Privacy Policy
Last updated: 2026-05-12.
What we collect
Account info (email, name), generation prompts and outputs, billing data (handled by Stripe), and analytics (only after cookie consent).
How we use it
To provide the service. We don't train on your content. We don't sell your data.
Data retention
Active accounts: data retained while subscription is active. Cancellation: 30-day hot / 60-day cold / day-91 hard delete. GDPR erasure available on request via your dashboard.
Cookies
Essential cookies (session, security) are always on. Analytics cookies (PostHog) require explicit consent — toggled via the banner on first visit.
Third parties
Stripe (billing), fal.ai (model gateway), PostHog (analytics post-consent), Sentry (error tracking, anonymized), Resend (transactional email).
Contact
Privacy questions: privacy@single.studio.
Beta access applications
When you apply for invited beta access, Wundam LLC, a company established in the United States (registered address available on request), is the controller of the information you submit. You can contact us about privacy matters at privacy@single.studio.
We use your application data only to receive, evaluate and respond to your request for beta access. The lawful basis is Article 6(1)(b) GDPR: processing necessary to take steps at your request before entering into a contract. Your email address is required because we cannot evaluate or respond to your application without it; every other field is optional.
Please tell us about your work rather than including sensitive personal information, children’s data or information about other people. We do not intentionally collect or use that information for this application flow and may delete or redact it where identified. We do not collect payment data through this form.
Applications are reviewed by a person. We do not use automated decision-making that produces legal or similarly significant effects.
We share this data only with service providers needed to run the application flow: our database host, our transactional email provider and, only where you have accepted analytics cookies, our EU-hosted analytics provider. This form data is not shared with payment providers, AI model providers or content storage providers at this stage. Our database host (Neon) and product-analytics provider (PostHog) store this data in the European Union, and our transactional email provider (Brevo) operates in the European Union. Where this data is transferred or accessed outside the European Economic Area, we rely on appropriate safeguards — the European Commission’s Standard Contractual Clauses, and for our analytics provider also the EU–US Data Privacy Framework. You can request a copy of these safeguards at privacy@single.studio.
We keep application data for up to 180 days from submission, after which it is automatically deleted. If we decline your application, we delete its data within 30 days of our decision. If we invite you and you create a beta account, we may link your application to that account; from then on, our main privacy policy governs it. You can also delete your application at any time using the personal deletion link in your confirmation email, or by contacting privacy@single.studio. Deleted data is removed from our active systems without undue delay and from encrypted backups within 30 days.
You have the right to access, rectify, erase or restrict the use of your data, to data portability and, where applicable, to object to processing. You can lodge a complaint with your local data protection supervisory authority. If you are in the UK, you may complain to the ICO. If you are in Turkey, you have the rights set out in Article 11 of the Personal Data Protection Law No. 6698 (KVKK) — including to learn whether your data is processed, to request correction or deletion, and to object to outcomes arising solely from automated analysis. The legal ground for this processing under KVKK is Article 5(2)(c) (processing directly related to the establishment of a contract, at your request). You can exercise these rights at privacy@single.studio; under KVKK you must apply to us first, and you may then complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).