Privacy Policy
This Privacy Policy explains what personal data Creator Studio collects, why, and what rights you have. Read it together with our Terms of Service.
1. Who is responsible for your data
WSD Agency s.r.o., Pri Hrubej lúke 3634/1, 841 02 Bratislava, Slovakia, is the controller for the account and service data described in this policy. Company registration number: [COMPANY REGISTRATION NUMBER]. VAT ID: [VAT ID]. Data-protection contact: [DPO CONTACT, IF ANY]. For any privacy request, see Contact.
2. Data we handle
- Account identifiers and email address.
- Uploaded images and videos.
- Character and reference settings.
- Prompts and source-video observations.
- Generation job status, provider identifiers and outputs.
- Connected WaveSpeed credentials (encrypted).
- Subscription and billing identifiers and status.
- Technical logs and support correspondence needed to run and troubleshoot the Service.
Uploaded media is stored in private storage, and we check your account access before serving it back to you. Connected WaveSpeed keys are encrypted at rest and used by our backend to carry out the requests you authorize; the account interface only ever shows a masked key. Encryption reduces risk but does not mean your credentials or media can never be processed by the Service.
3. What we use it for
We use account and workflow data to authenticate you, save your workspace, run the processing you request, return results and administer your subscription. Technical and support data help us diagnose failures, secure the Service and respond to your requests. We may keep billing records for as long as accounting or other applicable law requires.
Where you contract with us directly, most of this processing is necessary to perform that contract with you. Some billing, security or support processing may instead rely on a legal obligation or our legitimate interests. Any optional processing that the law requires consent for will be presented to you separately, with its own choice.
4. Service providers we use
Not every workflow uses every provider — the material sent depends on the workflow you choose.
| Service | What we use it for |
|---|---|
| Supabase | Account authentication and storage for your uploaded media. |
| Railway | Hosting the application, background job processing and the database. |
| WaveSpeed and its model providers | Running the generation workflow you request, including the references and prompts it needs. Billed to your own connected WaveSpeed account. |
| Google Gemini | Source-video analysis, for workflows that use it. |
| Anthropic Claude | Prompt rewriting, and the observations or instructions that task needs. |
| Stripe (once activated) | Hosted subscription checkout, payment administration and the billing portal. We keep the related customer/subscription identifiers and status; card details are entered directly into Stripe’s hosted checkout, not into our systems. |
We have not yet finalized which of the providers above may process data outside your country or which international-transfer safeguards apply. We will describe the confirmed transfers and safeguards here before this policy is published.
5. Cookies and local storage
We use authentication cookies and browser storage to run the Service — for example to keep you signed in and to preserve workflow drafts and preferences. We do not currently use analytics or advertising cookies; if we add any optional analytics or advertising tools in the future, we will assess and disclose them here before turning them on. This policy does not cover cookies set by third-party sites you may be sent to, such as Stripe’s hosted checkout.
6. How long we keep data
We have not yet finalized specific retention periods for account, media, workflow, credential, billing and security data; we will publish them here once confirmed. In the meantime: removing a character in the interface currently archives it rather than deleting it immediately, and a historical WaveSpeed key may be kept while jobs that used it are still running. We do not promise that information disappears immediately when you remove it from the interface.
7. Access, correction and deletion
We do not yet offer self-service account deletion. To ask about accessing, correcting or deleting your data, contact us using the details on our Contact page; we will explain any retention we are required to keep (for example for legal or accounting reasons, or to resolve a dispute) and how any provider-held data is handled. We may need to verify your identity before acting on a request.
8. Your rights
Depending on the law that applies to you, you may have the right to access and correct your data, request erasure or restriction of processing, object to some processing, and receive a portable copy of your data. Where we rely on your consent, you can withdraw it at any time without affecting processing already carried out. You can also complain to your local data-protection authority.
9. Changes to this policy
We will update this page and its “Last updated” date if we make material changes to how we handle your data.