An agency that is AI Early access

Privacy Policy

What we collect, why, and the promises behind it. Every promise on this page is written out in exact terms further down, and every one of them is true.

Studio58, Inc. · Last updated 12 September 2026 · Version 2.3

The promises, plainly

The rest of this page is the same promises, in the exact terms a lawyer and a regulator would hold us to.


Who we are

Studio58, Inc. ("Kaldune," "we," "us," or "our") is a Delaware corporation and the company that operates the Kaldune service. Studio58, Inc. is the data controller for the personal data described in this policy: it decides what we collect and why. This policy covers individual and business customers, and it applies to Kaldune's users worldwide.

1. What we collect and why

We collect only what we need to run Kaldune for you.

Your account. Your name (you sign in with it and we address you by it), your email address (to sign you in and send the service messages your account depends on), your time zone (so the studio knows your local time), and your language preference. Kaldune is passwordless: you sign in with Google or with a one-time code sent to your email. There is no password field in the product and no password stored anywhere.

Memory notes: none today, and yours to control if they ever exist. The studio keeps no memory of you between briefs; each brief starts from what you bring it. The studio is built to keep a small file of plain facts and preferences you've stated, the way an account team remembers a returning client, and it is not switched on. If it is ever switched on for your account, this is the commitment it arrives with, stated here first: each note is written in the studio's own words, carries its date, and is announced in the conversation when it is made; when you correct something, the note is updated then and there; if you run briefs for different clients of your own, notes are kept one file per client and never cross between them; memory never determines what the studio makes, and your current brief always outranks it; the studio does not note credentials or passwords, confidential or unannounced material, or sensitive-category personal details (health and the like); you can read, edit, or delete any note, or switch memory off entirely, in Settings; your data export includes the notes; and deleting your account deletes them on the same schedule as the rest of your data (Section 7).

Your card details, held by our payment processor, not by us. When you add funds or start a subscription, payment is handled by Stripe. Studio58, Inc. never sees or stores your full card details; they go directly to Stripe, which is bound to use them only to process your payment.

Your work, stored for you, not studied. The briefs you write, the files you attach, and the work the studio delivers to you. We store this so your studio is waiting when you return, so you can download everything whenever you want, and so you can resume a brief where you left off. It is your content, not a profile of you: we do not read it in the normal course, we do not profile you from it, we do not sell or share it, and we do not use it to train or improve any AI model.

Usage and technical data, kept to a minimum. Basic technical logs to keep the service secure and to fix faults, plus the ledger of your credits and receipts so your billing is accurate. Our error-diagnostics tooling is configured to keep your work out of the records it collects, and we do not use logs to build a profile of you.

We do not collect special-category data (health, biometric, and the like) as a matter of course. If your briefs happen to contain such data because that is the work you asked for, it is handled as your content under the promises above, not added to any profile of you.

2. The AI that does the work

The work in your brief is produced by AI models from third-party vendors, which we access through their commercial offerings. To answer your brief, the relevant parts of it are sent to the vendor producing that piece of the work, and the result is returned to your brief. This matters for your privacy, so we are specific:

The vendors that handle your content are listed in Section 4 and on our Trust page.

3. Every brief is its own sealed world

Every brief in Kaldune is worked in its own sealed context, and nothing carries from one brief to another:

A brief persists so you can leave it and come back; the same brief, resumed, is still that one sealed world, right where you left it. Persisting and resuming happen within a single brief; they never merge one brief into another.

4. Who we share your data with

We do not sell your personal data, and we do not share it except with the service providers we need to run Kaldune. Each is bound by contract to use your data only to provide its service to us, and nothing else.

| Provider | What it does for us | Where | |---|---|---| | Google Cloud Platform | Infrastructure and hosting; stores your work and our encrypted backups | United States (us-central1) | | Anthropic | AI model inference for the work in your brief | United States | | Google (Gemini API) | AI model inference for the work in your brief | United States | | fal.ai | Image, video, and media model inference | United States | | ElevenLabs | Audio generation, on briefs that include audio | United States | | Stripe | Payment processing (card details go to Stripe directly; we never see them) | United States | | Resend | Transactional email: sign-in codes, receipts, account notices | United States |

When we add a new provider. We give advance notice, currently 30 days, before a new provider that handles your data starts doing so, and business customers with a data processing agreement can object under it.

5. Where your data lives, and international transfers

Customer data lives on Google Cloud Platform in the United States (region us-central1). Kaldune operates from the United States, and our providers operate in the United States. When we move personal data out of the UK, the EEA, or Switzerland, we protect it with a recognized transfer mechanism, principally the European Commission's Standard Contractual Clauses together with the UK and Swiss addenda where they apply. If you are elsewhere in the world, your data is likewise processed in the United States; where your local law requires a transfer safeguard, we apply one.

