D mobile application).
We have provided supplemental notices below for residents of certain U.S. states and individuals located in Taiwan.
3. HOW WE COLLECT PERSONAL DATA
We collect Personal Data about you from the following sources:
4. PERSONAL DATA WE COLLECT
We collect personal information when you register for or use our Services, or when you fill out our contact form on our web or application endpoints requesting additional information about our Services. This personal information may include (as further described below) among other things, your name, contact information, body measurements, age, etc. If you contact our technical support team for questions about our Services, TONE3D will obtain information about you in order to confirm that you are a lawful user of our Services with a right to receive support, and in order to provide the requested support.
For certain Services, you may undergo a body scanning process which uses imaging cameras and infrared sensors, and/or other technologies to map out the shape and contours of your body and body data may be both gathered and created through the form of photographs which are processed to create body data, enhanced imagery, and hybrid digitally enhanced and observed body data. The body data and other data relating to you may be processed for the purpose of supplying goods or services to you, keeping proper records of those transactions, improving training model accuracy and assisting us in the development, debugging and testing of our mobile app and our Services. Body data and Scan Data Input may be viewed or handled by our designated access technicians to provide support. The legal basis for this processing is the performance of a user contract between you and us (or between you and one of our Customers), taking steps (at your request) to enter into such a contract, and/or your specific consent to use such information for these purposes.
If you supply any other person's personal data to us, you must do so only if that person has authorized you to do so. Note that providing body data or imagery of any other person’s personal data, willingly or accidentally, may void the Terms of Service and inhibit or corrupt your own data information.
Specifically, to perform such Services, we may collect the following types of Personal Data as follows:
5. COOKIES AND SIMILAR TECHNOLOGIES
TONE3D may use cookies and similar technologies such as pixel tags, beacons, GIFs and JavaScript (collectively “Cookies”) to inform us how and when on our Websites and Services and for user session management in order to operate, improve our Services and provide improved costumer user experiences. Cookies are small pieces of data included on or within the Services (such as on a website or in an email) or placed on your computer, tablet, phone, or similar device when you use that device to visit our Services. A cookie can be text data that a website transfers to the individual's browser from a web server that is stored on the individual's computer hard drive. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s). If you live in Europe, we will obtain your (opt-in) consent prior to deploying any cookies other than cookies which are regarded under European laws as being “strictly necessary” (i.e., Essential Cookies, as described below). We may use such data to create reports about the use of our Websites. For example Google, Inc. (“Google”) or Google Ads may also store this data. For more information about how Google stores and use your personal information, please see Google’s Privacy Policy. We may also use pixel tags, web beacons, and other similar technologies to record information about how individuals access our Services. This information is typically not personally identifiable and may include internet protocol (IP) addresses (or the DNS name associated with it) of the individual's computer, the website from which the individual linked to our Services, and the browser software the individual is using to access our Services.
Cookie Usage and Type. TONE3D may uses the following Cookies:
General online tracking opt-outs. There are a number of ways you can opt out of certain interest-based advertising and other online tracking activities, which we have summarized below.
Advertising industry opt-out tools.
Note that some opt-out features are Cookie-based, meaning that when you use these opt-out features, an “opt-out” Cookie will be placed on your computer or other device indicating that you do not want to receive interest-based advertising from certain companies. If you delete your Cookies, use a different browser, or use a different device, you will need to renew your opt-out choice.
Opting out of interest-based advertising does not mean that you will no longer receive online ads. It only means that such ads will no longer be tailored to your specific viewing habits or interests. You may continue to see ads on and about the Services.
6. HOW WE USE PERSONAL DATA
We may process and use Personal Data for the following purposes:
Service delivery, including to:
Research and development. We may create and use Aggregated Data, De-Identified Data, or other anonymous data from Personal Data we collect, including health and body data, for our business purposes, including to analyze the effectiveness of the Services, to improve and add features to the Services, and to analyze the general behavior and characteristics of users of the Services. We also use anonymous data for research purposes to help us answer important questions about human body health and create improved upon experiences for our members by identifying newly developed insights, providing new content, improving accuracy of outputs, processing, innovations and product features.
Direct marketing and advertising. We may use data from the Personal Data we collect, including health, fitness, diet and body data and other certain data collected when you browse our website, to send you direct offers or other TONE3D specific marketing messages or to advertise the Services or other TONE3D product offerings.
