Prompt Driven Studio
Privacy Policy
Last updated: July 24, 2026
This policy describes the information Prompt Driven Studio currently handles when you join the waitlist, use the studio, collaborate on a project, buy credits, connect an integration, or use its agent interfaces.
1. Scope
Prompt Driven provides Prompt Driven Studio. This policy applies to the Studio website, editor, account pages, project services, public feature-validation pages, agent API and CLI, and the integrations described below. It also covers information collected by the Sizzle marketing page and concept-routing flow served from the Studio website. It does not replace the privacy terms of third-party services you choose to use with the Studio.
2. Information the Studio handles
- Account and access data. Firebase Authentication supplies an account identifier and may supply your email address, email-verification status, display name, and sign-in provider. The current sign-in choices are Google and GitHub. Access approval and administrator status are also associated with an account.
- Waitlist and contact data. A waitlist submission includes your email address, the form source, product interest, the referring site's origin when available, and a submission time. The authenticated interest form also asks for a contact email, why you are interested, and how you intend to use the product.
- Feature-validation data. A public concept page can collect your email address, role, use case or qualification response, adoption timeline, and request for a pilot slot. The saved event also identifies the project, experiment, variant, collection surface and commitment level; records the event time; stores a one-way hash of the browser assignment identifier and an idempotency key that incorporates that identifier; and can include the displayed video's fingerprint and package version. The submitted form fields are stored in the raw experiment-event payload.
- Projects and media. The Studio handles project names and settings, scripts, prompts, storyboards, specifications, reference and style materials, uploaded images, video and audio, voice-reference recordings and transcripts, generated media, captions, music, render settings, review results, and distribution settings. Project history and provenance can connect an output to its prompt, references, model, and generation job.
- Review annotations. Frame review can save annotation text or a speech transcript, a video timestamp, drawings, and a composite frame image. In that annotation flow, microphone input is used for an on-screen level meter and browser speech recognition produces the saved transcript; the Studio does not intentionally save the raw annotation audio. A browser or operating-system speech service may process that audio to produce the transcript.
- Collaboration data. Project membership and invitations can include account identifiers, email addresses, display names, owner/editor/viewer roles, invitation status, project names, and invitation links. Reusable reference libraries and grants record who may use shared reference material.
- Billing and usage data. The Studio records credit balances, purchases, checkout state, generation and render usage, project and daily spend, pricing or model snapshots, and transaction history. Payment-card details are entered on Stripe's hosted checkout rather than in the Studio.
- Integration data. A YouTube connection includes the connected channel's identifier, title or handle, granted scopes, connection status, and related timestamps. OAuth access and refresh credentials are kept server-side. Upload records can include the selected video, thumbnail, captions, title, description, tags, visibility, returned YouTube identifiers, and publish receipts.
- Agent and security data. Agent API credentials have labels, scopes, optional project allowlists, and expiration information. The service records token creation, rotation, revocation, and use timestamps. Successful token use can also update a one-way hash of the requesting IP address when an IP forwarding header is available.
- Service and device data. Application and cloud logs can include timestamps, request method and URL, response status, errors, trace information, project or job identifiers, provider provenance, and resource usage.
3. How information is used
The Studio uses the information above to:
- authenticate accounts and enforce access, role, and project boundaries;
- save projects and perform the requested writing, generation, speech, music, review, rendering, and publishing workflows;
- enable collaboration, send project invitations, and apply reference grants;
- operate credit accounting and start the checkout you request;
- maintain agent credentials, audit access, investigate errors, and protect the service;
- manage waitlist access and respond to product or support requests; and
- measure interest in proposed features, attribute responses to a displayed experiment variant, and follow up on requests for product updates or a pilot slot.
4. AI, media, and infrastructure providers
The Studio sends the text, prompts, reference media, voice material, frames, audio, and settings needed for the operation you request to the provider configured for that operation. The provider varies by feature and deployment. The current implementation supports:
- Google services, including Firebase Authentication, Firestore, Cloud Storage, Cloud Run and Batch, Secret Manager, Vertex AI and Google AI services used for Gemini, Veo, Imagen and Lyria, Cloud Text-to-Speech and Chirp, Cloud Logging, Google Analytics on the marketing landing page, and YouTube APIs when connected;
- Anthropic and Z.ai for configured text, planning, or code-assisted generation workflows;
- BytePlus Ark and additional operator-configured video-generation backends when one of those alternate backends is selected;
- Qwen speech models in local, self-hosted, or cloud-batch configurations, and local Whisper implementations for transcription; configured fallback speech can use Microsoft Edge text-to-speech; and
- Remotion and FFmpeg for rendering and media processing.
These names describe product data flows, not a legal designation or a promise that every provider is used for every project. Provider availability and the configured model can change. Review the settings and generation provenance shown for your project before submitting sensitive material.
5. Storage, communications, analytics, and embeds
- Projects and generated files are stored in Google Cloud Storage in cloud deployments; local development can use local files. Account, project membership, waitlist, billing, and integration metadata can be stored in Firestore. Local job, review, status, or cost data can be stored in SQLite.
