Back home

Effective August 20, 2026

Privacy at StudioCue

Who we are

StudioCue provides workflow software for photography studios. Questions or privacy requests can be sent to support@studio-cue.com.

Data we process

Studios may provide account, client, project, vendor, crew, document, schedule, communication, invoice, and integration data needed to operate their business. We also process limited technical information needed to secure, support, and improve the service. StudioCue does not store client payment-card or bank-account credentials.

How information is used

We use information to deliver requested workflows, secure portals, provider synchronization, communications, reporting, audit history, customer support, and permission-aware AI assistance. AI output is advisory for legal, payment, insurance, and readiness decisions.

Google Calendar data

A studio may connect its own Google Calendar so StudioCue can offer clients only consultation times the studio is genuinely free, and place booked work on that calendar. StudioCue requests two Google OAuth scopes. The Google user data accessed under each is:

In addition to the calendar data above, StudioCue stores the OAuth access and refresh tokens issued for that Google Account, and for each entry it creates, the Google event identifier and event link.

How it is used. Free/busy availability is used to compute which consultation times to offer, and the event scope is used to keep the studio's calendar in step with its bookings. Google user data is used only to provide these features for the authorizing customer. It is not sold, used for advertising, shared with unrelated customers, or used to train or improve generalized artificial-intelligence or machine-learning models. Google Calendar data is not sent to StudioCue's AI features.

How it is stored and retained. Free/busy availability is requested at the moment a set of consultation times is calculated and is not written to StudioCue's records. Event identifiers and links are retained for as long as the consultation or project they belong to exists. Access and refresh tokens are held server-side in managed secret storage and are never exposed to the browser.

How to stop and remove access. Disconnecting Google Calendar in StudioCue removes its reference to the stored credential and ends all further access to the Google Account, including availability reads and calendar writes. Revoking StudioCue from the Google Account permissions page invalidates the issued tokens directly. Removing an entry in Google Calendar does not change the corresponding record in StudioCue.

AI features and Limited Use

StudioCue's use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used, transferred, or sold to create, train, or improve foundational or generalized artificial-intelligence or machine-learning models, whether in raw, aggregated, anonymized, or derived form.

StudioCue's AI-assisted drafting and review features run on Google Vertex AI, using Google's Gemini models, inside StudioCue's own Google Cloud project. StudioCue integrates no third-party AI service providers, model gateways, model aggregators, or self-hosted models. Data obtained from the Google Calendar API is not sent to these features at all: they operate on the studio's own StudioCue records, such as project, package, questionnaire, and document data. AI output is advisory and is never the authority for legal, payment, signature, permission, or readiness decisions, each of which requires a human decision.

Zoom data

If a studio connects Zoom, StudioCue processes OAuth authorization details and the meeting information needed to create, view, update, and cancel that studio's Zoom meetings. Zoom information is used only to provide the connected workflow for the authorizing customer. It is not sold, used for advertising, shared with unrelated customers, or used to train AI models.

Service providers and sharing

StudioCue uses service providers to host and operate the application and connected services selected by a studio. We disclose only the information needed for those providers to perform their services. We may also disclose information when required by law, to protect the service and its users, or as part of a business transaction subject to appropriate safeguards.

Security

Access is tenant- and project-scoped. Provider tokens remain server-side and are protected using managed secret storage and encryption. StudioCue uses HTTPS in transit, access controls, audit records, and operational monitoring. No system is completely secure, so suspected issues should be reported promptly to support@studio-cue.com.

Retention and deletion

We retain information while it is needed to provide the service, satisfy legal or accounting obligations, resolve disputes, and enforce agreements. A studio may disconnect an integration to stop future synchronization. Account and deletion requests are handled according to applicable requirements, subject to limited backups and records we must retain.

Your privacy rights

Depending on where you live, you may have rights to access, correct, export, restrict or object to processing, withdraw consent, or delete personal information. You may also have the right to appeal a decision or complain to a data-protection authority.

To exercise a right, email support@studio-cue.com with the subject “Privacy request.” We may verify your identity and authority before fulfilling a request. Authorized agents may submit requests where permitted by law.

Children and sports workflows

StudioCue does not create child accounts, message children directly, use facial recognition, or create public child profiles. Parents or guardians manage access and releases.

Changes to this policy

We may update this policy as StudioCue changes. The effective date above identifies the latest version. Material changes will be communicated through the service or another appropriate channel.