6. We do not read your work, and the two narrow exceptions

In the ordinary operation of the service, no one at Kaldune reads your briefs or the work in them. There are exactly two exceptions, and we state both plainly:

Support, when you ask. If you ask us for help with something in your work, and only then, a support specialist can open the specific brief or item you pointed us to, for the specific purpose you asked about, and nothing more. Every such access is logged: who opened it, when, and why. You can ask us for that record at hello@kaldune.ai.

A valid legal demand. We disclose your work or personal data to a government or law-enforcement authority only when we are legally compelled to, by a validly issued subpoena, court order, or warrant, or in a genuine emergency where someone is at risk of serious physical harm. When we get such a request, we check that it is valid, we push back on requests that are overbroad or vague, and we disclose only the specific data the law actually compels. Wherever we are legally permitted to, we tell you before we disclose, so you have the chance to protect your data. We never volunteer your work to anyone.

7. Retention: how long we keep your work, and when it is gone

Two things this section does not do: it does not delete your work because your credits ran low, and it does not delete work from a brief you left unfinished. Your work leaves only when you delete it or close your account, or where the law requires it.

| What | How long | |---|---| | Your work, while your account is open | Kept so you can come back to it and download it, until you delete it or close your account. A low or empty credit balance never shortens this. | | After you delete a brief | Removed from your studio immediately; recoverable for 30 days by contacting us, then permanently deleted from our systems. | | After you delete your account | Your account and your work are permanently deleted within 90 days, except billing records, which US tax law requires us to keep (currently seven years) in encrypted archive. | | Encrypted backups (the honest window) | Deleted data can persist in encrypted backups until they cycle out, no longer than 90 days after active-system deletion, after which it is unrecoverable. | | Technical logs | 30 days. | | Billing ledger (credits, receipts) | The life of the account plus the period US tax and accounting law requires, currently seven years. | | A page you published | Public while published, by your action only: 30 days per activation on pay-as-you-go, with free one-click reactivation, or the life of your subscription plus a 14-day grace period on a custom address. Taking a page down, or its expiry, removes the public copy immediately. The underlying work stays in your studio under the rows above. |

Legal holds. We may keep data longer where the law requires it, to resolve a dispute, or to deal with misuse.

8. Your controls, in Settings

Two of the most important rights are controls in the product itself, not a request you have to write:

One more control lives with the work itself: if you have published a piece of work as a public page, you can take that page down instantly, at any time. Nothing you make is public unless you publish it. The publishing rules by plan are in the Terms of Service, Section 3.9.

For anything these controls do not cover, email hello@kaldune.ai and we will help.

9. Your rights around the world {#where-you-are}

If you are in the UK, the EEA, or Switzerland (GDPR). You have the right to access the personal data we hold about you; to rectify data that is wrong; to erasure, subject to the legal-hold exceptions in Section 7; to restrict or object to processing, including any direct marketing; to data portability; to withdraw consent where we rely on it; and to lodge a complaint with your data protection authority. The legal bases we rely on are performance of a contract for the core service and billing, legitimate interests for security and reliability, consent for marketing email, and legal obligation for tax records and valid legal process. We respond within one month, as the GDPR requires.

If you are in California (CCPA/CPRA). You have the right to know what personal information we collect, use, and disclose; to access and receive a copy; to correct it; to delete it, subject to Section 7's legal-hold exceptions; to opt out of sale or sharing (we do not sell or share your personal information as the CPRA defines those terms, so there is nothing to opt out of, but the right stands); to limit use of sensitive personal information (we do not use it beyond providing the service); and not to be discriminated against for exercising any of these rights. We do not use your personal information for cross-context behavioral advertising.

If you are elsewhere in the world. Many countries give you similar rights over your personal data: to confirm we hold it, access it, correct it, delete it, or receive a copy. Where your local law gives you those rights and it applies to us, we honor them. We do not make you clear a higher bar because of where you live.

Verification and agents. We may need to verify your identity before acting on a request, and we honor requests made by an authorized agent where the law provides for it.

10. Cookies

Kaldune uses only the cookies it needs to work: the session and sign-in cookies that keep you signed in. We do not set advertising or cross-site tracking cookies, and there is no consent banner to click through because there is nothing to consent to. Marketing email, if you opt in, always carries an unsubscribe link, and we do not sell your contact details.

11. Security

We protect your data with encryption in transit and at rest, passwordless sign-in, access controls that give staff only the access they need, and the operational practices of a service that takes this seriously. The full picture, including our infrastructure, sub-processors, and vulnerability-reporting process, is published on the Trust page. If a data breach affects your personal data, we notify you and the relevant authorities as the law requires, without undue delay.

12. Children

Kaldune is not directed to children, and you must be at least 18 to use it. We do not knowingly collect personal information from anyone under 13; if we learn that we have, we delete it. If you believe a child has used the Service, contact hello@kaldune.ai.

13. Changes to this policy

When we change this policy, we update the date at the top. If a change materially affects your rights, we tell you directly, by email or in the product, before it takes effect, and where the law requires it, we ask for your agreement.

14. Contact {#contact}

For any privacy question, to exercise a right wherever in the world you are, or to ask for the record of any support access to your work: