Effective date: 1 October 2026 · Version 2026-10-01
Who we are
Cask Studio V.O.F., a general partnership (vennootschap onder firma) registered with the Dutch Chamber of
Commerce under KvK number 42081808, Zuideinde 123, 1551 ED Westzaan, the Netherlands, is the controller of your
personal data. For any privacy question or to exercise your rights, contact us at
[email protected]. You also have the right to lodge a
complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
This policy covers the Cask apps for macOS (Cask Studio, also called Cask Film, and Cask Motion, also
called Cask Flow), the service behind them, and the website cask.studio.
What we collect, why, and our legal basis
- Account & sign-in — email, display name, password (hashed) or Google sign-in identifiers, and any MFA you enable. Basis: performance of our contract with you (Art 6(1)(b) GDPR).
- Your generations — the prompts you write and the images, video, and audio you upload, plus the generated outputs. Basis: performance of our contract.
- Cloud projects — if you sync a project, the project file and the media it uses. Basis: performance of our contract.
- Payments & subscriptions — Stripe customer, subscription, and payment identifiers and your purchase history. Basis: contract, and our legal obligation to keep accounting records (Art 6(1)(b) and (c)).
- Security & abuse prevention — IP address, device label, user agent, and session tokens. Basis: our legitimate interest in keeping the service secure (Art 6(1)(f)).
- Service emails and notifications — verification, password reset, receipts, and the push notifications you allow. Basis: contract.
- Usage & billing telemetry — per-job usage and cost records. Basis: legitimate interest in operating and metering the service.
- Crash reports — only if you agree, when a Cask app crashes or hits an error (see below). Basis: your consent (Art 6(1)(a)).
- App analytics — only if you opt in, in the Cask apps (see below). Basis: your consent (Art 6(1)(a)).
- Website analytics — on cask.studio only, and only if you click Allow on the cookie notice (see below). Basis: your consent (Art 6(1)(a)).
- Marketing email — news about new features and offers for Cask products, sent to the email address on your account only if you opt in, when you sign up or later in the app's notification settings. It is off until you do. Every marketing email has an unsubscribe link, and you can also turn marketing email off in the app's notification settings at any time. Basis: your consent (Art 6(1)(a)).
- Marketing push notifications — only if you turn them on in the app's notification settings, and you can turn them off there at any time. Basis: your consent (Art 6(1)(a)).
- Organizations — if you belong to an organization (a team account), your membership and role, the invitations sent to you, and the organization's audit log and usage reports described below. Basis: performance of our contract (with you, and with the organization).
- Reports of illegal content — if you report content to us under the EU Digital Services Act: your name, email address, your explanation, and a keyed hash of your IP address. Basis: our legal obligation to handle such notices (Art 6(1)(c) GDPR, Art 16 DSA).
- Early-access list — if you sign up for early access on cask.studio: your email address, the profile or social link, role, and use case you give us, and a record of your consent (the version of the consent text, the time, and your IP address). Basis: your consent (Art 6(1)(a)).
You need to give us your account details, and payment details if you buy credits or a subscription, for
us to provide the service. Without them we cannot create your account or process your purchase.
Everything else in this list is optional.
Organizations (team accounts)
A business customer can set up an organization and invite people to it. When you work inside an
organization, the projects, files, prompts, and generations you create there belong to the
organization. For that content the organization is the controller and we process it on its behalf,
under our agreement with it; questions about it are best sent to the organization first. Your own
account data (sign-in, personal workspace, billing) stays with us as controller, as described in the
rest of this policy.
The organization's owners and admins can see who its members are (name, email address, role) and
its audit log: sign-ins of members (time, sign-in method, app, and IP address), member, role, and
invitation changes, settings changes, data exports, credit grants, and changes to the models the
organization allows. Owners, admins, and billing members can see usage reports: the number of
generations and credits used per member and per project. The audit log is kept for the period the
organization sets, 12 months unless it sets another.
If the organization turns on EU-only processing, its generations run only on AI providers that keep
processing inside the EU: Google Vertex AI through its EU endpoint and, when set up, OpenAI's European
data residency. Models from other providers are then not available in that organization.
When you leave an organization or it removes you, your access ends; what you created there stays with
the organization. When your account is erased, your membership and the invitations sent to you are
deleted, and in the organization's audit log your name, email address, and IP address are removed and
your account is replaced by a pseudonym.
