Privacy Policy
Last updated: June 19, 2026
1. Introduction
PF Studio ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our project management application at pfstudio.org, any associated subdomains, and our mobile applications available on the Apple App Store and Google Play Store (collectively, the "Service"). This policy applies equally to our website and mobile applications.
By using PF Studio, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Data Collection Summary
The following table summarizes the categories of data we collect, whether it is shared, and whether it is linked to your identity:
| Data Type | Collected | Shared With | Purpose | Linked to Identity |
|---|---|---|---|---|
| Email address | Yes | Stripe (for billing) | Account creation, authentication | Yes |
| Display name & username | Yes | None | Profile, collaboration | Yes |
| Password (hashed) | Yes | None | Authentication | Yes |
| Profile image | Yes | Cloud storage | User profile | Yes |
| User content (projects, notes, etc.) | Yes | None | Core service functionality | Yes |
| AI prompts & responses | Yes | Groq (processed, not stored) | AI assistant features | Yes |
| Payment info (card, billing) | No (Stripe only) | Stripe | Subscription billing | Yes (via Stripe) |
| IP address | Yes (analytics only) | None | Analytics, security | No |
| User-agent / device info | Yes (analytics only) | None | Analytics | No |
| Referrer URL | Yes (analytics only) | None | Analytics | No |
| Cookies (essential) | Yes | None | Session management | Yes |
| Preferences (theme, language) | Yes (localStorage) | None | User experience | No |
3. Information We Collect
We collect the following categories of personal information:
3.1 Information You Provide
- Account Information: Email address, display name, and username when you create an account
- Password: Securely hashed using industry-standard encryption (bcrypt) — we never store your password in plain text
- Profile Image: If you upload a profile picture or select an avatar
- User Content: Projects, notes, sprint cards, calendar events, scripts, goals, ideas, topic studies, whiteboard data, and reference images you create within the Service
- Feedback: Messages you submit through the in-app feedback form
3.2 Information Collected Automatically
- IP Address: Collected when you visit our landing page and access page for analytics purposes
- User-Agent: Browser and device information sent with page requests
- Referrer URL: The page you visited before arriving at PF Studio
- Cookies: We use essential cookies (authentication session tokens) and optional analytics cookies. You can decline analytics cookies via our cookie consent banner
3.3 Payment Information
If you subscribe to a paid plan, payment processing is handled entirely by Stripe, Inc. We store only your Stripe customer ID and subscription ID for account management. We never see, store, or process your credit card number, CVV, or full billing details.
4. How We Use Your Information
We use your personal information for the following purposes:
- Providing the Service: To create and manage your account, authenticate your identity, and deliver the features you use
- Communication: To send you in-app notifications about your account, team invitations, and important service updates
- Analytics: To understand how visitors interact with our landing pages so we can improve the experience (only if you accept analytics cookies)
- AI Features: When you use Forge AI (our AI assistant), your prompts are sent to a third-party AI provider for processing. We do not use your AI conversations to train models
- Security: To detect and prevent fraud, abuse, and unauthorized access
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
5. How We Store and Protect Your Data
Your data is stored on secure, cloud-hosted servers. We implement industry-standard security measures including:
- Encrypted data transmission (HTTPS/TLS)
- Password hashing with bcrypt
- JWT-based session management with secure, HTTP-only cookies
- Role-based access controls and authenticated API routes
- Cloud storage with access controls for uploaded files
While we take reasonable precautions to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
6. Third-Party Services
We share data with the following third-party services only as necessary to provide the Service:
- Stripe, Inc. — Payment processing for subscriptions. Subject to Stripe's Privacy Policy
- Groq, Inc. — AI language model processing for the Forge AI assistant. Your prompts are processed but not stored for training. Subject to Groq's Privacy Policy
- Cloud Storage Provider — Secure file storage for uploaded images and profile pictures
We do not sell, rent, or trade your personal information to any third party for marketing or advertising purposes. We will never share your data except as described in this policy.
