Trust
How we handle your data
This page describes what the studio actually does today. It will change when new services are switched on, and we will update it before they are.
What stays on your device
Exploring demos, writing a brief, choosing ideas, editing and downloading images and the campaign kit all happen in your browser. Drafts you have not saved are kept in this browser’s storage only — we cannot see them and cannot recover them for you.
What reaches our servers, and when
| Data | When | Why | Kept for |
|---|---|---|---|
| A guest session cookie | When you choose to save, render a video or send a request | To keep your saved work yours | Guest sessions last 30 days; a guest with no active session for 30 days is deleted with everything saved under it |
| Your email address | When you sign in | To send a one-time sign-in link and identify your account | Until you delete your account |
| Photos and logos | When you render a video or save a campaign | To compose your artwork; location data is removed in your browser first | Until you delete your data; removing a campaign from your list does not delete uploads that other versions may use |
| Rendered videos and exports | After a render | So you can download them | 72 hours, then deleted |
| Saved campaigns and versions | When you save | So you can reopen and compare them | Until you delete your data; a deleted campaign is hidden from your list immediately |
| Results you report | When you add them | Your own notes on how a campaign did | Until you delete them |
| A request to GGB | Only if you send one | Only the fields you ticked, to reply to you | Until handled or you delete your data |
| Product events | As you use the studio | Named steps (for example “export”) with no free text, under a one-way code, never your email | To improve the studio |
The public inspiration wall
Your campaigns are private by default. Only an email-signed-in account can submit a finished image for the inspiration wall. The publication permission is separate, unchecked by default, and applies to that image, its title, restaurant credit and city. A moderator checks each submission before it appears publicly. Original photos, account emails, briefs and private campaigns are not published.
We keep a gallery copy until you withdraw it or delete your account. Withdrawal immediately prevents the studio from serving the image again; people may already have saved it while it was public. Manage publication in My gallery submissions. The gallery API and image responses carry search-engine noindex instructions. Permission records are deleted with your account.
Who processes it
Cloudflare hosts the studio, its database and private file storage. Rendering runs in an isolated service we operate on the same provider. Resend processes your email address and one-time sign-in message to deliver account access. AI features (idea writing, translation, image generation) are switched off today; when they are switched on, the text or image needed for that one task is sent to the AI provider named in this page, which processes it to return a result. We will never claim a provider cannot see what it processes.
What we never do
- Publish your uploads, menus or artwork in a gallery or as a case study without your separate permission.
- Treat your uploads or ideas as a sales lead.
- Infer anything about your individual customers.
- Pre-tick a marketing box. Marketing consent is separate and off by default.
Deleting your data
Use Delete my data. It removes your account or guest session, brands, campaigns, uploads, renders, consent records and requests immediately. Our database provider keeps short point-in-time recovery copies for disaster recovery; deleted records can remain in those copies for up to 30 days before they expire.