Privacy Policy — 2045 Studio
Last updated: 10 September 2026
Version: 3.0
1. Who we are
2045 Studio is operated by 2045 Consulting Ltd, company number 16330275, of 124 Evering Road, London, England, N16 7BD. This notice covers personal information handled through studio.2045.io, its workspaces, connected services and customer support
For privacy questions or requests, contact will@2045.io, addressed to Will Dixon, our data protection contact
We are the controller of information used to administer accounts, manage customer relationships, bill for use, secure the Service and meet our own legal obligations. When a customer supplies personal information for processing in its workspaces, we generally act as a processor on that customer's instructions under the applicable agreement and data processing terms. The customer may be an organisation or an individual acting in a business capacity. Our role depends on the processing activity, not simply who uploaded a file
If an organisation provides your account, its own privacy information also applies. Contact it about decisions it makes concerning your information. We assist customers with requests concerning information we process on their behalf
2. Information we handle
Depending on the features you use, we handle:
- Account and organisation information: names, email addresses, account identifiers, memberships, roles and permissions
- Workspace content: uploaded files, extracted text, supported images or media, notes, methodologies, report instructions, personas, library entries and settings
- Conversations and outputs: questions, prompts, chat history, reports, generated material, revisions and saved memory items
- Connected-source information: selected Google Drive files or Notion pages, their content and metadata, source links, service identifiers and authorisation tokens
- Retrieval and source records: document indexes and embeddings used to find material, external research results, source references, model/workflow information and selected review or validation records
- Voice information: recordings submitted for dictation and resulting text
- Usage and support information: credit consumption, billing records, correspondence and feedback
- Technical information: IP addresses, browser/device details, authentication and session information, request logs, errors and performance measurements. Diagnostic records can include limited content or excerpts produced by the relevant workflow
Information comes from you, your organisation and authorised collaborators, services you connect, and public or external sources used by research features. Documents and research results may contain personal information about people who do not have an account
Provide only information you are entitled to use and that is appropriate for the task. Additional arrangements may be necessary for particularly sensitive information or regulated workloads
3. How we use information
We use information to provide accounts, workspaces, libraries and collaboration; process and retrieve documents; generate or edit requested outputs; read selected connected sources; carry out enabled research; transcribe dictation; maintain source and workflow records; administer credits and support; investigate faults and abuse; protect the Service; and meet legal obligations or establish and defend claims
We use operational and usage information to understand reliability, capacity and feature use. We do not sell personal information, use customer content for advertising, or use customer content to train our own AI models
4. AI processing and source records
AI features send information needed for the task to the relevant model or processing provider. This may include instructions, conversation context, selected documents and relevant workspace material. Providers vary by feature and model
We use business/API services for AI processing. Provider retention and handling depend on the service, account configuration and applicable terms. We do not promise that every provider or workflow has zero retention. Contact us for information about the arrangements relevant to your proposed use
Saved reports and conversations may reproduce or summarise input content. Some workflows also retain model information, source metadata and supporting context. A source listed as supplied to a report does not necessarily support every statement in it. Citations and review features help you assess an output; they do not guarantee accuracy or completeness
Saving an output to memory is separate from retaining conversation history, reports, revisions and processing or audit records as part of normal operation
5. Google Drive and Notion
Connections are optional. Other available inputs can be used without connecting an external account
Google Drive
Our report connector uses Google's selected-file permission, drive.file, with Google Picker. It reads files you select for use with 2045, including supported Google documents and other supported formats in Drive. It does not request permission to read your entire Drive or Gmail mailbox. Google's permission description includes creating, editing and deleting selected files; our report connector uses it to read them for your requested reports
Selected content is retrieved and extracted for report processing and may be sent to the AI provider used for the report. We retain connection credentials, file identifiers and source metadata to operate the feature. Saved outputs and audit or diagnostic records may contain information derived from selected files. Temporary retrieval does not mean that all information derived from a file disappears after a run
Our handling of Google API data follows the Google API Services User Data Policy, including applicable Limited Use requirements. We use it for requested, visible features, not advertising, sale or general-purpose model training. Transfers are limited to providing those features with your authorisation, security needs, legal requirements or other circumstances permitted by that policy. Human access requires your specific agreement, necessary security or legal work, or another permitted exception. These restrictions also cover information derived from Google API data
Notion
The report connector reads selected pages available to the authorised Notion integration, including supported content and metadata. Notion permissions determine which pages are accessible; your selection determines what is used for a report. The same distinctions between temporary retrieval and retained credentials, outputs and source records apply
Disconnection and sharing
Disconnect using the Service's connection controls, or revoke Google access through your Google Account connections. Notion also provides integration controls. Once effective, disconnection prevents subsequent access through that authorisation. It does not automatically remove earlier outputs, source records or content already supplied for a running task
A connection does not automatically give colleagues your provider credentials. Content included in shared workspaces or outputs may, however, be visible to people authorised to access them. Consider this before selecting confidential material
6. Who receives information
