Kaldune Back to Kaldune

Document 04 · Legal & Privacy

Privacy Policy

What we collect, why, and the promises behind it: we know two things about you (your name and your time zone), your work is yours and downloadable the moment it exists, every brief is its own sealed world, we don't use your work to train or improve any AI model, and the one time we'd disclose your data is a court order we tell you about. Kaldune serves users worldwide, operated from the US by Studio58, Inc.

Last updated 17 July 2026 · Version 1.4

The promises, plainly

Before the full policy, here is what it all comes down to. Every promise on this list is written out in exact terms further down, and every one of them is true.

That's the whole of it. The rest of this page is the same promises, in the exact terms a lawyer and a regulator would hold us to.


Where you are

Kaldune is used all over the world. Studio58, Inc. operates Kaldune from the United States, and people use it from many countries. Wherever you are, the promises above apply to you.

Some places give you specific legal rights over your data, and this policy spells the biggest ones out in full further down:

Whoever and wherever you are, you can reach us at the contact below and we'll help. And wherever we send data across borders to run the service for you, we protect it with the transfer safeguards in §5.


The full policy

Who we are. Studio58, Inc. ("Kaldune," "we," "us," or "our") is the company that operates the Kaldune service. Studio58, Inc. is the data controller for the personal data described in this policy, it decides what we collect and why. When we say "the studio" or "Kaldune," we mean the Kaldune service; when we say "we," "us," or "our," we mean Studio58, Inc.

This policy explains what personal data we collect when you use Kaldune, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers both individual customers and business customers, and it applies to Kaldune's users worldwide (see Where you are, above). Where a section applies only to one kind of customer or one place, we say so.

1. What we collect and why

We collect only what we need to run Kaldune for you, and we keep the personal profile we hold about you deliberately small. The plainest way to say it: the only personal data the studio holds about you as a person is your name and your time zone. Everything else on this page is either something we don't hold ourselves (your card details, held by our payment processor) or your own work (stored for you, not turned into a profile of you). Here is the full account.

Your personal profile, your name and your time zone. The studio keeps your name (because you sign in with it and we address you by it) and your time zone (read from your device's clock so the studio knows your local time). That is the entire profile we hold about you. We do not build any further picture of you, no behavioral profile, no record of your habits, no tracking of what you do across the service, and nothing about you is sold or shared for anyone else's purposes.

What you need to sign in. To run an account we also hold the credentials and settings the account itself needs, your email address (to sign in and to send you the service messages your account depends on), your password (stored hashed, never in the clear), and your language preference. These are the keys to your account, not a profile of you; we use them to let you in and to reach you about your account, and for nothing else. For business customers, this also includes the organization and the people it authorizes to use it.

Your card details, held by our payment processor, not by us. When you add funds, payment is handled by our payment processor, Stripe. The studio never sees or stores your full card details, they go directly to Stripe, which is bound to use them only to process your payment. See §4 (sub-processors) and, for the money terms themselves, the Terms.

Your work, stored for you, not studied. The briefs you write and the work the room delivers to you. We store this so your room is waiting for you when you return, so you can download it whenever you want, and so you can resume a brief where you left off. This is your content, and it is not part of the personal profile above, we don't read it in the normal course, we don't profile you from it, we don't sell or share it, and we don't use it to train or improve any AI model. See §2 (how the room works), §3 (every brief is sealed), §6 (retention), §7 (the one support exception), §5.3 (the one legal-disclosure exception), and §9 (your rights, including export).

Usage and technical data, kept to a minimum, and not about you. To keep the service running securely and to fix faults, we keep basic technical logs. We hold these to the aggregate level wherever we can, our error-diagnostics tooling is configured to scrub your work out of the records it collects, and we do not use them to build a profile of you or to track you across the service.

We do not collect special-category data (health, biometric, and the like) as a matter of course. If your briefs or your work happen to contain such data because that's the work you asked for, it is handled as your content under the promises above, not added to any profile of you.

