Legal
Privacy Policy
Effective June 12, 2026
1. Who we are
Studio Schema ("we", "us") operates studio-schema.com, the Academy at academy.studio-schema.com, and Schema OS at app.studio-schema.com. This policy covers all three. Questions about it go to hello@studio-schema.com — that address reaches the people who run the company, not a mailbox no one reads.
2. What we collect
Account data: when you create an account we collect your name, email address, and authentication identifiers. Authentication is handled by Clerk, our identity provider.
Billing data: payments are processed by Stripe. We never see or store full card numbers; we keep records of what you bought, when, and the subscription state needed to grant access.
Product data: in the Academy we store your lesson progress, notes, and bookmarks. In Schema OS we store the content you deliberately save to your workspace — captures, notes, graph data, tasks, and outputs.
Email capture: if you request the Field Guide or join the newsletter, we store your email address with the source of the signup.
Usage data: we use Vercel Analytics for aggregate, privacy-respecting traffic measurement. We do not run third-party advertising trackers.
3. How we use it
To provide the services you signed up for: delivering lessons, running your Schema OS workspace, sending purchase receipts and the e-books you request.
To operate AI features you invoke: content you save to Schema OS is processed by the AI providers configured for your workspace (Anthropic by default; OpenAI or Google only if you add those keys). We do not use your content to train models, and our provider agreements prohibit them from doing so via API usage.
To communicate: transactional email (receipts, account notices) always; marketing email only if you opted in, and every message carries an unsubscribe link that works on the first click.
4. What we never do
We do not sell your personal data. We do not rent lists. We do not share your content with third parties except the processors listed below, acting on our instructions.
5. Processors we rely on
Vercel (hosting and analytics), Supabase (database, with row-level security isolating each workspace), Clerk (authentication), Stripe (payments), Resend (email delivery), and Anthropic — plus OpenAI or Google only where you supply those keys. Each processes data under its own data-processing agreement with us.
6. Your keys, your content
API keys you add to Schema OS are encrypted with AES-256-GCM before storage and are used solely to run your workspace's requests. Your workspace content belongs to you: you can export it at any time, and deleting your account deletes it from production systems within 30 days, with encrypted backups expiring on a rolling 30-day schedule after that.
7. Your rights (GDPR / CCPA)
Wherever you live, we extend the same rights: access, correction, export, deletion, and objection to processing. If you are in the EEA or UK, the legal bases we rely on are contract (providing the service), legitimate interest (security, product improvement), and consent (marketing email). To exercise any right, email hello@studio-schema.com; we respond within 30 days. You can also lodge a complaint with your local supervisory authority.
8. Cookies
We use first-party cookies strictly for sessions (keeping you signed in) and for remembering your cookie choice itself. No cross-site tracking cookies, no advertising pixels.
9. Data security and retention
All traffic is TLS-encrypted. Database access is governed by row-level security so one workspace can never read another's rows. Sensitive columns carry additional access restrictions at the database layer. We retain account data while your account exists and for up to 90 days after deletion where required for accounting and fraud prevention.
10. Children
Our services are not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
11. Changes
When this policy changes materially, we email account holders and note the change here before it takes effect. The current version is always at studio-schema.com/legal/privacy.