Privacy Policy
How Emblem Studio handles personal data, for account holders and for people who fill in a form on a customer's site.
Last updated: 14 August 2026 · Version: 1.2-beta
Read this first: which part applies to you
Two different situations, and different answers for each.
- If you have an Emblem Studio account — you signed up to build forms — read Part A. Here we decide what happens to your data, so we are what the law calls the controller.
- If you filled in a form, popup, or sign-up box on someone else's website and it was built with Emblem Studio — read Part B. That website's owner decides what happens to your data. We only hold it because they asked us to, so we are the processor and they are the controller. For most of your rights, contact the website you signed up on, not us.
Who we are, in both cases: SERENICHRON S.R.L., a company registered in Romania. Full contact and registration details are in our Imprint.
Part A — If you have an Emblem Studio account
A1. What we collect and why
We collect only what the account needs to work. We do not sell your data, and we do not share it except with the service providers listed in A6, who work under contract on our behalf.
| What | Where it comes from | Why we hold it | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Your name and email | You, at sign-up | To create and run your account, and to contact you about it | Performing our contract with you — Art. 6(1)(b) |
| Your password | You (held by our login provider WorkOS, not by us in readable form) | To sign you in securely | Contract — Art. 6(1)(b) |
| Your profile photo, if you add one | You | To show it in the app | Contract — Art. 6(1)(b) |
| Your account and team settings | You, as you use the app | To run the workspace and your team's access | Contract — Art. 6(1)(b) |
| Sign-in records — the IP address and browser your session used, and when it was last active | Automatically, when you log in | To keep your account secure and detect misuse | Our legitimate interest in securing the service — Art. 6(1)(f) |
| Messages you send our support | You | To answer you | Legitimate interest in helping you — Art. 6(1)(f) |
| Usage patterns from your account — asset counts, shell types, activation and conversion rates | Automatically, from how you use the product | To understand overall usage of the service and improve it. Looked at account-by-account only internally, never published or shared outside our team | Legitimate interest — Art. 6(1)(f) |
On IP addresses, stated plainly so it is not misread later. We do not store the IP addresses of people who fill in your forms (one narrow exception — see B4). We do keep the IP address of your own sign-in sessions, for security, for the short life of each session. These are two different things and we keep them apart.
A2. What we do NOT do
- We do not sell your personal data. We do not "share" it for cross-context advertising.
- We do not use the content of your forms, your leads, or your designs to train any AI model — not on an opt-in basis, not on an opt-out basis, not at all.
- We do not read your forms, leads, or designs as a routine matter. A member of our team can only do so with your explicit, time-limited permission, tied to a support request, and you can see it in your own logs. The permission and logging mechanism is still being built. Until it is live, we access your content only when you ask us to as part of a support case.
A3. Marketing emails to you
If you are our customer, we may email you about our own similar products and features, and you can unsubscribe from any such message in one click. Set-up emails — setting your password, team invites, password resets — are part of running your account and are not marketing.
A4. How long we keep your account data
- While your account is open, we keep it.
- If you delete your account, we keep the data for 135 days, then delete it permanently. The 135 days let you recover an account you closed by mistake. The clock starts when you delete, not when you last logged in.
- If a free account is dormant — no active forms and no login for 90 days — we send one or two warnings and then delete it.
- You can ask us to delete your data at any time (A7).
Both periods above are our policy. Enforcing them automatically on a timer is still being built, so until it is live we apply them on request and when you delete your account (A9).
A5. Where your data is processed, and transfers outside the EU
Our servers are managed through Cloudron. The hosting provider and the region they run in are to be added. Some of our service providers are in the United States (A6). Where data leaves the EU, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) with each provider. You can ask us for a copy of the safeguards.
A6. Who we share account data with (our processors)
We use a small number of service providers, each under a data-protection contract, each using your data only to provide their service to us:
| Provider | What they do | Where |
|---|---|---|
| WorkOS, Inc. | Login and passwords | United States |
| Hosting — to be added | Runs our servers and database | To be added |
| Anthropic | Powers the optional in-app AI chat, only if you use it and only if we have enabled it | United States |
| Email — to be added | Sends account emails | To be added |
The always-current list, including any changes, is our Sub-processor list.
