Registered office: 86-90 Paul Street, London, United Kingdom, EC2A 4NE
Short version. Studiark uses the information needed to create and share AI videos, operate social features, process purchases and keep the service safe. We do not sell personal data, do not use private face or voice media for advertising, and do not use private Inputs to train foundation models unless a person separately opts in to a clearly described future programme.
1. Who we are and how to contact us
Studiark is operated by HELMBYTE LTD ("Helmbyte", "we", "us" or "our"), a company registered in England and Wales under company number 16913968, with its registered office at 86-90 Paul Street, London, United Kingdom, EC2A 4NE. Helmbyte is the controller of personal data processed for the Studiark application and service unless a notice says otherwise.
Use the Privacy Request form on the public Studiark Help & Safety page linked from the App Store listing, or Settings > Privacy > Privacy Request in the app. You may also write to our registered office. These routes are available to people who do not have a Studiark account.
If Helmbyte appoints a data protection officer, EU representative or another legally required local representative, the current contact details will be shown in this Policy and on the Help & Safety page.
2. Who may use Studiark
Studiark accounts, AI generation, purchases and social features are for people aged 18 or over. Studiark is not directed to children. We do not currently permit photographs, videos or voice recordings of anyone under 18 to be used as AI-generation references.
If we learn that an under-18 account or prohibited minor reference media has been submitted, we may restrict the account, stop processing, delete the material and preserve or report information where required for child safety or by law.
3. Personal data we collect
| Category | Examples | How we obtain it |
|---|---|---|
| Account and profile | Apple sign-in identifier; email or Apple relay email; username; display name; avatar; age confirmation; account settings; language and country/storefront | From you, Apple and your device settings |
| AI Inputs | Prompts; photographs; video; audio; voice recordings; reference media; generation settings; edits and selected models | From you, or from another user acting with permission |
| AI Outputs and library | Generated or modified videos; audio; thumbnails; drafts; saved clips; provenance and model information | Created through Studiark and its AI providers |
| Face, voice and consent | Whose media it is; permission scopes; Cast Friend approvals; voice-pack settings; consent receipt, expiry and revocation; privacy-preserving asset identifiers | From the uploader, the depicted person and Studiark records |
| Social activity | Published videos; captions; audience; follows or friends; likes or votes; remixes; challenges; reports; blocks; feed interactions | From your use of social features and other users' interactions |
| Location | Optional approximate location or coarse area used for Nearby; permission status | From your device after the iOS permission prompt |
| Device and diagnostics | App and OS version; device model; IP address; session, crash, security and performance logs; push token; language and time zone | Automatically from the app and infrastructure |
| Purchases | Product, subscription status, credit balance, transaction identifier, refund or chargeback status | From StoreKit and Apple; we do not receive full payment-card details |
| Safety and support | Reports; appeals; removal requests; correspondence; evidence; moderation decisions; account and content identifiers | From reporters, users, rights holders, depicted people, automated systems and authorities |
We do not upload your entire photo library, address book or microphone stream merely because you grant an iOS permission. You choose the media to upload. Camera, microphone, photo, location and notification access should be requested just in time for the feature that needs it.
4. Information about other people
A user may submit media that identifies another adult. In that case we receive personal data from the uploader rather than directly from the depicted person. The uploader must have permission covering the proposed AI generation and selected audience. Public posting, downloads, reusable characters, voice packs, remixes, commercial use and ongoing use may require direct approval from the depicted person through Cast Friend or a no-account consent link.
A depicted person can use the public Help & Safety page to ask what permissions are recorded, withdraw ongoing permission, object to processing, or request restriction or removal. We may ask for proportionate verification, but we will not require the person to create an account.
5. Why we use personal data and our legal bases
| Purpose | Data normally used | Legal basis where UK/EEA law applies |
|---|---|---|
| Create and operate an account | Account, profile, device and settings | Contract; legitimate interests in service administration and security |
| Generate, edit and store AI media | Inputs, Outputs, settings, technical data and selected provider | Contract; explicit in-app permission for disclosed third-party AI transfers; consent where required for optional device data |
| Use another adult's face or voice | Reference media, consent receipts and selected scopes | Consent where directly obtained; otherwise legitimate interests in providing the requested private feature, balanced against the person's rights, with stricter direct approval for expanded uses |
| Publish and operate social features | Public content, audience, social graph and interactions | Contract; legitimate interests in operating and improving the community |
| Nearby feed | Optional approximate location and feed activity | Consent through the device permission and feature choice |
| Purchases and credits | StoreKit transaction, entitlements and account | Contract; legal obligation for financial records; legitimate interests in fraud prevention |
| Safety, moderation and legal compliance | Inputs, Outputs, reports, logs, consent and account records | Legal obligation; legitimate interests in protecting people, preventing abuse, enforcing rules and defending legal claims |
| Support and product reliability | Correspondence, diagnostics and relevant content | Contract; legitimate interests in support, debugging and service improvement |
| Optional marketing or model-training programme | Only the data clearly described at the time | Consent; off by default and withdrawable |
Where we rely on legitimate interests, those interests are operating a reliable creative service, protecting users and rights holders, preventing fraud and abuse, improving performance and establishing or defending claims. We consider the nature of the data, reasonable expectations, risks and available controls. You may object where applicable.
