1Who we are
StudioIA is provided by LUIZ CARVALHO DESENVOLVIMENTO DE SOFTWARE LTDA, CNPJ 61.993.795/0001-70, based at Rua Luiz de Freitas, 81, Centro, Alegrete/RS, CEP 97541-350, Brazil. It is the controller of your personal data under Brazil's General Data Protection Law (Law 13,709/2018, the LGPD).
For anything about privacy, write to carolina@studioia.app. This is the channel for you to reach us, and also the one for Brazil's National Data Protection Authority (ANPD).
The LGPD asks whoever processes personal data to appoint a data protection officer, the person responsible for this contact. Small-scale processing agents like us are exempt from appointing one (ANPD Resolution CD/ANPD No. 2/2022), so this address fills that role.
2What we collect
- Account: your name, email and sign-in data, through Clerk, the service that handles sign-in. If you sign in with an account from another service, we receive the basic profile data it shares.
- Projects: the screenshots of your 3D model, the areas you mark, the photos in your product library, your material notes, your instructions and the renders generated.
- Render ratings: when you rate a render, the rating (positive or negative), your comment, if any, and the render's kind, model and resolution. If you turn on rating sharing, also a copy of the rated render and of what was used to make it: the screenshot, the masks, the product photos and the instructions.
- Credits: your balance and usage history.
- Purchases: when you buy a plan or a pack, your name, email, CPF or CNPJ, mobile number and address go to Asaas, our payment processor, and you type your card details straight into its page, without them passing through our servers. We keep the identifier of your record at Asaas, the card's brand and last 4 digits, and your purchase history: what was bought, the amount, the dates, each payment's status, refunds and invoices. Your CPF or CNPJ, address and mobile number do not stay with us: on your next purchase, we fetch them from Asaas to fill in the form.
- Acceptance of the Terms of Use and of this policy: which version you accepted, when, from which IP address and from which browser.
- Requests about your data: the requests you make to us under the LGPD and our answers.
- AI usage record: for every request to the AI model, we keep the complete request (the text sent, including your notes and instructions), every image sent and every image generated, the model's response and the safety filters it triggered, together with your account's identifier, the IP address, the date and the time.
- Contact form: the email address and the message you write.
- Site visits: the page visited, the site you came from and how long the page took to load, which your browser sends to Cloudflare Web Analytics together with your IP address and its identification (the user agent). From them, Cloudflare counts visits without cookies, by country, browser, operating system and type of device. We see only totals, never who visited.
- Technical data: the IP address and request details in the servers' logs.
We do not ask for sensitive personal data.
3Why we use it, and on what legal basis
- Providing the service (account, projects, renders, credits, and the sign-in and account emails): performance of a contract (LGPD, art. 7, V).
- Processing purchases (charges, credits, asset packs, withdrawals and refunds, and the emails about them): performance of a contract (art. 7, V).
- Issuing invoices and keeping payment records for the period tax law sets: legal obligation (art. 7, II).
- Preventing purchase fraud, such as unfounded card disputes and repeated purchases followed by withdrawal: legitimate interest (art. 7, IX) and the regular exercise of rights (art. 7, VI).
- Keeping your acceptance of the Terms of Use and of this policy, the record of the account's deletion and requests about your data, as proof of what was accepted and of what we did: the regular exercise of rights (art. 7, VI).
- Keeping the application access logs for 6 months: legal obligation (art. 7, II, and Brazil's Internet Civil Framework, the Marco Civil da Internet, art. 15).
- Keeping the AI usage record: preventing abuse and protecting the service. Legitimate interest (art. 7, IX) and the regular exercise of rights (art. 7, VI).
- Analyzing the quality of the renders you rate, to improve the service: legitimate interest (art. 7, IX) for the rating and the comment; your consent (art. 7, I) for our team to see the copy of the render and of what was used to make it, only if you turn on rating sharing. You can withdraw your consent at any time in Manage account > Privacy, which deletes the copies.
- Counting the site's visits, to learn how people find it and improve it: legitimate interest (art. 7, IX).
- Answering contact messages: your request and our legitimate interest in answering it (art. 7, V and IX).
We do not sell data, we do not use your data for advertising and we do not use your projects to train AI models, including the renders you share when rating.
4How long we keep it
- Account: for as long as it exists. You can delete it in the app, under Manage account > Delete account, or ask for it to be deleted by email.
- Projects: until you delete them. A deleted project can be recovered for 30 days; after that, it is permanently deleted with its images.
- AI usage record: 6 months, the minimum the Marco Civil da Internet sets for access logs. It is kept for that period even if you delete the project or the account, and deleted afterwards. We only keep it longer when the law requires it, when an authority or a court asks for it, or while we investigate abuse.
