KILN № 001 · PRIVACY

PRIVACY · NO PLATE

PRIVACY · THE NOTICE

KILN Privacy Policy

Effective: August 17, 2026

This policy was written against the system as it is actually built, not against a template. Every category below was checked in the schema and the code; nothing is listed that the studio does not collect, and nothing collected has been left out.

01Who we are

Studio KILN (“KILN”, “we”) is a one-person creative studio in Utah, USA. Henry Jolly runs it.

This policy covers everything we operate:

  • studiokiln.io — the marketing site.
  • projects.studiokiln.io — the client portal, where clients read documents, exchange messages, take delivery, and pay.
  • sign.studiokiln.io — the e-signature service, which we host ourselves.
  • The booking calendar behind the portal’s “pick a time” pages, which we also host ourselves.

Questions about this policy go to hello@studiokiln.io.

02What we collect

The marketing site (studiokiln.io)

Analytics. In production, the site loads Google Tag Manager, and Google Analytics 4 runs inside it. Google Analytics sets cookies and collects usage data: the pages you view, roughly where you are, what device and browser you use, and how you arrived. We use this to understand how the site is read. We do not use it to identify you, and we do not tie it to anything in the portal.

This site uses Google Analytics, a web analytics service provided by Google. Google’s use of the data it collects is governed by Google’s privacy policy: https://policies.google.com/privacy. You can opt out of Google Analytics on every site you visit by installing Google’s browser add-on: https://tools.google.com/dlpage/gaoptout.

The contact form.If you write to us through the site, we collect your name, your email address, your company if you give one (it is optional), and your answer to “What are you building?” — your project brief, in your own words. That goes straight into the portal as a lead record.

Your IP address.When you use the contact form, your address is held briefly in the server’s memory so the form can be rate-limited against bots; that copy is never written down. Two other places do record an address, and this notice would be wrong to leave them out. When you sign a document, our signing service writes the signer’s IP address into the audit certificate that stands behind the signature, and that certificate is held in the studio’s own database — it is part of the evidence the signature rests on and cannot be stripped out without destroying it. And the web servers that answer these sites keep the routine access logs every web server keeps, which include the addresses that asked for pages.

The client portal (projects.studiokiln.io)

Nothing here is collected from casual visitors. It applies to people who inquire and to clients.

Lead records. Your name, email, company, and project brief, as submitted above or as taken down when you simply email us. Records created under an earlier version of our intake form may also hold answers about scope and timeline that we no longer ask for.

Your account. Your name and email. There is no password. You sign in with a link we email you, which works once and expires in fifteen minutes. We store only a hash of that login link and a hash of your session — never the values themselves.

Messages and attachments.The correspondence between you and the studio, including any files either of us attaches. These are held in the portal’s own database, on the studio’s server.

Delivered work. The finished files, held the same way, so they stay in your archive after delivery.

Your case-study answer.Once a piece of work is delivered, the portal asks on that work’s own page whether we may name you in a case study. We keep your answer — yes or no — against that piece of work, along with the exact wording of the question you were shown when you gave it. You are the only person who can set it: there is no control on our side of the system, and we cannot answer it for you. You can change it whenever you like, in either direction, for as long as the work is in your portal; each answer is recorded in the activity log below.

Signed agreements.The full text of the agreement exactly as you agreed to it, your name as signer, and the signed PDF. The technical audit trail behind the signature — timestamps and signing metadata — is held by our self-hosted signing service (see “Signing” below).

Payment activity. Stripe checkout and payment references, the amount, the currency, the date, and whether it cleared. Your card and bank details go directly to Stripe. They never reach our servers and we never see or store them. Stripe’s privacy policy: https://stripe.com/privacy.

Bookings.When you pick a time to talk, we collect your name, your email, the time you chose, and your timezone. The scheduling runs on Cal.com, which we host on our own server rather than using a scheduling service. That server is connected to the studio’s Google Calendar, and this is where your details leave our machine: the booking is written to that calendar as an event carrying your name, your email and the time you chose, and a Google Meet room is created for the call. Google therefore holds those details as our calendar and video provider, under Google’s privacy policy: https://policies.google.com/privacy. The portal keeps the call’s time, title, status, and video link.

Operator notes. Private working notes about your project — what was decided, what to chase, what to remember. They are ours, and they are about the work.

Activity log. An append-only log of significant account events — a document signed, a payment made, a document viewed — kept as part of the same legal record as the agreements themselves.

Signing (sign.studiokiln.io)

E-signing runs on Documenso, which we host on our own server. It is not a third-party signing cloud, and your document does not leave our infrastructure to be signed. Documenso holds the document, your name and email as the signer, the signature you make, and the timestamps and audit record that stand behind it.