6. AI generation and third-party AI providers
Studiark routes generation requests to Helmbyte systems and selected third-party AI providers. Current providers may include Google Cloud/Vertex AI for Veo models and BytePlus/ModelArk for Seedance or related models. The available provider depends on the model, feature and territory.
Before a prompt or personal media is first sent to a provider, Studiark identifies that provider and explains what will be sent, why, relevant retention or processing information and a link to more details. We request explicit provider-specific permission. If you decline, we do not send the data to that provider; the affected generation feature will not work, but unrelated features remain available where feasible.
We normally send only the selected prompt, media, generation settings and technical information needed to generate the Output, secure the service, prevent abuse and comply with law.
Providers may apply automated safety filters, reject content and process data in other countries under contractual and legal safeguards.
Helmbyte does not use private Inputs or private Outputs to train its own foundation models and does not instruct a provider to use them for foundation-model training. Any materially different training programme requires a separate, optional, specific notice and opt-in.
Provider policies and product configurations can change. The just-in-time provider notice shown before transfer forms part of this Policy and controls if it gives more specific current information.
Faces and voices. A photograph or voice recording may be personal data. It becomes biometric special-category data only in some circumstances, such as when technically processed for unique identification. Studiark does not currently create face or voice templates for identity matching. If that changes, we will provide a separate biometric notice and obtain any explicit consent required before creating the template.
7. Automated safety systems and human review
Studiark and its providers use automated systems to detect prohibited content, suspected minors, spam, fraud, unsafe generation requests, impersonation, policy circumvention and security threats. These systems can refuse generation, limit a feature, add a warning, reduce distribution or refer content for review.
Private media is not routinely viewed by staff. Authorised reviewers may access limited relevant data when needed to investigate a report, respond to support, handle an appeal, protect a person, prevent serious abuse, comply with law or diagnose a specific technical problem. Access is limited and logged where appropriate.
Moderation may be partly automated, but users can appeal significant content or account decisions. Studiark does not use automated processing to make credit, employment, insurance or similarly consequential decisions about users.
8. Publishing, audiences and remixes
Drafts remain private unless you choose an audience or share them. Public and audience-limited content is processed to display it, recommend it, enable permitted interactions and enforce the selected settings. If you enable downloads, Make Yours, Continue, Challenge or another remix feature, other users may create or retain permitted versions.
Public content can be copied, screen-recorded or shared outside Studiark. Deleting the original or changing settings stops future Studiark access where technically possible, but cannot automatically remove independent copies made by others. Valid privacy, safety and intellectual-property requests remain available.
9. When we share personal data
| Recipient | Why data is shared | Typical data |
|---|---|---|
| AI providers | Generate media, apply safety controls and prevent abuse | Selected prompt, media, settings and necessary technical data |
| Cloud and delivery providers | Host databases and media, deliver content, back up and secure the service | Account, content, logs and encrypted backups as needed; providers may include Google Cloud and Cloudflare |
| Apple | Sign in, StoreKit purchases, push notifications and App Store operations | Apple identifiers, transaction and push-routing data |
| Safety and support vendors | Process reports, support requests, diagnostics and security events | Relevant report, correspondence, logs and identifiers |
| Other users and the public | Display content according to your selected audience and enabled social features | Profile and content you publish, audience and permitted interactions |
| Authorities and rights holders | Respond to valid legal process, report child sexual exploitation or other serious illegality, protect rights and safety | Only information reasonably necessary and legally permitted or required |
| Corporate transaction parties | Evaluate or complete a financing, reorganisation, acquisition or sale | Necessary records subject to confidentiality and continued protection |
Service providers act under contracts and may use data only for the agreed services and legal obligations. We do not allow them to use private face or voice media for their own advertising.
10. International transfers
Helmbyte is based in the United Kingdom and Studiark is offered internationally. Data may be processed in the UK, European Economic Area, United States, Singapore and other locations where our providers operate. The specific AI provider and relevant processing information are disclosed before transfer.
Where a restricted transfer requires safeguards, we use an adequacy regulation or decision, approved standard contractual clauses, the UK International Data Transfer Addendum or Agreement, contractual and technical safeguards, or another lawful mechanism. You may request information about the safeguard relevant to your data through the Privacy Request form.