- Render ratings: for as long as the account exists. Shared copies are deleted 12 months after the rating, or sooner, as soon as you turn sharing off or delete the project, the view or the account; the rating stays, without the images.
- Purchases: for as long as the account exists, as your purchase history. After the account is deleted, until the end of the fifth year after the year of the deletion, because tax law requires each payment's records for 5 years from the year after it (Brazil's National Tax Code, art. 173, I). Asaas keeps your record with it for as long as the law requires it to.
- Acceptance of the Terms of Use and of this policy, and the record of the account's deletion: for the same period, as proof, within the 5 years Brazil's Consumer Protection Code allows for claims (art. 27). The deletion record keeps your email only as a code (a hash) that cannot be read back.
- Requests about your data: until the end of the fifth year after the year of each request.
- Contact messages: 12 months.
- Site visits: as totals, for about 6 months, at Cloudflare.
- Server technical logs: about 30 days.
- Backups: encrypted, and deleted within 40 days. Data deleted from the app may remain in them until then.
5Who we share it with
We rely on providers that process data on our behalf, only to provide the service. Each follows its own data protection terms and privacy policy:
- Google Cloud: Google's Gemini AI models, on Vertex AI, which receive your screenshots, product photos and instructions and generate the renders, and the infrastructure the service runs on (Cloud Run, Cloud Storage and Cloud Tasks). Under Google Cloud's terms, Google does not use this data to train its AI models. To fight abuse, Google runs every request through automated safety filters; if a request looks suspicious, Google may keep it for up to 90 days, and authorized Google employees may review it (how Google monitors abuse). Google Cloud Privacy Notice and data processing terms.
- Google Firebase: hosting for the site and storage for contact messages (privacy in Firebase).
- Cloudflare: the site's domain and the counting of its visits, for which it receives the IP address, the browser's identification and the pages visited (privacy policy).
- Neon: the app's database (privacy policy).
- Clerk: sign-in and account management (privacy policy).
- Asaas: card payment processing and issuing invoices. It receives your name, email, CPF or CNPJ, mobile number and address, the card details you type into its page and what was bought. For its own legal duties, such as those of a payment institution, Asaas is also a controller of this data and keeps it for as long as the law requires it to (privacy policy).
- Resend: sending email (privacy policy).
Each payment's invoice (nota fiscal) carries the buyer's name, CPF or CNPJ and address to the city government, as the law requires. We also hand data to authorities when the law requires it or under a court order.
6International transfer
Except for Asaas, a Brazilian company, these providers process data outside Brazil, mainly in the United States: the app runs on Google Cloud and the database is on AWS, in Ohio. Google's AI models may process a request in other countries where Google has infrastructure. The transfer follows art. 33 of the LGPD, under the contractual safeguards these providers offer.
7Cookies and browser storage
The site uses no cookies and no advertising tools. To count visits, it loads Cloudflare Web Analytics from Cloudflare's servers, which uses no cookies, stores nothing in your browser and does not follow you from site to site. The site stores only your theme preference, light or dark, in your browser. When you use the contact form, the site loads the Firebase SDK from Google's servers to send the message.
The app uses Clerk's session cookies, which keep you signed in, and stores the theme, the language and the last project you opened in your browser.
8Security
Data travels over encrypted connections (HTTPS) and is encrypted on the servers. Your projects can only be opened by your account. The AI usage record is kept apart from the app: only a small group of named people can read it, and every read is logged. The copies of shared ratings are also kept apart from your projects, only our team sees them, and every look is logged.
9Your rights
Under the LGPD (art. 18), you can ask for:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of data that is unnecessary, excessive or processed against the law;
- portability of your data;
- information about who we share your data with;
- review of decisions made solely by automated processing;
- withdrawal of your consent, where consent is the basis for processing, as with rating sharing.
You can also object to processing based on legitimate interest. To exercise these rights, write to carolina@studioia.app from your account's email address; we answer within 15 days. Some data may be kept even after a deletion request, where the law allows it (art. 16), such as the AI usage record during its 6 months and purchase records for the period tax law sets (section 4).
If you are not satisfied with our answer, you can complain to the ANPD, at gov.br/anpd.
10Children and teenagers
StudioIA is a professional tool for people aged 18 and over, and it is not directed at children or teenagers. If we learn that an account belongs to someone under 18, it will be closed.
11Illegal content
We never tolerate child sexual abuse or exploitation material. When found, it is removed and reported to the competent authorities, as Brazilian law requires (Statute of Children and Adolescents, art. 241-B, and Law 15,211/2025), and the account is closed.
12Changes to this policy
When this policy changes in a meaningful way, we will tell you by your account's email or in the app before the change takes effect. The date at the top of the page shows the last update. The Terms of Use complete this policy.
Versions
- October 15, 2026 (in force)