StudioLink legal
Privacy Policy
Effective August 19, 2026
StudioLink ("StudioLink," "we," "us," or "our") is a Washington, United States-based provider of software that connects users with AI coding tools and Roblox Studio through a local desktop application and related website, account, licensing, support, and payment services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Data, and the choices and rights available to you.
StudioLink is an independent service. Roblox, OpenAI, ChatGPT, Codex, Google, Discord, Stripe, Supabase, Cloudflare, GitHub, Resend, and Squarespace are separate companies and are not controlled by StudioLink. Their own terms and privacy notices apply when you use their services.
1. Scope and Data Controller
This Policy applies to Personal Data processed through the StudioLink desktop application, studiolink.art and related pages, StudioLink accounts, license fulfillment, support, and communications. It does not apply to third-party websites or services that StudioLink links to but does not control.
For purposes of the GDPR, UK GDPR, and similar laws, StudioLink is the controller of Personal Data described in this Policy unless we state otherwise. Contact: contact@studiolink.art. Location: Washington, United States.
2. Personal Data We Collect
Information you provide
- Account and profile information, such as your name, email address, date of birth, gender selection, profile image, user ID, and sign-in provider.
- Authentication and security information, such as password-verification results, session identifiers, multi-factor authentication status, and security-event metadata. StudioLink does not receive or store the password you use with Google or Discord. Email passwords are handled by Supabase Auth and are not stored by StudioLink in readable form.
- Purchase and license information, such as plan, payment status, Stripe checkout/session identifiers, purchaser email, license status, redemption time, and access expiration. StudioLink does not store full payment-card numbers.
- Projects, settings, and preferences, including project names, personalization instructions, selected models, themes, and workflow settings.
- User content, such as prompts, chat messages, code, feedback, support messages, and content you choose to process with an AI provider. StudioLink chats are stored locally on the device unless a feature expressly says otherwise. Prompts and related context are transmitted to the AI provider you select so that provider can generate a response.
- Roblox Studio information made available through the local MCP connection, such as place structure, scripts, or objects needed to carry out your request. This information is processed locally and by the selected AI provider; StudioLink does not operate a separate cloud copy unless a feature clearly states that it does.
- Communications you send to StudioLink, including support, legal, privacy, security, refund, or accessibility requests.
Information collected automatically
- Device and application information, such as app version, operating system, architecture, update status, connection status, and local diagnostic events.
- Security and service logs, such as authentication attempts, license verification, errors, crash context, webhook event identifiers, and timestamps. Desktop diagnostic logs are stored locally unless you choose to send them to support.
- Website information, such as IP address, browser/device type, pages viewed, referral information, and cookie or similar-technology choices, to the extent the website provider or consented tools collect it.
Information from others
- Google or Discord may provide account identifiers, email, name, avatar, and provider metadata when you choose social sign-in.
- Stripe provides payment, checkout, fraud, and transaction information needed to fulfill a purchase and handle disputes or refunds.
- Service providers may provide security, delivery, support, or usage information needed to operate and protect the Services.
We do not intentionally collect health information, precise geolocation, government identification numbers, or biometric templates through the ordinary Services. Do not submit sensitive Personal Data in prompts or support messages unless it is necessary and you are authorized to do so.
3. How and Why We Use Personal Data
We use Personal Data to:
- provide accounts, authentication, licensing, AI connectivity, local chat and project features, updates, and support;
- process purchases, deliver license keys, maintain transaction records, and prevent duplicate or fraudulent fulfillment;
- secure the Services, investigate misuse, enforce minimum supported versions, rate-limit risky actions, and detect incidents;
- personalize settings and remember choices;
- communicate about verification, security, purchases, service changes, support, and legal notices;
- comply with law, respond to valid legal process, and establish, exercise, or defend legal claims; and
- improve reliability and accessibility using aggregated or de-identified information where practical.
Where GDPR or similar law applies, our legal bases are performance of a contract, legitimate interests in operating and securing the Services, compliance with legal obligations, protection of vital interests when applicable, and consent where required. We rely on consent for non-essential website cookies and may rely on consent for optional marketing communications or sensitive data when required. You may withdraw consent at any time without affecting processing already completed lawfully.
4. AI Processing and User Content
StudioLink is a connector and interface; it is not the underlying AI model. When you use Codex, ChatGPT, or an OpenAI API key, prompts, code, relevant Roblox Studio context, and generated responses are processed by OpenAI under the OpenAI terms and privacy documentation that apply to your account or API use. If StudioLink later supports another AI provider, that provider's terms will apply.
Do not submit Personal Data, confidential information, or third-party content unless you have authority to process it. AI output may be inaccurate, incomplete, or insecure. Review and test output before using or publishing it.
5. Cookies and Similar Technologies
The StudioLink desktop app does not use advertising or analytics cookies. It uses local files and secure operating-system storage for necessary preferences, encrypted credentials, session recovery, chats, and logs.
The StudioLink website may use strictly necessary cookies or local storage for security, checkout routing, accessibility, and saving cookie choices. These necessary technologies operate without optional consent where permitted by law. Analytics, advertising, personalization, or other non-essential technologies will remain off until you affirmatively consent where consent is required. The website must provide equally accessible Accept All, Reject All, and Customize choices. You may change or withdraw consent at any time through Cookie Settings. Withdrawing consent does not affect the lawfulness of prior processing.
Browser signals such as Global Privacy Control will be honored where legally required. Because "Do Not Track" is not interpreted consistently across the industry, we do not respond to it unless required by law.
