Privacy Policy
Last updated: September 1, 2026
MyStudios is built around one idea: your photos are yours. This policy explains what we collect, why, and what we never do with it.
What we collect
- Account data: email, name, and authentication data (password hash or Google sign-in), managed by our authentication system.
- Your photos: training photos you upload, room photos, and the photos you generate. Stored in our object storage and delivered over unguessable, unlisted links tied to your studios. They are never indexed, listed, or published.
- Billing data: handled by Stripe; we never see or store card numbers.
- Usage data: job history, credit ledger, and the technical logs needed to operate the service.
- Newsletter: your email address, if you leave the newsletter box ticked when creating an account (it is pre-ticked, untick it to skip). Every email has an unsubscribe link.
How photos are used
Uploaded photos are used to train your private model and are sent to our AI infrastructure provider (fal.ai) solely to run your jobs. Generated photos are delivered to your private studios. We do not use your photos to train shared or third-party models, we do not publish them, and we do not use them in marketing. Everything on our landing page comes from our own demo studios.
Deletion
Deleting a model removes its training photos and trained weights from our storage, together with its studios and every photo and clip in them. Deleting a single studio removes that studio's photos the same way and leaves the model in place. You can delete your whole account from your account settings: it first blocks new uploads and jobs, refuses to continue while a job is running, cancels any active subscription, and records every owned storage key until Cloudflare confirms its deletion. If billing or storage cannot be confirmed, the account or resource stays fenced and retryable instead of reporting a completed deletion. After confirmation, its database rows are removed and the action cannot be undone. Backups expire on a rolling schedule afterwards. fal.ai and any model provider it routes a job to may retain temporary job inputs or outputs under their own service terms; contact us if a downstream deletion request is needed. If you would rather we handled the request for you, write to support@mystudios.ai.
Who we share with
The processors used to run the service are Neon (database), Cloudflare (storage, delivery, and optional Turnstile abuse checks), fal.ai and the model providers it routes to (AI compute), Stripe (payments), Resend (transactional email and the newsletter), Upstash (sessions and rate limiting), Vercel (hosting), Sentry (error and performance diagnostics), Google (optional sign-in), and Visitors (audience measurement). Sentry is configured not to collect default personal information; application reports omit procedure input, client IP, email, and live credential links, but may carry an opaque job, resource, account, or provider identifier when one is needed to reconcile a failure. Optional Discord operational notifications contain event totals or plan names, not account identifiers. Visitors receives the page address, referrer, time on page, scroll depth, outbound link destinations, browser, device and connection type, and page-performance timings, plus the random identifier described under Cookies if you accepted it; its own handling of that data is described at visitors.now/privacy. We don't sell personal data, run ads, or share data with brokers.
Cookies
Three cookies, and only the last one is yours to decide.
- Session: keeps you signed in after you log in. Set only once you have an account, and strictly necessary to have one.
- cookie_consent: remembers whether you accepted or refused the next one, so the banner stops asking. Kept 13 months after an acceptance, 6 months after a refusal, then the question comes round again.
- visitor: set by our analytics provider, Visitors, and only if you accept. It holds a random identifier, no name and no email, so a returning reader can be told from a new one. It is renewed for a year on each visit while your consent lasts, and refusing deletes it.
Before you answer, and if you refuse, audience measurement still runs without any identifier: the address of the page you open (including anything after the ?), the page that referred you, how long you stay, how far you scroll, links you follow off-site, and page-performance timings are counted, and nothing is stored on your device to recognise you next time. Pages whose address carries a one-time link, such as a password reset, are left out of analytics entirely. Your studios and photos are never part of it.
You can change your choice at any time: . Visitors also honours your browser's Global Privacy Control and Do Not Track settings; with either switched on, it records nothing at all. Opening any page with ?visitors=false added to the address stores a flag in this browser's local storage that stops all analytics events (and ?visitors=true removes it); that flag does not remove the visitor cookie, which is what Refuse is for. No advertising cookies, ever.
Your rights
You can ask to access, export, correct, or delete your data at any time. Models, studios, individual media, account details, and the account itself can be corrected or deleted in the product; for a full access or export request, write to support@mystudios.ai. EU/EEA users: running your account and your studios rests on contract performance; the newsletter rests on your consent, given by leaving the sign-up box ticked and withdrawable through any email's unsubscribe link; counting pages and referrers without any identifier rests on our legitimate interest in knowing whether the site works; joining your visits into one journey through the visitor cookie rests on your consent, asked for by the cookie banner and withdrawable at any time from the Cookies control. You may lodge complaints with your local authority.
Changes
We'll announce material changes by email or in-product. Questions: support@mystudios.ai.