Legal

Privacy Policy

Effective date: August 14, 2026 · Version 2026-08-14

Your manuscript is not training material

Eria Studios does not use your manuscript to train foundation models or permit an AI provider to train on it. AI features use only the material needed for a request and must use an approved zero-retention/no-training route. If that protection is unavailable, the feature must remain disabled.

1. Who we are and when this policy applies

Eria Studios, Inc. (“Eria,” “we,” “us,” or “our”) operates Enspeller. This policy applies to enspeller.com, studio.enspeller.com, and related Enspeller services. For personal accounts and our websites, Eria generally determines why and how personal information is processed and acts as controller. When an organization customer controls an account or project, the organization may be the controller and Eria processes its Customer Personal Data under our Data Processing Addendum. Ask your organization about its own privacy practices.

The Eria Studios corporate website has a separate policy at eriastudios.com/privacy.html.

2. Information we collect

3. Sources

We collect information directly from you; from collaborators and organization administrators; automatically when your device interacts with the service; from Stripe for billing status; from WorkOS and connected identity providers for authentication; and from service providers that return delivery, security, or requested feature results. We do not buy data brokers’ profiles about Enspeller users.

4. Why we process information and our legal bases

Purpose Information Legal basis where required
Provide accounts, offline/cloud sync, storage, collaboration, export, requested AI analysis, and support. Account, project, AI/voice, device, and communication data. Perform our contract with you; take steps at your request; or follow the controller’s instructions.
Secure Enspeller, authenticate users, prevent fraud and abuse, debug faults, and maintain reliability. Account, device, log, security, transaction, and limited project metadata. Contract and our legitimate interests in protecting users, manuscripts, and the service; legal obligations where applicable.
Process subscriptions, invoices, cancellations, refunds, tax, and accounting. Account, billing, transaction, and communication data. Contract and legal obligations; legitimate interests in preventing fraud and keeping business records.
Send authentication, security, billing, collaboration, support, and material service notices. Name, email, account, project-event metadata, and message delivery status. Contract, legal obligations, and legitimate interests in communicating about the service.
Understand performance and improve product operation without training models on manuscripts. Feature events, reliability metrics, feedback, and de-identified or aggregated information. Manuscript text is excluded from ordinary analytics. Legitimate interests, balanced against user privacy; consent for optional cookies or analytics where required.
Establish, exercise, or defend legal claims and comply with binding requests. Information reasonably necessary for the matter. Legal obligations and legitimate interests in protecting legal rights.

Where we rely on legitimate interests, we consider necessity, proportionality, and your rights. Where consent is the basis, you may withdraw it at any time for future processing.

5. Manuscripts, AI, and automated processing

Your content remains yours. Enspeller is analytical: it critiques, cross-references, and asks questions. It does not silently replace manuscript prose. Any proposed change must remain attributable and subject to user acceptance or rejection.

AI work runs after sync or on an explicit request, not on the keystroke path. We send only the portion reasonably needed for the feature to an approved provider. Production AI accounts must prohibit training on requests and meet the zero-retention controls stated in our Subprocessor Register. We store Enspeller’s resulting analysis and provenance when needed to show the feature, but providers may not retain a copy for their own model training.

Enspeller does not use solely automated processing to make legal or similarly significant decisions about you. Analytical findings may be wrong; authors and organization users decide whether and how to act on them.

6. When we disclose information

We do not sell personal information and do not share it for cross-context behavioral advertising. We do not provide manuscript content to data brokers or advertisers.

7. International processing

Enspeller’s primary production hosting region is the United States. Other providers may process data in the United States or the other locations stated in the Subprocessor Register. For transfers that require safeguards, we use applicable adequacy decisions, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism. We assess transfer risks and apply supplementary technical and contractual measures where needed. Organization customers receive the contractual terms in our DPA.

8. Retention and deletion

We keep information only as long as reasonably necessary for its purpose. The criteria include whether your account, project, or subscription remains active; whether data is needed to provide a requested feature; security and dispute needs; user/organization deletion choices; and tax, accounting, contract, or other legal duties.

Deletion removes live copies and then residual encrypted backups through scheduled rotation. Offline copies on a device remain under the device/account holder’s control until cleared or the application completes its local closure workflow.

9. Security

We use administrative, technical, and organizational safeguards designed for manuscript data, including TLS in transit, encryption at rest, project-scoped application-layer encryption, managed key operations, role and tenant isolation, scoped collaboration tokens, least privilege, content-minimized logs, encrypted backups, and incident response procedures. No system is completely secure. Report a suspected security issue to compliance@eriastudios.com.

10. Your rights and choices

Depending on your location and the circumstances, you may have rights to be informed; access and receive a copy; correct; delete; restrict or object; port data; withdraw consent; opt out of certain targeted advertising, sale, or profiling; appeal a refusal; and complain to a regulator. These rights may have legal exceptions. You may also change profile data, export supported project data, manage collaborators, cancel billing, and close a personal account through Enspeller where available.

To submit a request, use account privacy controls or email compliance@eriastudios.com from the address associated with your account and state the right you wish to exercise. We will verify your identity proportionately and respond within the period required by law. Do not email passwords, government IDs, or manuscript content unless we provide a secure method. Authorized agents may act where law allows, subject to proof of authority and direct verification when permitted.

If an organization controls your account, submit the request to that organization first; we will assist it as processor. We will not discriminate against you for exercising a privacy right.

11. Regional information

12. Children

Enspeller is intended only for adults who are at least 18 years old. We do not knowingly permit anyone under 18 to create or use an account. If you believe a person under 18 provided personal information to Enspeller, contact us so we can investigate, disable the account, and delete the information as required by law.

13. Cookies and local storage

Read our Cookie Notice. The marketing site does not use optional analytics or advertising cookies as of this version. The studio uses necessary storage for accounts, security, settings, and offline editing. Optional analytics may run only after an affirmative choice where consent is required.

14. Changes

We may update this policy as Enspeller, our providers, or law changes. We will post the new version and effective date and provide prominent in-product or email notice before a material change takes effect. We will obtain consent where law requires it. An earlier version continues to govern processing that cannot lawfully be changed without consent.

15. Contact

Eria Studios, Inc.

1111B S Governors Ave STE 34533
Dover, DE 19904
United States
Privacy, data protection, security, and legal inquiries: compliance@eriastudios.com
Product and billing support: support@eriastudios.com