Security & Privacy

Student and client data deserve deliberate protection.

Studio OS Cloud combines technical safeguards with clear photographer responsibilities. This page explains the protections without claiming certifications the service has not earned.

Account separation

Database access rules are designed so one photographer cannot read another photographer’s records.

Protected media access

Private gallery and download routes validate access before protected photos or files are delivered.

Encryption

The service uses encrypted HTTPS connections in transit and encrypted storage for hosted objects.

Two-factor authentication

Photographer accounts can add authenticator-based MFA for an additional sign-in check.

Backup and recovery

Documented backup and recovery procedures protect operational data while respecting deletion and retention rules.

Responsible student-data workflow

Photographers control the rosters, photos, galleries, and access they create. The Data Responsibility Agreement documents consent, authorized use, retention, deletion, and incident responsibilities.

Read the agreement

Payments and account data

Stripe processes card details; Studio OS Cloud does not receive the full card number. Supabase provides authentication and database services, Cloudflare stores media, and Vercel hosts the application.

Read the privacy policy

Report a security or privacy concern.

Do not include passwords, authenticator codes, student photos, or other sensitive material in your first message. We will reply with a safe way to continue the investigation.

Contact Security