Privacy Policy
This Privacy Policy describes how Studiola ("Studiola," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use the Studiola mobile application (the "App"). This Policy is designed to comply with the European Union General Data Protection Regulation ("GDPR"), the United Kingdom GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable U.S. state privacy laws.
If you do not agree with this Policy, please do not use the App.
1. Who We Are (Data Controller)
For users in the European Economic Area ("EEA"), United Kingdom, and Switzerland, the controller of your personal data is:
Studiola
Contact: support@codingascreating.com
If you are located in the EEA or UK and wish to exercise your data protection rights, you may contact us at the email above. We will respond within 30 days, as required by GDPR.
Studiola does not require you to create an account or sign in to use the App.
2. Face Data — What We Collect, Why, and Who We Share It With
This section specifically describes our collection, use, disclosure, sharing, and retention of face data (the selfie or photo you choose to generate a portrait from), as required by App Store review guidelines.
- What we collect. When you choose a selfie or photo inside the App and tap Generate, that image — which may depict your face — is uploaded from your device to our backend and then forwarded to our third-party AI image-generation provider.
- Who it's sent to. Your photo and the style prompt you selected are sent to Replicate, Inc., which we use to run the Google "nano-banana" (Gemini) image model. Replicate and Google process the image solely to run the requested model and return the generated portrait.
- All planned uses. The photo is used for exactly one purpose: generating the AI portrait you requested in that session. We do not perform facial recognition, identity verification, or biometric matching against any database, and we do not use your photo to train any AI model.
- Before it's sent. The first time you generate a portrait, the App shows an in-app disclosure describing what will be sent and to whom, and requires you to tap "Agree & Continue" before the photo leaves your device.
- Retention. We do not retain a copy of your source photo on our servers after the generation request completes. Per Replicate's own documentation, prediction inputs, outputs, and logs submitted through its API are automatically deleted one hour after the prediction completes (see Replicate's data retention policy). The generated portrait is saved locally on your device (see Section 6).
- No third-party sharing beyond generation. We do not share your photo with advertisers, data brokers, or any party other than the AI provider needed to fulfill your generation request.
3. Information We Collect
3.1 Information You Provide Directly
- Photos and images. See Section 2 above.
- Custom prompts. Any text prompts or style descriptions you enter to guide portrait generation.
- Support communications. If you contact us for support, we collect the contents of your message and your contact details.
3.2 Information Collected Automatically
- Installation identifier. A random identifier generated and stored on your device (not tied to any account or Apple ID) used to enforce free-trial and weekly generation limits and for support diagnostics.
- Usage data. Generation counts, timestamps, subscription status, app interaction events.
- Device data. Device model, operating system version, app version, language and region, and crash diagnostics.
- Subscription data. StoreKit transaction identifiers and receipts associated with in-app purchases (processed by Apple).
3.3 Information We Do Not Collect
- We do not require an account, and do not collect your name, email, or Apple ID.
- We do not collect your precise geolocation.
- We do not collect your contacts, calendar, microphone, or health data.
- We do not use third-party advertising SDKs or behavioral ad networks.
- We do not sell your personal information (see Section 10).
4. Legal Bases for Processing (EEA / UK Users)
Under the GDPR, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the core App functionality (generation, local history) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing your selfie image to generate a portrait | Performance of a contract; explicit consent for biometric inference where applicable (Art. 9(2)(a)) |
| Processing subscription payments | Performance of a contract; legal obligation |
| Diagnostics and crash reports | Legitimate interests in maintaining a secure, functioning App (Art. 6(1)(f)) |
| Responding to support requests | Legitimate interests; performance of a contract |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
You have the right to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of prior processing.
5. How We Use and Share Your Information
We share information only with the following categories of recipients, and only as necessary for the purposes described:
5.1 Sub-processors and Service Providers
- Supabase (backend hosting and edge functions) — acts as a proxy that forwards your request to our AI provider and enforces subscription entitlements. Data may be processed in the United States or other regions where Supabase operates.
- Replicate, Inc. and Google (AI image generation) — your selfie image and style prompt are sent to Replicate, which runs Google's "nano-banana" (Gemini) image model, and the generated portrait is returned to the App. See Section 2 ("Face Data") for full detail on this specific data flow.
- Apple Inc. — App Store and in-app subscription processing, push notification delivery (APNs).
