LegalPrivacy Policy
Privacy Policy
What Angelo collects, why, who helps us process it, how long we keep it and the choices you have. Plain words, and accurate to how our systems work today.
Who we are and what this covers#
Angelo is made by Hyperbond Studio Pte. Ltd. (“Angelo”, “we”, “us”), a company incorporated in Singapore. This policy explains how we handle personal data in:
- the Angelo app, the AI-native 3D studio built on Blender, which runs on your computer;
- angelo.studio, this website;
- Angelo Teams: the console at console.angelo.studio, the model gateway at gateway.angelo.studio and the MCP endpoint for external AI apps (together, the “Services”).
Our role. We decide how and why personal data is processed for your account, sign-in, billing, security and the website, so for that data we're the controller (the “organisation” under Singapore's Personal Data Protection Act 2012, the “PDPA”). When an organization uses Angelo Teams, it decides what its members put into the console and which AI providers it uses. For that content (the library, IPs, QC reviews and the requests relayed through the gateway) we act on the organization's behalf, as its processor or data intermediary, and the organization is responsible for it. If your organization needs a data processing agreement, write to legal@angelo.studio.
Not covered. AI providers you or your organization connect, the official Claude Code and Codex tools you install, AI apps you connect through MCP, and Stripe's checkout and billing pages each handle data under their own privacy policies.
The Angelo app#
The app runs on your computer. Your scenes, chats and files stay there unless you send them somewhere, and we don't operate a server in between when you use your own keys or subscriptions.
- No analytics or telemetry. Angelo sends no usage analytics, telemetry or crash reports to us or anyone else. It keeps a small performance record (timings and token counts, no conversation text) on your computer only, and Blender writes crash logs to a local file.
- No calls home. The app doesn't contact Angelo's servers unless you sign it in to an Angelo Teams organization.
- AI providers, directly. When you connect a provider, the app sends your requests straight to that provider: your messages, information about your scene, viewport images, attachments, files you let the agent read, and generation prompts and reference images. If you approve a hand-off between two connected providers, the relevant context goes to the second one. Results are downloaded from the provider's own servers. The providers handle this data under your agreement with them.
- Claude Code and Codex. Coding agents run through the official Claude Code and Codex tools, which you install and sign in to yourself. They're governed by Anthropic's and OpenAI's terms and may send their own usage data to those companies.
- Checking saved keys. When the app starts, it checks each saved key with a request that isn't billed, such as listing the provider's models, sent only to that key's provider.
- Your keys stay in your operating system's credential store: the Keychain on macOS, Credential Manager on Windows and the Secret Service keyring on Linux. They're never written to plain files, project files, logs or transcripts; if the store can't be used, a key stays in memory until you quit.
- Local history. Chats, scene snapshots, attachments, generated media and their prompts are saved in the app's data folder on your computer. Delete them there at any time.
- Voice (experimental, off by default). If you turn it on, your microphone audio streams to OpenAI through your Codex connection while it's active. Angelo doesn't save the audio.
- Blender's online features. Blender's extension and online asset libraries contact extensions.blender.org only if you allow online access in Blender's settings. That setting doesn't control the AI connections above, which you turn on by connecting a provider.
- Signing in to Angelo Teams. If you sign the app in to an organization, it opens your browser to sign in, keeps a renewable sign-in token in your operating system's credential store, and sends your computer's name so you can recognize the device in the console. Requests that use your organization's keys then go through the gateway (described below). Connections that use your own keys or subscriptions never do.
This website#
- No cookies, no analytics, no ads. angelo.studio sets no cookies and loads no analytics, advertising or tracking scripts. It keeps one note in your browser's session storage so the intro animation plays once per visit; it's gone when you close the tab.
- Fonts from Google. The site loads its typefaces from Google Fonts, so your browser sends your IP address and browser details to Google when it fetches them. Google's privacy policy applies.
- Hosting. The site is hosted by Fly.io in Singapore. Like any web host, it processes your IP address and request details to deliver pages and protect the service. Our own server software doesn't keep request logs.
