StudioKit legal

Privacy Policy

Effective: July 22, 2026

This Privacy Policy explains how STUDIO SAPIENS LIMITED COMPANY (“StudioKit,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you use the StudioKit websites, mobile applications, and related services (collectively, the “Service”). It does not govern third-party services that publish their own privacy policies.

1. Information we collect

Account and profile information

We collect the email address and stable account identifier required to create and authenticate an account. You may provide a name, phone number, time zone, postal address, teacher notes, billing and reminder preferences, and a calendar-feed token.

Studio records entered by adults

Teachers and adult account holders may enter studio relationships, student or family names and contact details, tags, schedules, attendance and status, availability, invoices and items, payment status, messages, announcements, notification settings, and sent-email metadata. These records may concern minors, but minors do not receive StudioKit accounts and should not use the Service directly.

Payments and billing

We store Stripe account, customer, and subscription identifiers and records such as amounts, dates, invoice and payment status, billing details, categorical payment methods such as cash or check, and transaction references. Stripe collects and processes payment credentials; StudioKit does not store full payment-card numbers. Optional online collection of lesson payments through Stripe Connect is currently available only to eligible US-based studios. Invoices and manual payment tracking do not require Stripe Connect.

Authentication, device, and technical information

We process short-lived email sign-in codes, hashed refresh tokens, session and access identifiers, push notification tokens, and security or reviewer markers. Our systems and hosting providers may process IP addresses, browser or device type, operating system, requested paths, search terms, timestamps, and operational or error logs when you use the Service.

Analytics and support

We use PostHog’s US-hosted analytics and support services. PostHog receives a generated anonymous identifier and standard browser, app, device, and operating-system context. After sign-in, we identify your activity using your StudioKit account ID, account-holder email and name, persona, and studio role. We record product events such as app lifecycle, screens viewed, key feature actions, and categorical errors. On the web, certain specifically tagged button and form interactions may be captured; element text and attributes are masked.

PostHog may use the connection IP address to derive approximate geographic information such as country or region. StudioKit does not request device location permission or collect precise location.

In product analytics events, we do not send PostHog student or family records, studio identifiers, message text, invoice or payment details, free-form error text, or session-replay content. Broad element capture, session replay, heatmaps, surveys, and automatic exception capture are disabled. If you contact support, PostHog Support processes the information and messages you choose to submit.

Communications

We process your email address, communication preferences, and delivery metadata to send sign-in codes, service messages, studio communications, invoice or schedule notices, and support responses. If you enable push notifications, Apple Push Notification service or Google Firebase Cloud Messaging processes a device token, notification title and body, routing metadata, and notification-delivery information.

Waitlist

If you voluntarily join the StudioKit waitlist, Kit (formerly ConvertKit) receives the email address and signup information you submit and uses it to deliver StudioKit updates. You can unsubscribe using the link in any waitlist email.

2. Where information comes from

We receive information directly from you; from other adult users who manage a shared studio or records concerning you; automatically from your browser, device, and use of the Service; and from providers such as Stripe when they report subscription, account, payout, or transaction status.

3. How we use information

We use personal information to:

  • create accounts, authenticate users, and maintain account and studio access;
  • provide scheduling, messaging, invoicing, payments, notifications, support, and other Service features;
  • process subscriptions and facilitate optional Stripe lesson-payment collection;
  • understand feature usage and improve the usability and reliability of the Service;
  • prevent, detect, investigate, and respond to fraud, abuse, security incidents, and policy violations;
  • enforce our Terms of Service, resolve disputes, and meet legal, accounting, and tax obligations; and
  • protect the rights, safety, and property of users, StudioKit, and others.

4. How we disclose information

We disclose personal information only as needed for the purposes above:

  • Service providers. Neon provides database infrastructure; Vercel hosts the web application and API and maintains operational logs; Resend delivers email; PostHog provides analytics and support; Kit manages the optional waitlist; Apple and Google deliver push notifications; and Stripe provides subscription and payment services. They process information under their own agreements with us and, where applicable, with you.
  • Other authorized users. Information is visible to the teachers, studio personnel, and adult account holders authorized for the relevant studio records and conversations.
  • Legal and safety reasons. We may disclose information when we reasonably believe it is required by law or necessary to respond to lawful process, enforce agreements, investigate abuse, protect the Service, or protect someone’s rights, property, or safety.
  • Business transfers. Information may be disclosed as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to applicable law.

We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.

5. Retention and account deletion

We retain information while needed to provide the Service and for legitimate business purposes such as security, fraud prevention, dispute resolution, and enforcing agreements. Retention also depends on the type of record, the duration of the account or studio relationship, and legal, tax, and accounting duties.

You can request account deletion from authenticated Settings or at our public account deletion page. After you confirm the request, we immediately block login and authenticated API access, revoke active sessions, disable push notifications, and clear nullable optional profile fields. We manually complete the remaining deletion within 30 days, including removal of your direct account identity, messages authored by your account, and PostHog analytics and support identity.

We retain invoice, payment, transaction, tax, accounting, and fraud-prevention records when required for those purposes. Shared studio records, records created by other users, and records needed to preserve another user’s account or legitimate business history may also remain without your active account identity. Before requesting deletion, cancel any active StudioKit subscription through the web billing portal or contact support@studiokit.io for help.

6. Your choices and privacy requests

You can update available profile fields and communication preferences in the Service, control push notifications in your device settings, and cancel a StudioKit subscription through the Stripe billing portal on the web. Because StudioKit does not sell personal information or use it for targeted advertising, there is no sale or targeted-advertising opt-out required to use the Service.

Depending on where you live and subject to legal exceptions, you may have rights to request access to, correction of, deletion of, or a copy of personal information about you. Email support@studiokit.io to make a request. We may need to verify your identity and authority, and we will respond within the time required by applicable law. You may use an authorized agent where applicable law permits it. We will not discriminate against you for exercising an applicable privacy right.

7. Security

We use administrative and technical safeguards designed to protect personal information, including access controls, time-limited email authentication codes, hashed session credentials, and encrypted network connections. No storage or transmission system is completely secure, so we cannot guarantee absolute security. Please protect access to your email account and notify us promptly if you suspect unauthorized use.

8. Adults and records about minors

StudioKit is an adult business service for account holders age 18 and older. It is not directed to children, and children may not create accounts or use the Service directly. Adults may enter records about minors they are authorized to manage. The adult entering those records is responsible for obtaining any permission and providing any notice required by law. If you believe a child created an account or submitted information directly to StudioKit, contact us so we can investigate and take appropriate action.

9. Processing locations

StudioKit is operated in the United States. We and our service providers may process information in the United States and other locations where they operate, subject to their security measures and applicable law.

10. Changes to this policy

We may update this Privacy Policy as the Service or legal requirements change. We will post the revised policy with a new effective date. When required by law, we will provide additional notice or request consent before applying a materially different use to information already collected.

11. Contact us

Privacy questions and requests: support@studiokit.io.

STUDIO SAPIENS LIMITED COMPANY
117 S Lexington St
Harrisonville, MO 64701-2444
United States