Version 1.2-beta, in force from 14 August 2026. This document applies to your use of Emblem Studio. It is still under legal review, and we will email you before anything material changes.

Privacy Policy

How Emblem Studio handles personal data, for account holders and for people who fill in a form on a customer's site.

Last updated: 14 August 2026 · Version: 1.2-beta


Read this first: which part applies to you

Two different situations, and different answers for each.

Who we are, in both cases: SERENICHRON S.R.L., a company registered in Romania. Full contact and registration details are in our Imprint.


Part A — If you have an Emblem Studio account

A1. What we collect and why

We collect only what the account needs to work. We do not sell your data, and we do not share it except with the service providers listed in A6, who work under contract on our behalf.

What Where it comes from Why we hold it Legal basis (GDPR Art. 6)
Your name and email You, at sign-up To create and run your account, and to contact you about it Performing our contract with you — Art. 6(1)(b)
Your password You (held by our login provider WorkOS, not by us in readable form) To sign you in securely Contract — Art. 6(1)(b)
Your profile photo, if you add one You To show it in the app Contract — Art. 6(1)(b)
Your account and team settings You, as you use the app To run the workspace and your team's access Contract — Art. 6(1)(b)
Sign-in records — the IP address and browser your session used, and when it was last active Automatically, when you log in To keep your account secure and detect misuse Our legitimate interest in securing the service — Art. 6(1)(f)
Messages you send our support You To answer you Legitimate interest in helping you — Art. 6(1)(f)
Usage patterns from your account — asset counts, shell types, activation and conversion rates Automatically, from how you use the product To understand overall usage of the service and improve it. Looked at account-by-account only internally, never published or shared outside our team Legitimate interest — Art. 6(1)(f)

On IP addresses, stated plainly so it is not misread later. We do not store the IP addresses of people who fill in your forms (one narrow exception — see B4). We do keep the IP address of your own sign-in sessions, for security, for the short life of each session. These are two different things and we keep them apart.

A2. What we do NOT do

A3. Marketing emails to you

If you are our customer, we may email you about our own similar products and features, and you can unsubscribe from any such message in one click. Set-up emails — setting your password, team invites, password resets — are part of running your account and are not marketing.

A4. How long we keep your account data

Both periods above are our policy. Enforcing them automatically on a timer is still being built, so until it is live we apply them on request and when you delete your account (A9).

A5. Where your data is processed, and transfers outside the EU

Our servers are managed through Cloudron. The hosting provider and the region they run in are to be added. Some of our service providers are in the United States (A6). Where data leaves the EU, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) with each provider. You can ask us for a copy of the safeguards.

A6. Who we share account data with (our processors)

We use a small number of service providers, each under a data-protection contract, each using your data only to provide their service to us:

Provider What they do Where
WorkOS, Inc. Login and passwords United States
Hosting — to be added Runs our servers and database To be added
Anthropic Powers the optional in-app AI chat, only if you use it and only if we have enabled it United States
Email — to be added Sends account emails To be added

The always-current list, including any changes, is our Sub-processor list.

On our own website — emblemstudio.ai and these pages — we use Google Analytics to count visits, and only for people who agree to it there. It does not run in your dashboard, it is not part of the script on your website, and it never sees your leads. You can change your answer at any time from Cookie settings in our footer. Details are in the cookie table.

A7. Your rights

You can ask us to: see a copy of your data; correct it; delete it; limit or object to how we use it; or receive it in a portable format. To exercise any of these, email contact@emblemstudio.ai. We respond within one month.

You can also complain to a supervisory authority. In Romania this is the ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal), at www.dataprotection.ro. You may also complain to the authority where you live or work.

A8. Cookies in the dashboard

When you are logged in, we use a small number of strictly-necessary cookies and browser storage keys to keep you signed in and the app working — no advertising or tracking cookies. The full list is in the Cookie table.

A9. Deleting your data

Email contact@emblemstudio.ai and we will delete your account and everything in it — your account, sites, forms, revisions, and the leads and analytics your forms collected. This works whether or not any timed retention above has run.


Part B — If you signed up through a form on someone else's website

You are reading this because a website you used had a form, popup, or sign-up box built with Emblem Studio, and you entered your details.

B1. Who is responsible for your data

The website you signed up on is responsible for your data — they are the controller. They decided what to ask you, why, and what they do with it afterwards. We are their technology provider: we store and pass on what you submitted, on their instructions, and nothing more.

So for most things — to see, correct, or delete your data, or to ask why they contacted you — contact that website. If you don't know who they are or can't reach them, you can contact us (B7) and we will help route your request to them; we generally cannot decide it ourselves.

B2. What we hold about you, on the website's behalf

Only what you typed into their form:

We do not add tracking, session recording, keystroke logging, or mouse-movement capture. We only keep what you affirmatively submitted.

B3. If the website connects itself to our system later

Some websites start out using only the free version of our tools, with everything staying on their own site. If the website owner later connects their site to us, here is what that means for data you already gave them: your existing submission — not just future ones — is copied to our servers at that point, so the website owner can manage it in one place.

The website owner is still the one responsible for your data, and connecting their site is their decision, made under their own instruction to us (B1). We think you should know it can happen, though, even for a form you filled in before that website was connected to anything.

B4. Anonymous, non-identifying analytics

So the website owner can see how their form performs, we record simple events — that a form was shown, clicked, or completed. With these we store:

B5. IP addresses — the plain truth

We do not store your IP address when you fill in a genuine form. The one exception: if a submission trips our spam trap (a hidden field only automated bots fill in), we keep that submission's IP so the website owner can see and block the attack. Genuine sign-ups do not have their IP stored.

When you submit a form, we work out its approximate location (country, region, city) from your IP address, to help the website owner. We do this on our own server, at the moment you submit, using a location database we hold ourselves — your IP address is not sent to any outside company, and we do not store your IP. The location is saved with your submission; the website owner may also have it passed to their own tools.

B6. Where it goes next

On the website owner's instructions, what you submitted may be passed to the tools they have connected — for example their own email/CRM system (such as FunnelKit running on their own website) or a web address (webhook) they configured. Those destinations are chosen and controlled by the website owner, not by us.

B7. How to reach us

If you can't reach the website owner, contact contact@emblemstudio.ai and we will help connect your request to the right controller. You can also complain to the ANSPDCP in Romania or the data-protection authority where you live.


Changes to this policy

If we make a material change, we will update the version and date above and — for account holders — tell you by email before it takes effect. Changing how we use data we have already collected would need your fresh agreement, not just a notice.