Privacy notice
What Tingle Studio collects about you, why we use it, who else handles it, how long we keep it, and what you can ask us to do.
Last updated
Who we are
Tingle Studio is operated by Tingle Press, London, United Kingdom. Tingle Press decides how and why personal information is used to run Tingle Studio, so under UK data protection law it is the controller. Write to info@tingle.press about anything on this page.
To be completed by Tingle Press: Tingle Press’s legal form and registered address, its company number if it is a company, and its ICO registration (data protection fee) number.
Our two roles
- Your account. For your account, how you sign in, the security records we keep and the emails we send, Tingle Press is the controller.
- Projects. For the content of projects (source text and scripts, designs, prompts, reference images, generated pictures, video and sound, and the notes and decisions of the people who work on them), Tingle Press acts as a processor for the organisation that owns the project. That organisation is the controller of any personal information in its projects, so questions about it should go to them first; we will help them answer. Business customers can ask us for a data processing agreement.
What we collect
Your account
Your email address, whether it has been verified, your name, and your confirmation that you are 18 or over, with the time you gave it. We also keep your language and time-zone settings, and a random identifier for passkeys, so that your devices never learn your account number.
How you sign in
Tingle Studio has no passwords. Depending on how you sign in, we keep:
- Passkeys: the passkey’s public key and identifier, technical details your device reports (such as the type of authenticator and whether the passkey is synced between your devices), the name you give it, and when it was added and last used. The private key, and the fingerprint, face or PIN you use to unlock it, never leave your device. We never receive biometric data.
- Email links: when you ask for a sign-in link, we keep your email address, the time, your IP address and browser details, and a scrambled (hashed) copy of the link and its 6-digit code, never the link itself. A link works once, for 15 minutes.
- Google, Microsoft or Apple: we ask these services only for your email address, whether they have verified it, your name, and the account identifier they give you. We keep that identifier, the email address at the time you linked the account, and when you last used it. We never see your password for those services. If you use Apple’s Hide My Email, we receive only the relay address Apple gives us.
Sessions and the audit log
When you sign in, we start a session. We keep a hashed copy of its token, how you signed in, your IP address and browser details, and when the session started, was last used and expires.
We also keep an audit log of what happens in accounts and organisations: sign-ups, sign-ins and failed sign-in attempts, sign-outs, changes to passkeys and linked accounts, invitations and role changes, provider keys added or removed, budget changes, and production decisions such as kept takes, locked designs and likeness checks. Each entry records who did it, when, and from which IP address and browser.
Organisations and invitations
The organisations you belong to and your role in each; an organisation’s name, web address, kind and country, and its VAT number if it gives one. If someone invites you, they give us your email address and the role, and we email you the invitation.
Provider keys
If your organisation adds its own keys for AI providers, we store them encrypted (see Security). After a key is saved, we show only its last four characters, its label, whether it works and when it was last used.
Project content
Everything an organisation puts into Tingle Studio or makes with it: source text and scripts, designs and reference images, prompts, generated images, video, voices and sound, review decisions and notes, and the record of who approved what. A delivery pack names the people who wrote, decided and approved, as a record of human authorship.
The desktop app
If you pair the Tingle Studio Agent with your account, we keep the device’s name, operating system, app version, free disk space, when it was last seen, and a hashed copy of its credential. Files the agent keeps on your computer stay there unless you or the agent upload them.
Emails we send
We send sign-in links and invitations through Azure Communication Services, from mail.tinglestudio.com. They contain no tracking pixels and no tracked links, so we do not know whether you open them.
Server logs
Our servers record each request: the time, the address requested, the result and your IP address, together with error and performance data. We use these logs to keep Tingle Studio secure and working.
If you write to us
We keep your message, your email address and our reply.
What we don’t do
- No passwords, and no biometric data.
- No analytics, advertising or tracking cookies, no tracking pixels, and no third-party scripts in the app. If we ever want product analytics, we will ask for your consent first.
- We don’t sell or rent personal information.
- We don’t use your content to train AI models.
- We don’t take payments yet, so we hold no card details.
Why we use it, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Creating your account, signing you in and providing Tingle Studio to you and your organisation | Contract |
| Checking that you are 18 or over | Contract, and our legitimate interest in keeping a service made for adults to adults (some AI providers require it) |
| Keeping accounts and the service secure: sessions, rate limits, the audit log and server logs | Legitimate interests: security and preventing abuse |
| Sending sign-in emails | Contract |
| Sending invitations | Legitimate interests: the inviting organisation’s, in adding you, and ours, in delivering its request |
| Processing project content, including sending it to the AI providers the project uses | We act on the organisation’s instructions, as its processor; the organisation needs its own lawful basis |
| Checking designed faces against celebrity recognition and reverse image search | Legitimate interests: stopping Tingle Studio being used to imitate real people |
| Answering your messages and requests about your rights | Legitimate interests, and legal obligation for rights requests |
| Keeping records and reporting to the authorities where the law requires it | Legal obligation |
Who else handles it
Microsoft Azure
Tingle Studio runs on Microsoft Azure in its UK South region (London). The database, stored files, encryption keys (Azure Key Vault) and logs (Azure Monitor) are all there. Requests reach us through Azure Front Door, Microsoft’s global network, which may receive them at a location near you before passing them to UK South. Emails are sent by Azure Communication Services, with its data held in the UK.
