Privacy policy
How we handle your data
moki.studio is a small design studio that creates seamless designs and sells licences to use them. This page explains what personal data we collect when you register and buy, why we collect it, how long we keep it, and what your rights are under the General Data Protection Regulation (GDPR).
01Who is responsible
The controller for the personal data described on this page is MOKI Studio, established in the Netherlands, in the European Union. You can reach us at info@moki.studio. We have not appointed a data protection officer, because we are a small studio; the contact above handles every privacy request.
02What we collect
We only collect what the service needs. Nothing on this page is bought from third parties or gathered from other websites.
When you register or are invited
- Email address and name. With Google or Apple sign-in these come from your provider; with a studio invitation we enter the email you gave us and you choose your own password.
- Profile picture, if your Google account has one and you sign in with Google.
- Sign-in provider and the provider's user id (Google, Apple, or a password account), so we can recognise you next time.
- Password, only for password accounts, and only as a salted hash. We cannot read it. A password-set link is valid for 48 hours.
- Role and access rights: which studio apps you may open and who granted that access.
When you use the studio
- Session: a random session id in a cookie, with its creation and expiry time.
- Security log: sign-ins, sign-outs, access grants and similar events, with your user id, the time and the IP address the request came from. We keep this to detect abuse and to prove who did what.
- Usage counters: which app and endpoint you called, and when. No page content, no keystrokes, no mouse tracking.
- Files you upload as references to create prints, the prints that come out of them, your tags, favourites, notes and repeat sizes. These are the work you do in the studio and stay linked to your account.
- Notifications we send you inside the studio, and whether you read them.
When you buy
- Order: order number, date, the prints and licences you bought, the prices, the total and the payment status.
- Billing details you give us for the invoice: company name, address and VAT number where applicable.
- Payment confirmation from the payment provider: the amount, the date and a transaction reference. Never your card number or bank credentials (see Purchases and payments).
When you write to us
Your email address and what you wrote, for as long as we need it to answer you and handle any follow-up.
03Why, and on what legal basis
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Creating and running your account | Email, name, picture, provider id, password hash, role | Contract (art. 6(1)(b)) |
| Keeping you signed in | Session cookie and session record | Contract (art. 6(1)(b)) |
| Making, storing and delivering your prints | Uploads, prints, tags, notes, sizes | Contract (art. 6(1)(b)) |
| Selling licences and invoicing | Order, billing details, payment confirmation | Contract (art. 6(1)(b)) and legal obligation to keep accounts (art. 6(1)(c)) |
| Security, abuse detection, proving access | Security log with IP address, usage counters | Legitimate interest in a secure service (art. 6(1)(f)) |
| Answering your messages | Email and message content | Legitimate interest and, where relevant, contract |
| Studio notifications about your work and orders | Email, notification content | Contract (art. 6(1)(b)) |
We do not send marketing email and we do not profile you. If that ever changes, we will ask for your consent first and you can withdraw it at any time.
04Signing in with Google or Apple
You can sign in with a Google account or an Apple ID instead of a password. When you do, your provider sends us your email address, your name and (Google only) your profile picture, together with an id that identifies your account with them. We store those to create and recognise your studio account. We never see your Google or Apple password, and we do not get access to your contacts, files, photos or anything else in those accounts.
Your provider also learns that you signed in to moki.studio and processes that under its own privacy policy: Google, Apple. Apple lets you hide your real email address; in that case we receive a relay address and Apple forwards our messages to you.
Password accounts are created by the studio on invitation. You receive a link to set your own password, which is stored only as a salted hash.
05Purchases and payments
When you buy a print licence we record the order under your account so you can download the print, in every version, whenever you like. Payment is settled by invoice or through the payment provider shown at checkout. Card numbers, bank details and payment credentials are entered with the payment provider, never on our servers, and we never receive them. We receive only the confirmation that the payment succeeded, the amount, the date and a reference we can match to your order.
Invoices and order records are kept for as long as tax law requires (see retention), even if you delete your account.
07Pinterest and other services
We show our own prints on Pinterest. Pinning happens from our server to our own Pinterest boards, using our own Pinterest account. No data about you is sent to Pinterest by that process, and Pinterest is not loaded on our pages. If you click a link or a "Pin it" button that takes you to pinterest.com, you leave moki.studio and Pinterest's own privacy policy applies from that moment.
Our pages load the Inter and JetBrains Mono typefaces from Google Fonts. Your browser requests those files from Google's servers, which lets Google see your IP address; Google states that it does not use these requests for tracking. We are working on serving the fonts from our own server.
The prints themselves are generated with AI models that run on our own hardware. Your uploads and prompts are not sent to any external AI service.
08Where your data is stored
Everything lives inside the European Union.
- Accounts, sessions, orders, logs and the print library: on a server rented from Hetzner Online GmbH, located in Helsinki, Finland.
- Print generation: on the studio's own workstation, which connects to the server through an encrypted tunnel.
- Email we send you (invitations, order messages): through our mail provider STRATO in Germany.
Google and Apple sign-in, and Google Fonts, are provided by companies that may process data outside the EU. Those transfers are covered by the EU–US Data Privacy Framework and the European Commission's standard contractual clauses, as described in their privacy policies linked above.
09How long we keep it
| Data | Kept for |
|---|---|
| Account (email, name, picture, provider id, password hash) | While your account exists, then deleted within 30 days of your request or of the studio closing the account |
| Session records | 30 days, or until you sign out |
| Password-set links | 48 hours |
| Uploads, prints, tags, notes | While your account exists. Prints you have licensed stay downloadable for as long as your account exists |
| Orders, invoices, payment confirmations | 7 years after the end of the financial year, as required by tax law |
| Security log (with IP address) | 12 months |
| Usage counters | 12 months |
| Notifications | While your account exists |
| Email correspondence | Until your request is handled, at most 2 years |
Backups of the server are kept for 30 days and then overwritten. Data deleted from the live system disappears from backups on that schedule.
11Your rights
Under the GDPR you can ask us at any time to:
- Access the personal data we hold about you, and get a copy.
- Correct data that is wrong or incomplete.
- Delete your data. We will delete everything except what we must keep by law (orders and invoices).
- Restrict processing while a question about the data is resolved.
- Receive the data you gave us in a machine-readable format (portability).
- Object to processing based on our legitimate interest, such as the security log.
- Withdraw consent, where processing relies on consent, with effect for the future.
Most of this you can do yourself: open Account settings (the person icon next to Sign out in MOKI Studio) to change your invoice details and e-mail preferences, download everything we hold about you as a file, or delete your account. For anything else, send your request to info@moki.studio from the email address on your account. We answer within one month; for complex requests we may take up to two more months and will tell you why. There is no charge.
If you think we handle your data unlawfully you can complain to a data protection authority. You may do so in the EU country where you live or work, or with our lead authority, the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
12Security
All traffic to moki.studio is encrypted (HTTPS with HSTS). Session cookies are HTTP-only, secure and same-site. Passwords are stored as salted hashes. The server is reachable over SSH with keys only, and the workstation that generates prints is connected through an encrypted tunnel. Access to accounts and orders is limited to the studio's owner. If a breach ever affects your data, we will inform you and the authority within the deadlines the GDPR sets.
13Children
moki.studio is a business service for designers, brands and manufacturers. It is not meant for children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
14Changes to this policy
When we change how we handle your data we update this page and its version and date at the top. For significant changes we also tell you inside the studio or by email before they take effect.
15Contact
MOKI Studio
info@moki.studio
moki.studio