What we do not collect

No card or bank numbers. No tracking cookies in the portal. No advertising profiles. No data bought from brokers or scraped from anywhere. No location beyond what Google Analytics infers from an IP address on the marketing site.

03How we use it

  • To run the engagement: talk to you, schedule calls, send documents, and keep the correspondence in one place.
  • To deliver the work and to invoice for it.
  • To answer inquiries, whether they come through the form or by email.
  • To keep legal records of agreements you signed and payments you made.
  • To understand how the marketing site is used. Analytics runs on the marketing site only, never in the portal.

We do not use your information to build a profile of you, and we do not use it to advertise to you.

04What we share

We do not sell personal data. We never have and we will not. We do not rent it, trade it, or hand it to advertisers or data brokers.

We share only what is needed with the services that run the studio:

  • Stripe — payments. Card and bank details go to Stripe directly, so Stripe holds them and we do not. https://stripe.com/privacy
  • Google— two things, and only these two. Analytics on the marketing site, never in the portal. And the studio’s calendar and video: a booked call is written to our Google Calendar with your name, your email and the time you chose, and the call itself happens in a Google Meet room. https://policies.google.com/privacy
  • Email.We send mail from the studio’s own mailbox over SMTP, currently through our mail host. Anything we email you passes through that provider’s servers, as all email does.
  • Hosting. The marketing site is hosted by Vercel. The portal, the booking calendar, and the signing service all run on a single private server that KILN rents and administers. That server holds your messages, your files, your signed documents, and your account.

We will disclose information if the law compels it — a subpoena, a court order, a lawful government request — or where disclosure is necessary to establish or defend a legal claim, such as enforcing a signed agreement. Where we are permitted to tell you, we will.

05Cookies

The portal sets one kind of cookie: the session cookie that keeps you signed in after you use your login link. It is strictly necessary. There are no analytics cookies and no tracking cookies anywhere in the portal.

The marketing site sets Google Analytics cookies through Google Tag Manager, in production only. You can opt out at https://tools.google.com/dlpage/gaoptout, or block or clear cookies in your browser. Nothing on the marketing site breaks if you do.

The signing service (sign.studiokiln.io) sets its own strictly necessary session cookies while you sign a document. Nothing there tracks you.

06Retention

Signed agreements, payment records, and the activity log are kept permanently, or as long as tax and legal requirements demand. That includes the signature’s audit record, which cannot be removed without destroying the evidence the signature rests on. A signed agreement is the only record of what both sides agreed to, and it has to survive.

Messages, files, delivered work, and lead records are kept for the engagement and after it ends, so your archive is there when you come back for it. We do not put a clock on them. There is no automatic deletion sweep in this system: nothing deletes your records on a schedule. We would rather tell you that than publish a timetable no part of the software keeps. What ends the keeping is you asking, or the studio deciding it no longer needs the record — and the first of those is the one you can rely on.

Analytics data is kept for the retention window configured on our Google Analytics property.

If you ask us to delete your information, we will, except for records we are required to keep — signed agreements, payment history, the activity log that forms part of the same legal record, and anything covered by an open legal matter. We will tell you what we kept and why.

07Security

  • Everything runs over HTTPS.
  • Login links and sessions are stored as hashes, never as the values themselves. A copy of our database does not let anyone sign in as you.
  • The portal, booking, and signing services run on one private server that only we administer. Booking and signing are reachable only through the portal or through their own address; they are not shared tenancy on someone else’s platform.
  • Payment details never touch our servers. Stripe takes them directly.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your information, we will tell you.

08Your choices

Email hello@studiokiln.io to ask for a copy of what we hold about you, to correct it, or to have it deleted. Say what you want and we will do it, subject to the records in Section 6 that we have to keep. We will not charge you and we will not make you jump through hoops.

To opt out of analytics on the marketing site, use Google’s opt-out add-on: https://tools.google.com/dlpage/gaoptout.

On state privacy laws. The Utah Consumer Privacy Act, the CCPA, and similar US state laws apply to businesses above revenue and data-volume thresholds that a one-person studio does not currently meet, so we are not obligated under them today. We think the honest thing is to honor access, correction, and deletion requests anyway, so we do. If KILN ever crosses those thresholds, this section gets rewritten with the formal rights and response deadlines spelled out.

09Children

These sites are for businesses hiring a creative studio. They are not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has given us information, email hello@studiokiln.io and we will delete it.

10Changes

If this policy changes, the new version is posted on this page with a new effective date. Material changes will also be sent to active clients by email.

11Contact

Studio KILN
Utah, USA
hello@studiokiln.io

THE ASK

Taking work now.

Say what needs making. Answered personally, within a day.