AI providers
To make a film, Tingle Studio sends material from your project to the AI providers that do the work. A provider receives only what its job needs, and only the providers a project actually uses receive anything.
| Provider | What it does in Tingle Studio | What it receives |
|---|---|---|
| fal | Keyframes, design sheets and stills; training identity models (LoRA); Kling and Veo video, upscaling and lip-sync through fal | Prompts, reference and training images, and the video and audio those jobs need |
| Kling | Video | Prompts, reference images and, when editing a clip, the video |
| Runway | Video repair; Seedance video | Prompts, images and video |
| Veo video (Gemini API) | Prompts and reference images | |
| Luma AI | HDR video | Prompts and reference images |
| BytePlus | Seedance video | Prompts and reference images |
| ElevenLabs | Voice design, dialogue, sound effects and music | Voice descriptions, dialogue text, and sound and music prompts |
| sync. | Lip-sync | Video and the dialogue audio |
| Topaz Labs | Upscaling selected shots | Video |
| Anthropic | Claude: the automated quality check on each take and, once it is available, the writing studio | Frames from takes, reference images, the shot description and the project’s rules; for writing, the source text and drafts |
| Replicate | Alternative routes to open models | Prompts and images for those jobs |
| AWS Rekognition | Celebrity check on designed faces | The face image |
| TinEye | Reverse image search on designed faces | The face image, or a link to it that expires after 10 minutes |
Each provider handles what it receives under its own terms. Tingle Studio copies each result to our storage as soon as a job finishes, but providers keep their own copies of inputs and outputs for periods their terms set. Some providers’ standard terms let them use inputs to improve their models unless the account holder opts out or agrees otherwise. To be completed by Tingle Press: which providers Tingle Press’s own accounts have opted out of training with, and which providers do not allow an opt-out. When your organisation uses its own key with a provider, your own agreement and settings with that provider apply.
Signing in with Google, Microsoft or Apple
If you sign in with one of these, that company handles your sign-in under its own privacy policy and is responsible for what it does with your information.
Nobody else
We don’t share personal information with anyone else unless the law requires us to.
International transfers
Tingle Studio’s own data is held in the UK. Project material sent to AI providers is processed outside the UK: mostly in the United States; the Kling and BytePlus services we call directly are in Singapore; and some routes may be processed in China. AWS Rekognition is called in AWS’s London region unless the AWS account used for the check is set to another region.
To be completed by Tingle Press: the safeguard used for each provider’s transfers, for example the UK International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or the UK–US data bridge.
How long we keep it
- Your account: while it is open. If you ask us to delete it, we erase it within 30 days, keeping only records the law requires us to keep. Audit log entries outlive the account, with your identity replaced by a pseudonym.
- Sessions and sign-in links: a session ends after 30 days without use, or when you sign out. A sign-in link expires after 15 minutes, and a passkey or Google, Microsoft or Apple sign-in in progress after 5 or 10 minutes. To be completed by Tingle Press: how long records of ended sessions and used or expired sign-in links, with their IP addresses and browser details, are kept.
- Audit log: To be completed by Tingle Press: how long audit log entries are kept.
- Server logs: To be completed by Tingle Press: how long server logs are kept (the production log workspace is configured for 30 days).
- Project content: until the organisation deletes it or closes its account. To be completed by Tingle Press: how long a closed organisation’s projects are kept before they are deleted. Deleted files can be recovered for 30 days, and database backups are kept for up to 35 days; after that, deleted data is gone from them too.
- Messages to us: for as long as we need them to deal with what you asked.
Security
- Session tokens, sign-in links and codes are stored only as hashes, so a copy of our database would not let anyone sign in.
- Everything is encrypted in transit (HTTPS only) and at rest.
- Provider keys are encrypted with a key unique to your organisation, which is itself protected by a hardware-backed key in Azure Key Vault. A provider key is decrypted only when a job is sent to that provider, and it is never shown again, logged or sent to your browser.
- Organisations are kept apart in the database and in storage, and your browser fetches files through links that expire within an hour.
- Sensitive changes, such as adding a provider key, need a recent sign-in.
Cookies and browser storage
Tingle Studio uses only cookies that are strictly necessary to sign you in and keep your account secure, so it does not ask for consent to them. On our own address they are:
| Cookie | What it does | How long it lasts |
|---|---|---|
__Host-ts_session | Keeps you signed in | 30 days, renewed as you use Tingle Studio |
__Host-ts_csrf | Stops other websites making requests in your name (cross-site request forgery) | 30 days |
__Host-ts_webauthn | Tracks a passkey sign-in or set-up while it is in progress | 5 minutes |
__Host-ts_oauth | Tracks a Google, Microsoft or Apple sign-in while it is in progress | 10 minutes |
If you choose a light or dark theme, the choice is saved in your browser’s local storage (ts-theme). It never leaves your browser.
Your rights
You can ask us to:
- give you a copy of the personal information we hold about you;
- correct it;
- delete it;
- restrict how we use it, or stop using it where we rely on legitimate interests;
- give it to you, or to another service, in a machine-readable form.
Email info@tingle.press and we will respond within one month, as the law requires. Some rights have limits, for example where the law requires us to keep a record. For personal information inside a project, we will pass your request to the organisation that controls it and help it answer.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office at ico.org.uk. We would be grateful for the chance to put it right first.
Age
Tingle Studio is for adults only, and every account confirms that its holder is 18 or over. If we learn that an account belongs to someone under 18, we will close it and delete its information.
Changes to this notice
If we change how we use personal information, we will update this page and the date at the top. The Terms of Service and the Acceptable Use Policy cover everything else about using Tingle Studio.