Google sign-in, project submission, workspace records, project messages, optional phone-appointment scheduling, revisions, Google Drive references, agreement records, and Stripe-hosted payment are active parts of the Studio service. The Studio does not use SMS marketing, advertising pixels, or non-essential analytics.
Controller and scope
Breauti LLC, a U.S.-based limited liability company registered in Mississippi, determines how and why personal information is handled through the Breauti Studio public website and client workspace. This policy applies to Studio marketing and policy pages, the project-request experience, shared Breauti accounts, project records, messages, Google Drive references, agreements, and billing records.
For those Studio services, Breauti acts as the controller or business responsible for the disclosed processing. When Breauti later operates a client-built site or app strictly on that client's documented instructions, the client may instead be the controller or business and Breauti a processor or service provider. The signed project terms and any data-processing terms required for that work will define the parties' roles, instructions, confidentiality and security commitments, subprocessors, assistance with individual rights, and return or deletion of client data. This public policy does not replace a client's own notice or legal duties for its service.
Breauti offers Google sign-in for a shared Breauti account. You may type a draft before signing in, but sign-in is required to submit it, preserve it in the workspace, or connect a Google Drive project folder. The site does not operate a marketing-email list, SMS program, or non-essential analytics program. It is not directed to children, and Breauti does not knowingly ask children to submit personal information here.
privacy@breauti.com is Breauti's monitored privacy contact. Do not send passwords, full payment-card numbers, government identifiers, medical records, or other sensitive material by ordinary email. If Breauti needs information to verify a request, we will explain the minimum required and provide an appropriate way to share it.
Data, purposes, and legal bases
The following describes the present site and the limited categories used to review requests and operate the client relationship. The stated GDPR bases apply only where the GDPR applies.
| Category | Purpose | GDPR basis when applicable | Current status |
|---|---|---|---|
| Site delivery and security data | IP address, browser or device information, requested URL, timestamps, referrer, and diagnostic or security events may be processed by a hosting or security provider to deliver and protect the site. | Legitimate interests in reliable and secure site operation; legal obligation when applicable. | Processed for public hosting and security; not used for advertising. |
| Theme preference | Your Auto, Light, or Dark selection is stored in your browser so the appearance remains consistent. | Functional necessity and legitimate interests. | Stored locally on your device. |
| Unfinished request draft | Your current project description is kept for the active browser session so it can survive sign-in and normal navigation. If you choose “Remember unfinished drafts,” a copy remains on this device after the browser closes. | Steps requested by you before a contract; consent for optional cross-session draft storage where applicable. | Local to this browser and not sent to Breauti until you submit the request. |
| Breauti account profile | When you use Google sign-in, Breauti receives your Google-provided user identifier, name, email address, and profile image. Firebase Authentication manages the sign-in session, and Cloud Firestore stores a minimal profile, provider name, timestamps, and the Breauti product where the account was used. | Steps requested by you before a contract and legitimate interests in secure account access and a consistent cross-product identity. | Active and required when you continue from the initial request draft. |
| Request and project records | Name, organization, verified account email, optional phone number and call consent, project description, communication channels, messages, appointment purpose, availability note, offered and selected phone times, timezone, scheduling status, revisions, decisions, approvals, status history, and support records are used to respond, clarify scope, avoid double-booking, perform an accepted engagement, and keep necessary business records. | Steps requested before a contract, contract performance, legitimate interests, consent where required, and legal obligations. | Saved to the signed-in client workspace when submitted. Phone appointments are optional and use the callback number only for project communication. A client may choose to open a prefilled Google Calendar page or download a standards-based calendar file; Breauti does not request calendar-account access, and the callback number is not placed in that calendar handoff. |