Interest-based advertising. We engage our advertising partners, including third party advertising companies and social media companies, to advertise our Services. We and our advertising partners may use Cookies and similar technologies to collect information about your interaction over time across the web, our communications, and other online services, and may use that information to serve online ads. We comply with the Digital Advertising Alliance Self-Regulatory Principles for Online Behavioral Advertising. To learn more about the industry self-regulatory programs and other information and choices about interest-based ads, please see the section above entitled “Online tracking opt-outs.”
Compliance and protection. Including to:
7. HOW WE SHARE PERSONAL DATA
We may share a portion or all, as may be required, of your Personal Data with:
8. HOW YOU MAY SHARE PERSONAL DATA THROUGH THE SERVICES
Depending on how you use the Services, you may share Personal Data with:
9. TONE3D SUBSCRIPTION SERVICES AI & THIRD-PARTY AI TECHNOLOGY
TONE3D utilizes generative Artificial Intelligence ("AI") features, such as TONE3D Assist, that are intended to help you understand and make progress to your goals, decipher TONE3D data and concepts, provide educational and motivational guidance, and integrate with the rest of your TONE3D experience. TONE3D Assist creates a narrative or chat experience by combining your unique anonymized TONE3D metrics with the science of TONE3D data to help you optimize your health, fitness, and performance.
If you decide to use TONE3D Assist note that TONE3D may leverage third-party AI technology provided by our LLM partner, by our own LLM development, or by a combination of third party and self hosted LLM technology. This technology is trained on real-world data to generate intelligent and personalized responses in conversations with users. Responses from TONE3D Assist are based on your inputs, your requests and relevant information collected through your TONE3D metrics.
We require any LLM partner to use your anonymized TONE3D metrics only for the purpose of allowing TONE3D to generate content for you. We have ensured that our LLM partner has a “Zero-Retention/Zero Training Policy” with respect to your TONE3D metrics, meaning that our LLM partner will not store or retain any of the anonymized TONE3D metrics they receive through your use of TONE3D, and our LLM partner will not use any of the anonymized TONE3D metrics they receive for training any algorithms or LLM technology.
We will only share anonymized TONE3D metrics with our direct LLM partner. We ask that you refrain from providing any identifying information, such as your full name, in conversations with TONE3D Assist. TONE3D may retain the history of your conversations with TONE3D Assist to ensure you continue to have access to previous conversations while using the feature. When you revisit any topics from previous interactions, TONE3D may share the context of your previous inputs with new TONE3D Assist sessions to create a tailored experience for you. You may delete your TONE3D chat data at any time by either accessing the chat icon in TONE3D Assist or TONE3D Settings to view your conversation history.
If you choose to use TONE3D Assist please note that, consistent with our privacy principles, TONE3D employees will only ever access member Personal Data when required to provide services and support, which may include collected information about your experience with TONE3D to assess the performance of and improve TONE3D Assist and other product offerings. In the case that TONE3D Assist suggests connecting to Membership Services, you can opt in and have your support request automatically filed with our team. In this case, they will only have access to that specific conversation to provide you with the best support.
Membership Services Intelligence. TONE3D Membership Service also may utilize generative AI features that are intended to assist you in receiving member support. Membership Services thus may use third-party AI technology provided by our LLM partner. This technology is trained on real-world data to generate intelligent and personalized responses in conversations with users. Responses from Membership Services are based on your requests and relevant information collected through your TONE3D membership. For example, if you ask Membership Services a question regarding your order, Membership Services will draw on your purchase records. We require our LLM partner to use your anonymized TONE3D metrics only for the purpose of allowing Membership Services and AI to generate content for you. We have ensured that our LLM partner has a “Zero-Retention/Zero Training Policy” with respect to your TONE3D metrics, meaning that our LLM partner will not store or retain any of the anonymized TONE3D metrics they receive through your use of Membership Services, and our LLM partner will not use any of the anonymized TONE3D metrics they receive for training any algorithms or LLM technology. We will only share anonymized TONE3D metrics with our direct LLM partner(s).
TONE3D may retain the history of your conversations with Membership Services to ensure you continue to have access to previous conversations while using the feature. When you revisit any topics from previous chats, TONE3D may share the context of your previous conversations with Membership Services to create a better experience for you. Consistent with our privacy principles, TONE3D employees will only access member Personal Data when required to provide services and support, which may include collecting information about your experience with Membership Services to assess the performance of and improve Membership Services AI and other product offerings.
