1. Overview
Shroom Studio is a collaborative AI media workspace that lets teams generate, organise, and review images produced by third-party AI models such as OpenAI, Google AI, Flux, xAI, and Fal. To run the Service reliably we process certain personal data — this policy explains what, why, and how.
We act as the data controller for account, billing, and usage data that you provide directly. For generated media and prompts processed on your behalf, we act as a data processor for your workspace owner.
2. Data we collect
We collect the following categories of information:
Account data
- Email address, display name, and password hash (managed via AWS Cognito).
- Workspace, project, and team membership information, including invitation tokens.
- Profile preferences such as theme (light/dark) and language.
Content data
- Prompts, reference images, generation parameters, and model selections you submit.
- Generated images and associated metadata (model, parameters, timestamp, seed, cost).
- Comments, approvals, and activity logs tied to generations and projects.
Billing data
- Subscription plan, credit balance, top-up history, and invoice records.
- Payment is processed by Stripe. We receive only tokenised identifiers and billing metadata — we do not see or store full card numbers.
Usage & technical data
- IP address, user agent, device type, and timestamps of requests.
- Feature usage events (e.g. generations created, comments posted), error reports, and performance logs.
3. How we use data
We process personal data only for the purposes below, and only where we have a lawful basis to do so under the GDPR (see our GDPR page).
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Authenticate users, run generations, store outputs, route collaboration events. | Contract |
| Billing & credits | Charge subscriptions, meter credit usage, issue invoices, prevent fraud. | Contract / Legal obligation |
| Security & abuse prevention | Rate limiting, anomaly detection, sweeping orphan jobs, audit logs. | Legitimate interest |
| Product improvement | Aggregated usage analytics, performance monitoring, bug tracking. | Legitimate interest |
| Transactional email | Account confirmation, invitations, billing receipts via AWS SES. | Contract |
| Marketing (opt-in only) | Product announcements, where you have actively subscribed. | Consent |
4. AI model providers
When you submit a generation, your prompt and parameters are forwarded to the AI provider you select. Each provider operates under its own terms and privacy policy. We act as a proxy — we never share your API keys, and providers receive only the content needed to perform the request.
| Provider | Purpose | Policy |
|---|---|---|
| OpenAI | DALL-E / GPT image generation | openai.com/policies |
| Google AI | Gemini / Imagen image generation | policies.google.com |
| Black Forest Labs (Flux) | Flux / Flux Kontext image generation | blackforestlabs.ai |
| xAI | Grok image generation | x.ai/legal |
| Fal.ai | Hosted model inference (async jobs) | fal.ai/privacy-policy |
Provider terms can change. Review each provider's policy before submitting sensitive content.
6. Storage & security
Account data is stored in Amazon DynamoDB; generated media and uploaded assets are stored in Amazon S3 with server-side encryption. Data is encrypted in transit (TLS) and at rest.
- Access to production data is restricted to authorised personnel and is logged.
- Passwords are hashed and managed by AWS Cognito; we never see them in plain text.
- We rotate secrets and monitor for anomalous activity through automated sweeps and audit logs.
No system is perfectly secure. If we discover a personal data breach that is likely to affect you, we will notify you and the relevant supervisory authority in line with applicable law.
7. Data retention
- Account data is retained for as long as your account is active.
- Generations, comments, and project data are retained as long as the owning workspace exists.
- Billing records are retained for up to seven years to meet tax and accounting obligations.
- Server logs are retained for up to 90 days for security and debugging.
After account deletion, we remove or anonymise personal data within 30 days, except where retention is required by law.
9. Your rights & choices
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. See our dedicated GDPR page for details and how to exercise them.
You can also update most personal information directly in the Account and Settings pages, and delete your account there or by contacting us.
10. International transfers
Shroom Studio is operated from the United States and stores most data in AWS regions located in the US and the EU. When personal data of EEA/UK residents is transferred outside their region, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and supplementary measures.
11. Children
Shroom Studio is not directed to children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version here and update the "Last updated" date above. For material changes we will notify active users by email or in-app notice before the change takes effect.
13. Contact us
Questions, requests, or complaints about this policy or your personal data can be sent to:
If you are in the EEA or UK and believe we have not resolved your concern, you have the right to lodge a complaint with your local data protection authority.