Legal / Privacy
Privacy Policy
Effective August 3, 2026
1. Who is responsible for your data
Donatello Studio operates the Donatello service at donatello.studio. Privacy requests can be sent to privacy@donatello.studio. Additional operator details will be published before the service moves beyond early access.
2. Information we collect
When you use Google to create or access an account, we receive:
- your Google account's stable user identifier, email address and email-verification status;
- your display name and profile picture, when available; and
- the technical information required to create and protect your Donatello session.
We do not request access to Gmail, Google Drive, your contacts or your Google password. When creative generation opens, prompts, uploaded inputs, generated outputs and related settings may also be processed to provide the service.
3. Why we use information
We use information to:
- create, authenticate and maintain your account;
- provide the studio and preserve your work;
- prevent fraud, abuse and security incidents;
- diagnose failures and improve reliability; and
- meet legal obligations and respond to valid requests.
These activities are based on providing the service you request, our legitimate interest in securing and improving it, consent where the law requires it, and applicable legal obligations.
4. Cookies and local storage
Donatello currently uses only essential authentication and security cookies. The Donatello session cookie is encrypted in transit, unavailable to browser scripts and normally expires after 30 days. Google may set or read its own cookies while providing Google Sign-In under Google's policies. We do not currently run advertising or behavioral analytics cookies.
5. Service providers and international processing
We use specialized infrastructure and authentication providers to operate Donatello. Google processes information when you use Google Sign-In. Creative inference providers will receive only the prompts and assets required to perform a requested generation once that functionality is enabled. We will identify active generation providers and relevant transfer safeguards before public generation begins.
We do not sell personal information and do not share it for third-party behavioral advertising.
6. Retention and security
Account identity data is retained while your account remains active and for the limited period required for security, dispute resolution or legal compliance afterward. Active sessions normally expire after 30 days and can be revoked when you sign out. We use access controls, hashed session tokens, encrypted transport and infrastructure isolation to protect information. No online system can guarantee absolute security.
7. Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. You may also complain to your local data-protection authority. Contact privacy@donatello.studio to make a request. We may need to verify your identity first.
8. Children
Donatello is not directed to children under 18. Do not create an account if you are below the age required to consent to online services in your country.
9. Changes to this policy
We may update this policy as the studio evolves. Material changes will be identified on this page and, when appropriate, announced inside the service before they take effect.