D’Alessio Creative Workspace Privacy Policy
Effective September 27, 2026.
About this policy
D’Alessio Creative Workspace is a creative production application operated by D’Alessio Inc. This policy explains how the workspace handles project information and connected services. It applies to the workspace, not to unrelated websites or the independent services described below.
Privacy contact: dalessio@me.com.
## Information the workspace handles
The workspace handles information you enter or generate, including project names, scripts and briefs, prompts, reference images, generated images and audio, video job records, scene and shot assignments, tags, output preferences, and selected takes. Project information can contain personal information if you include it in your materials.
The hosting service may process technical request information, such as IP addresses, browser information, request times, and error or diagnostic information, to deliver and operate the application.
How information is used
Information is used to organize projects, save and reopen work, analyze briefs, create requested assets, maintain continuity references, and operate or troubleshoot the workspace. Relevant project content is sent to an external generation service when you request an operation that uses that service.
Browser and drive storage
Browser projects are stored in the browser’s local database. Folder projects are written to a folder you select on your computer or connected drive, with a recovery copy in the browser. Folder access depends on your browser permissions. Other people with access to your device, browser profile, or selected folder may be able to access those copies.
Choosing a local folder does not make AI generation offline. Requested analysis and generation still send the necessary prompts and supported reference content through the application server to the relevant provider.
The application also includes database-backed project features. Where configured and used, these can store project metadata, briefs, delivery settings, and production information on the server. Cloud storage is not currently offered as a project-creation storage option.
AI and infrastructure providers
Depending on the operation and configured services, information may be processed by OpenAI for brief analysis and reference-image generation, Google for image editing and Veo generation, the configured Seedance API gateway for video generation, ElevenLabs for voice-over, music, voice conversion, audio isolation and transcription and sound generation, Higgsfield for Seedance video generation and shot transformations, and Topaz for video enhancement you approve. When you upload images, MP4 footage or WAV audio in Higgsfield Seedance or Shot Transformation, those files go directly to Higgsfield storage. Generation sends the media links, reference bindings and edit directions to Higgsfield. Higgsfield generation and transformation job metadata, including project identifiers, prompts, source links and results, is stored in the application database even for local-drive projects so requests can be recovered without duplicate submission. Local project files also retain these records. A Topaz estimate sends video metadata and enhancement settings; approving processing sends the selected video. Enhancement settings and job records are saved with the project and in browser recovery storage. Provider download links are temporary; save completed videos to your own storage. The application is hosted on Vercel. A service appearing in Connections does not mean that it receives every project or that every listed integration is operational.
These providers process information under their applicable terms, privacy policies, and account settings. This policy does not promise particular provider retention periods or training exclusions. Only submit material you are authorized to use and share with the selected service. Processing may occur in countries other than your own.
Pinterest connection — planned, not currently enabled
The Pinterest connector is under development and subject to Pinterest approval. It is intended to let an authenticated account owner browse their own boards and Pins and associate references with creative projects. It is not currently collecting Pinterest data through the API.
Before activation, this policy will be updated to identify the permissions requested, account and board information retrieved, authorization-token storage, reference caching, retention, and disconnection and deletion controls. Authorizing Pinterest access will not by itself authorize sending Pinterest media to an AI provider. Any such feature must respect Pinterest’s requirements and applicable permissions for the media.
Retention and deletion
Browser copies remain until the relevant site data is cleared or otherwise removed. Drive copies remain until you delete them from the selected folder. Clearing browser data does not remove drive copies, and deleting drive files does not necessarily remove browser recovery copies. Keep a backup of work you want to retain before removing site data.
Server-side records and hosting logs are separate from those local copies. Contact the privacy address above to request review or deletion of information held by D’Alessio. The current application has no automatic expiry or self-service deletion for server project records. Where those records exist, removal requires administrator action. Hosting logs and infrastructure backups follow the hosting or database provider’s configured retention; deleting an active record does not imply immediate removal from every backup. Contact us to identify the copies involved and request deletion. External providers may separately retain requests and outputs under their own policies.
Your choices
You can choose which materials to submit, which available generation provider to use, and whether to grant browser folder access. You can revoke folder permissions through your browser. Revocation prevents future access but does not erase existing copies.
Depending on the laws applicable to you, you may have rights to request access, correction, deletion, or other handling of personal information. Send requests to the privacy contact above; we may need information to verify your request.
Security
Provider API credentials are configured on the application server. Device security and browser permissions also affect the protection of local projects. No system can guarantee absolute security. This policy does not represent that account authentication, user isolation, or a secure Pinterest token store has already been implemented.
Higgsfield account connection
When you connect Higgsfield Ultra, D’Alessio stores encrypted access and refresh tokens on its server and displays your account identity and credit balance. Selected prompts and references are sent to Higgsfield when you use its tools. Job records and media references are saved with your project. This connection is shared by people who can enter this password-protected workspace; they can spend the connected credit balance. Disconnecting removes the stored authorization and attempts provider revocation, but does not delete saved projects, job records or downloaded files. You can also revoke access in Higgsfield.
Changes
This policy carries an effective date. Changes to connected services or data handling will be reflected in updated policy text before those features are represented as available.