| Google Drive project folder | When you choose or create a project folder through the Studio flow, Breauti stores its Drive identifier, name, folder type, view link, limited metadata, permission reference, and access status. The folder-level permission covers current and future files and subfolders until you revoke it. The file bytes remain in your Google Drive rather than being uploaded to Breauti storage. | Steps requested before a contract, contract performance, and legitimate interests in secure project collaboration. | Selected-folder access only. Breauti cannot browse the rest of your Drive. The automated access monitor receives Viewer access; assigned project staff receive Editor access so they can add, update, organize, or remove project files, including correcting accidental uploads. An existing populated folder may require a one-time direct share in Drive before the Studio can verify access. You can revoke folder access in Google Drive; the workspace may alert you when required access is lost. |
| Reference links | When you or authorized Studio staff add an online reference to a project, Breauti stores the URL, the required explanation of how it should be used, who added it, and edit timestamps. | Steps requested before a contract, contract performance, and legitimate interests in clear project collaboration. | Up to 10 links per project. Links remain separate from the Google Drive project folder and may lead to third-party services with their own privacy practices. |
| Agreement and signature records | Agreement content, record version, canonical HTML and its integrity hash, completed signed PDF and its integrity hash, typed signer name, Google-authenticated user and email, recent-authentication time, version and integrity hash of the electronic-record disclosure, consent and intent record, server time, masked network address, and a digest of browser information support electronic execution, reproducible copies, integrity, and auditability. Sensitive network and device evidence remains in a private audit record rather than the client-facing PDF. | Contract performance, legal obligations, and legitimate interests in authentication, fraud prevention, record integrity, and legal claims. | Created only when an agreement is prepared and signed. |
| Workspace and billing records | Project activity, access events, subscription or installment status, invoices, payment status, cancellations, refunds, disputes, and tax or accounting records support the client workspace and billing. | Contract performance, legal obligations, and legitimate interests in security, fraud prevention, support, and legal claims. | Workspace records are active. Stripe-hosted payment and billing records are created when an approved project enters payment. |
Stripe, not Breauti Studio forms, collects full payment-card or bank credentials. Breauti receives limited transaction, billing, and payment-method details needed to operate and support the engagement, but not full card numbers or card security codes.
Local storage, cookies, and links
The site uses required browser storage to remember functional appearance preferences, maintain secure Firebase Authentication when you choose Google sign-in, protect payment and account flows, and preserve the active request while you complete it. Required Google and Firebase service libraries may receive ordinary connection, device, diagnostic, and security data when account features load; Breauti uses those services for the functional account experience, not advertising. The first-visit privacy choices control separately asks whether this device may remember an unfinished request after the browser closes. A draft remains local until you deliberately submit it. You can change that choice through the “Privacy choices” control in the footer, sign out through the Breauti account control, and remove local data through your browser's site-data controls.
Breauti does not intentionally run non-essential analytics, advertising pixels, cross-site profiling, or marketing cookies on the current site. The privacy choices control therefore does not present fictional analytics or advertising categories. If optional analytics, advertising, or similar technology is introduced, Breauti will update this notice and provide any consent or opt-out controls required before activation.
Google Drive access uses Google's authorization, Picker, and Drive interfaces. Breauti does not store your Google password or a reusable Drive refresh token. The Studio accepts a project folder rather than individual loose files; if you ask the site to create that folder, it is created in and controlled through your Google Drive. Only the selected or flow-created folder is shared with Breauti's read-only access-monitoring identity and the limited authorized Studio staff identities assigned to the project. Assigned staff receive Editor access so they can add, update, organize, or remove project files, including correcting accidental uploads; neither the monitor nor staff can browse the rest of your Drive. That folder-level access applies to its current and future contents without an expiration date and remains until you revoke it. Google may require a one-time direct share in Drive for a populated existing folder. Losing either required permission can pause work that depends on the folder. Project reference links are stored separately and should not contain credentials or private access tokens. External websites have their own privacy practices, which Breauti does not control.
Recipients and international transfers
When the site is publicly hosted, ordinary technical data may be available to hosting, network, and security providers acting for Breauti. Information may also be disclosed to professional advisers, insurers, courts, regulators, or authorities when reasonably necessary to comply with law, protect rights, prevent fraud, or resolve a dispute.