- Email. If you write to us, we receive your email address and whatever you include, and use them to reply.
What Angelo Teams collects#
| Data | What it includes | Where it comes from |
|---|---|---|
| Account | Your email address and name, a sign-in provider identifier, and when you last used the console. | You, your organization's identity provider, or Google if you continue with Google. |
| Sign-in and security | Sign-in events; your IP address and browser user agent, which are passed to our sign-in provider when you sign in; session records (stored as hashes, never the session itself). To stop code guessing we keep hashed forms of your email address and network address for two days. | Your browser and device. |
| Organization | The organization's name, its members, their roles and seats, and invitations (the invited email address, who invited them, when). | Owners and admins, and you when you accept an invitation. |
| Devices and connected apps | The device or app name (for example your computer's name, or the name an AI app gives itself), what it may access, and when it was connected, last used and revoked. | The Angelo app and AI apps you connect. |
| Billing | Stripe customer, subscription and invoice references, seat counts, amounts, currency, billing periods and payment status. Stripe collects the billing contact, billing address, tax ID and payment details; we never receive card numbers. | Owners and admins, and Stripe. |
| Provider keys | Your organization's AI provider keys, encrypted, with a label, the last four characters and who added them. | Owners and admins. |
| Usage | For each member, day, provider and model: the number of requests and generations, token counts and the estimated cost. Never the content of requests. | The gateway and the QC check. |
| Library and IPs | Files and their thumbnails; titles, descriptions, tags and file details (name, type, size, dimensions, a content hash); for generations saved from the Angelo app, the prompt, model, provider, settings and app version; IP names, loglines, entities, versions and reference images. | Your organization's members. |
| QC reviews | Review states, verdicts, notes, checklists, who did what, and the results of AI checks (scores, findings and a summary), with hashes of the images checked. | Reviewers, and the AI provider your organization's key calls. |
| Audit log | Who changed what and when, naming the person by their name or email address. | Your organization's activity. |
| Technical logs | Request routes, status codes, timings and internal identifiers. Google's load balancer, in front of our services, also records your IP address and the requested address. | Your browser, the app and our services. |
We don't store profile pictures, contacts, precise location or any special categories of personal data, and we don't ask for them.
The gateway and AI requests#
When a member uses the organization's keys, the Angelo app sends the request to our gateway, which adds the organization's key and relays it to the provider. The answer streams straight back.
- Prompts and responses aren't stored. The gateway passes them through without saving them, and reads only what it needs to meter the request: the model name and the token counts the provider reports.
- What it records: the usage figures above, and a log line per request with the organization, provider, model, status, timings and token counts. The log line doesn't name the person and never contains prompts, outputs or keys.
- What providers see: the request itself and your app's user-agent string, sent from our servers with your organization's key. The gateway removes your credentials, cookies and IP address before forwarding. Reference images may go to a provider as short-lived links that it fetches from our storage.
- The QC check: when a reviewer runs an AI check, our servers send the image under review, its reference images and the written design notes to the provider your organization prefers (Google, Anthropic or OpenAI), using your organization's key. We keep the check's result with the review.
- Providers' own handling, including whether and how long they retain requests, is governed by your organization's agreement with each provider.
Prompts aren't kept by the gateway, but they are kept where your team saves them: a generation saved to the library keeps its prompt with it, as described above.
AI apps connected through MCP#
- You can connect an external AI app, such as Claude or Cursor, to read your organization's library and IPs as you. Access is read-only, and we ask for your consent every time an app connects.
- A connected app can see what you can see in the library and IPs, including generation prompts saved with library items, and gets short-lived links to files. It never receives email addresses: teammates appear by name only.
- We log each call's app, tool, outcome and duration, never its arguments or results. You can disconnect an app in the console at any time, and admins can disconnect it for the organization.
- Whatever the app reads goes to that app and its vendor, under their terms and privacy policy.