An owner can export the organization's data (projects, files, generation history, credit ledger,
members, and audit log) and can ask us to delete the organization. We then wait 30 days, during which
the owner can cancel, and then erase the organization's projects, files, invitations, members, and
settings. We keep its credit ledger, without the names of the members who used the credits, for
7 years under Dutch tax law.
Analytics in the Cask apps
The Cask apps can use Google Analytics for Firebase, provided by Google Ireland Limited, to tell us
which features people use and where they get stuck. It is off until you opt in, either when the app
first starts or later in Preferences. You can turn it off again in Preferences at any time; the app then
stops sending analytics.
If you opt in, the app sends: which screens you open and which features you use (for example, signing
in, opening a project, starting a checkout), a random app-instance identifier, your Cask account ID and
plan, the app and macOS version, device model, language, and an approximate location (country and
region) that Google derives from your IP address. Advertising features and Google signals are turned
off, and the app does not collect the identifier for vendors (IDFV) or any advertising identifier. We do
not send your prompts, uploads, outputs, name, or email address. We do not use the data for advertising.
Google keeps event-level data for at most 14 months.
Purchase events. Checkout runs in your browser, so the app cannot see when a payment
completes. If you have opted in, the app gives our server its Firebase app-instance identifier when you
start a checkout; we store it with the Stripe checkout session, and when the payment succeeds our server
sends Google Analytics one purchase event: the checkout reference, the amount and currency, and the pack
or plan bought. If you have not opted in, the app sends no identifier and our server sends nothing.
Crash reports
The Cask apps send crash and error reports to Sentry only if you agree. The app asks you, and you can
change your answer in Preferences at any time. Reports go to Sentry's EU region
(ingest.de.sentry.io) and are stored in Germany. A report contains the error and stack trace, the steps
that led to it, the app and macOS version, device model, and, if you are signed in, your Cask account ID
and plan. The apps run Sentry with its default personal-data collection switched off, so they do not add
your name or email address to reports. Sentry keeps reports for up to 90 days.
Cookies and website analytics
The website cask.studio uses Google Analytics 4, provided by Google Ireland Limited, to understand
which pages and sections visitors read and which links they click. It runs only after you click
Allow on the cookie notice. If you decline, or make no choice, Google Analytics sets no cookie and
your visit is not tied to a browser. If you allow it, Google Analytics stores two cookies
(_ga and _ga_*, kept for up to 13 months) that recognise your browser on
return visits, and collects the pages and sections you view, time on them, links clicked, an
approximate location (country and city, derived from your IP address and not stored), device and
browser type, and where you came from. We do not use the data for advertising. Event-level data is
kept for 14 months. You can withdraw consent at any time with the "Cookie settings" link in the footer of
the website, or by clearing this site's cookies and site data in your browser, after which the notice
shows again.
Who processes your data for us
We use service providers who process personal data on our behalf and only on our instructions. Each is
bound by data-processing terms that meet Art 28 GDPR, either a signed agreement or terms built into the
provider's service contract. The Subprocessors page lists, for each provider, what it does, what data
it receives, where it processes it, the transfer basis, and the status of its data-processing terms. We
do not sell your personal data. The full, current list is on our
Subprocessors page.
- Hosting — our servers, database, and file storage run with Hetzner Online GmbH in its data centres in the EU; files are stored in Germany.
- Network — Cloudflare, Inc. provides DNS and sits in front of our websites and API as a CDN and TLS proxy, so it handles your IP address and the traffic between you and us.
- Payments and email — Stripe (Stripe Payments Europe, Ltd.) and Resend.
- Push notifications — Apple delivers the notifications you allow through the Apple Push Notification service.
- Crash reports and analytics — Sentry, and Google (Firebase and Google Analytics, only with your consent).
- AI generation — see the next section.
AI providers and model training
To generate media we send your prompts and uploaded files to the AI provider that runs the model you
choose. Your inputs may contain personal data, for example the faces or voices of identifiable people in
the media you upload. Cask does not use your prompts, uploads, or outputs to train AI
models. What each provider may do differs:
- OpenAI (OpenAI Ireland Ltd for users in the EEA) — a data-processing agreement is signed. OpenAI does not use data sent through its API to train its models.
- Google Vertex AI — covered by the Google Cloud Data Processing Addendum. Google does not use this data to train its models.