2. How the room works, the AI provider

Kaldune's room is powered by Claude, an AI system made by Anthropic, which we access through Anthropic's commercial API. To answer your brief, the relevant parts of it are sent to Anthropic to generate a response, then returned to your room.

This matters for your privacy, so we are specific about it:

Anthropic acts as our data processor for this work. Anthropic in turn relies on its own infrastructure providers, Google Cloud Platform, Amazon Web Services, Microsoft Azure, and Cloudflare, to host and route data, worldwide. See §5 (international transfers) for how that is protected.

3. Every brief is sealed and worked on its own

Every brief in Kaldune is completely independent. Each one is worked in its own sealed context, its own working memory, and nothing carries from one brief to another:

How this fits with resuming a brief. A brief persists so you can leave it and come back, and the same brief, resumed, is still that one sealed world, right where you left it (see §6 and the Terms on ownership and resuming). Persisting and resuming happen within a single brief; they never merge one brief into another. Sealed-and-independent applies between briefs; resumable applies within one.

How this fits with search and memory. Two features touch more than one brief, and neither breaks the seal:

4. Who we share your data with, sub-processors

We do not sell your personal data, and we do not share it except with the service providers we need to run Kaldune. Each is bound by contract to use your data only to provide its service to us, and nothing else. Our sub-processors are:

ProviderWhat it does for usWhere
Anthropic (Anthropic, PBC; Anthropic Ireland, Limited for UK/EEA/Swiss customers)Powers the room, the AI models that answer your brief, via the commercial APIUnited States (Anthropic Ireland contracts with UK/EEA/Swiss customers)
Cloud hosting providerHosts the app and the database; stores your work and our encrypted backups(To be named)
Stripe, Inc.Processes card payments for prepaid top-ups (card data is tokenized by Stripe; we never see or store card numbers)United States
Transactional email providerSends account emails, sign-in, resets, notifications(To be named)
Product analytics providerMeasures aggregate usage so we can improve Kaldune(To be named, privacy-respecting, see §10)
Error-monitoring providerDiagnoses crashes and faults so we can keep the service reliable (configured to scrub your work from its records)(To be named)
Customer-support providerRuns the help-desk tooling that handles your support requests (this is where the support access in §7 happens, when you ask for it)(To be named)

The providers marked (to be named) are confirmed and their locations published here before this policy goes live; each one's contract restricts your data to running Kaldune and nothing else. Stripe (payments) is confirmed and named, consistent with the Terms (§7.5) and the DPA. Anthropic's no-training commitment (§2) is stated absolutely because it is in Anthropic's Commercial Terms.

When we add a new sub-processor. We give you advance notice, our current policy is 30 days, before a new sub-processor starts handling your data, and business customers can object under the DPA.

5. International transfers

Kaldune operates from the United States, and some of our providers operate in the United States and other countries. When we move personal data out of the UK, the EEA, or Switzerland, we protect it with a recognized transfer mechanism:

If you are elsewhere in the world, your data is likewise processed in the United States and the other countries where our providers operate; where your local law requires a transfer safeguard, we apply one.

5.1 We don't sell or share your data

We do not sell your personal data, and we do not share your Customer Content, except with the sub-processors above who are contractually bound to use it only to run Kaldune for you. This holds worldwide.

5.2 We don't read your work in the normal course

In the ordinary operation of the service, no one at the studio reads your briefs or the work in your room. The only in-house exception is support, and only when you ask, that is set out in full in §7. Written here so this section is complete; the canonical wording is §7.

5.3 When a government or a court asks for your data

This is the one exception to §5.2 that neither we nor you choose, and we treat it as narrowly as it deserves. It is written here in the same words as the Terms (§5.3), so the two can never say different things.