10. YOUR CHOICES
Access, update, or delete. When you log in to your account, you may access, and, in some cases, edit or delete certain information you’ve provided to us, such as first and last name, username and password, email and mailing address, and other information in your profile. When you update information, however, we may maintain a copy of the unrevised information in our records. You may request access to or a full deletion of your account and corresponding data by contacting privacy@tone3d.com or via Data Management features available in the TONE3D Services. You may be asked to complete a verification form in connection with such access or deletion request in order to ensure that you have the authority to access or delete your account. We may need to retain certain Personal Data in our records, as well as aggregated data or de-identified data derived from or incorporating your Personal Data that does not identify you after you update or delete it.
Privacy settings. You can review and in some cases may be able to change certain privacy settings or opt-out requests via Settings, located on the Main Menu page of the TONE3D mobile application.
Push notifications and device permissions. You can change your settings related to push notifications and device permissions through the settings on your mobile device.
Geolocation data. You may allow or disallow TONE3D to collect geolocation data by enabling or disabling location services on your mobile device. If you decline to grant TONE3D access to this data, we may not be able to provide certain Services, capabilities, or features to you.
TONE3D Assist and general support. You can choose whether or not to enable and interact with TONE3D Assist. We will only share your anonymized TONE3D metrics with our LLM partner that powers TONE3D Assist if you enable and engage with the feature. If you wish to update your data preferences, you can visit the “Assisting Mode” section of your TONE3D Assist settings. If you no longer wish to use TONE3D Assist, you can simply not interact with the feature, or you can disable the feature entirely from your TONE3D mobile application settings at any time.
Marketing communications. You can opt-out of marketing-related emails and other communications by contacting privacy@tone3d.com or by following the opt-out or unsubscribe instructions contained in the marketing-related message. You cannot opt-out of receiving certain non-marketing emails regarding the Services or access to your account.
Online tracking opt-outs. There are a number of ways you can opt-out of certain interest-based advertising and other online tracking activities, which we summarize in the “Online tracking opt-outs” section above.
Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to online services. The Services may not currently support all “Do Not Track” requests or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
11. OTHER SITES AND SERVICES
The Services may contain links to websites and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control mobile applications, websites, or online services offered or operated by third parties, and we are not responsible for their actions. You can learn about and control how these third parties use and share Personal Data, including with TONE3D, by reviewing their privacy notices and exercising the privacy choices the third party may offer.
12. DATA SECURITY AND RETENTION OF PERSONAL DATA
We employ a number of physical, technical, organizational, and administrative security measures designed to protect the Personal Data we collect. While we endeavor to protect the privacy of your account and other Personal Data we hold in our records, no security measures are failsafe, and we cannot guarantee the security of your Personal Data.We retain Personal Data for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a business need to do so, or as required by law (e.g., for tax, legal, accounting, or other purposes), whichever is longer.
13. PERSONAL DATA OF CHILDREN
TONE3D Services are intended only for users 15 years of age and over. Furthermore, if you are under the age to consent to data sharing, as applicable based on your jurisdiction, please do not attempt to register for the Services or send any Personal Data about yourself to us. If we learn that our services have collected Personal Data from a child under the age to consent in data sharing, as applicable to a given jurisdiction, we will delete that information as quickly as possible. If you believe that a child under the age to consent in data sharing may have provided Personal Data, please contact us at privacy@tone3d.com.
14. U.S. STATE-SPECIFIC PRIVACY NOTICE
If you are a resident of California, Colorado, Connecticut, Delaware (as of January 1, 2025), Iowa (as of January 1, 2025), Maryland (as of October 1, 2025), Minnesota (as of July 31, 2025), Montana, Nebraska (as of January 1, 2025), New Hampshire (as of January 1, 2025), New Jersey (as of January 15, 2025), Oregon, Tennessee (as of July 1, 2025), Texas, Utah, and Virginia, the law in your state may provide you with the following rights:
In addition, and as set forth below, California law requires us to identify, for the 12-month period prior to the date of this Privacy Policy, what information we may have “sold” or “shared” about you. For the 12-month period prior to the date of this Privacy Policy, TONE3D has not sold ANY Personal Data. TONE3D does not sell Personal Data. For the 12-month period prior to the date of this Privacy Policy, TONE3D has only shared Personal Data as described above. As we explain in this Privacy Policy, we use Cookies and other tracking technologies to analyze website and application traffic and use, and to facilitate advertising. To limit use of Cookies and other tracking technologies, please review the instructions provided in the “Online tracking opt-outs” section. You may also direct us to share your data, as described in the “How You Share Personal Data Through the Services” section of the Privacy Policy.You are entitled to exercise the rights described above free from discrimination.