- fal (fal - Features & Labels, Inc., United States) — covered by fal's data-processing addendum, with Standard Contractual Clauses. fal holds a SOC 2 Type II report. fal's terms for our account do not include a contractual promise not to train on customer data: its data-processing addendum allows fal to use de-identified data to improve its services. To limit what fal keeps, we send every request with fal's payload storage switched off (
X-Fal-Store-IO: 0), so fal does not keep a copy of the request or response. The files fal generates for us are private, not public links, and are set to be deleted from fal's storage one hour after they are created; we copy them to our own storage before then. We do not upload your input files to fal: fal reads them from our storage through links that expire after a few minutes.
- BytePlus (Byteplus Pte. Ltd., Singapore) — covered by BytePlus's data-processing addendum, with Standard Contractual Clauses. We have not yet received written confirmation that BytePlus does not train on customer data.
- Runway (RunwayML, Inc.) — not currently used. Its models are switched off, and we will not send it data unless a data-processing agreement is in place.
International transfers
Your account data and files are stored with Hetzner inside the European Economic Area (files in Germany).
Some providers process data outside the EEA: the AI providers above (United States and Singapore), and
Cloudflare, Stripe, Resend, Sentry, and Google for part of their processing. For each such transfer we
rely on the European Commission's Standard Contractual Clauses or, for US providers certified under it,
the EU–US Data Privacy Framework. The Subprocessors page shows the basis for each provider. You can
request a copy of these safeguards at [email protected].
How long we keep it
- Account data: kept while your account is open. When you close your account from the app, your access ends straight away and your sessions are revoked. Within 90 days of closure we erase or anonymise the personal data we hold about you, including your prompts, job records, and files, except accounting records we must keep for 7 years under Dutch tax law. Content you created inside an organization stays with that organization (see Organizations). You can ask for erasure sooner by emailing [email protected].
- Prompts and job records: kept while your account is open, so that your generation history stays available to you, and erased with your account as described above.
- Uploaded files and outputs: an upload that is started but never completed is deleted automatically after about 24 hours. Other files are kept until you delete them; a file you delete is normally removed from our storage immediately. When you close your account, your files are erased within 90 days as described above.
- Cloud projects: we keep the latest 20 versions of a synced project and one version per day for the last 30 days, and delete older versions automatically. A project you delete is removed permanently 14 days later.
- Financial and accounting records: 7 years, as required by Dutch tax law. We keep these even after you close your account, with only the personal data the law requires.
- Crash reports: up to 90 days at Sentry. App analytics: at most 14 months at Google.
- Marketing consent: we keep the record of your choice while your account is open. When you unsubscribe or turn marketing off, we stop sending straight away.
- Early-access list: kept until you unsubscribe with the link in our early-access emails, or ask us to delete it. Unsubscribing deletes your entry.
- Security and audit logs: kept for at most 12 months.
- Organization audit logs: kept for the period the organization sets, 12 months unless it sets another.
- Organizations: when an owner asks us to delete an organization, we erase its content 30 days later, as described under Organizations.
- Payment and email provider notifications: the messages Stripe and our email provider send our servers about payments and email delivery can include your name, email address, and billing address. We keep the full message for 90 days; after that we keep only its identifier, type, and time, so that we never process the same notification twice.
- Reports of illegal content: the reporter's name, email address, IP hash, and explanation are kept until 12 months after we decided on the report (longer while an appeal is open). After that we keep only the category, our decision, and the dates, to count reports for our transparency obligations.
Your rights
You have the right to access, correct, delete, export (data portability), object to, and restrict
the processing of your personal data, and to withdraw consent at any time without affecting processing
that took place before. You can close your account and turn app analytics and crash reporting off from
within the app. To ask for a copy of your data, or for its erasure, email
[email protected] and we will respond within one month.
A copy of your data comes as a ZIP file with your account details, projects, prompts and generation
history, files, billing history, and consents, in a machine-readable format (JSON). We send it to the
email address on your account as a download link that works for 7 days, and delete the file after that.
Content you created inside an organization is not in this copy: the organization's owner can export it.
Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly
significant effects (Art 22 GDPR). Automated safety filters, ours or an AI provider's, may refuse a
generation. Decisions to suspend or close an account are made by a person.
Security
Passwords are hashed with argon2id, traffic is encrypted in transit, files are served only through
short-lived signed URLs, and secrets such as MFA keys are encrypted at rest.
Children
Cask Studio is for adults. You must be 18 or older to use the service.
Changes to this policy
If we make a material change we will notify you by email. The effective date and version above
always reflect the current policy.