Legal
Privacy policy
Last updated September 17, 2026
Who we are
OpenStudio is a product of Costa Security Inc., 3790 El Camino Real #1090, Palo Alto, CA 94306. This policy covers the website at openstudio.tech and the OpenStudio application. Where a section applies to only one of the two, it says so.
The website
This site is static and has no accounts. Our hosting provider, AWS Amplify, keeps standard server logs (IP address, user agent, request timestamps) for operating the service, on AWS’s usual retention terms. If you email us, we keep the correspondence for as long as we need it to respond and to keep our records straight.
If you request an invitation, we keep your email address and, if you give one, your answer to what you would build first. We use them for one thing: deciding and sending invitations. We delete them on request, and when the invitation program ends.
The OpenStudio application
OpenStudio is in development. When you use it, we will collect:
- Account details you provide, such as your name and email address.
- Content you create in OpenStudio.
- When you choose to connect a third-party service, data from that service — limited to what you authorize when you connect it.
- Product analytics: how OpenStudio is used — pages and features, actions taken, device and browser, approximate location from IP address. We use it to see what works and what does not. Some of it is processed by third-party analytics providers on our behalf under contract; they are listed with our other subprocessors on the trust portal.
We collect what the features you use need, and nothing on spec.
Connected services
OpenStudio works by connecting to services you already use — your CRM, your email, your calendar, your company’s tools. Whatever the service, the same rules apply to the data we receive from it:
- We access only what you authorize. Each connection requests only the permissions its feature needs, and we do not request permissions ahead of need.
- We use it only for you. Data from a connected service is used solely to provide and improve the features you have asked for. We do not use it for advertising, we do not sell it, and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. This one does not have an opt-in: if you turn on training for your own content, connected-service data stays out of it.
- We store it carefully. Encrypted in transit and at rest, retained only while your connection is active and only as long as the feature needs it.
- We do not pass it around. We do not transfer it to others except to service providers that help us operate OpenStudio under confidentiality obligations, when required for security or legal compliance, or as part of a corporate transaction with notice to you.
Disconnecting a service stops collection from it, and you can also revoke OpenStudio’s access from the service’s own security settings at any time.
Google user data
OpenStudio’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke OpenStudio’s access at any time from your Google security settings.
Training
We do not train AI or machine learning models on your content unless you turn it on. It is off by default on every plan, including free and invitation access, and we will not make it a condition of using OpenStudio.
If you or your organization want to opt in — to get a model tuned to how you actually work — an administrator can turn it on in settings or in an order form. Turning it on takes a deliberate action; we do not treat a dismissed notice or continued use as agreement. You can turn it back off at any time, which stops any further use of your content for training. We will be straight with you about what that cannot undo in a model already trained.
Two things stay out of training whatever you choose:
- Data from services you connected. Your CRM, your inbox, your calendar. Some of those services prohibit it outright — Google Workspace data cannot be used to train non-personalized models under Google’s policy, and your permission does not change that.
- Other people’s data. Opting in covers your organization’s content, not anything belonging to someone who did not.
Product improvement is separate and narrower: aggregated, de-identified usage data — counts, latency, error rates, which features get used — never the content you create.
How we share data
We do not sell personal data, we do not share it for advertising, and we do not share it for cross-context behavioral advertising. We share data only with service providers who process it on our behalf under contract, when the law requires it, to protect the security of the service, or as part of a corporate transaction — in which case this policy continues to apply until you are told otherwise.
Our subprocessors are listed at trust.costa.app, with 30 days’ notice before a new one is added.
Retention and deletion
The website retains nothing about you beyond the server logs and email described above. In the application:
- Account data is kept while your account is active, and for 30 days after it closes.
- Content you create is kept while your account is active.
- Connected-service data is deleted within 30 days of disconnection.
- Billing records are kept for six years, because tax and audit law requires it.
To delete your account and its data, email hello@openstudio.tech. We acknowledge within 3 business days and disable the account, leave a 30-day window for you to export what you want, and delete within 30 days after that window closes.
Security
Data is encrypted in transit (TLS 1.2 and above) and at rest (AES-256). Access to production systems is role-based, least-privilege, and requires multi-factor authentication. If you believe you have found a security vulnerability, our security page explains how to report it.
Your rights
You can ask us what data we hold about you, ask us to correct it, export it, or delete it — our data requests page explains how. If you are in a jurisdiction with statutory data rights — the GDPR in the European Union, the United Kingdom, and Switzerland, the CCPA and CPRA in California — those rights apply and we honor them. We respond within 30 days under the GDPR and 45 days under the CCPA, and we tell you before taking the extension either law allows.
We honor the Global Privacy Control as a valid opt-out signal. We do not honor Do Not Track, because the industry never agreed on what it requires.
Children
OpenStudio is not directed at anyone under 18, and we do not knowingly collect data from children.
Changes
Material changes to this policy are posted here with a new date at the top. If a change affects how we handle Google user data, we will notify connected users before it takes effect.
Contact
hello@openstudio.tech, or by post: Costa Security Inc., 3790 El Camino Real #1090, Palo Alto, CA 94306.