RISE STUDIO
Models Features Scenes API
Open the studio
Rise Studio · legal

Privacy Policy

Last updated 28 August 2026 · Rise Asia PTE. Limited, Singapore

1. Who is responsible

Rise Asia PTE. Limited, 3 Phillip Street, #14-05, Royal Group Building, Singapore 048693, operates Rise Studio and is the data controller for the personal data described here. We comply with Singapore's Personal Data Protection Act (PDPA), and where the GDPR or UK GDPR applies to you, with those too. Questions and requests: support@risestudio.ai.

2. What we collect

  • Account data. When you sign in with Google we receive your email address, display name and profile photo. We never see your Google password. You can set a different display name in Settings.
  • Content. The prompts you write, the reference media you upload, and the media you generate, together with the settings of each generation (model, size, options) — this is the product working, not analytics.
  • Usage and billing records. A double-entry ledger of credit movements, the cost and status of each job, and which API key spent what. We keep these accurate because they are your bill.
  • Security and audit records. Administrative actions (member changes, key changes, credit grants, sharing) with the acting account, IP address and time — including failed attempts, because failures are the signal that someone is trying to break in.
  • Technical logs. Standard request logs (IP, user agent, timing, errors) with short retention, used to run and secure the Service.

We use no advertising trackers and no third-party analytics cookies. Browser storage is used to keep you signed in and remember interface preferences.

3. What we use it for

  • Delivering the Service: running your generations, storing your work, syncing your cast and assets across your devices and workspace.
  • Billing: metering credits, enforcing the spending caps workspace owners set.
  • Security: authenticating you, detecting abuse, keeping the audit trail workspace owners rely on.
  • Improving the Service: aggregate, de-identified usage patterns (which models are used, how often jobs fail). We do not use your prompts, uploads or outputs to train AI models, and we do not sell personal data.
  • Communicating with you about the Service — operational messages, and product news you can opt out of.

4. Who processes it — the part that matters most

When you run a generation, your prompt and any attached reference media are sent to the third-party provider operating the model you chose. Today those providers are fal.ai, Replicate, and WaveSpeed, fulfilling models from vendors such as ByteDance, Black Forest Labs, OpenAI, Kuaishou and xAI. Each processes that data under its own terms and privacy policy to fulfil your job. If your workspace connects its own provider accounts (BYOK), your direct agreement with the provider governs their processing.

Our infrastructure processors:

  • Cloudflare — application hosting, networking, and media file storage (R2).
  • Neon — our Postgres database, hosted in the AWS eu-west-2 (London) region.
  • Google Firebase — sign-in authentication.

Because model providers and our infrastructure operate in multiple regions, your data may be processed outside your country, including in the United States. We transfer it only to deliver the Service you asked for, under each processor's contractual safeguards.

5. Who can see your work inside the Service

Workspaces are the privacy boundary, and a workspace is a shared creative space: members of the same workspace can see each other's renders and live generation activity, attributed by name, and production assets (characters, styles, character sheets) are shared across the workspace by design. Workspace owners additionally manage all of it, including members and usage — that is what ownership means here. Scene drafts remain visible only to their author and the owner. Nothing is visible across workspaces, and nothing is public unless you share it. If you do not want colleagues to see your work, use a workspace of your own.

6. How long we keep it

  • Content — until you delete it or your workspace is deleted.
  • Account data — while your account exists.
  • Ledger and audit records — retained after deletion, because billing history and security records must stay auditable; they reference amounts, actions and identifiers, not your content.
  • Technical logs — days to weeks.
  • Backups roll off on a fixed schedule after deletion.

7. Your rights

You can access and correct your account data in Settings, delete individual content, and delete an entire workspace you own — the deletion dialog tells you exactly what will be removed. Beyond that, you may ask us to access, correct, export or erase your personal data, or object to a use of it, by emailing support@risestudio.ai. We respond within the time the PDPA or GDPR requires. If you are unsatisfied, you may complain to the Singapore PDPC or your local data protection authority.

8. Security

All traffic is encrypted in transit. Provider credentials you connect are sealed with envelope encryption and are never returned to a browser. API keys are stored only as hashes. Access inside a workspace is governed by per-key permissions and spending caps, and administrative actions are recorded in an append-only audit log.

9. Children

The Service is not directed at children and requires users to be 18 or older. If you believe a minor has an account, contact us and we will remove it.

10. Changes

We will announce material changes to this policy on the Service or by email at least 14 days before they take effect. The "last updated" date above always reflects the current version.

Rise Asia PTE. Limited · 3 Phillip Street, #14-05, Royal Group Building, Singapore 048693 · support@risestudio.ai

RISE STUDIO

An Arena Entertainment venture

Terms Privacy Contact
Rise Asia PTE. Limited 3 Phillip Street, #14-05, Royal Group Building, Singapore 048693
© 2026 Rise Asia PTE. Limited