7. Cookies
PF Studio uses the following types of cookies:
- Essential Cookies: Required for authentication and session management. These cannot be disabled as the Service would not function without them
- Analytics Cookies: Used to track page views on our landing and access pages (IP address, user-agent, referrer). These are optional and you can decline them via the cookie consent banner shown on your first visit
- Preference Cookies: Store your theme, language, and workspace mode preferences in your browser's localStorage
You can manage or delete cookies through your browser settings at any time. Disabling essential cookies will prevent you from using the Service.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to Access: You can request a copy of all personal data we hold about you. Use the "Download My Data" feature in Settings to export your data at any time
- Right to Rectification: You can update your name, username, and profile image directly in Settings
- Right to Deletion: You can permanently delete your account and all associated data using the "Delete My Account" feature in Settings. This action is irreversible
- Right to Data Portability: You can download your data in a machine-readable format (JSON) using the "Download My Data" feature
- Right to Object: You can decline analytics cookies to stop non-essential data collection
- Right to Withdraw Consent: You can withdraw consent for analytics at any time by clearing your cookies and declining when the consent banner reappears
To exercise any of these rights, use the in-app features described above or contact us at [email protected]. We will respond to your request within 30 days.
9. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specific retention periods are as follows:
- Account data (email, name, username, profile image): Retained while your account is active. Permanently deleted within 30 days of an account deletion request
- User content (projects, notes, sprint cards, calendar events, scripts, goals, ideas, whiteboards, topic studies): Permanently deleted immediately upon account deletion
- AI conversation data: Prompts are sent to Groq for processing and are not stored by Groq or PF Studio after the response is generated. No AI conversation history is retained on our servers
- Payment records: Stripe customer ID and subscription ID are deleted upon account deletion. Stripe may retain transaction records per their own retention policy
- Uploaded files: Removed from cloud storage immediately upon account deletion
- Analytics data: Anonymous analytics data (page views with anonymized information) may be retained for up to 12 months for service improvement purposes
- Feedback submissions: Retained for up to 24 months for product improvement, then deleted
When you delete your account, we initiate deletion of all your personal data within 30 days. Some data may persist in encrypted backups for up to 90 days before being permanently purged.
10. Children's Privacy
PF Studio is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] and we will promptly delete the information.
11. California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request details about the personal information we collect and how it is used
- Right to Delete: You may request deletion of your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
- Do Not Sell: We do not sell your personal information to third parties. Ever.
12. European Residents (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Contract Performance: Processing necessary to provide the Service you signed up for
- Legitimate Interest: Analytics and service improvement, security monitoring
- Consent: Analytics cookies (which you can decline or withdraw at any time)
You have the rights described in Section 8 above, plus the right to lodge a complaint with your local data protection authority.
13. Cross-App Tracking
PF Studio does not track users across other companies' apps or websites. We do not use advertising identifiers (IDFA, GAID), device fingerprinting, or any cross-app tracking technologies. We do not participate in any advertising networks or data broker programs.
The only analytics we perform are first-party page view tracking on our own landing pages, which requires your explicit consent via our cookie banner.
14. Mobile Applications
PF Studio is available as a mobile application on the Apple App Store and Google Play Store. The mobile app accesses the same account and data as the web version. In addition to the data described above, the mobile app may:
- Camera & Photo Library: Access your camera or photo library only when you choose to upload a profile picture or reference image. We do not access these without your explicit action
- Push Notifications: Send push notifications for team invitations, project updates, and service announcements if you opt in. You can disable these at any time in your device settings
- Local Storage: Store your preferences (theme, language, workspace mode) locally on your device
The mobile app does not collect device identifiers for advertising, location data, contacts, call logs, or any sensor data. We do not use any third-party advertising SDKs.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will notify you through the Service (via in-app notification). Your continued use of PF Studio after changes are posted constitutes acceptance of the revised policy.
16. Contact Us
If you have any questions about this Privacy Policy, your data, or your rights, please contact us:
- Email: [email protected]
- In-App: Settings → Feedback form
- Website: pfstudio.org