When a government or a court asks for your data. We disclose your work or your personal data to a government or law-enforcement authority only when we're legally required to, when we're compelled by valid legal process, such as a subpoena, court order, or warrant, or in a genuine emergency where someone is at risk of serious physical harm. When we get a request like that, we don't just hand everything over: we check that it's valid, we push back on requests that are overbroad or vague, and we disclose only the specific data the law actually compels, nothing more. And wherever we're legally allowed to, we tell you before we disclose, so you have the chance to protect your data, unless a court has ordered us not to, or someone is in danger. A compelled disclosure like this is the one narrow exception to our promise that we don't read your work in the normal course (§7): the law can open this one door, and when it does, we open it as little as the law allows and we tell you we're doing it.

How this fits with the AI provider. Because Kaldune uses Anthropic's commercial API (not a consumer product), if a government seeks your content held at Anthropic's layer, Anthropic's published policy is to ask the requester to contact its customer, that's us, Studio58, Inc., in the first instance. So the request comes to us, where the narrow, notify-you-first posture above applies. Anthropic's separate consumer good-faith-sharing posture does not apply to Kaldune, because we are not on the consumer product. We never volunteer your work to law enforcement; we respond only to valid legal process.

6. Retention, how long we keep your work, and when it's gone

We keep two clocks, and we tell you both: our own storage (what Kaldune keeps so you can return to your work) and the AI provider's processing (what Anthropic holds briefly to answer your brief).

Two things this section does not do: it does not delete your work because a payment balance ran low or ran out, and it does not delete work from a brief you left unfinished. Your work leaves only when you delete it or close your account, or where the law requires it. Running low on funds pauses new work; it never removes what you already have.

Our storage:

WhatHow long
Your work, while your account is openKept so you can come back to it and download it, until you delete it or close your account. A low or empty balance does not shorten this.
After you delete a briefRemoved from your studio immediately, with everything in it, delivered work included; deleted from our active systems within 30 days.
After you delete your accountYour account and your work are deleted from our active systems within 30 days of the request. Before deletion, you can export everything, see §9.
Encrypted backups (the honest window)Data you've deleted from our active systems still sits in our encrypted backups until those backups cycle out. This takes no longer than 90 days after active-system deletion, after which it is overwritten and cannot be recovered.

A note on the backup window, kept honest. The "no longer than 90 days" above is our protective ceiling while we confirm the true rotation period of our backups. When it's confirmed, we publish the real number here, shorter if it's faster, and the true longer number if it's longer. We won't round it down to sound better. This is the one number on this page still being confirmed; it matches the same figure in the Privacy Choices page and the DPA, and all three change together.

The AI provider's processing:

WhatHow long
Anthropic's handling of what it processes for usDeleted from Anthropic's systems within 30 days of receipt or generation.
If Anthropic's trust-and-safety systems flag content as a usage-rules violationRetained by Anthropic up to 2 years; safety-classification records up to 7 years (see §2).

Legal holds. We may keep data longer where the law requires it, to resolve a dispute, or to deal with misuse, at both layers above.

7. We don't read your work, and the one exception, stated plainly

This is the reconciliation of two things that are both true, written here exactly as it is written on our support pages so the two can never say different things:

We don't read your work, and here's the one exception, stated plainly.

In the normal course, no one at the studio reads your briefs or the work in your room. We're not sitting behind the glass reading over your shoulder.

The one exception is support. If you ask us for help with something in your work, and only then, a support specialist can open the specific brief or item you've pointed us to, for the specific purpose you asked about, and nothing more. Every one of those accesses is logged: who opened it, when, and why. You can ask us for that record.

We never browse your work for any other reason, and we never use it to train AI models.

There is one other exception, and it is not one we choose: when the law compels us to disclose your data. That is set out in §5.3, and it is the only other time your work leaves the normal course, narrow, checked, and told to you wherever we're allowed to tell you.

