Privacy
What Studio stores, who else sees it, and how to get rid of it. Written specifically rather than generically, because a privacy policy that could describe any product tells you nothing about this one.
Last updated 30 August 2026. Operated by Garv Dixit, sole proprietor trading as Garv Dixit Automate, Vasna Bhaiyli, Vadodara. Questions: garv@gdautomate.com.
The short version
- Your conversations are not training data. We do not train on them and do not sell them.
- Whatever you send to a model goes to that model’s provider. That is the point of the product, and it is the main place your data leaves this server.
- Your API keys are encrypted at rest and are never sent back to your browser.
- Deleting a chat deletes it, including its files. Deleting your account deletes everything.
- No advertising, no third-party analytics tracking you across other sites.
Who is responsible for it
Studio is run by Garv Dixit, sole proprietor trading as Garv Dixit Automate — Garv Dixit, operating as a sole proprietor rather than a company. Under India’s Digital Personal Data Protection Act, 2023 that person is the data fiduciary for everything described below, and is the contact for any question or complaint about it:
Garv Dixit
Vasna Bhaiyli, Vadodara
garv@gdautomate.com
There is no privacy team to escalate past, and no ticket queue. The same address handles a data export, a deletion request and a complaint, and the same person answers all three.
What is stored, and why
Your account. Email address, and the name and avatar your sign-in provider supplies. Needed to have an account at all.
Your conversations. Messages, the instructions and goals you set, and the replies. Stored so a chat is still there tomorrow.
Documents you upload. Text is extracted, split and indexed so it can be searched. The original file is not kept— only the extracted text and its embeddings.
Provider keys. Encrypted with AES-256-GCM. Decrypted only inside the request that uses one. The interface only ever shows you the last few characters.
Usage and billing. Per-message token counts and cost, in an append-only ledger, plus a record of top-ups. This is financial data and is kept for as long as tax and accounting rules require, even after an account is deleted.
Code and commands. For Studio Code projects: the files in the workspace, and an audit log of every command run, its exit code and how long it took — including commands that were refused.
All of it is processed for one purpose: running the service you asked for. Creating the account is the consent for the account data; sending a message is the consent for that message to reach the model you picked. Nothing here is collected for a purpose you would have to read this page to discover.
Who it is sent to
Studio is a workspace in front of other people’s models, so the contents of a turn necessarily leave this server. These are everyone who receives anything:
OpenRouter
Routes model requests, and is the provider of record for chats billed to Studio credit.
The contents of the turn being sent, and its token counts.
Model providers
Anthropic, OpenAI, Google, DeepSeek and the others you select, whether reached through OpenRouter or with your own key.
The contents of the turn you send to that model.
Your payment gateway
Takes card payments and tells Studio a top-up succeeded.
Your payment details, which are handled by the gateway and never reach Studio's servers.
Your sign-in provider
Google or GitHub, if you sign in with one.
Your email address, name and avatar URL.
Providers set their own retention. Most keep API traffic briefly for abuse monitoring and state that they do not train on it, but that is their commitment to make and their policy to read — not ours to promise on their behalf.
One consequence worth naming: when you use your own key, the request goes to your provider account, and appears in your own dashboard and bill rather than ours.
Where it physically is
Studio’s own database and file storage sit on a single rented server in FILL IN — VPS region, e.g. Mumbai, India. The model providers above are mostly in the United States, so the contents of a turn cross a border by design — that is what sending a prompt to a model in another country means, and no configuration avoids it.
If you are in the EU or the UK, that transfer relies on the provider you selected and on your instruction to send the message. If you are in India, transfers are permitted under the DPDP Act except to countries the government restricts, and none of the providers above is in one today. If you would rather your prompts stayed with a particular provider, choose that provider — the model picker is the control, and it is per-chat.
What is not done with it
No training on your content. No selling or renting it. No advertising network, no cross-site tracking pixels, no data brokers.
“Nobody reads your chats” has a specific meaning in a one-person business, so here it is exactly: Garv Dixithas the database access that running the service requires, and does not read conversations with it. The exceptions are the two you would expect — you send one in yourself to get help with a problem, or a specific investigation into abuse or a security incident makes it necessary. There is no third case, and no one else has access at all.
Cookies
A session cookie so you stay signed in, and a cookie remembering whether you chose light or dark. That is all of them. There is no consent banner because there is nothing to consent to.
Keeping it safe
Keys are encrypted at rest. Every request re-checks that the row you are asking for is yours, and a record that is missing and a record that belongs to someone else return the same response, so neither can be used to discover the other. Code runs in an unprivileged container with no route to the database or the host.
No system is perfect. If you find a security problem, write to garv@gdautomate.com before disclosing it publicly and we will work with you.
If a breach does happen and your data is in it, you will be told — what happened, what was exposed and what to do about it — and so will the Data Protection Board of India, as the DPDP Act requires. You will hear it from us rather than from someone else.
How long it is kept
Chats, documents and projects stay until you delete them or delete your account. Deleting a chat also deletes its workspace files and any document attached only to it. Generated images expire on their own schedule and are swept.
Billing records outlive the account, because they have to. Nothing else does.
Your rights
You can ask for a copy of what is stored about you, ask for it to be corrected, or ask for it to be deleted. Deleting your account does the last one immediately and without asking anyone. For the others, or for anything that needs a person, write to garv@gdautomate.com; we will answer within 30 days.
Depending on where you live you may also have the right to object to processing, to ask for your data in a portable format, or to complain to a data protection authority. Ask and we will help rather than making you invoke a statute.
If you are in India and an answer from Garv Dixitdoes not resolve it, the DPDP Act lets you take the complaint to the Data Protection Board of India. Please use the address above first — it is faster, and it is the step the Board will ask whether you took.
Children
Studio is not for anyone under 18. India’s DPDP Act treats everyone under 18 as a child and requires verified parental consent before their data is processed, which is not something a service this size can do properly — so rather than pretend otherwise, the age limit is 18 and there is no under-18 tier.
We do not knowingly collect data from children; tell us at garv@gdautomate.com if you believe we have and the account and its data will be deleted.
Changes and contact
The date at the top changes when this does. For a change that materially affects how your data is handled, we will tell you before it takes effect.
Garv Dixit, sole proprietor trading as Garv Dixit Automate, Vasna Bhaiyli, Vadodara. Write to garv@gdautomate.com, or see the contact page.