11. How long we keep data
The following launch retention schedule is the default unless a shorter in-app notice applies or law requires a different period:
| Data | Default retention |
|---|---|
| Account and profile | While the account is active; normally removed or de-identified within 30 days after account deletion, subject to the exceptions below |
| Generation working files | Temporary job copies are normally deleted within 30 days after completion or failure unless saved to the user's library, needed for a support case or a shorter provider period applies |
| Saved private and published content | Until the user deletes it or closes the account; primary copies normally removed within 30 days and encrypted backup copies age out within 90 days |
| AI-provider processing copies | For the period stated in the provider-specific notice and applicable contract; no longer than needed for generation, security, abuse prevention and legal compliance |
| Approximate location | Normally used for the current Nearby request and not retained as continuous location history; coarse security or feed logs may remain for up to 30 days |
| Consent and face/voice permission records | While the permission or related content is active and for up to six years afterwards to demonstrate scope, withdrawal and compliance |
| Security, moderation and safety records | Normally up to six years, shorter where risk permits, or longer for an active investigation, legal hold or mandatory reporting requirement |
| Routine technical logs | Normally up to 12 months, unless aggregated, needed for an investigation or required by law |
| Support correspondence | Normally three years after the request closes |
| Purchase and accounting records | Normally seven years or the period required by tax, accounting and consumer law |
Deletion can be delayed where data is needed to protect a person, prevent fraud, complete a transaction, preserve evidence, respond to a legal claim or comply with law. When continued identification is unnecessary, we may irreversibly de-identify data instead.
12. Your controls and choices
Account and content: edit your profile, audience and social settings; delete drafts, published content and your account in Settings.
Face and voice permissions: review and revoke ongoing Cast Friend, reusable character and voice-pack permissions in Settings > Face & Voice Permissions or through the no-account route.
AI providers: decline a provider-specific transfer or withdraw permission for future transfers; this disables only the affected provider or generation feature where feasible.
Device access: change Photos, Camera, Microphone, Location and Notification permissions in iOS Settings.
Location: use feeds that do not require location, or turn off location access; Nearby will not function normally without it.
Marketing and tracking: unsubscribe from marketing and decline App Tracking Transparency. Studiark does not condition core paid functionality on tracking permission.
Blocking and recommendation controls: block users, report content and use available feed or recommendation controls.
13. Your privacy rights
Depending on where you live and subject to lawful exceptions, you may have rights to:
- know whether we process your personal data and obtain access to it;
- correct inaccurate data;
- delete data;
- receive certain data in a portable format;
- restrict or object to processing, including processing based on legitimate interests;
- withdraw consent for future processing without affecting earlier lawful processing;
- opt out of sale, sharing, targeted advertising or certain profiling where those concepts apply; and
- appeal a refusal of a privacy request and complain to a regulator.
Submit a request through the public Privacy Request form or Settings > Privacy. We may verify identity and authority proportionately, using information already associated with the account where possible. We do not discriminate for exercising privacy rights. An authorised agent may submit a request where local law permits, but we may verify the authority and the person's identity.
UK users may complain to the Information Commissioner's Office. EEA users may complain to their local supervisory authority. Other users may contact the privacy or consumer-protection authority in their jurisdiction. We encourage you to contact us first so we can investigate.
14. Sale, advertising and tracking
Helmbyte does not sell personal data for money and does not currently share personal data for cross-context behavioural advertising. We do not use private Inputs, private Outputs, faces, voices or precise location for advertising. If Studiark introduces targeted advertising or a use that legally counts as sale or sharing, we will update this Policy and provide any required opt-out and consent controls before that use.
Studiark does not track activity across other companies' apps or websites without the permission required by Apple's App Tracking Transparency framework.
15. Security
We use measures designed to protect data, including encryption in transit, encryption at rest where appropriate, access controls, separation of production duties, secret management, logging, rate limits, vulnerability management, backups and incident response. No online service can guarantee absolute security.
If a breach creates a legally reportable risk, we will notify the relevant regulator and affected people as required. Please report suspected account compromise or a security issue through Help & Safety.
16. Account deletion and data belonging to another person
You can request account deletion from inside the app. We will explain what will be deleted, what may remain temporarily in backups and what must be retained. Deleting an account does not automatically erase safety reports, transaction records, consent evidence, lawful remixes made before revocation or copies outside our control.
If Studiark holds your face, voice or other personal data because another user submitted it, use the public Help & Safety route. You do not need an account. We may restrict future generation immediately while verifying a credible request.
17. Changes to this Policy
We may update this Policy when the product, providers, laws or data practices change. We show the effective date and keep the current version available in the app and App Store listing. Before a materially different use, such as model training, advertising use of face or voice data, biometric identification or a new third-party AI transfer, we provide a specific notice and obtain any additional permission required.