Skip to content
Proposition Studio
Product
FeaturesWorkflowProofGeneration tree
FAQ
Sign inRequest access
FAQFeaturesWorkflowProofGeneration treeSign inRequest access
Legal/Privacy Policy

Proposition Studio

Privacy Policy

This Privacy Policy explains which personal data Proposition Studio processes across the public website and the account-based application, why it is used, which recipient categories receive it, how long it is retained, and how to exercise privacy rights.

Version 2026-08-29Effective 29 August 2026

Contents

  1. 1. Controller and contact
  2. 2. Scope
  3. 3. Data we process
  4. 4. Sources of data
  5. 5. Purposes and legal bases
  6. 6. Service providers and data recipients
  7. 7. Provider training and human review
  8. 8. Administrative access
  9. 9. International transfers
  10. 10. Retention
  11. 11. Deletion, export and rights requests
  12. 12. Cookies and public-site analytics
  13. 13. Security and incidents
  14. 14. Children and changes

1. Controller and contact

The controller is the Provider identified in section 1 of the Terms of Service, unless a specific notice says otherwise. Contact: hello@propositionstudio.com.

You may also lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland or, where applicable, another competent EEA supervisory authority.

2. Scope

This notice covers visitors to propositionstudio.com, people who submit a Request Access or pilot-interest form, invited and registered app users, customers, support and complaint contacts, and people whose personal data appears in User Content.

The public marketing website and app.propositionstudio.com are separate technical surfaces. The app requires an account and uses authentication; the marketing website runs public content and a Request Access and pilot-interest form.

3. Data we process

We process the data described below when it is provided, generated by the Service or required for a specific function.

  • Account and identity data: email address, display name, account and workspace identifiers, invitation, Request Access and activation records, Google OAuth identifiers where Google sign-in is used, password credentials in hashed form, sessions and security state.
  • Product content: project names, prompts, input and reference images, generated outputs, masks, annotations, settings, model and operation metadata, lineage, export and archive state.
  • Usage, credit and operations data: credit balance and ledger events, generation jobs, provider references, request timestamps, limits, costs, failures and support diagnostics.
  • Public-site and access-request data: email, first name, last name, country, profession, inbound channel, locale, form placement, referrer host and permitted UTM parameters; public page path, referrer, language, approximate region, screen or device information, performance metrics and the typed engagement events described in the Cookie Notice. Free-text answers provided for “other” profession or inbound channel stay in the Admin request record and are not sent on the private inbound alert.
  • Communication data: support, complaint, privacy and legal requests, attachments, resolution records, invitation and password-reset delivery records.
  • Technical and security data: IP address where received, user agent, timestamps, session cookies, rate-limit signals, request and error records, security and administrative audit events.
  • Future payment data only when a purchase flow is offered: order and payment-provider identifiers, status, gross amount, currency, tax and invoice information. Full card data is intended to be handled by the payment provider rather than stored by us.

4. Sources of data

We receive data directly from you, from activity in the Service, from an organisation that invites you, from Google when you choose Google sign-in, from our service providers, and from security or support investigations.

User Content may contain data about third parties. The user who uploads it is responsible for having a lawful basis and providing required information. A represented person may contact us to identify and request review or removal of content involving them.

5. Purposes and legal bases

We process account, project and generation data to enter into and perform the contract, provide requested AI operations, maintain projects, manage credits and provide support. For pre-contract Request Access or pilot requests, processing is necessary to respond to the request.

We process billing, invoice and transaction records to perform the contract and comply with tax, accounting and consumer-law obligations when paid access is offered.

We process security, anti-abuse, fraud, reliability, logging and administrative audit data based on legitimate interests in protecting the Service, users, providers and legal claims, balanced against individual rights.

We process complaints, privacy requests and legal correspondence to comply with legal obligations and establish, exercise or defend claims.

Marketing email, testimonials, case studies and public portfolio use require a separate lawful basis and, where required, an opt-in. We do not use account or project content for public marketing without separate permission.

We use public-site analytics to understand visits, acquisition, performance and whether the landing page is useful. The current implementation is limited to the public marketing hostname and does not track activity inside the product application.

6. Service providers and data recipients

We disclose only data reasonably needed for a function to these recipient categories: cloud hosting, database, storage and security; authentication and transactional email; AI generation and prompt processing; public-site analytics; private operational communications; and payment, tax or invoicing services only when a paid flow actually uses them. A recipient may act as a processor, independent controller or another legally defined recipient depending on the service.