8. Legal bases for using your data (GDPR)

If you are in the UK, the EEA, or Switzerland, we rely on these legal bases under Article 6 of the GDPR:

What we doLegal basis
Run your account, store your work, and deliver what you brief, the core servicePerformance of a contract (Art. 6(1)(b)), we need to do this to provide the service you signed up for.
Bill you and keep financial recordsPerformance of a contract and legal obligation (Art. 6(1)(b), (c)).
Keep the service secure, reliable, and free from misuseLegitimate interests (Art. 6(1)(f)), running a safe, working service, balanced against your rights.
Send you service messages (an answer's ready, a question from the room, a security notice)Performance of a contract (Art. 6(1)(b)).
Send you marketing emailConsent (Art. 6(1)(a)), opt-in, with an unsubscribe link in every message.
Comply with a legal obligation, including responding to valid legal process (§5.3)Legal obligation (Art. 6(1)(c)), and, where applicable, our or a third party's legitimate interests (Art. 6(1)(f)) in cooperating with lawful requests.

Where we rely on legitimate interests, you can object, see §9.

9. Your rights

If you are in the UK, the EEA, or Switzerland (GDPR). You have the right to:

You can exercise the everyday versions of these rights yourself, memory and deleting a brief are controls in the product, and exporting your work or deleting your account is one email to privacy@kaldune.ai (see Privacy Choices for every control and its real mechanism). Exporting your work is always available while your account is open, and is not tied to your payment status. For anything else, contact us (§13). We respond within one month, as the GDPR requires.

If you are in California (CCPA/CPRA). You have the right to:

You can exercise these rights through the controls and channels in Privacy Choices or by contacting us (§13). We do not use or disclose your personal information for cross-context behavioral advertising.

If you are elsewhere in the world. Kaldune serves users worldwide (see Where you are, near the top). Many countries, for example Brazil (under the LGPD, Lei nº 13.709/2018) and Canada (under PIPEDA), give you rights over your personal data that resemble the ones above, such as to confirm we hold your data, access it, correct it, delete it, or receive a copy. Where your local law gives you those rights and it applies to us, we honor them. Use the same contact in §13 and we'll help; we don't make you clear a higher bar because of where you live. We describe this honestly: we honor the data-rights your local law gives you where they apply, we don't claim a separately certified compliance program for every country's regime, and if you'd like to know how a specific right works for you, just ask.

Authorized agents and verification. We may need to verify your identity before acting on a request, and we honor requests made by an authorized agent on your behalf where the law provides for it.

10. Cookies and tracking

Kaldune uses only the cookies it needs to work, the session and sign-in cookies that keep you logged in. For understanding aggregate usage, our default is privacy-respecting analytics that don't set tracking cookies and don't identify you individually, so there's no consent banner to click through.

Marketing emails, if you opt in, always carry an unsubscribe link, and we don't sell your contact details.

11. Security

We protect your data with encryption in transit and at rest, access controls that give staff only the access they need, and the operational practices of a service that takes this seriously. Our AI provider, Anthropic, maintains its own security program, encryption (AES-256 at rest, TLS 1.2 or higher in transit), least-privilege access, annual third-party audits and penetration testing, and independent certifications (SOC 2, ISO 27001). No system is perfectly secure, but we hold ourselves and our providers to a high, verifiable standard.

If a data breach affects your personal data, we notify you and the relevant authorities as the law requires, without undue delay.

12. Changes to this policy

When we change this policy, we update the "last updated" line and the version at the top. If a change materially affects your rights, we'll tell you directly, by email or in the product, before it takes effect, and, where the law requires it, we'll ask for your agreement.

13. Contact us

For any privacy question, to exercise a right (wherever in the world you are), or to ask for the record of any support access to your work, contact us:

Business customers processing their own end-users' personal data through Kaldune should also see our Data Processing Addendum, which governs that relationship and in which Studio58, Inc. acts as your processor.

Back to Kaldune

Kaldune is a product of Studio58, Inc.