Skip to content
EzraGallerySTUDIO
Back to the studio ↗Contact

Privacy

Your artwork is yours.
Here’s how we look after it.

A clear picture of what stays on your device, what is processed for a download, and how to contact us about your data.

Updated 12 September 2026

On this page

01Your artwork, step by step02Information we use03Why we use it04How long information stays05Services involved06Cookies and device storage07Your choices and rights08Updates to this notice

01

Your artwork, step by step

  1. Preview on your device. Selecting a file loads its pixels into your browser’s memory. Browsing scenes does not send that artwork to our server. Reloading or closing the page clears the app’s working copy; your original file stays on your device.
  2. Request a cloud download. Requesting a finished image sends the selected artwork to private temporary storage and an authorized rendering service to create and deliver your finished image. For a paid single image, artwork is staged privately before opening checkout so returning from payment does not depend on the original tab staying open.
  3. Remove temporary files. Temporary artwork is removed after rendering; the detailed timing below also covers interrupted uploads and finished images.

We do not claim ownership of your artwork, add it to our scene library, sell it, use it in our marketing without separate permission, or use it to train AI models. Studio composites your actual image; it does not redraw it with generative AI.

02

Information we use

  • Accounts and purchases: your verified Clerk account identifier and the email or Google account information used to sign in; Stripe customer, checkout and subscription identifiers; payment/access status; scene, format and resolution; file sizes, image dimensions and checksums that identify artwork for a purchase. A checksum is a fingerprint, not a stored copy of the pixels.
  • Payments: Stripe collects payment and billing details in its checkout. Studio does not receive your full card number or security code.
  • Support: your name, email address, message, receipt reference and anything you send. Studio validates and rate-limits the contact form, verifies a Cloudflare Turnstile security token, then sends the bounded support fields through Resend to our support inbox. No artwork is attached automatically. Email attachments follow support retention, not the rendering cleanup schedule.
  • Technical information: hosting and security services process connection information such as IP addresses, request timing and errors. Studio records render status and operational/security events to deliver downloads and investigate problems.

Individual purchases can be made as a guest. A necessary, secure, HttpOnly cookie keeps access to recent downloads in the same browser for up to 24 hours, including after a refresh. Clearing cookies, private browsing, or switching browsers can remove that access; contact support with your receipt if needed. We do not identify a returning customer just because they enter a matching email address. We need artwork to render an image, verified account information for membership, and payment information to complete a purchase. Without those inputs, those features cannot work. Do not upload sensitive personal records or information about other people unless you have the necessary rights.

Optional monthly scene emails

When you explicitly join, we collect your email address, signup placement, requested scene tags, a keyed hash of your IP address, the consent wording and version, and request and confirmation times. MailerLite manages the list and sends a confirmation email. You join only after confirming. Resend delivers the welcome email and one monthly update. Signing in, paying or asking for support does not subscribe you. Optional checkboxes start unchecked. The lawful basis for these emails is your consent.

Confirmation issues one single-use $2 finished-image credit. We keep a pseudonymous credit ledger containing a hashed code, issue time and redemption job/fingerprint to prevent reuse. It is separate from payment records, contains no artwork, and remains valid if you unsubscribe. A verified account may be linked so members receive a relevant version of the monthly email.

Use the unsubscribe link or your email app’s one-click unsubscribe control. We suppress queued delivery immediately after your request; provider synchronization follows automatically. Your account and purchases are unaffected. Unconfirmed addresses are removed from our active records after 30 days. After unsubscribing, the email address and scene tags are removed after 30 days; MailerLite’s forget process can take a further 30 days. We retain consent evidence for up to two years and a minimal keyed suppression/credit identifier for as long as needed to honor your opt-out and prevent a repeat joining credit. Delivery content is removed after 90 days. Provider security logs and backups follow their own retention terms. You may request earlier deletion at the contact address below.

We use device-local storage only to limit the quiet signup card to once per 14 days. No newsletter opens or clicks are tracked by our code. The newsletter supplies view and successful-submit event hooks for a future analytics integration, without email or artwork; confirmed signup events are recorded server-side with the placement for up to 90 days. Anonymous confirmation counts are sent to PostHog Cloud (EU); no newsletter email address or consent record is included.

03

Why we use it

Where data-protection law requires a lawful basis, we use information to perform our agreement with you: create requested images, manage purchases and provide support. Our legitimate interests cover service security, preventing payment abuse and fixing faults. Legal obligations cover applicable accounting and lawful disclosure requirements. Support messages do not subscribe you to marketing.

Payment and download permissions are checked automatically. If a check appears incorrect, ask us to review it. We do not operate an advertising-profile system.

