LEGAL
Privacy Policy
This policy explains what personal data InfoSolve Co.,Ltd collects when you use GeneratorStudio, why, who it is shared with and the choices you have. We are responsible for this data. Questions go to [legal contact email].
1. What we collect
- Account: your email address and name. If you register with a password we store a salted hash of it, never the password itself. If you sign in with Google, Google shares your email address and name with us.
- Workspaces: which workspaces you belong to, your role, and a record of membership and plan changes.
- Projects: the data models, settings and files you create, and the connection and deployment details you save, such as database server names, GitHub repository addresses, server hosts and user names, GitHub tokens, SSH keys and Azure credentials. Tokens, keys and passwords are stored encrypted.
- Activity: each generation run with its result and log, and a usage record of each generation run and AI request, with the time, the project, the AI model and the number of tokens used. We keep this to apply plan limits and bill for use.
- Security: failed sign-in counts and lockouts. Your IP address is used, in memory only, to limit how often the account forms can be submitted.
- AI requests: what you type into AI features and the parts of your project they need, such as your current data model, together with the proposals that come back.
- Email: the account emails we send you, such as confirmation and password reset links.
- Preferences: your chosen theme, saved with your account, and the Studio's panel layout, saved in your browser.
We do not use advertising or analytics trackers.
2. How we use it
- to run the Studio: sign you in, keep workspaces separate, generate and deploy what you ask for;
- to keep it secure: confirm email addresses, stop password guessing and abuse;
- to apply plan limits and, for paid plans, to bill;
- to send account emails you need, and to reply when you contact us;
- to meet legal obligations.
[Legal bases, if the GDPR or a similar law applies: contract for running the service; legitimate interests for security and abuse prevention; legal obligation for records we must keep.]
3. Who we share it with
We do not sell personal data. We share it only with the services that run parts of the Studio, and only what each needs:
- Microsoft Azure hosts the Studio and its databases, in [Azure region, currently Southeast Asia].
- Google, if you choose to sign in with Google.
- The AI provider the Studio is configured to use, Microsoft Foundry or OpenRouter, receives AI requests when you use AI features. OpenRouter passes requests on to the company that runs the chosen model.
- [email delivery provider] delivers account emails.
- Content delivery networks, cdnjs (Cloudflare) and jsDelivr, serve some of the Studio's scripts and styles, so your browser sends them your IP address and browser details when a page loads.
- Services you connect, such as your GitHub repositories, your servers and your Azure subscription, receive what you tell the Studio to send them.
We may also disclose data when the law requires it, or to protect the rights and safety of our users and others.
4. International transfers
[Where data is processed outside your country, and the safeguards used, for example standard contractual clauses.]
5. How long we keep it
- Your account is kept until it is deleted.
- Projects belong to their workspace and are kept until someone in the workspace deletes them. Deleting a project deletes its generation history with it.
- Usage records and membership and plan change records are kept for [period, e.g. 7 years for billing records], including after the project they mention is deleted, because billing and security reviews depend on them.
- Database backups keep deleted data for up to [backup retention period].
6. How we protect it
Connections to the Studio are encrypted. Passwords are hashed, and saved tokens, keys and passwords are encrypted. Each workspace's projects are available only to its members. Accounts lock after repeated wrong passwords, and the account forms are rate limited.
7. Your choices and rights
- You can export any project's design as a JSON file from the Studio.
- To get a copy of your personal data, correct your name or email address, or have your account deleted, email [legal contact email]. Deleting your account removes your sign-in and membership; projects stay with their workspace for its other members unless you ask us to delete projects you own.
- [Rights under the laws that apply to you, such as objecting to processing or complaining to a data protection authority.]
8. Cookies and browser storage
The Studio uses only the cookies it needs to work: one that keeps you signed in, one that protects forms against forged submissions, and a short-lived one that completes Google sign-in. Your browser also stores the Studio's panel layout. There are no advertising or analytics cookies.
9. Children
The Studio is not meant for anyone under [16], and we do not knowingly collect their data.
10. Changes
We will show the new effective date here when this policy changes, and tell account holders by email about significant changes before they apply.
11. Contact
InfoSolve Co.,Ltd, [registered company address]. Email: [legal contact email].