Legal
Last updated 20 August 2026
JH Creative AI Studio is sold as an isolated workspace for your business. This page explains how we treat customer and prospect data. It sits alongside the Privacy Policy, Terms and Cookies pages.
Account details, Business Brain, leads, drafts, files you upload and usage needed to run the product are stored in our hosted application database (Supabase / Postgres) and related storage for that workspace. Billing is handled by Stripe. Transactional email uses our email provider. We do not sell your data.
Each customer organisation has its own workspace. Application access is scoped to that organisation. JH Creative Master HQ is the owner environment for running the studio — it is not a public product and is not how customers browse other tenants.
You and users you invite to your workspace. JH Creative operators may access a workspace only to provide support, fix faults or meet a legal duty — not to mine it for other clients. We do not use your brand materials to train third-party foundation models.
Workforce features call AI providers to draft and analyse content from the brief you store. Prompts include the business context you have given the workspace. We do not present underlying model vendors on the public site as a product claim. Treat any AI draft as something you review before it represents your business.
We keep account and workspace data while the subscription is active and as needed for billing, security and legal records. You can request deletion via contact. Backups and logs may persist for a limited period after deletion.
Hunting and auto-send stay off until you switch them on. Default outreach is draft → you approve → send. You set AI rules in onboarding and Business Brain. You can cancel from billing; access continues until the period ends.
We act as controller for your account data and as processor for personal data you load about your prospects and customers. You remain responsible for having a lawful basis to process those contacts. Do not upload data you are not allowed to use. UK GDPR rights (access, correction, deletion, objection) can be exercised through contact.
Production traffic is HTTPS. Auth cookies are scoped to the site with SameSite=Lax. Passwords are handled by the auth provider — we do not store plaintext passwords. Report a security issue through contact.