Authorised workspace members and organisation administrators can access information according to permissions and customer configuration. Suppliers receive information appropriate to their function, under applicable contractual protections
Principal infrastructure and processing suppliers include Vercel for hosting, Supabase for database/storage, Pinecone for retrieval, Clerk for authentication, and Google Cloud, OpenAI and Anthropic for supported AI and processing workflows. Google Cloud also supports selected document/media processing and storage. Search and relevance-ranking services receive queries or material needed for enabled features. The suppliers used depend on the task and configuration
Providers may also support communications, operational support and payment administration. Contact us for current supplier information relevant to your organisation. Customer agreements govern applicable subprocessor notices and objections
Authorised personnel may access information as needed for support, security or legal purposes, subject to confidentiality and access controls. Google data has the additional restrictions in section 5. Information may be disclosed where required by law or necessary to protect legal rights. If the business changes ownership, any transfer remains subject to appropriate safeguards, required notices and Google's specific requirements for its data
7. Location and security
We use EU-hosted services for parts of our infrastructure, including our primary database configuration. Some hosting, identity, AI and supporting services operate internationally, including in the United States. Not all processing stays in the UK or EU
Where UK or EU data protection law requires transfer safeguards, the applicable arrangements must provide an appropriate mechanism, such as an adequacy decision or relevant contractual safeguards. Contact us for information about the safeguards applicable to your data and how to obtain a copy, subject to necessary redactions
Our security programme covers access control, managed encryption, workspace permissions, development practices, monitoring and incident response. It is informed by recognised frameworks; this is not a claim of ISO certification. Security and recovery depend partly on provider capabilities and configuration. No service can guarantee absolute security. We notify customers and regulators of incidents where required by law or contract
8. Retention and deletion
Retention depends on the purpose, record type, customer agreement, active use, deletion requests, recovery needs and legal obligations:
- Account and organisation records: while needed for the relationship and subsequently for necessary administration, legal obligations or disputes
- Workspace content, documents, conversations and outputs: generally while retained by the customer, subject to deletion and account/contract termination arrangements
- Connection credentials: while connected and, where necessary, briefly afterwards to complete disconnection or resolve operational issues. Source records and outputs have separate retention lifecycles
- Audit and diagnostic records: for accountability, investigation and operational needs. Some audits are initially soft-deleted; our current policy includes a subsequent removal window of up to 90 days for those records, subject to lawful preservation requirements
- Billing and legal records: as needed for applicable financial obligations and legal claims
- Temporary processing data: for the processing and cleanup workflow. Dictation may involve a temporary audio file and a transcription provider. Dictated text can be retained in the content you create
Deletion from active systems does not necessarily remove backups immediately. Backup copies remain subject to access controls and their retention lifecycle; provider-held copies follow the applicable service arrangements. We do not promise immediate deletion from every system through one action
Product controls export and delete supported data within your permissions and organisation context. Shared organisational records may require the organisation's involvement; some audit and legally required records may remain. Deleting product data does not necessarily close the separate authentication account. Contact us for help with a complete account or data request, including data outside self-service controls
9. Lawful bases
For activities where we act as controller, we rely on the basis appropriate to the purpose:
- Contract: providing and administering a service you contract for
- Legitimate interests: managing organisational accounts, communicating with business users, supporting customers, maintaining reliability and protecting the Service, where these interests are not overridden by individuals' rights
- Legal obligation: applicable record-keeping, disclosure and other duties
- Consent: where required for optional processing. Withdrawal does not affect the lawfulness of earlier processing
External-account authorisation is a product permission; it does not itself determine the lawful basis for every subsequent use. For customer-controlled content, the customer determines the lawful basis and we process on its instructions
Identity, access and billing information may be necessary to supply an account or feature. Without required information we may be unable to provide it. Optional sources need only be connected if you want to use them
10. Your rights
Depending on applicable law and the circumstances, you may request access, correction, erasure, restriction or portability, object to processing, and withdraw consent where relied on. Rights are subject to applicable conditions and exceptions, including other people's rights and lawful retention
Contact will@2045.io. We may need to verify identity and clarify your request. We respond within applicable legal time limits, normally one month, and explain any lawful extension. Requests about customer-controlled content may need to be handled with your organisation
The Service assists human work; it is not intended to make solely automated decisions with legal or similarly significant effects on individuals. Contact us about concerns relating to automated processing
You may complain to the UK Information Commissioner's Office or, where applicable, your local data protection authority
11. Cookies and browser storage
Cookies and browser storage support authentication, security, sessions and preferences. Server-side logs and usage records also provide operational information. We do not use customer content for advertising
Where optional analytics or other non-essential storage is introduced or enabled, we will provide relevant information and obtain consent where required. Browser restrictions on storage may affect sign-in and other functions
12. Children
2045 Studio is designed for business use and is not directed at children. We do not knowingly collect information through accounts intended for children under 16. Contact us if you believe such information has been supplied
13. Changes and contact
We update this notice as practices change and provide notice of material changes through the Service or customer communications. Where consent or renewed authorisation is required, we obtain it before the changed use
2045 Consulting Ltd
Company number: 16330275
124 Evering Road, London, England, N16 7BD
Data protection contact: Will Dixon — will@2045.io