Breauti uses Cloudflare for public hosting; Google Firebase Authentication, Cloud Firestore, Cloud Functions, Google Picker, and Google Drive for account access, project records, and selected-folder collaboration; Google Workspace and Gmail for transactional account email; and Stripe for provider-hosted payment and billing experiences. Firebase project data is configured in the United States in the Dallas region. Provider-specific privacy information is available from Cloudflare, Firebase, Google, and Stripe.
Breauti is based in the United States. If GDPR-restricted data is transferred outside the European Economic Area, Breauti will use an available legal mechanism, such as an adequacy decision, Standard Contractual Clauses, or another permitted safeguard, and will assess supplementary protections where required.
Breauti does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or profile people for decisions that produce legal or similarly significant effects.
Your privacy rights
EEA and UK rights
Where the GDPR or UK GDPR applies, you may have rights to access, correct, erase, restrict, or receive eligible personal data; object to certain processing; withdraw consent without affecting earlier lawful processing; and challenge qualifying solely automated decisions. These rights are not absolute and can depend on the data, purpose, legal basis, and a lawful exemption.
You may complain to the supervisory authority where you live, work, or believe a violation occurred. The European Data Protection Board lists EEA supervisory authorities.
United States state rights
Where an applicable U.S. state privacy law covers Breauti and the processing, residents may have rights to know or access personal information, correct inaccuracies, delete eligible information, obtain a portable copy, opt out of qualifying sale, sharing, targeted advertising, or certain profiling, appeal a denied request, and exercise rights without unlawful discrimination. An authorized agent may act where the applicable law permits and the authorization can be verified.
Breauti will honor legally required browser preference signals if it begins a covered sale, sharing, or targeted-advertising practice. No such practice is active today. Breauti may request proportionate information to verify a rights request and may retain records needed to document the request, prevent fraud, comply with law, or establish or defend legal claims.
Signed-in Studio customers can delete their account and eligible workspace data directly from the Breauti account control by typing DELETE and confirming with Google. You may also request access, correction, deletion, restriction, portability, an objection, or an available appeal by emailing privacy@breauti.com. No special form is required. Breauti will verify the request proportionately and respond within the period required by applicable law.
Retention, security, children, and changes
Breauti uses purpose-based retention. Browser-local preferences and drafts remain until you, the account-deletion control, or the browser removes them. An account profile and project workspace remain while needed for the relationship, service delivery, security, account administration, taxes, accounting, disputes, legal claims, or another disclosed purpose. Self-service deletion removes the Firebase sign-in, profile, eligible drafts and requests, messages, appointment records, revisions, stored Drive references, and other eligible workspace data; it also attempts to revoke Drive permissions created through Studio. Active project work, ongoing care, and installment schedules must be ended first because deleting an account does not itself cancel an active service or payment obligation. Signed agreements, invoices, payment, tax, dispute, fraud-prevention, deletion-request, and narrowly necessary legal records may be retained for the applicable period. You can also send a deletion request to privacy@breauti.com. Revoking a Drive permission ends Breauti's access to that item but does not automatically erase a legally required audit record. After ongoing care ends, a hosted client site may be held in a paused or deactivated state for up to three months to allow reactivation or migration, then removed from active storage if no transition occurs. Legally required records and ordinary backup copies may remain longer under the applicable retention schedule.
Breauti uses reasonable administrative and technical safeguards appropriate to the information it handles, limits production access by role, and requires relevant service providers to protect data under their control. Breauti assesses suspected security incidents and will notify affected people and authorities when applicable law requires it. No online system is completely secure, and browser-local information is also subject to your device, browser, synchronization, and backup settings.
The public Studio site is intended for adults and organizations, not children. Education organizations can use products built by Studio in contexts involving students or families; those customer systems require project-specific roles, notices, agreements, permissions, and safeguards. This Studio marketing policy does not replace those obligations.
Breauti will update this policy before introducing materially different processing, such as SMS, non-essential analytics, advertising, expanded account data, or a substantially different payment or messaging workflow. Material changes will receive a new effective date and, where appropriate, a prominent notice.