How we use it#
We use personal data to:
- provide the Services: sign you in, run your organization, store its library and IPs, and relay its AI requests;
- show owners and admins their organization's members, seats, usage, estimated costs and audit log;
- bill subscriptions and keep financial records;
- keep the Services secure and reliable: rate limits, abuse prevention, investigating incidents and fixing errors;
- send the emails the Services need: invitations, sign-in codes and billing messages;
- answer your questions and requests;
- meet our legal obligations and enforce our terms.
We don't sell personal data, use it for advertising or build profiles of you, and we don't use your content to train AI models. We don't make decisions about you based solely on automated processing.
Legal bases#
Where laws such as the GDPR and the UK GDPR apply, we rely on these bases:
| Purpose | Legal basis |
|---|---|
| Providing the Services you or your organization signed up for | Performance of a contract |
| Processing your organization's content and its members' data on its behalf | Your organization's instructions, under its own legal basis; we act as its processor |
| Billing, invoices and tax records | Performance of a contract and legal obligations |
| Security, abuse prevention, logs and the audit log | Legitimate interests in protecting the Services, our customers and their data |
| Delivering the website, including fonts | Legitimate interests in running the website |
| Answering messages and requests | Legitimate interests, or a contract where you're a customer |
| Complying with the law and legal requests | Legal obligations |
Under the PDPA, we collect, use and disclose personal data with your consent, which you give by signing up for or using the Services for the purposes in this policy, or where the PDPA otherwise permits it, for example for legitimate interests.
International transfers#
We're based in Singapore, and our main servers and database are there. Some providers process data elsewhere, including in the United States and Japan, and AI providers your organization chooses may process requests in other countries.
When we transfer personal data out of Singapore, we make sure the recipient protects it to a standard comparable to the PDPA, through contracts and the provider's own commitments. For data from the European Economic Area, the United Kingdom or Switzerland, we rely on adequacy decisions or on the European Commission's Standard Contractual Clauses (with the UK addendum) in our providers' data processing terms. Write to privacy@angelo.studio for more about these safeguards.
How long we keep it#
| Data | How long |
|---|---|
| Your account | Until you ask us to delete it, as described below. |
| Your organization's data: members, library, IPs, QC reviews, usage and the audit log | While the organization exists. Library items are deleted, files included, as soon as someone deletes them; IPs are archived rather than deleted. Everything else goes when the organization is deleted at an owner's request. |
| Sign-in sessions | A sign-in lasts up to 14 days; ended sessions are kept as records until the account is deleted. |
| Hashed sign-in and invitation-email counters | Two days. |
| Invitations | Links expire after 7 days; the record of the invitation stays with the organization. |
| AI app registrations | Deleted a day after registering if never connected, or 90 days after the app was last disconnected. |
| Technical logs, including the gateway's and Google's load balancer logs | 30 days. |
| Database backups | 7 days. |
| Billing and tax records | As long as tax and accounting laws require; in Singapore, generally five years. |
| Messages you send us | As long as we need them to help you, and then as the law requires. |
| Data in the Angelo app | On your computer, until you delete it. |
Deleting your account and data#
- Library items can be deleted in the console at any time, by anyone the library's permissions allow. Deleting removes the file and its details from our storage straight away.
- Your account: email privacy@angelo.studio from the address you sign in with. We'll confirm the request and delete your account and its personal data within one month. Your organization keeps its own records of your work, such as the audit log, usage figures and items you added to its shared library; we remove or anonymize your name and email address in them unless the organization needs them for a legal reason.
- An organization: an owner can ask us at the same address to delete the organization and all its data. Download anything you want to keep first: deletion can't be undone.
- Leaving an organization: an admin can remove you, which ends your access and your connected devices for that organization. Your account remains until you ask us to delete it.
- Deleted data can remain in backups for up to 7 days and in logs for up to 30 days before it expires.
- The Angelo app: delete its data folder, and remove saved keys in the app or in your operating system's credential store.
How we protect it#
- Everything travels over encrypted connections (HTTPS).
- Provider keys are encrypted with AES-256-GCM under a data key for each organization, which is itself protected by Google Cloud KMS. They're decrypted only in memory, by the gateway and the QC check, to make a request, and they're never shown again or sent to members' devices. Revoking a key erases it.
