Skip to content
Founding Customer Early Access is open. Learn more

Privacy notice

How Surge Solutions handles personal data when you use Studio365.

Last updated: September 28, 2026

Business draft policy

This is a working business draft prepared by Surge Solutions. It should be reviewed by qualified legal counsel before anyone relies on it, and it is not legal advice.

1. Who we are

Surge Solutions operates Studio365 and is the data controller for the personal data described here: we decide why and how it is processed. For data your organization stores inside the apps it builds, your organization is the controller and we process it on its behalf.

2. Data we collect and why

  • Account data (name, email, login credentials, organization and role) — to create and secure your account and provide the service.
  • Project content (prompts, chat with Amanda, code, files, settings) — to build, preview, version and export your software.
  • Voice data, if you enable it — to transcribe requests. Microphone audio is not stored by default.
  • Usage and technical data (credit usage, logs, IP address, device and browser identifiers) — for billing limits, security, fraud prevention, troubleshooting and product improvement.
  • Support and marketing (messages you send, early-access requests, email preferences) — to respond to you and, with your consent, send updates.

3. Legal basis

We rely on performance of our contract with you (providing the service), legitimate interests (security, fraud prevention, improvement), consent (optional marketing, voice features and non-essential cookies), and legal obligation (tax and record keeping).

4. Who we share data with

  • Paddle, our Merchant of Record, for the sale of subscriptions, subscription management, payments, tax compliance and invoicing. Paddle processes payment details under its own privacy notice; we do not receive full card numbers.
  • Service providers for hosting, databases, AI model processing, preview sandboxes, email and support tooling, under contracts limiting their use of data.
  • Professional advisers such as lawyers and accountants.
  • Authorities where required by law.

5. AI and training

Your project content is private to your project by default and is not used to train models for other customers. Any broader use requires explicit opt-in and review.

6. Retention

We keep account and project data while your account is active. After closure, data is deleted or anonymised within a reasonable period (target 90 days), except records we must keep for legal, tax, security or dispute purposes. Backups expire on their normal schedule.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent. UK/EEA users may complain to their data protection authority. We respond within one month. You can also export your projects at any time.

8. International transfers

Our providers may process data outside your country. Where required, we use safeguards such as Standard Contractual Clauses.

9. Security

We use technical and organisational measures including encryption in transit, access controls, organization isolation, encrypted secret storage and audit logging. No system is perfectly secure.

10. Cookies

We use essential cookies and local storage for sign-in and security, and limited analytics to understand site use. You can manage cookies in your browser; blocking essential cookies may stop sign-in from working.

11. Contact

To exercise your rights or ask a privacy question, reach Surge Solutions through our contact page.

Related: Terms · Privacy · Refund policy · Contact