Privacy Policy
What this server collects about you, why, who else receives it, how long it is kept, and how to see it or delete it.
- Last updated 3 October 2026
1. Who is responsible
the operator of this Studio Umbra server runs this server and decides what happens to your data on it, which makes us the "controller" under data protection law ("we", "us"). Studio Umbra is self-hosted software: your data is kept on our own equipment and not by the people who wrote the software. Questions or requests about your data: an administrator of this server (the people with the Admin role).
2. What we collect
| What | Detail | Why |
|---|---|---|
| Your account | Email address (which is also your sign-in name), a salted hash of your password (never the password itself), passkeys and two-factor settings if you add them, your role and section access, account status, and the personal access tokens you make (stored as hashes). | To let you sign in, and to decide what you may open. |
| What you make and say | Conversations with models and the images and files you attach; project notes; library files and everything the image, 3D, voice, video and sound tools generate, with the prompts and settings that made them; workflows and their runs; scheduled tasks; boards, cards, comments and whiteboards; Shade messages, files, reactions and direct messages; Talk transcripts and the voice-over takes you keep; your profile picture, nickname, friends and blocks; your personal settings. | To provide the features you use. |
| Usage records | For each model reply: which model, token counts, speed and tool calls. Per run: what a generation cost and what it produced. Who is online or in a voice channel right now. | To show you usage, to size and fix the service, and to show who is present. |
| Network details | Each internet address you are seen using while signed in, your browser's identification string, and when each was first and last seen. Only for devices on our own local network, the device's hardware (MAC) address as well. Ordinary server logs of requests (address, page, time, errors). | Security and abuse control: so an administrator has something to ban, and to find faults. |
| Moderation records | What an administrator did to your account (flag, suspension, ban, password change, role change), the date, who did it, and any notes they wrote. Bans on addresses and email addresses. | Running the site fairly and safely, and being able to show what was done. |
| Notifications | If you turn them on, your browser's push subscription (an address at your browser maker's push service, and keys for it). | To tell you when an agent is waiting for your approval. |
| Sound and pictures | Audio you record for dictation, Talk or the voice-over studio is sent to the speech-to-text server to be turned into text. Takes you keep, and sounds you add to a soundboard, are stored as files. Voice and video calls go directly between the people in them and are not recorded or stored by the server. | To provide voice features. |
The photo and video editors work in your browser, and what you edit stays on your device unless you use an action that saves to or loads from your library. We do not collect payment card details. We do not run advertising, analytics or tracking tools, and we do not sell your personal data.
3. How we use it
- To run the site and the features you ask for, and to keep your account secure.
- To prevent abuse, enforce our rules, and keep the server working and affordable (rate limits, bans, usage figures).
- To answer you and to meet legal obligations.
We do not use your content to train models, and we do not make decisions about you by automated means that have legal or similarly serious effects.
4. Who else receives it
- Other people you share with. Whatever you post in a server, project, board or whiteboard is seen by its members, and a direct message by the other person.
- Administrators and support. Administrators can see accounts, activity and the addresses above, and can reach the server and its database and files. Nothing on this server is end-to-end encrypted. We look at private content only to run, secure or repair the service, to look into a report, or where the law requires. Support staff see less than administrators and cannot see credentials.
- The model behind a conversation. Your messages, attachments, history and the results of any tools or searches are sent to the model that conversation or agent is set to use. That can be a server we run, or a service run by someone else, such as a connection you added yourself. Its own privacy terms then apply to what it receives.
- Web search. A search is sent to a search service we set up (SearXNG), which passes the query on to public search engines.
- Image, 3D, speech and video servers. Prompts, uploads and audio are sent to the machines we run for those tools (ComfyUI and the speech servers).
- Calls. To set up a voice or video call your browser asks a public STUN service (by default one run by Google) for its public address, and the other people in the call can see your address.
- Push services. A notification goes through your browser maker's push service (for example Google, Mozilla or Apple). The message is encrypted so that it can read only that a notification exists.
- Umbra Arcade. The game hub opens inside the site but is a separate service that shares the account database. When you open it we hand it a one-time note that identifies your account so you do not have to sign in again. Its own data is under its own rules.
- Your own computer. Tools that act on your machine run there, and what they read goes where you tell them to send it.
- Authorities and advisers. Where the law requires, to protect people from harm, or to establish or defend a legal claim, and to professional advisers under a duty of confidence. If the server is passed to a new operator, its data goes with it.
5. Where it is kept, and how it is protected
Your data lives in a database and in files on equipment we control. Passwords are stored as hashes. Access to sections and to files is checked on the server, sign-in cookies are protected from scripts, and a site served over HTTPS marks them secure. Access to the server itself is limited to people who run it. No system is perfectly secure, so we cannot promise it, but if a breach is likely to harm you we will tell you and the authorities as the law requires. Because the equipment is wherever we have put it, your data may be held in a country other than yours, and the services in Section 4 may be in others. Where the law restricts such transfers, we rely on the safeguards it allows.
6. How long we keep it
- Your conversations, files and other content are kept until you or an administrator delete them. There is no automatic expiry.
- Account details are kept while your account exists.
- When your account is deleted, what you made is deleted too if you chose that (see Section 7). Moderation records and bans are kept afterwards, because they are the site's record rather than your content. Where your name appeared on other people's things (who drew a shape, who approved a call), it is blanked.
- Server logs and backups are kept for as long as we need them to keep the service secure and working, and then removed in the ordinary course.
7. Your choices and rights
- See and download your data: Account → Personal data.
- Correct it: Account → Email, Change password, and your settings and profile.
- Delete it: Account → Delete Personal Data. It removes your account. Tick Also delete everything I made to remove your conversations, library files, workflows, schedules, pictures, preferences and notification subscriptions, and decide whether servers and projects other people are in are handed on, and whether your messages elsewhere are deleted. Direct messages are deleted for both people.
- Turn notifications off: Your settings → Notifications, or in your browser.
- Cookies and browser storage: see the Cookie Policy.
Depending on where you live, you may also have the right to object to or ask us to restrict how we use your data, to receive it in a portable form, to withdraw consent you gave, and to complain to your data protection authority. Residents of California and some other places have rights to know, delete and correct, and to opt out of the sale or sharing of personal data: we do not sell or share it in that sense. Write to us to use any of these. We may need to check that you are who you say you are, and will answer within the time the law allows, normally one month.
8. Our legal bases
Where the law asks for one, we rely on:
- Contract, to provide the account and features you ask for;
- Legitimate interests, in keeping the service secure, preventing abuse and understanding how it is used, which we balance against your rights;
- Consent, for the microphone, camera and notifications, which you can withdraw in your browser; and
- Legal obligation, where a law requires us to keep or hand over something.
9. Children
The site is not for anyone under 18. If we learn that someone younger has an account, we will close it and delete their data. If you think that has happened, please tell us.
10. Changes
We may update this policy. The date at the top shows when it last changed, and for a change that matters we will say so on the site.
11. Contact
For privacy questions and requests: an administrator of this server (the people with the Admin role).