Last updated: 9 October 2026.
This policy explains what personal data we process when you use Procedural Mesh Studio — the desktop app, the engine plugins, this website and the account area — why, for how long, who else handles it, and what your rights are under the EU General Data Protection Regulation (GDPR).
Who is responsible
The data controller is Dotlabs Studios di Emanuele Masala (DotLabs Studios), Via Tarragona 31/a, 07041 Alghero (SS), Italy, VAT number IT02966720902. For anything about your data, write to [email protected].
What we process, and why
Your account. You sign in with Google. We receive your email address, your name, your profile picture address and Google’s identifier for your account. We use them to create and recognise your account, to link your licenses and purchases to it, and to write to you about them. In the Studio you can also sign in with your license number. Legal basis: performance of the contract (art. 6(1)(b) GDPR).
Licenses and purchases. We keep your license number, plan, status and dates, and the identifier Stripe gives you as a customer. Payments are made on Stripe’s own pages: your card details go to Stripe and never reach us. Before you pay, you accept the Terms and ask for immediate access; we record which version of the Terms you accepted and when, and Stripe keeps the same record with the payment. We keep invoices and payment records as tax law requires. Legal bases: performance of the contract, and legal obligation (art. 6(1)(c)).
Your computers. When the Studio signs in, it registers the computer so a license can be used on a limited number of them. We store a one-way hash of a machine fingerprint (not the fingerprint itself), the computer’s name and operating system, the app version, the country derived from the connection’s IP address, and when it was last seen. You can sign a computer out from the app or from your account. Legal basis: performance of the contract.
Credits and usage. For each assistant reply, with credits or with your own key, we record when it happened, the model used, the number of tokens, the credits charged and how it ended, and every movement of your credit balance. These records never include what you asked or what the model answered. They let us charge exactly what you use and show you your history. Legal basis: performance of the contract.
What you ask the assistant. To answer, your request — your message, the script being edited and, when the assistant checks its work, pictures of the model — passes through our server to the AI model and back. The request carries none of your account details: not your name, your email or your account identifier. We do not store the content of these conversations, and we do not use it to train models.
- With credits, the model is run by DeepSeek, on our account.
- With your own key, the request goes to the provider you chose (for example OpenAI, Anthropic, DeepSeek, Z.ai, MiniMax or Google). Your key stays encrypted on your computer; it passes through our server with each request and is never stored there. That provider handles the request under its own terms and privacy policy.
Avoid putting personal data in your requests: they do not need any. Legal basis: performance of the contract.
Emails. We send emails about your account and purchases: your license number, a failed payment, a renewal coming up, a license that ends. Legal basis: performance of the contract.
Security. Our server keeps technical logs and records events that may signal misuse, such as a reused sign-in token or a license used on too many computers, to protect your account and the service. Legal basis: our legitimate interest in keeping the service secure (art. 6(1)(f)).
Visiting the website. The website sets no advertising or analytics cookies and does not track you. Our server, which delivers it, and Cloudflare, which protects it, process your IP address and browser details to send you the pages and to stop attacks. The cookie policy lists the cookies. Legal basis: legitimate interest.
Support. If you write to us, we use what you send to answer. Legal basis: performance of the contract or legitimate interest.
On your computer. The Studio keeps your settings, your own models and scripts, and your AI keys (encrypted with your operating system’s protection) on your computer. Crash reports are off unless you turn them on in Settings.
To use the Service you need an account: without the data above we cannot provide it. We do not take decisions about you based solely on automated processing that have legal or similarly significant effects; the automatic checks in the Service (computers per license, usage limits) apply the rules of the Terms.
Who else handles your data
We use service providers that process data on our behalf, under contracts that bind them to protect it:
- Stripe — payments, invoices and the customer portal;
- Google — sign-in;
- Cloudflare — network delivery and protection against attacks;
- Contabo — hosting of the website, the server and the database, in a data centre in Germany;
- our email provider — the emails described above;
- AI model providers — DeepSeek for requests paid with credits, and the provider you choose when you use your own key.
We may also share data with professional advisers and public authorities where the law requires it. We do not sell personal data.
Transfers outside the European Union
Some of these providers are based in, or process data from, countries outside the European Economic Area:
- the United States (Stripe, Google, Cloudflare): these companies take part in the EU–US Data Privacy Framework, which the European Commission has found adequate; where it does not apply, the Commission’s standard contractual clauses do;
- the People’s Republic of China (DeepSeek, for requests paid with credits): there is no adequacy decision, and the transfer relies on the safeguards the GDPR provides, such as the standard contractual clauses. These requests carry no account details. If you prefer that your requests do not go to China, use your own key with another provider.
You can ask us for a copy of the safeguards in place.
How long we keep it
- Account, licenses, computers, credits and usage records: while your account exists. When you delete your account they are deleted or made anonymous.
- Invoices, payment records and the record of your acceptance of the Terms: ten years, as Italian law requires for accounting records.
- Security events: twelve months, then deleted automatically.
- Server logs: four weeks.
- Support emails: as long as needed to deal with your request.
Your rights
You can ask us for access to your data, to correct it, to delete it, to restrict or object to its processing, and to receive it in a portable format — the account area has a button that downloads everything we keep about your account, and another that deletes the account. Write to [email protected].
You can also lodge a complaint with a supervisory authority: in Italy, the Garante per la protezione dei dati personali, or the authority of the country where you live or work.
Security
Connections are encrypted; sign-in tokens are short-lived and stored as hashes; the server runs in an EU data centre, reachable only through Cloudflare, and keeps encrypted backups. No system is perfectly secure, but we work to protect your data and will inform you and the authorities of a breach as the law requires.
Children
Procedural Mesh Studio is a tool for professionals and is not directed at children. You must be at least 18 to buy a license or credits.
Changes
If we change this policy we will publish the new version here with its date, and tell you by email when the change is significant.