AnyStudio
How it works The studio Shots How it fits together Video WhatsApp For platforms Pricing
Try on WhatsApp Sign in Start free
Legal

Privacy Policy

Effective 6 September 2026 · Version 1.0

What we collect when you use AnyStudio, what we do with it, who else sees it and how to get it back or make it go away. No trackers on this site, no selling of anything, and nothing you upload trains anyone's model.

Contents
  1. 1. In short
  2. 2. What we collect
  3. 3. What we use it for
  4. 4. Legal basis
  5. 5. Who we share it with
  6. 6. AI model providers
  7. 7. Connected platforms
  8. 8. Cookies
  9. 9. How long we keep it
  10. 10. Your rights
  11. 11. Security
  12. 12. International transfers
  13. 13. Children
  14. 14. Changes and contact

01In short

We collect what it takes to run a studio: your account, what you upload, what you generate, what you pay and where you publish. We use it to do those things and to keep the service safe and running. We share it with the providers that do the work — hosting, payment, AI models, the platforms you connect — and with no one else unless the law says so. You can export everything, delete everything, and turn off every optional use in Settings.

02What we collect

What you give us

  • Account details — name, email address, password (stored as a one-way hash), the workspace name and logo, your language and market, and whether you ticked the marketing box (we store the exact wording you agreed to and when).
  • Sign in with Google — your Google email, name and profile picture, and nothing else; we never see your Google password.
  • Your material — product photos, brand kits, captions, product names, prices and descriptions, catalogue data synced from Shopify or WooCommerce, and anything you send to the WhatsApp assistant, including your WhatsApp number.
  • Billing details — your billing name, address and tax ID where required, and invoices. Card and mobile-money numbers go straight to Paddle or Flutterwave; we hold only a reference, the last four digits where shown, and the result.
  • Messages to us — support conversations, refund requests and their reasons, and job applications with the CV you attach.

What the service produces

  • Generated content — every image, video, audio clip and text the studio makes for you, kept in your library until you delete it.
  • Usage and ledger — which tools you ran, when, what they cost in credits, and every credit movement, so your balance and invoices can always be explained line by line.
  • Publishing history — what was posted where and whether it succeeded.

What we record automatically

  • Security events — sign-ins, sign-in failures, password and email changes, new devices and API-key use, each with the IP address, rough location derived from it, browser and time. They are shown to you in Settings › Security.
  • Technical logs — request logs and error reports for keeping the service up, held for a short, fixed time (section 9).

03What we use it for

  • To provide the studio: generate content from what you upload, keep your library, publish to the platforms you connected, run the WhatsApp assistant, and answer the API.
  • To bill you: take payment, issue invoices and receipts, run usage billing for organizations, and handle refunds.
  • To keep the service safe: detect abuse, enforce our Terms including the acceptable-use rules, protect accounts, and rate-limit.
  • To talk to you about your account: receipts, invoices, security alerts, and changes to the service or these policies. These are not optional while you have an account.
  • To send product news, only if you ticked the box, and only until you untick it in Settings or click unsubscribe.
  • To improve the product, using aggregated usage statistics that do not identify you. We do not use your uploads or outputs to train AI models, ours or anyone else's.
  • To meet legal obligations — tax records, responding to lawful requests, and the reporting duties in section 7 of the Terms.

04Legal basis (for readers in the UK, EU/EEA and similar regimes)

We process your data to perform our contract with you (the studio, billing, publishing); for our legitimate interests in keeping the service secure, understanding how it is used and improving it, where those interests do not override your rights; with your consent, for marketing email and for connecting third-party accounts; and to comply with legal obligations such as tax and accounting rules. Where we act for an organization that uses our API for its own users, we are that organization's processor and it is the controller.

05Who we share it with

We share data with providers that process it for us, under contracts that limit them to our instructions. We do not sell personal data, and we do not share it with advertisers.

ProviderWhat forWhat they see
RenderApplication hosting and the databaseEverything the service stores, encrypted at rest
CloudflareWebsite delivery, edge security, file storage (R2)Requests to our sites; uploaded and generated files
ResendTransactional and marketing emailYour email address and the contents of emails we send you
Paddle, FlutterwavePayments, invoicing, refunds, taxBilling details, payment method, amounts; Paddle is merchant of record in the markets it covers
AI model providersGenerating images, video, audio and textThe inputs a generation needs — see section 6
Meta, TikTok, Shopify, WooCommercePublishing, the WhatsApp assistant, catalogue syncOnly what the feature sends — see section 7
Error monitoring (Sentry), where enabledCatching crashesError reports with a request ID and your user ID, never the content of an upload

We may also disclose data if the law requires it, to enforce our Terms or protect someone's safety, or as part of a merger or sale of the business — in which case this policy continues to apply to it, and we will tell you.