- Sessions, sign-in tokens, invitation links and app access keys are stored only as one-way hashes. Card details go straight to Stripe.
- Files are stored privately and reached only through links that expire within an hour.
- Access is checked on the server for every request, by role and organization. Changes to an organization's members, keys, billing, library, IPs and reviews are written to an audit log that can't be edited, and logs are scrubbed of credentials.
No system is perfectly secure. If a data breach affects your personal data, we'll notify you and the authorities as the law requires. To report a vulnerability, write to security@angelo.studio.
Your rights#
Wherever you live, you can ask us what personal data we hold about you, and ask us to correct or delete it. Write to privacy@angelo.studio. We may need to confirm your identity first. We don't charge for requests unless they're clearly excessive, and we answer within one month, or tell you why we need longer where the law allows. If we hold the data for your organization, we'll pass your request to it, or help it respond.
Singapore (PDPA)
- You can ask for access to your personal data and how it has been used or disclosed in the past year, and ask us to correct it. We respond as soon as reasonably possible, and within 30 days or tell you when we will.
- You can withdraw your consent to our collecting, using or disclosing your personal data. We'll tell you the likely consequences, for example that we can no longer provide the Services, and stop as the PDPA requires.
- When we transfer personal data outside Singapore, we make sure it receives protection comparable to the PDPA (see International transfers).
- Our Data Protection Officer can be reached at privacy@angelo.studio. If you're not satisfied with our answer, you can contact the Personal Data Protection Commission.
European Economic Area and United Kingdom (GDPR and UK GDPR)
- You have the right to access, correct and erase your personal data, to restrict or object to our processing (including processing based on legitimate interests), to data portability, and to withdraw consent at any time without affecting earlier processing.
- You can complain to your local data protection authority or, in the UK, the Information Commissioner's Office.
California (CCPA, as amended by the CPRA)
- In the past 12 months we collected these categories of personal information: identifiers (name, email address, IP address), commercial information (subscriptions and billing records), internet or network activity (sign-in events, usage figures and logs), professional information (your organization and role), and the content your organization stores. They come from the sources, and serve the purposes, described above.
- We disclose them for business purposes only to the service providers listed above. We don't sell or share personal information for cross-context behavioural advertising, and haven't in the past 12 months. We don't use sensitive personal information to infer characteristics about you.
- You can ask to know, correct or delete your personal information, including through an authorized agent, and we won't treat you differently for using these rights.
Japan (APPI)
- You can ask us to disclose, correct, add to or delete your retained personal data, to stop using it or providing it to third parties, and to disclose records of third-party provision.
- Your data is processed in Singapore and in the other countries listed in Who we share it with, by providers bound to protect it. Ask us for details of the countries and of the measures we take.
Google user data#
If you choose Continue with Google, Google shares your name, email address and profile picture with our sign-in provider, WorkOS, and confirms that your email address is verified. We ask Google only for basic sign-in access (the openid, email and profile scopes). We keep only your name and email address, and we don't receive or keep Google access tokens.
- We use this data only to sign you in, identify your account and show your name and email address to your organization.
- We don't use it for advertising, don't sell it, and don't transfer it to anyone except as needed to provide the Services (such as to WorkOS for sign-in), to comply with the law, or as part of a merger or acquisition.
- We don't use it to train AI models, and no person at Angelo reads it unless you ask us to, for security reasons or as the law requires.
Angelo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can remove Angelo's access at any time in your Google Account settings.
Children#
Angelo isn't directed at children under 16, and we don't knowingly collect personal data from them. If you believe a child has given us personal data, write to privacy@angelo.studio and we'll delete it.
Changes to this policy#
We'll update this policy when our services or the law change, and post the new version here with its effective date. If a change is significant, we'll also tell account holders by email or in the console before it takes effect.
Contact#
Hyperbond Studio Pte. Ltd., Singapore.
- Privacy requests and our Data Protection Officer: privacy@angelo.studio
- Accounts, billing and help: support@angelo.studio
- Security vulnerabilities: security@angelo.studio
- Our Terms of Service: legal@angelo.studio