pstudio Privacy Policy
Last Updated: October 8, 2026
This policy applies to pstudio, the AI video studio operated by Pathors Technology Co., Ltd. ("Pathors", "we") at https://pstudio.pathors.com. pstudio has two entry points: the web app, and a remote MCP server at https://pstudio.pathors.com/mcp that AI assistants such as ChatGPT and Claude connect to through OAuth. Both are covered here. It explains what personal data pstudio collects, why, who receives it and how long it is kept. Our general Privacy Policy covers our other services; for pstudio, this policy applies.
1. Personal Data We Collect
Account data
- Google sign-in: your name, email address, profile picture and whether Google has verified the email address. We request only the openid, email and profile scopes and never see your Google password.
- Single sign-on (Cloudflare Access): the name and email address of your organization account.
- Email and password: used only for accounts we create for app review and testing. You cannot sign up with a password.
- Profile details you add: job title, username and an uploaded avatar.
- Workspace membership: the workspaces you belong to, your role in each, and invitations (the invited email address and who sent the invitation).
Content you create or upload
- Projects, scripts, project briefs, storyboards and shots, prompts, and elements such as characters, locations, props, voices and styles
- Images, video and audio you upload or import from a URL, and the images, video, voice, sound effects, music, transcripts and rendered MP4 files generated for you
- When you build a character from photos of a person, your answer to the consent question (the person is you, has consented, or is fictional), and who recorded it and when
- Capture metadata read from the files you upload: capture time, GPS location, the nearest city derived from that location, and the camera or phone model
This content may itself contain personal data, such as faces or voices of people in your footage.
Usage and credit records
- A record of every generation, transcription and render job: the model used, its settings, status, timestamps, and estimated and actual cost
- Credit grants and charges for each workspace
- An activity log of changes made in a project (who changed what, and whether it was done in the web app or through a connected AI assistant)
- The project and panel you last had open, so an assistant can tell what "this project" means
Connection and technical data
- The session cookie that keeps you signed in
- The IP address and browser user agent stored with each sign-in session
- For each AI assistant you connect: its OAuth client registration (name and redirect address) and the access and refresh tokens issued to it
- Server logs, including errors
2. What We Receive from AI Assistants
When you use pstudio from ChatGPT, Claude or another AI assistant, pstudio does not receive your conversation history with that assistant. It receives only the arguments of the tool calls the assistant chooses to send (for example a project name, a script, or a prompt for an image) and returns the result. We treat what arrives in a tool call as content you provided. How the assistant handles your conversation is governed by its provider's privacy policy.
pstudio itself does not call a language model. Writing scripts, prompts and edit decisions is done by the assistant you use, not by pstudio.
3. How We Use Your Data
- To sign you in and to authorize the AI assistants you connect
- To store, show and organize your projects and media library
- To run the generation, transcription and rendering jobs you or your assistant request
- To estimate costs, reserve and charge credits, and show spending
- To let members of a workspace work together and see who changed what
- To keep the service secure, prevent abuse and enforce our terms
- To answer your support requests
We do not sell your personal data, use it for advertising, or use your content to train AI models.
4. Who Receives Your Data
AI model providers
When a job runs, the input that job needs is sent to the provider that performs it: the prompt or script text, and any reference images, video or audio. We do not send your name or email address with these requests. Each provider processes the data under its own terms and privacy policy.
| Provider | Used for |
|---|---|
| OpenRouter | Image and video generation. OpenRouter routes each request to the vendor of the chosen model; the models offered today come from Google, OpenAI, Black Forest Labs, ByteDance, Kuaishou (Kling), Alibaba (Wan) and MiniMax. |
| ElevenLabs | Voice, sound effects, music, speech-to-text, and timing alignment for captions |
| Alibaba Cloud Model Studio (DashScope) | Voice (Qwen text-to-speech) |
| Soniox | Speech-to-text |
The list of models changes as we add or retire them; the providers above are the ones pstudio can send data to. After a Soniox transcription is retrieved, pstudio asks Soniox to delete the uploaded audio and the transcript.
Infrastructure providers
- Cloud hosting provider (application servers and database)
- Object storage and network provider (every uploaded, generated and rendered file)
- Sign-in providers (Google, and Cloudflare Access for single sign-on)
Other recipients
- Other members of your workspace, who see your name, email, profile, the content you create there and the activity log
- AI assistants you connect, which can read and change your workspace content within the access you grant them
- Authorities, where the law requires it
5. How Long We Keep It
| Data | Retention |
|---|---|
| Account and profile data | Until you ask us to delete your account |
| Workspace content (projects, elements, media files, transcripts) | For as long as the workspace exists, or until you ask us to delete it. Deleting a project removes the project but keeps its media in the workspace library. Deleting media in the library hides it, but the file stays in storage so that timelines using it still render, until the workspace or your account is deleted at your request. |
| Job, credit and activity records | For as long as the workspace exists; longer where the law or resolving a dispute requires |
| Sign-in sessions | A session expires 7 days after it was last renewed (it is renewed at most once a day while you use pstudio). Expired session records, including IP address and user agent, are deleted within 90 days of expiry |
| AI assistant access tokens | Access tokens expire after 1 hour and refresh tokens after 30 days, or earlier if you disconnect the assistant |
| Server logs | Kept for up to 90 days |
| Data held by AI model providers | As set by each provider's own policy |
When you ask us to delete your account or workspace, we complete the deletion or de-identification within thirty days. Content you created in another person's workspace belongs to that workspace and stays there for its other members.
6. Your Rights and How to Delete Your Data
You may ask to access, correct, export or delete your personal data, or ask us to stop processing it. From the email address you sign in with, write to contact@pathors.com; see our Data Deletion Instructions for what to include. We act once we have confirmed your identity.
You can also disconnect pstudio from ChatGPT, Claude or another assistant at any time in that assistant's connector or app settings, and remove pstudio's access to your Google account in your Google account settings.
7. Cookies
The pstudio app uses only the cookies needed to keep you signed in, plus settings that remember your language and theme. It uses no analytics or advertising cookies.
8. Data Protection
Data is encrypted in transit. Access to a workspace is limited to its members, and files are served through short-lived signed links. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires.
9. Cross-Border Data Transfers
Pathors is based in Taiwan. Our hosting providers and the AI model providers above operate in other countries, so your data may be processed outside Taiwan and outside your own country.
10. Policy Updates
We may update this policy from time to time. We will post changes on this page with a new date and notify you of significant changes.
11. Contact
Pathors Technology Co., Ltd., Taipei, Taiwan. contact@pathors.com