04

How long information stays

Artwork submitted for rendering
Deleted after a rendering attempt. Interrupted or abandoned uploads expire after one hour; hourly cleanup is designed to remove them within two hours in normal operation.
Finished cloud downloads
Images completed while signed in, including small previews, are saved privately in My downloads until you remove them or request account deletion. No membership is required to retrieve a saved image. Removal immediately hides the image from My downloads; the file is deleted after its original 24-hour delivery window and the next hourly cleanup, or at the next cleanup if that window has passed. Guest files and ZIP bundles remain accessible for 24 hours, then are normally deleted at the next hourly cleanup. Files already deleted before account saving was introduced cannot be restored.
Account, purchase and support records
These are separate from image files. We retain records needed for your account, payment verification, support, fraud prevention and applicable tax or legal claims. They are not automatically erased on the image schedule. Resend processes the message for delivery; its service retention and the received support email are separate from artwork cleanup. The received email follows our support-record criteria. We review deletion requests against these purposes and explain any information that must remain.

Outages can delay physical deletion. New cloud work is paused when required cleanup checks are unhealthy. The image timetable does not describe providers’ own security logs, billing records or backups; their policies also apply. Original uploaded artwork is processed temporarily and is not backed up. Account storage holds finished images only.

05

Services involved

  • Cloudflare: website hosting, private file storage, database, delivery infrastructure and Turnstile spam protection. Invisible verification is subject to the Turnstile Privacy Addendum ↗. Privacy policy ↗
  • Browserless: the cloud browser for authorized final renders. Privacy policy ↗
  • Clerk: email verification, optional Google sign-in and account sessions. Privacy policy ↗
  • Stripe: payments, subscription management and payment security. Artwork pixels are not sent to Stripe. Privacy policy ↗
  • MailerLite: optional newsletter list management and double opt-in confirmation. Privacy policy ↗
  • Resend: delivers support messages, configured account emails, and confirmed newsletter welcome/monthly emails. Privacy policy ↗
  • Google: optional Google sign-in and hosted business email when configured. Privacy policy ↗

We are based in the United States. These services may process information in the US and other countries; Studio does not promise storage exclusively in your country. Our rendering endpoint is in the United States; hosting, account, payment and support providers may process information internationally under their applicable terms and privacy notices linked above. Contact us for information about the arrangements relevant to your data. We do not promise that your information remains in one country.

We disclose information as necessary to provide the service, comply with applicable law or protect against fraud and misuse. We do not sell personal information or share it for cross-context behavioral advertising.

06

Cookies and device storage

Studio’s own code does not add advertising pixels, marketing cookies or persistent artwork storage in your browser. Studio uses necessary download-access cookies for up to 24 hours; these contain access credentials, not artwork pixels, and are not readable by page scripts. My downloads also uses a secure, HttpOnly, image-bound cookie lasting up to one minute to start native file downloads after account verification. Hosting, sign-in and Stripe may use cookies or similar technology for authentication, payment security and their services; their policies explain those uses. Our fonts are served with the site rather than requested from a third-party font service.

Visit attribution. Our own first-party sessionStorage remembers approved campaign tags (UTM source, medium and campaign), the referring site origin and the landing-page path for the current tab. It contains no visitor ID and normally clears when the tab closes. These values accompany checkout and are stored with the order to understand which channels bring purchases. A tab-scoped, hashed transaction marker prevents repeat purchase events on refresh; it does not identify a person. PostHog itself uses memory only.

Measurement. PostHog Cloud (EU) measures page views and actions such as using sample artwork, selecting scenes and completing a purchase. No emails, artwork, filenames, credit codes or payment credentials are sent as analytics event properties. Cookieless analytics writes no cookies or browser storage and uses no persistent visitor ID. To count daily visitors, the provider transiently processes IP addresses and browser user-agent information into a rotating hash, then strips IP addresses before enrichment. Daily hashes reset; we do not enable person profiles, session replay, location enrichment or advertising tracking. Our purpose is to understand and improve site performance. You can object using the contact details below. Necessary sign-in, security and download cookies remain separate.

07

Your choices and rights

Email hello@ezra-gallery.com to request access, correction or deletion. Depending on applicable law, you may also have rights to portability, restriction, appeal and withdrawal of consent where processing relies on it. We may request proportionate information to verify your identity, and will respond within the applicable legal timeframe.

You may object to processing based on our legitimate interests. Tell us what you object to and why. We will review the request under applicable law. Exercising a privacy right will not lead to discriminatory treatment.

You may complain to your local data-protection authority. In the EEA, consult the EDPB authority directory ↗; in the UK, contact the ICO ↗. Contacting us first is welcome but is not required.

Studio is intended for adults, not children under 18. If you believe a child has submitted personal information, contact us so we can investigate and remove it where appropriate.

08

Updates to this notice

We will update the date on this page when practices change and give appropriate notice of material changes before they take effect. New uses requiring separate permission will not be authorized simply by changing this page.

EzraGallery Studio privacy enquiries: hello@ezra-gallery.com. Full business details.

Made for the work you love.
ContactPrivacyUsage termsBack to the studio