- Brevo receives the recipient email address and project invitation details when the Studio sends a collaboration invitation.
- Stripe receives checkout and payment information when you choose to buy credits through its hosted checkout.
- The marketing landing page loads Google Analytics and sends its standard page-view measurement. Analytics is intentionally excluded from the project editor. The landing page also contains a privacy-enhanced YouTube embed; loading or playing it can connect your browser to Google or YouTube.
- The browser stores information needed for sign-in and interface preferences. Browser, extension, and device controls may let you clear or restrict that storage and third-party requests, although doing so can prevent features from working.
- Public feature-validation pages create a random assignment identifier in browser local storage so repeat submissions remain attributed to the same experiment variant. The submitted event stores a one-way hash of that identifier and an idempotency key that incorporates the identifier. When the configured Sizzle concept router assigns a variant, it also sets a variant cookie with a maximum age of 90 days. Clearing site data removes the browser's local assignment identifier and cookie, but does not remove events already submitted.
6. Collaboration and external distribution
Project owners can invite viewers or editors. Content and project details are made available according to those roles. Reusable reference-library owners and administrators can separately create or revoke grants to reference material. Invitation emails disclose the project and invitation details needed by the recipient to join.
When you direct the Studio to publish through YouTube, the Studio submits the selected video, metadata, thumbnail, captions, and visibility setting to the connected channel. Supported visibility choices are private, unlisted, and public. Automated workflows default to private or unlisted, and the product requires explicit approval before a public publish.
7. YouTube OAuth permissions
The YouTube integration currently requests these Google scopes:
youtube.uploadto upload videos to the connected channel;youtube.readonlyto read channel and video information;youtube.force-sslto manage resources used by the publishing workflow, including metadata, thumbnails, or captions; andyt-analytics.readonlyto read channel or video analytics used by the Studio.
The Studio requests offline access so publishing can continue after the initial connection. You can disconnect YouTube from the Studio. When the stored credential can be read, the disconnect flow requests revocation from Google before removing the Studio's credential; an upstream revocation failure is reported and leaves the connection connected. If the stored credential cannot be read, the current flow can remove the local credential and mark the connection disconnected without confirming Google revocation. You can use your Google Account's third-party access controls to confirm or revoke remaining access. Content already published to YouTube remains subject to your YouTube settings and controls.
8. Your controls
- Sign out and manage the Google or GitHub account used to authenticate.
- Request deletion of a project through the Studio's project controls. In cloud mode, this deletes the primary project metadata record and its direct invitation records, then attempts to delete the project's Cloud Storage tree. If storage deletion fails, project files can remain after the metadata is gone. The control does not currently delete separately stored operational project records such as jobs, review annotations, pipeline status, costs, experiments, or experiment responses.
- Invite, remove, or change the roles of project collaborators, and revoke invitations or manage reusable reference grants when available to the reference-library owner or administrator.
- List, rotate, and revoke agent API tokens and limit them by scope, project, or expiration.
- Disconnect YouTube and use YouTube's own controls for content already submitted there.
- View credit balances and filter available usage records.
- Export saved voice references through the account data page. A project owner can request deletion there of their own saved voice reference when it is not managed by a reusable reference library. A successful deletion removes the reference from the catalog and project voice settings, then attempts to delete its stored audio bytes. If storage deletion fails after those references are removed, unreferenced audio bytes can remain. You can also submit a voice-reference correction or opt-out request, including for a reference in a project you do not own; that request blocks matching clone settings while it is unresolved.
The current account data export covers saved voice references; it is not a complete account or project export. The Studio does not currently expose a self-service full-account deletion control. For help with information not covered by these controls, email support@promptdriven.ai.
The Studio does not currently expose a self-service control for deleting an individual feature-validation response. Clearing browser site data removes locally stored assignment information, not a response already submitted.
9. Retention and deletion
Retention varies by the type of information and the system processing it. This policy does not promise a single fixed retention period. In cloud mode, project deletion removes the primary project metadata and direct invitations and requests deletion of the project's Cloud Storage tree. It does not currently remove separately stored project-scoped jobs, review annotations, pipeline status, costs, experiments, or raw experiment responses. Voice-reference deletion removes catalog and project references before attempting deletion of the associated stored audio bytes. Disconnecting YouTube removes the Studio's stored OAuth credential as described above.
Operational logs, audit or transaction records, backups, invitation records, and copies already sent to collaborators, distribution services, or generation providers may follow different technical or provider-controlled lifecycles. Deleting a Studio copy does not delete a copy already published to YouTube or retained by another service.
10. Security
The current implementation uses authenticated project access, owner/editor/viewer roles, server-side integration credentials, scoped agent tokens, and audit records. No networked service can guarantee absolute security. Keep sign-in and agent credentials private, restrict project access, and revoke credentials you no longer need.
11. Changes and contact
This policy may be updated as the Studio and its provider configurations change. The date at the top identifies this version. Questions about this policy or the controls described here can be sent to support@promptdriven.ai.