Privacy Policy
How Studio 17 LLC handles data in Accentor. The two things people most want to know: we do not train models on your content, and we send only what a job requires to the model provider that runs it.
1.What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, name, workspace name, role, authentication identifiers | To create and secure your account and workspace |
| Workspace content | Briefs and instructions you write, files you upload, brand kits, and the outputs produced for you | To produce the work you asked for and let you edit and revisit it |
| Usage and billing | Jobs run, output types, usage drawn down, plan and subscription state, payment records | To meter your allowance, show you where it went, and bill correctly |
| Technical | IP address, browser and device metadata, request logs, error diagnostics | Security, abuse prevention, and debugging failures |
| Analytics | Aggregate page and feature usage via Google Analytics 4 | To understand which parts of the product get used |
We do not ask for, and you should not upload, more sensitive personal data than your work requires. If your use involves health, financial or other regulated data, talk to us about an Enterprise agreement and a DPA before you do.
2.What we do not do
Model providers process your content to return a result, under contracts that restrict their use of it to providing the service. Their own retention and training terms are their own — we choose providers with business terms appropriate to this, and we publish the full list so you can review them. See Subprocessors.
3.How your content moves when you run a job
This is the part most privacy policies leave vague, so: when you run a job, Accentor plans it, then dispatches the parts that need a model to one or more external providers. What leaves our infrastructure is the material that job needs — your prompt or brief, and the specific inputs it references, such as an image you asked to edit or a document you asked to analyse.
- Content is sent over encrypted transport, to the provider selected for that job.
- Unrelated projects, files and workspace history are not sent. A job carries its own inputs, not your account.
- The receipt attached to each output records which providers ran, so you can always see after the fact where a piece of work went.
- Deterministic work handled by our own software plane — format conversion, rendering, assembly and similar — does not leave our infrastructure at all.
4.Who else processes your data
We use third parties to run Accentor. Each is bound by contract to process data only as needed to provide their service to us. The complete, current list — model providers and infrastructure alike, with what each one does — is at Subprocessors.
We may also disclose data when the law requires it, to protect the rights or safety of people or the service, or in connection with a merger or acquisition — in which case we will tell you before your data becomes subject to a different privacy policy.
5.Where your data lives, and how it is separated
Data is stored in managed Postgres and object storage. Workspace data is separated by tenant, with row-level security policies and, for provisioned workspaces, dedicated database projects rather than shared tables. See Security for the controls in detail.
By default, infrastructure is hosted in the United States. Enterprise customers can request data residency in the EU or APAC. If you are outside the US, using Accentor on a self-serve plan means your data is transferred to and processed in the US.
6.How long we keep it
| Data | Retention |
|---|---|
| Workspace content and receipts | For as long as your workspace is active. After cancellation, readable and exportable for 90 days, then deleted. |
| Content you delete yourself | Removed from the product immediately; purged from backups on the ordinary backup cycle. |
| Usage and billing records | Retained as long as required for tax, accounting and audit obligations, after account closure. |
| Technical and security logs | Short-lived — retained only as long as useful for debugging and abuse investigation. |
7.Your rights
Depending on where you live, you may have rights to access, correct, delete, port or restrict processing of your personal data, and to object to certain processing. You can exercise most of these directly: your workspace lets you export your work and delete your content and account.
For anything you cannot do in the product, email [email protected]. We will respond within the period the applicable law requires. If we act as a processor for your organisation, we will refer your request to them and assist them in answering it.
You may also complain to your local data protection authority. We would rather you told us first, but that right stands regardless.
8.Cookies
Accentor sets a small number of cookies — session cookies that keep you signed in, and Google Analytics cookies that measure aggregate usage. There are no advertising cookies. The full list is at Cookie Policy.
9.Children
Accentor is not directed at children under 13, and we do not knowingly collect their personal data. Where Accentor is used in a school, the school or district administers the accounts and acts as the controller for student data. If you believe a child has created an account directly, contact [email protected] and we will remove it.
10.Changes to this policy
We will post updates here with a revised date, and give notice in the product or by email before a material change takes effect. The subprocessor list changes more often than this policy — subscribe to notice of those changes as described on that page.
Contact
Studio 17 LLC · [email protected]. The postal address and the identity of our EU/UK representative, where required, will be stated here on legal review.
Questions about this document? [email protected]