06AI model providers

Each tool in the studio runs on one or more third-party models. Depending on the tool and the market, that may be OpenAI, Anthropic, Google (Gemini and Vertex AI), Replicate, fal, Black Forest Labs, Higgsfield, HeyGen, Photoroom or ElevenLabs. We send them only what the generation needs — the photo, the prompt we build from your product details, a voice sample where you supplied one — and receive the output back. We use their API services, not their consumer apps; under those services' terms, inputs are not used to train their models, and they are retained by the provider only for the short period their abuse-monitoring requires. We do not send them your name, email, payment details or account history.

07Connected platforms

When you connect an account we receive an access token from that platform and store it encrypted. We use it only for the feature you connected it for, and we stop using it — and delete the token — when you disconnect.

  • WhatsApp — your number and the messages you exchange with the assistant, through Meta's WhatsApp Business API. Meta's business data terms apply to that traffic.
  • Meta (Facebook, Instagram) and TikTok — the pages or profiles you choose, and the posts we publish there on your instruction, with basic results. We can read what we posted; we do not read your inbox or your followers.
  • Shopify and WooCommerce — your product catalogue: titles, descriptions, prices and images. We do not read orders or customers.

You can also delete data we hold from these connections by disconnecting them in Settings › Connections, or by closing your account (section 10). Platform users who want us to delete data we received about them via one of these integrations can write to privacy@anystudio.ai.

08Cookies

The studio sets one cookie: a signed session cookie that keeps you signed in, scoped to our own host. The marketing site sets none and loads no third-party analytics or advertising scripts. Your theme and a few interface choices are kept in your browser's local storage and never leave it. Because there is nothing optional to consent to, there is no cookie banner.

09How long we keep it

DataKept
Account, uploads, library, brand kitsWhile your account is open, then removed 30 days after you ask us to delete it (section 10)
Ledger, payments, invoicesAs long as tax and accounting law requires, typically seven years, in a form that no longer names you once your account is deleted
Security eventsTwelve months
Request logs and error reportsThirty days
Support and refund conversationsTwo years after they close
Job applicationsTwelve months after the role closes, unless you ask us to remove them sooner
BackupsRoll off within 30 days of the change

10Your rights

Wherever you live, you can do all of this from Settings without asking us:

  • Export — Settings › Account › Export gives you a file with your profile, workspaces, ledger, library index and connections.
  • Delete — Settings › Account › Delete schedules the account for removal in 30 days. Sign in before then to cancel. After that your personal data is erased and your records are anonymised; invoices are kept as the law requires but no longer point at you.
  • Correct — edit your name, email, workspace and billing details any time.
  • Withdraw consent — untick marketing email in Settings, or disconnect a platform.

You also have the right to ask us what we hold about you, to object to or restrict processing, to take your data elsewhere, and to complain to your data-protection authority. Write to privacy@anystudio.ai; we answer within 30 days, and we will ask you to prove it is your account before we release anything.

11Security

Everything travels over TLS. Passwords are hashed, platform tokens are encrypted with a key held outside the database, session cookies are host-locked, and staff access to production is logged and limited. Two-step verification is available on every account, and we recommend it. If we learn of a breach that puts your data at risk, we will tell you and the relevant authority as the law requires — and sooner than it requires where we can.

12International transfers

Our servers and most of our providers are in the United States and the European Union; the AI model providers and the platforms you connect are wherever they are. When personal data leaves the UK or EEA we rely on the provider's adequacy status, standard contractual clauses, or the UK addendum, as applicable. Ask us for a copy.

13Children

AnyStudio is for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it. If you think a child has an account, tell us.

14Changes and contact

When this policy changes in a way that matters, we email you and post the new version here before it takes effect. The version and date at the top tell you which one you are reading.

Privacy questions and requests: privacy@anystudio.ai. Everything else: hello@anystudio.ai.

→ Terms of Service → Refund Policy
AnyStudio

One photo, everything you post. Built for sellers, creators and the platforms that host them.

+1 775 303 2588
Product How it worksThe studioMerchant shotsReels & adsBatchWhatsApp botPricing
For platforms API referenceProjects & keysUsage billingWebhooks
Account Sign inCreate accountForgot password
Company Why AnyStudioCareersMobile app — soonPrivacyTermsRefundshello@anystudio.ai
© 2026 AnyStudio. All rights reserved. Prices are set per market and do not track the daily exchange rate.