On our own website — emblemstudio.ai and these pages — we use Google Analytics to count visits, and only for people who agree to it there. It does not run in your dashboard, it is not part of the script on your website, and it never sees your leads. You can change your answer at any time from Cookie settings in our footer. Details are in the cookie table.
A7. Your rights
You can ask us to: see a copy of your data; correct it; delete it; limit or object to how we use it; or receive it in a portable format. To exercise any of these, email contact@emblemstudio.ai. We respond within one month.
You can also complain to a supervisory authority. In Romania this is the ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal), at www.dataprotection.ro. You may also complain to the authority where you live or work.
A8. Cookies in the dashboard
When you are logged in, we use a small number of strictly-necessary cookies and browser storage keys to keep you signed in and the app working — no advertising or tracking cookies. The full list is in the Cookie table.
A9. Deleting your data
Email contact@emblemstudio.ai and we will delete your account and everything in it — your account, sites, forms, revisions, and the leads and analytics your forms collected. This works whether or not any timed retention above has run.
Part B — If you signed up through a form on someone else's website
You are reading this because a website you used had a form, popup, or sign-up box built with Emblem Studio, and you entered your details.
B1. Who is responsible for your data
The website you signed up on is responsible for your data — they are the controller. They decided what to ask you, why, and what they do with it afterwards. We are their technology provider: we store and pass on what you submitted, on their instructions, and nothing more.
So for most things — to see, correct, or delete your data, or to ask why they contacted you — contact that website. If you don't know who they are or can't reach them, you can contact us (B7) and we will help route your request to them; we generally cannot decide it ourselves.
B2. What we hold about you, on the website's behalf
Only what you typed into their form:
- Your email address.
- Any other fields that form asked for — for example your name or phone number — and only the fields that form actually contained. Anything else that arrives is discarded, not stored.
We do not add tracking, session recording, keystroke logging, or mouse-movement capture. We only keep what you affirmatively submitted.
B3. If the website connects itself to our system later
Some websites start out using only the free version of our tools, with everything staying on their own site. If the website owner later connects their site to us, here is what that means for data you already gave them: your existing submission — not just future ones — is copied to our servers at that point, so the website owner can manage it in one place.
The website owner is still the one responsible for your data, and connecting their site is their decision, made under their own instruction to us (B1). We think you should know it can happen, though, even for a form you filled in before that website was connected to anything.
B4. Anonymous, non-identifying analytics
So the website owner can see how their form performs, we record simple events — that a form was shown, clicked, or completed. With these we store:
- A shortened IP address with the last part removed, so it cannot identify you.
- A random per-browser id in a cookie, used to count how many different people saw the form and tell new visitors from returning ones. It is not linked to your name and not shared.
- Your browser type and the page path you were on (without the part after a
?).
B5. IP addresses — the plain truth
We do not store your IP address when you fill in a genuine form. The one exception: if a submission trips our spam trap (a hidden field only automated bots fill in), we keep that submission's IP so the website owner can see and block the attack. Genuine sign-ups do not have their IP stored.
When you submit a form, we work out its approximate location (country, region, city) from your IP address, to help the website owner. We do this on our own server, at the moment you submit, using a location database we hold ourselves — your IP address is not sent to any outside company, and we do not store your IP. The location is saved with your submission; the website owner may also have it passed to their own tools.
B6. Where it goes next
On the website owner's instructions, what you submitted may be passed to the tools they have connected — for example their own email/CRM system (such as FunnelKit running on their own website) or a web address (webhook) they configured. Those destinations are chosen and controlled by the website owner, not by us.
B7. How to reach us
If you can't reach the website owner, contact contact@emblemstudio.ai and we will help connect your request to the right controller. You can also complain to the ANSPDCP in Romania or the data-protection authority where you live.
Changes to this policy
If we make a material change, we will update the version and date above and — for account holders — tell you by email before it takes effect. Changing how we use data we have already collected would need your fresh agreement, not just a notice.