Exercising Your Rights. To exercise these rights, you can submit requests as follows:
Please note that we are only required to honor ‘requests to know’ twice in a 12-month period.
California Shine the Light. This Privacy Policy describes how TONE3D may share your Personal Data for marketing purposes. If you are a California resident, the Shine the Light law permits you to request and obtain from us once per calendar year information about any of your Personal Information as shared with third parties for their own direct marketing purposes, including the categories of information and the names and addresses of those businesses with which we have shared such information. To request this information and for any other questions about our privacy practices and compliance with California law, please contact us through the contact form on our website.
15. NEW TRANS-ATLANTIC DATA PRIVACY FRAMEWORK
The judgment in the Schrems II case issued by the European Court of Justice in 2020 found that Privacy Shield framework no longer provides adequate safeguards for the transfer of personal data to the United States from the EEA.The US and the European Commission announced in 2022 an “agreement in principle” to develop a new Trans-Atlantic Data Privacy Framework (“ TADP Framework”). The TADP Framework is intended to re-establish a legal mechanism for transfers of EU personal data to the U.S. after the Court of Justice of the European Union invalidated the EU-US Privacy Shield. In the interim, to ensure that transfers of personal data from the EU to the US can occur in line with European data protection laws, TONE3D will enter into the Standard Contractual Clauses with our vendors who process personal data, and with our customers upon request. These Standard Contractual Clauses legitimize the transfer of personal data from the EU to the US.
16. PRIVACY NOTICE FOR EUROPEAN RESIDENTS
If you are a resident of Europe, you may have additional rights under the General Data Protection Regulation (the “GDPR”) and other European data protection and e-privacy laws. To the extent of any conflict between the provisions set out in this Section 16 and Section 17 and any other provision in this Privacy Policy, the former shall control to the extent of such conflict.Controller and European Representatives. TONE3D will be the controller of your Personal Data processed in connection with the Services. TONE3D may utilize professional representatives for Data Protection Services within Europe.You may contact us to receive information on any one of our EU representatives at: privacy@tone3d.com.The “How We Use Personal Data” section above explains how we use your Personal Data. We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others but will depend on the type of Personal Data and the specific context in which we process it. However, the legal bases we typically rely on for each category of processing activity are set out below.
Service delivery. Processing is necessary to perform our contract, or to take steps that you request in engaging our Services. Where we cannot process your Personal Data as required to operate the Services on the grounds of contractual necessity, we process your personal information for this purpose based on our legitimate interest in providing you with the products or Services you access and request.
Research and development. These activities constitute our legitimate interests.Marketing and advertising: Processing is based on your consent where that consent is required by applicable law. Where such consent is not required by applicable law, we process your personal information for these purposes based on our legitimate interests in promoting our business.
Compliance and protection. From time to time, we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
Consent. To the extent that wellness data that we collect is considered consumer health data or another special category of Personal Data subject to the GDPR, we will ask for your explicit consent to process this data. You can use your account settings and tools to withdraw your consent at any time, including by installing the TONE3D mobile application, stopping use of a feature or subscription tier, removing our access to a Third-Party service, or deleting your data or your account. In addition, in some cases, such as when you direct us to share it, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, you have the right to withdraw it any time in the manner indicated at the time you give consent or in as listed in our Services.We may use your Personal Data for reasons not described in this Privacy Policy where permitted by law and where the reason is compatible with the purpose for which we collected it. If we need to use your Personal Data for an unrelated purpose, we will notify you and explain the applicable legal basis.
Retention. To determine the appropriate retention period for your Personal Data, we consider the amount, nature, and sensitivity of the information, the value and request of a user to retain such information regarding the Services to be performed, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Solely automated decision-making. We do make decisions based on automated processing that may invole personal data, including profiling, which produce legal effects or similarly significantly affects you, including in connection with the personal data processing activities described under this Privacy Policy and Section 8 and Section 9 above.
