1. Scope and responsibility
This Privacy Notice explains how Ghost Kitchen handles personal information when you use ghostkitchen.studio, the Asset Store, Ghost Kitchen software that connects to us, creator workflows, or other products that link to this notice.
Ghost Kitchen is responsible for the practices described here. Some third-party services process information under their own notices when you interact with them directly. This notice does not cover a third party’s independent practices.
2. Information we collect
The information we collect depends on what you use. The Ghost Kitchen studio site accepts trial, waitlist, proof-cohort, and studio-evaluation requests and emits limited first-party sales events. It does not use cross-site advertising trackers. Connected creator services collect the information needed to operate accounts, licensing, purchases, and publishing.
- Account information, such as email address, display name, password hash, roles, account status, and invitation records.
- Account and product information, such as licenses, subscriptions, installed products, device authorizations, and support history.
- Creator information, such as project names and configuration, uploaded models and textures, file metadata, rights declarations, validation findings, review decisions, publication history, collaborator details, and privacy-safe performance metrics.
- Partnership information, such as a contact name, work email, company, website, requested activation, target timing, and brief.
- Creator-tool sales information, such as the requested product, trial or waitlist intent, studio name and size, project stage, campaign source, subscription plan, seat quantity, and activation or export milestones.
- Technical and security information, such as IP address, request metadata, device or client identifiers, build version, operating system, authentication events, service logs, crash or error information, abuse signals, and audit records.
- Communications and support information you choose to send us, including the contents of messages and any attachments.
- Local data stored on your device, such as project drafts, preferences, installed-product state, and short-lived access or authentication cookies.
3. Where information comes from
We collect information directly from you, automatically from your browser, app, or interaction with our Services, from other members of a declared collaboration, and from service providers acting for us. We may also receive information from a storefront or platform when you choose to connect or transact through it.
We do not seek sensitive government identifiers, precise real-world location, health data, or payment-card numbers through current account and creator forms. Do not include that information in free-text fields or uploaded files.
4. How we use information
We use personal information only for legitimate product, business, safety, and legal purposes, including to:
- create and secure accounts, authenticate users and devices, and enforce permissions;
- operate product licensing, downloads, updates, purchases, support, and account continuity;
- receive, validate, review, publish, attribute, distribute, and measure Asset Store submissions;
- respond to support, rights, privacy, partnership, and security requests;
- detect abuse, cheating, fraud, malware, account compromise, and violations of our terms;
- debug, maintain, test, and improve reliability, accessibility, performance, and product design;
- keep required accounting, transaction, provenance, publication, security, and audit records; and
- comply with law, enforce agreements, and protect people, rights, and services.
7. Public and creator-facing information
A display name, attribution, published asset, listing revision, and related public activity may be visible to other users. Do not use a name or upload content that reveals information you want to keep private.
Creator metrics are designed to report aggregate, publication-level signals rather than expose individual player trails. Authorized staff may still access underlying records where reasonably necessary for operations, fraud review, security, or support.
8. Retention and deletion
We keep personal information only as long as reasonably necessary for the purposes described here, including account operation, security, dispute resolution, legal obligations, and enforcement. Retention depends on the record and the state of the product.
Active account and license records generally remain while the account is open. Short-lived access credentials expire automatically. Security logs, audit events, moderation decisions, published revision provenance, and transaction records may be retained longer to preserve system integrity and meet legal or accounting needs.
Deleting a project or closing an account may not erase immutable published revisions, content already distributed to player clients, records subject to a legal or security hold, or temporary backup copies. Where appropriate, we may de-identify retained records instead of deleting them.
9. Security
We use administrative, technical, and organizational measures designed to protect information in light of its sensitivity and the state of our products. Measures include hashed passwords and service credentials, scoped authorization, access controls, audit records, and encrypted transport where supported.
No service or storage method is perfectly secure. Protect your credentials, keep devices and software updated, and contact hello@ghostkitchen.studio promptly if you believe your account or information has been compromised.
10. Your choices and privacy rights
You may update certain account and profile information through the Services. You may also ask to access, correct, delete, or receive a copy of personal information, object to or restrict certain processing, or withdraw consent where those rights apply. We may need to verify your identity and may retain information where an exception applies.
To make a request, email hello@ghostkitchen.studio with “Privacy” in the subject line and identify the account or interaction involved. An authorized agent may submit a request where permitted, but we will require proof of authority and identity. We will not discriminate against you for exercising a privacy right.
Because we do not currently sell personal information or use it for cross-context behavioral advertising, there is no sale or targeted-advertising opt-out to process. We will update this notice and provide any required mechanism before that practice changes.
11. Children’s privacy
Our Services are not directed to children under 13, and we do not knowingly collect personal information from them. Do not create an account or submit personal information if you are under 13.
If you believe a child under 13 has provided personal information, contact hello@ghostkitchen.studio. We will investigate and take appropriate steps to delete the information unless we are legally required to keep it.
12. International use
Ghost Kitchen and its service providers may process information in the United States and other places where they operate. Those places may have different data-protection laws than your home jurisdiction. Where required, we use an appropriate legal basis or transfer safeguard.
If local law requires consent for a particular use, we will seek it. Otherwise, processing may be necessary to perform a contract with you, meet a legal obligation, protect vital or legitimate interests, or operate and secure the Services, depending on the context and applicable law.
13. Updates and contact
We may update this notice to reflect product, operational, or legal changes. We will post the new date and provide additional notice when required. If a change materially affects how we use information already collected, we will take any further steps required by law.
Questions, privacy requests, and complaints may be sent to hello@ghostkitchen.studio with “Privacy” in the subject line. You may also have the right to contact the privacy or data-protection authority where you live.