6. How We Disclose Personal Data
We disclose Personal Data only as reasonably necessary:
- to Supabase for account authentication, database, and Edge Function hosting;
- to Stripe and payment networks for checkout, payment processing, fraud prevention, disputes, and accounting;
- to Resend or another email provider for verification, license, security, and support email;
- to OpenAI when you use Codex, ChatGPT sign-in, or the OpenAI API;
- to Google or Discord when you choose their sign-in services;
- to Cloudflare for Turnstile bot protection, where enabled;
- to GitHub for software release and update delivery;
- to Squarespace or another website host for website operation;
- to professional advisers, insurers, auditors, and vendors bound by appropriate duties;
- to government authorities or other parties when required by law, valid process, safety, rights protection, or fraud prevention; and
- in a merger, financing, reorganization, sale, or transfer, subject to appropriate confidentiality and notice obligations.
We do not sell Personal Data for money. As of the effective date, we do not share Personal Data for cross-context behavioral advertising or use sensitive Personal Data to infer characteristics. We do not permit service providers to use Personal Data for their own purposes except as permitted by their direct relationship with you or required by law.
7. Data Retention
We retain Personal Data only for as long as reasonably necessary for the purpose collected, including security, accounting, dispute, and legal needs. The following schedule is the default unless a longer or shorter period is required by law, contract, a dispute, or a valid deletion request:
| Data category | Default retention |
|---|---|
| Account and profile data | While the account is active; deleted or de-identified within 30 days after a verified deletion request, subject to exceptions below |
| Local chats, preferences, encrypted API key, and desktop logs | Until the user deletes them, clears app data, or uninstalls; rotating desktop logs are limited in size |
| Cloud projects | While the account is active; deleted with the account or earlier at the user's request |
| Authentication sessions | Maximum seven-day StudioLink app session before interactive sign-in; provider-side records may follow provider settings |
| Password reset and magic links | Intended to expire within one hour; single-use or provider controls may end them sooner |
| Security and webhook logs | Generally up to 12 months, unless needed for an active investigation or legal obligation |
| Support communications | Generally up to 24 months after resolution |
| Purchase, tax, chargeback, and transaction evidence | Up to seven years or the period required by applicable accounting, tax, fraud, or legal rules |
| Consent records and legal acceptance evidence | For the duration needed to demonstrate compliance and enforce the agreement, generally up to seven years after account closure |
| Backups | Removed or overwritten on a rolling basis, generally within 90 days, unless isolated for security or legal preservation |
Deletion from active systems may not immediately remove data from encrypted backups. Backup data is isolated from ordinary use and deleted through the backup lifecycle.
8. Security
We use safeguards designed to protect Personal Data, including encrypted operating-system storage for desktop refresh tokens and API keys, no readable password storage, PKCE for OAuth, multi-factor authentication options, least-privilege public keys, row-level database security, authenticated server functions for license and deletion actions, Stripe webhook signature verification, rate limits, restricted Electron privileges, input escaping, and minimum-version enforcement.
No system is completely secure. You are responsible for protecting your device, email, authentication codes, API keys, and license keys. StudioLink staff will never ask for your password, multi-factor code, Stripe secret, or Supabase service-role key. If you believe your information is at risk, contact contact@studiolink.art promptly.
If a breach requires notice, we will provide notice in accordance with applicable law, including Washington breach-notification law where applicable.
9. International Data Transfers
StudioLink is based in the United States, and providers may process data in the United States and other countries. Where required for transfers from the EEA, United Kingdom, or Switzerland, StudioLink will use an approved transfer mechanism—such as an adequacy decision, Standard Contractual Clauses, the UK Addendum, or another lawful mechanism—and supplementary safeguards when appropriate.
10. Your Privacy Rights
Depending on your location, you may have rights to:
- know or access Personal Data and receive a portable copy;
- correct inaccurate Personal Data;
- delete Personal Data;
- restrict or object to certain processing;
- withdraw consent;
- opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
- appeal a denied privacy request where applicable; and
- complain to a data-protection authority.
You can update profile information, download a data export, clear local data, and delete your account from Settings > Privacy & Data. You may also email contact@studiolink.art with the subject "Privacy Request." We may verify identity and authority before acting. Authorized agents may be required to provide proof of authority. We will respond within the time required by applicable law.
GDPR Article 17
Where GDPR Article 17 applies, you may request erasure without undue delay when the legal requirements are met. The right is not absolute. We may retain limited information when processing is necessary for freedom of expression and information, legal compliance, public interest, archiving or research where applicable, or the establishment, exercise, or defense of legal claims. A deletion request will not require StudioLink to delete records independently controlled by a third party; you must contact that provider directly when necessary.
11. Children and Teen Users
The Services are not directed to children under 13, and we do not knowingly collect Personal Data from a child under 13. If we learn that we have done so, we will delete it as required by law. Users who are under the age of legal majority where they live may use the Services only with permission and supervision of a parent or legal guardian who agrees to the Terms of Service on their behalf. EU parental-consent ages may vary from 13 to 16.
If you believe a child provided Personal Data unlawfully, contact contact@studiolink.art.
12. Accessibility
StudioLink aims to make its privacy notices and privacy controls accessible, including keyboard operation, visible focus, meaningful labels, sufficient contrast, reduced-motion support, semantic headings, and screen-reader status messages. We target WCAG 2.2 Level AA as an engineering goal and will provide a reasonable alternative method for a privacy request when needed. Accessibility feedback may be sent to contact@studiolink.art with the subject "Accessibility."
13. Changes to This Policy
We may update this Policy to reflect changes in law, technology, or the Services. We will post the updated date and provide additional notice when a change is material or consent is required. Continued use after an effective update constitutes acknowledgment only to the extent permitted by law; we will obtain consent when law requires it.
14. Contact
StudioLink
Washington, United States
Email: contact@studiolink.art
Privacy requests: use Settings > Privacy & Data or email contact@studiolink.art with the subject "Privacy Request."