We have entered into (or rely on) data processing terms with these vendors that include the appropriate safeguards required by GDPR (including, where applicable, the European Commission's Standard Contractual Clauses for international transfers).
5.2 We Do Not Share Your Data For:
- Targeted advertising.
- Sale to data brokers.
- Training third-party AI foundation models. (Our AI service provider processes inputs only to run the requested model; per their terms, prediction inputs and outputs are not used to train their hosted models unless the underlying model provider's terms state otherwise.)
5.3 Legal Disclosures
We may disclose information if required to do so by law, valid legal process, or to protect the rights, property, or safety of Studiola, our users, or the public.
5.4 Business Transfers
If we are involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you and any acquirer will be bound by this Policy unless you are notified otherwise.
6. Data Retention
- Generated portrait images are stored locally on your device in the App's Documents directory. We do not retain copies on our servers after generation completes.
- Source selfies are transmitted to Replicate/Google for processing. Replicate automatically deletes prediction inputs, outputs, and logs one hour after the prediction completes (see Section 2, "Face Data").
- Installation identifier is retained for the lifetime of the App install on your device.
- Subscription transaction records are retained for as long as required by tax and accounting law (typically 7 years).
- Crash logs and diagnostic data are retained for up to 90 days.
- Support correspondence is retained for up to 2 years after resolution.
When you request deletion of your data (see Section 7), we delete or anonymize it within 30 days, except where we are required to retain it by law.
7. Your Rights
7.1 Rights Available to All Users
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data.
- Export your data in a portable format.
- Opt out of non-essential notifications.
You can delete locally stored generations from within the App at any time. To request deletion of any other data or to exercise other rights, contact support@codingascreating.com.
7.2 Additional Rights for EEA / UK Users (GDPR)
- Right of access (Art. 15).
- Right to rectification (Art. 16).
- Right to erasure / "right to be forgotten" (Art. 17).
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20).
- Right to object to processing based on legitimate interests (Art. 21).
- Right to lodge a complaint with your local supervisory authority (e.g., the Irish Data Protection Commission, the UK ICO, or your national DPA).
7.3 Additional Rights for California Residents (CCPA/CPRA)
You have the right to:
- Know what categories of personal information we collect, the sources, purposes, and recipients.
- Access the specific pieces of personal information we hold about you.
- Delete your personal information, subject to legal exceptions.
- Correct inaccurate personal information.
- Limit the use of sensitive personal information (we do not use sensitive personal information beyond what is necessary to provide the service you requested).
- Opt out of "sale" or "sharing" of personal information — we do not sell or share your personal information for cross-context behavioral advertising, so this right is not applicable in practice.
- Non-discrimination for exercising your rights.
To exercise any CCPA/CPRA right, email support@codingascreating.com with the subject line "CCPA Request." Since the App does not use accounts, we will verify your request using the information you provide (e.g., the email you contact us from and any details that let us locate your install). Authorized agents may submit requests on your behalf with written permission.
7.4 Other U.S. State Rights
Residents of states with comparable privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others as such laws come into effect) have rights substantially similar to those described above. Contact us at the email above to exercise them.
8. International Data Transfers
If you are located outside the United States, please be aware that information we collect may be transferred to and processed in the United States, where our backend and AI service providers operate. For transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum where applicable.
9. Children's Privacy
The App is not directed to children under 13 (or under 16 in the EEA, depending on the member state). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. "Do Not Sell or Share My Personal Information"
We do not sell or share personal information as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months and have no plans to do so. This statement satisfies any requirement to provide a "Do Not Sell or Share My Personal Information" disclosure.
11. Security
We use industry-standard technical and organizational measures to protect your information, including:
- TLS encryption in transit.
- Authenticated, scoped access to backend resources via row-level security policies and signed JWTs.
- API keys for third-party AI providers stored as encrypted secrets on the server; never embedded in the App.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you and any applicable regulators of a personal data breach without undue delay where required by law.
12. Automated Decision-Making
The App uses an AI model to generate stylized portraits from your selfie. This processing is automated, but it does not produce legal or similarly significant effects on you within the meaning of Article 22 of the GDPR. You can choose not to use the feature at any time.
13. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you in-app or by email and update the "Effective Date" above. Your continued use of the App after the effective date constitutes acceptance of the revised Policy.
14. Contact
For questions, requests, or complaints about this Policy or your personal data:
Email: support@codingascreating.com
If you are in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.