Privacy notice
How Surge Solutions handles personal data when you use Studio365.
Last updated: September 28, 2026
Business draft policy
This is a working business draft prepared by Surge Solutions. It should be reviewed by qualified legal counsel before anyone relies on it, and it is not legal advice.
1. Who we are
Surge Solutions operates Studio365 and is the data controller for the personal data described here: we decide why and how it is processed. For data your organization stores inside the apps it builds, your organization is the controller and we process it on its behalf.
2. Data we collect and why
- Account data (name, email, login credentials, organization and role) — to create and secure your account and provide the service.
- Project content (prompts, chat with Amanda, code, files, settings) — to build, preview, version and export your software.
- Voice data, if you enable it — to transcribe requests. Microphone audio is not stored by default.
- Usage and technical data (credit usage, logs, IP address, device and browser identifiers) — for billing limits, security, fraud prevention, troubleshooting and product improvement.
- Support and marketing (messages you send, early-access requests, email preferences) — to respond to you and, with your consent, send updates.
3. Legal basis
We rely on performance of our contract with you (providing the service), legitimate interests (security, fraud prevention, improvement), consent (optional marketing, voice features and non-essential cookies), and legal obligation (tax and record keeping).
4. Who we share data with
- Paddle, our Merchant of Record, for the sale of subscriptions, subscription management, payments, tax compliance and invoicing. Paddle processes payment details under its own privacy notice; we do not receive full card numbers.
- Service providers for hosting, databases, AI model processing, preview sandboxes, email and support tooling, under contracts limiting their use of data.
- Professional advisers such as lawyers and accountants.
- Authorities where required by law.
5. AI and training
Your project content is private to your project by default and is not used to train models for other customers. Any broader use requires explicit opt-in and review.
6. Retention
We keep account and project data while your account is active. After closure, data is deleted or anonymised within a reasonable period (target 90 days), except records we must keep for legal, tax, security or dispute purposes. Backups expire on their normal schedule.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent. UK/EEA users may complain to their data protection authority. We respond within one month. You can also export your projects at any time.
8. International transfers
Our providers may process data outside your country. Where required, we use safeguards such as Standard Contractual Clauses.
9. Security
We use technical and organisational measures including encryption in transit, access controls, organization isolation, encrypted secret storage and audit logging. No system is perfectly secure.
10. Cookies
We use essential cookies and local storage for sign-in and security, and limited analytics to understand site use. You can manage cookies in your browser; blocking essential cookies may stop sign-in from working.
11. Contact
To exercise your rights or ask a privacy question, reach Surge Solutions through our contact page.
Related: Terms · Privacy · Refund policy · Contact