Privacy Policy
Last updated 2 September 2026. This describes the private beta as the product actually works today, not an aspiration — see Terms of Use for the rules of using it.
Who operates this deployment. [OPERATOR LEGAL NAME, ENTITY TYPE, REGISTERED ADDRESS AND JURISDICTION — TO BE FILLED IN BEFORE THIS BETA IS OPENED TO ANYONE OUTSIDE A TRUSTED, INVITED GROUP.] This text is a placeholder, not an omission: the operating entity is a fact only the person running this deployment knows, and it belongs here before this document is shown to anyone it has not already been agreed with directly.
What this beta receives, and why
Everything below is what reaches the server when you use the studio at /studio. Nothing here is inferred or aggregated beyond what is listed — this is the complete list, checked against the code that handles it.
The business description you type
Up to 5,000 characters describing the business, product or service — what generation is built from.
The generation settings you choose
Language, an optional preferred visual style, and an optional call-to-action label.
The contact facts you confirm
Email, phone, website and address, when you type them into the form. These are treated as authoritative — copied onto the page exactly as typed rather than rewritten by the model.
The generated landing page
The business profile and the copy the model writes, and the compiled page built from them — headlines, sections, the QA report describing it.
Saved projects and version history
A successful generation is saved automatically, without a separate click, as a new version of a project — so the description, the contact facts, the generated content and the compiled page above are written to the server's storage, not only held in your browser.
An anonymous identity cookie
A cookie named "studio_owner", set the first time you open the studio, that is how the server recognises "the same visitor" well enough to show you your own saved projects. It is HttpOnly (invisible to any script on the page, including this one), sent only to this site, and carries no personal information — it is a randomly generated id, signed so it cannot be forged.
An email address, only if you attach one
If you choose to sign in, the address you enter is stored with the account it creates, and a short-lived sign-in link record and a session record are stored while they are valid. It is used to send you sign-in links and to show you which address you are signed in as. It is not linked to your feedback notes, and it is never sent to the AI provider.
Beta feedback you submit
A category ("bug", "quality", "ux" or "other") and a note of up to 2,000 characters, if this deployment has feedback configured. A feedback note is deliberately NOT linked to your identity cookie, your projects, or anything else — it is not answerable directly, which is why it should include your own contact details if you want a reply.
Technical request information
The kind of information any web server sees to answer a request at all — used briefly to enforce fair-use limits (so one visitor cannot exhaust the service for everyone) and never combined with anything above.
Live AI generation
This product can generate a page in one of two ways, depending on how a given deployment is configured:
When this deployment is configured for live generation (an operator setting, AI_PROVIDER=anthropic): your business description, your chosen settings and any contact facts you confirmed are sent to Anthropic, the AI provider that setting selects, solely to produce the business profile and the page copy. Anthropic processes that request under its own terms as a service provider to this deployment; this product does not send your data to any other AI provider or to any AI provider at all beyond the one the operator has configured.
When this deployment is left on its default configuration: generation runs entirely on this server, from fixed example content, and nothing you type is sent to any AI provider or leaves the server. If you are unsure which mode a deployment you are using is running in, ask whoever invited you.
What the operator can see, and what it deliberately cannot
Beyond the saved project data above, this product keeps an operational log — one line per request, read by whoever runs the deployment to see whether it is working and what it is costing. That log is built, by design, to never carry:
your business description, the generated copy, your confirmed contact facts, your feedback note's text, the identity cookie's value, your anonymous id, or any API key or signing secret. What it carries instead is categories and counts — that a generation started, that it succeeded or failed and how, that a page was exported, that a project was saved — correlated by a random id minted for that one request, never by who sent it.
This is a description of the log stream specifically, not a claim that the underlying data does not exist anywhere: your description, contact facts and generated content ARE written to this server's storage as a saved project, exactly as the section above says. The two are different places with different rules, and this section is only about the second one.
Anonymous identity, and its real limitation
By default “who you are” to this server is entirely the signed cookie described above — no password, no login. You may optionally attach an email address to it (see the next section). Without one, that has one consequence worth stating plainly, because it is easy to discover the hard way:
clearing your cookies, using a different browser, a different device, or a private/incognito window all mean the server no longer recognises you, and every project you saved becomes unreachable — not deleted, just unreachable to you. Without an attached email there is no way to recover it. Nothing proves a project was yours beyond the one cookie that pointed at it. Export anything you want to keep.
Optional email sign-in
You can attach an email address to this browser's projects from the studio. A sign-in link is sent to that address; opening it in the same browser you asked from, and confirming, signs you in and lets you reach the same projects after clearing cookies or from another device. Signing in creates an account holding your address and the identity your projects already belong to — nothing is copied or moved. A second cookie, “studio_session”, then identifies the signed-in session; it is HttpOnly, sent only to this site, lasts about thirty days, and is ended by logging out. Sign-in links work once and for fifteen minutes.
Beta feedback
A note you send through the studio's feedback button is written to this deployment's storage as its own record — separate from the project store, and, as above, not linked to your identity cookie or your projects in any way. If a deployment has not configured a feedback destination, the button tells you so and nothing is sent or stored; your note stays on your screen so you do not lose it.
Requesting deletion
You can delete a whole project yourself, from the studio's list of saved projects. It asks you to confirm, and then it is done:
the project and every version of it are removed from this deployment's live storage. There is no undo, no archive and no bin to recover it from. What we keep afterwards is the usage record of the generations you already ran — how many, how many tokens, what they were estimated to cost — which is never linked to a project and is not given back to your daily allowance. Deleting a project does not refund it.
One honest caveat about backups. This deployment takes periodic backup copies of its whole storage, and a copy taken before you deleted something still contains it until that copy is rotated out of the retention window the operator has configured. So “deleted” means gone from the running product immediately, and gone from the backups within that window.
Renaming a project is also yours to do, from the same list. It changes the project's name and nothing else — the stored versions are not rewritten by it, which is what keeps the version history trustworthy.
What you cannot delete from inside the product is a single version on its own, or a feedback note. For those, contact the operator (below). If you have attached an email address, that address identifies you; without one, the operator generally cannot verify on its own that a request belongs to you — expect to be asked to identify what you want removed as specifically as you can (a project name, roughly when you made it). The operator can act on the request manually; there is no guaranteed turnaround time and no automated confirmation, because neither exists yet in this beta.
Contact
This deployment has not configured a public contact address yet. Reach the person who invited you to this beta directly.