Data Subject Rights. You have certain rights with respect to your Personal Data, including:
17. PRIVACY NOTICE FOR TAIWAN RESIDENTS
How We Share Personal Data. Personal Data that we collect may be stored, processed in, or transferred between parties located outside your jurisdiction, including the United States, Germany, Japan, United Kingdom, France, Canada, and India. We take reasonable steps to ensure that the parties responsible for the storage of Personal Data on overseas servers adhere to this Privacy Policy.
The duration for which the Personal Data is to be used, stored, processed, transferred, and engaged in any other acts as set forth in this Privacy Policy is the entire duration required by applicable laws, or necessary for the purposes provided herein, including but not limited to Section 5 or Section 6, or pursuant to your authorization and purposes as listed in Section 8 and Section 10.
The methods of which the Personal Data is to be used, stored, processed, transferred, and engaged in any other acts as set forth in this Privacy Policy include but not limited in writing, through electronic document, telephone, facsimile, or other automated or non-automated means.
Your Choices to access, update, or delete. In addition to the right to request access to or a full deletion of your account and corresponding data, you may request a copy of Personal Data and that TONE3D ceases processing or use of Personal Data by contacting privacy@tone3d.com or via the “Settings” feature available in the TONE3D application.
In addition to your choices as set forth in Section 10 above and relevant rights to opt-out in accordance with Section 5 above you are entitled to exercise the following rights under Personal Data Protection Act of Taiwan, unless otherwise provided by the laws or if it is necessary for TONE3D and the categories of entities as described in Section 5 or Section 6 to provide services:
You are entitled to exercise any of the aforementioned rights from time to time at your discretion, however, please be advised that the provision of relevant services would therefore be precluded in circumstances where the necessary and accurate Personal Data is not available for TONE3D and the entities as listed herein.
By using the TONE3D Services you fully understand that this Policy is consistent with the requirements of Personal Data Protection Act and other relevant legislation in Taiwan, and that your acts in using any of TONE3D’s services, registering for or participating in any of TONE3D’s activities, whether online or offline, via TONE3D’s applications, software, website, platform, center, or other access means, or providing Personal Data for any other transactions between TONE3D and you, constitutes your consent for TONE3D to collect, process, use, transfer, and otherwise engage your Personal Data as set forth in this Policy.
18. SELECT DEFINITIONS
We use some specifically defined terms in our Privacy Policy and when we communicate about our Privacy Policy. We want to be clear on how the terms we use are defined to help you better understand our policies.
Aggregated Data: Aggregated Data is data that has undergone a process whereby raw data is gathered and expressed in a summary form for statistical analysis. Raw data can be aggregated over a given time period, across individuals, or both, to provide statistics such as average, minimum, maximum, sum, and count. After the data is aggregated analysis can be performed to gain insights about particular data sets or across sub-sets of particular data. When data is aggregated across a number of individuals, the resulting aggregation is considered anonymized such that it is no longer Personal Data.
Cookies: Cookies are small files which are stored on a user’s computer. They are designed to hold a modest amount of data specific to a particular user and website and can be accessed either by the web server or the user computer. This allows the server to deliver a page tailored to a particular user, or the page itself can contain some script which is aware of the data in the cookie and is therefore able to carry information from one visit to the website (or related site) to the next.
De-Identified Data: De-Identified Data is data where all the personally identifiable information has been removed, rendering the data anonymous by stripping out information that would allow an individual’s identity to be determined from the remaining data. Data is “de-identified” to protect the privacy and identity of individuals associated with the data. De-identified Data is no longer Personal Data.
19. CHANGES TO THIS PRIVACY POLICY
We strive to constantly and consistently improve our Services and may need to change this Privacy Policy from time to time. Changes will be posted on the TONE3D website and available on other TONE3D Services. We will alert you to material changes by placing update notices on the TONE3D website, by sending you an email, and/or by some other means. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.
20. CONTACTING TONE3D
If you have any questions or concerns regarding our privacy policy or policies or wish to exercise your rights please send us a detailed message at the mailing address or email contact below.
TONE3D c/o Aemass, Inc. Attn: Privacy and Legal Department
711 Calle Artis
San Jose, California, USA 95131
privacy@tone3d.com
support@tone3d.com
www.tone3d.com
pp 2025 v.1.01