Trust

Security

Last updated September 13, 2026

StudioSide holds your bookings, your clients’ contact details, and your money. This page says exactly how that data is protected, who else can see it, and what we have not built yet. We would rather tell you the second part than have you find it.

Every studio is separated in the database itself

The usual way to keep one customer’s data away from another’s is to be careful in the application code. We do that too, but it is not what we rely on. Every table in our database carries row-level security — a rule enforced by the database, underneath the app, that filters every single query to the studio you belong to.

The practical difference: a mistake in our code cannot show you another studio’s sessions, because the code is not what is holding the line.

Encryption

  • Everything travels over HTTPS. There is no unencrypted path into StudioSide.
  • Data is encrypted at rest on disk, including backups.
  • Passwords are stored hashed and salted. Nobody at StudioSide can read yours, including us.
  • Google Calendar refresh tokens are encrypted with their own key before they are written down, so a database copy alone does not open your calendar.

A password on its own is not enough, if you say so

Every account can turn on two-factor sign-in: as well as your password, you enter a six-digit code from an app on your phone. It is set up under Settings → Account, and you get recovery codes in case you lose the phone.

A studio owner can require it of everyone in the studio, so it is not left to each person to remember. If you sign in with Google, you already get whatever two-step verification your Google account uses.

Card details never touch our servers

Card numbers go from your client’s browser to Stripe directly. We never receive them, never store them, and never log them. What we see is the same thing you see: an amount, a status, and the last four digits.

There is a record of who changed what

Sessions, gear, roles, and payments write to an audit log as they change — who did it, what it was before, and when. Each studio controls how long that history is kept (one to twenty-four months), and a nightly job removes anything past that.

What we send to other companies, and what they get

11 companies help us run StudioSide. Each receives only what it needs to do its job. This is the whole list — the same one our privacy policy and data processing agreement show, because all three pages read from one file.

SupabaseDatabase, sign-in, and file storage

All studio data — sessions, clients, invoices, payments, team, and gear.

VercelApplication hosting, scheduled jobs, and page-view counts

Everything the app sends or receives while you use it, plus standard server logs. Its page-view counter also runs inside the app and records the address of each page you open, which for some screens contains the id of a client or an invoice.

StripeSubscription billing and client card payments

Billing contact details and invoice amounts. Card numbers go straight to Stripe and never reach our servers.

ResendTransactional email

The recipient’s name and email address, and whatever the message contains — an invoice, an invite, a session reminder.

Google CalendarOne-way calendar syncOnly if you connect a Google account

Session times, titles, and rooms. We only ever write into a calendar we created, and we never read anything back out of yours.

Google GeminiDrafting help-centre answers from support ticketsOnly if you write to support and we turn your ticket into a published answer

The subject, message and outcome of a support message you sent us, when a StudioSide staffer turns that ticket into a general help-centre answer. A staffer reads and edits the draft before anything is published, and Google does not train its models on this.

SentryError monitoring

Crash reports, tagged with the signed-in operator’s id and email. Client email addresses and phone numbers are stripped out before the report is sent.

PostHogProduct analytics and session replay

Your user id, email, studio name, and role, plus which screens you visit. Replays mask all text and form inputs.

MapboxAddress and city lookup

The address or city you type while setting up your studio, and your IP address. It is called from your browser, so it sees the request directly.

OpenStreetMapAddress lookup, as a fallback when Mapbox has no answer

The address you type, and your IP address.

Google AnalyticsMarketing-site visitor counts

Nothing from inside the app. It loads only on public pages, because app URLs carry client and invoice ids.

We do not sell your data, we do not share it with advertisers, and we do not use your studio data to train AI models.

What our own monitoring can see

Two tools watch the app so we can fix things: one collects crash reports, the other counts which screens get used. Both are pointed deliberately away from your clients.

  • Crash reports strip out email addresses and phone numbers before they leave your browser.
  • Session replays mask every piece of text and every form field, so a replay shows the shape of a screen and not its contents.
  • Marketing analytics never loads inside the app at all, because app addresses contain client and invoice ids.

Your data stays yours

You can export everything — sessions, clients, invoices, payments, gear, team — as spreadsheets, in one click, any time, without asking us. If you leave, we keep the export available and then delete your data within 30 days.

Where it lives

StudioSide runs in the United States and your data is processed there.

What we don't have yet

StudioSide is a small, young company, and there are things larger vendors have that we do not. Saying so is the point of this page.

  • We are not SOC 2 certified. We have written the plan to get there and we will say so here on the day it is real, not before.
  • We have not commissioned an independent penetration test.
  • We do not offer a contractual uptime guarantee.

If your organisation needs any of these before it can buy, tell us — that is the signal that moves it up the list. Email hello@studioside.app.

Found a vulnerability?

Please tell us at hello@studioside.app. We will acknowledge within three working days and keep you posted until it is closed. We will not take legal action against anyone who reports a problem in good faith, gives us a reasonable chance to fix it, and does not access, change, or delete other people’s data while looking.

Machine-readable version: /.well-known/security.txt.

Questions

Anything not answered here, email hello@studioside.app. See also our privacy policy, terms, and data processing agreement.

← Back to home