Privacy
What Enablement Studio collects, what it does not sell, and how to ask us to delete it.
What we collect
- Email — only if you create an account. We use it to send one-time sign-in links (the first one also confirms a new account), a welcome note once the account is ready, and, if you ask, a password reset link.
- Password — only if you set one; signing in by email link or Google needs none. We store a slow hash of it, never the password itself.
- Google sign-in — only if you choose Continue with Google. Google tells us your email address, that Google has verified it, and the Google account number behind it. We use them only to sign you in, to link that Google account to your Studio account, and to send one welcome note. We never see your Google password, contacts, or files, and we do not share or sell what Google sends.
- Kits saved to your account — when you are signed in with a confirmed address: each kit’s source text (your paste, or the text of the files and links you added), the drafts, your edits, and the conversations with the studio’s agents; your Settings (name and workspace notes); for each model call, its tokens and what it cost, which is how your plan’s allowance is measured; and a short activity list (kit made, renamed, moved to the trash). They are stored in Cloudflare’s database, which runs the studio, and kept until you delete them. Kits in the trash are deleted for good after 30 days.
- Payments — only if you choose Plus or Pro. Stripe takes the payment on its own pages; we never see or store your card number. We keep the Stripe customer and subscription ids, your plan, its status, and its billing period, so the studio can apply your plan. Stripe’s privacy policy covers what it keeps.
- Visitor kit cookie
es_sid— an HttpOnly cookie so this browser can keep its own kits for about an hour when you are not signed in. The client never mints it. - Optional account cookie
es_aid— set after you open a sign-in link, sign in with a password, or sign in with Google, so this browser stays signed in for 30 days. With each sign-in we keep which browser and system it was (for example, Chrome on macOS) and the country Cloudflare saw, never the IP address, so Settings → Account can show where you are signed in and sign any of them out. We keep only a hash of it. - Practice answers — only when someone shares a kit’s quiz as a practice link. For each learner we keep which option they chose on their first try, tied to a random cookie
es_lrn: no name, no email, no account. A practice link and its answers are deleted 90 days after it was shared. - Online lesson answers — only when someone shares an online lesson as a link. For each learner we keep their first answer to each activity and whether they reached the end, tied to the same random cookie
es_lrn: no name, no email, no account. A lesson link and its answers are deleted 180 days after it was shared. What a learner writes in the lesson, and their progress, stay in their own browser.
What we do not do
We do not sell your email, pastes, or kits. We do not run ads against them. We do not put a learner portal or a learning-platform login on this host, and nothing here tracks a named learner. A practice link or a lesson link is one anonymous page: no sign-in, and it never records who answered.
Cookies
Only essential, first-party cookies, unless you accept more: es_sid keeps this browser’s kits for an hour, es_aid keeps you signed in for 30 days, es_lrn marks a learner on a practice or lesson link, and es_gst lives ten minutes while you sign in with Google. They are HttpOnly, SameSite=Lax, and Secure on the public host. Your appearance and cookie choices stay in this browser’s localStorage.
The newsletter form on the home page is run by MailerLite. Only if you choose Accept all in the cookie notice does MailerLite’s script load; it then keeps its own identifier (ml_guid) and a cookie that remembers it showed you the form. With Essential only it never loads. Change your choice any time with Cookie settings at the bottom of the home page.
Page analytics
We use PostHog for anonymous, cookieless page analytics. PostHog runs in the US cloud. There is no cookie and no local storage for analytics. We do not record sessions. Page text and form values are masked and never sent. We honor Do Not Track. We do not identify you, and we do not build a profile. Practice and lesson links and their results pages load no analytics at all.
When a generate runs
After you confirm the address, your own paste can run through generate(). If you run a paste that is not labeled EXAMPLE DATA, the draft is sent to OpenAI so generate() can write the kit. EXAMPLE DATA, Keep / Drop, kit chrome, and exports of what is already in the session never spend that path. Doors work without an account. When you ask one of the studio’s agents about a kit, the kit and your workspace notes are sent to OpenAI with the question, and when you ask the model to write an online lesson, the kit is sent with that request. Signed in, a draft runs in the background so closing the tab does not lose it: the request waits in Cloudflare’s database until the draft finishes, then it is deleted.
Files and links
Files you add are read on our server. We keep the text they contain with the kit, not the files themselves. A link is fetched from our server; for job boards and Google files we read the posting or the export behind the page. A scanned PDF or a picture of text has no text to read, so after you confirm the address it is sent to OpenAI to be transcribed, and the kit marks that source as read from the page images.
Your data
Signed in, open Settings: Export my data downloads every kit, your settings, and your activity as one file, and Delete account deletes your account, every kit in your library, your settings, your activity, and the practice and lesson links you shared, right away. A plan that still renews is cancelled in Manage billing first, so Stripe does not charge an account that is gone.
Deletion
You can also write Contact or login@enablementstudio.app and ask us to delete the account on that email. Visitor kits die with the es_sid cookie. Practice links and their answers are deleted 90 days after they were shared, lesson links after 180 days; write to us to delete one sooner.