A first access request may create one private inbound notification accessible only to the owner. It contains first name, email, request date and time to the minute, country, profession, inbound channel and a safe Admin link. Last name and free-text “other” answers are excluded. Delivered inbound history remains after account deletion.

7. Provider training and human review

AI providers have their own service, security, abuse-monitoring and retention rules, which may vary by product, account tier, endpoint and setting. We configure data-sharing or storage restrictions where supported and necessary, but do not promise that providers never use data for training or product improvement unless the exact live provider contract and account setting support that statement.

Do not submit special-category, biometric, health, government-ID, financial, children’s or highly confidential third-party data unless we have expressly agreed a lawful and appropriately protected workflow.

8. Administrative access

Other customers do not receive access to your workspace through ordinary product functions. Administrative access by authorised Proposition Studio personnel is possible for support, billing, security, abuse investigation, legal compliance and service operation. The product includes administrative project and media access and audit controls.

We limit administrative access to authorised purposes and personnel. We may disclose data to public authorities, courts, advisers, insurers or counterparties when required by law or reasonably necessary for legal claims, security or a lawful business transaction.

9. International transfers

The main application database is configured in the EEA, but cloud, email, authentication and AI providers may process data outside the EEA. We do not claim that all data remains in the EU.

Where Chapter V GDPR applies, we rely on an available lawful transfer mechanism such as an adequacy decision, the EU-US Data Privacy Framework where applicable, standard contractual clauses and supplementary measures. Provider location and subprocessor arrangements may change.

10. Retention

Account and project content is retained while the account and projects remain active and while reasonably needed to provide the Service. Archiving a project or media item is a reversible product state and is not physical deletion.

The current runtime has no fixed automatic purge for project images, prompts or outputs. Content can therefore remain stored until a valid manual deletion request is completed, the account is closed through an operator process, or we introduce and disclose a verified retention schedule.

Application observability records carry intended expiry metadata, commonly ranging from days to months by severity and security purpose, but the current code does not prove a fixed automatic physical purge. We therefore make no promise of deletion on the metadata date.

Pilot-interest records are retained while the related contact is active and for a reasonable suppression, accountability or claims period. The original access request and already-delivered private inbound Discord history remain after account deletion. Support, privacy, complaint and security records are retained for the time needed to handle the matter and relevant limitation periods.

Transaction, invoice, tax and accounting records are retained for statutory periods. Backups and provider copies may persist for bounded technical cycles after a deletion action. Data needed for fraud, security, legal obligations or claims may be isolated and retained for those purposes.

11. Deletion, export and rights requests

Self-service account deletion is not currently available. Send an access, correction, export, deletion, restriction, portability or objection request to hello@propositionstudio.com. We may verify identity before acting.

There is no fixed automatic purge for User Content in the current runtime. We will assess requests under applicable law and delete, return, restrict or de-identify data where required and technically possible, subject to legal, accounting, security, provider, backup and claims exceptions.

We respond without undue delay and normally within one month under GDPR, subject to a lawful extension. Withdrawing consent does not affect processing already performed and does not prevent processing based on another lawful ground.

12. Cookies and public-site analytics

The app uses session and security cookies needed for authentication. A shared language cookie may remember an explicit locale choice for up to one year. The public marketing site loads self-hosted Umami analytics only on propositionstudio.com and records sanitised page, acquisition, engagement and performance information; the app does not load that tracker.

The Cookie Notice gives current details. If we add non-essential advertising, replay or similar technologies that require consent, we will update the notice and implement the required choice mechanism before loading them.

13. Security and incidents

We use measures appropriate to the Service and risk, including access controls, encrypted transport, scoped media URLs, authentication, rate limits, audit events, provider controls and incident handling. No internet service is completely secure, and users must protect credentials and exported files.

If a personal-data breach occurs, we assess notification duties and notify the competent authority and affected people where required by law.

14. Children and changes

The Service is for adults and is not directed to children. Do not upload children’s personal data without a valid, assessed and authorised reason.

We update this Policy when the product, providers, legal basis or retention practice changes. A material update receives a new version and effective date. Earlier versions may be retained as legal and operational evidence.

Contact: hello@propositionstudio.com

Proposition Studio

The browser workspace where you turn one view into many directed visual directions without losing the sources.

Open the app

Platform

  • Overview
  • Workflow
  • Proof
  • Generation tree

Resources

  • FAQ

Company

  • Contact

Social

  • Instagram

Legal

  • Legal hub
  • Privacy Policy
  • Terms of Service
  • Cookie Notice

© 2026 Proposition Studio

English
  • English
  • Polski