Privacy Policy

Last updated: 1 September 2026

This Privacy Policy describes how Studio X ISH ("we", "us", or "our") collects, uses, and protects your information when you use our website and services at studioxish.com.

Who we are (data controller): Studio X ISH, operated by Inga Sand Holth, Oslo, Norway. Contact: inga.holth@gmail.com. We are the controller responsible for the personal data described in this policy.

1. Information we collect

Account information: When you sign up, we collect your email address and any profile details you choose to provide, such as your name. If you sign in with Google or Apple, we receive the email address (or Apple private relay address) and display name that provider shares with us. We never receive your password.

Usage data: We collect information about the classes you watch, save, and schedule, as well as your membership status and subscription history.

Optional calendar data: If you choose to connect Google Calendar, we store the connection tokens needed to add scheduled classes to your calendar and read back event confirmations.

Purchase information: If you subscribe on the web, Stripe processes your payment and we store your subscription status, plan, and renewal date — never your card number. If you subscribe inside the iOS app, the purchase is made through Apple's In-App Purchase system and we only receive an anonymous purchase identifier confirming that your membership is active.

Technical data: We automatically receive standard device and browser information (such as IP address, browser type, and operating system) to help us keep the service secure and performant.

2. How we use your information

We use your information to provide and improve the studioxish service, process your membership payments, personalise your practice library, send you service emails (such as sign-in and account emails, contact-form replies, and renewal reminders), and respond to your support requests. We do not send marketing or newsletter emails.

3. Sharing your information

We do not sell your personal information. We share data only with trusted service providers that are necessary to run the app:

  • Supabase — for secure authentication, database hosting, and user management.
  • Stripe — for processing membership payments and subscriptions.
  • Apple — for Sign in with Apple and, in the iOS app, for processing In-App Purchase memberships.
  • RevenueCat — to verify the status of memberships purchased through Apple's In-App Purchase system.
  • Vimeo — for hosting and streaming the class videos you watch.
  • Lovable — for hosting the app and sending service emails from notify.studioxish.com.
  • Google — only when you explicitly connect Google Calendar, to sync scheduled classes to your calendar.

Photos and camera: the studioxish app does not access your camera, microphone, photo library, or contacts. Profile images are generated or set from your sign-in provider, so no camera-roll permission is requested.

4. International data transfers

We are based in Norway (EEA). Some of our service providers — including Stripe, Apple, RevenueCat, Google, Vimeo, Supabase, and Lovable — are established in, or process data in, the United States and other countries outside the EEA. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V of the GDPR, namely:

  • the EU–U.S. Data Privacy Framework (and the UK extension / Swiss–U.S. framework where relevant) for providers certified under it; and/or
  • the European Commission's Standard Contractual Clauses, combined with supplementary technical measures such as encryption in transit and at rest, where a provider is not certified under the Data Privacy Framework.

You can request more information about these transfer mechanisms, or a copy of the relevant safeguards, by contacting us at the email address below.

5. Cookies and analytics

We use essential cookies and local storage to keep you signed in and maintain your session. We do not use advertising cookies and we do not sell or share your data with advertising networks. Our video player (Vimeo) may set its own cookies when you play a class; you can control cookies through your browser settings.

6. Data retention

We keep your account information for as long as your account is active. If you delete your account, your personal data is removed immediately, except payment and invoicing records that our payment providers are legally required to retain for accounting and tax purposes.

7. Your rights

If you are in the EU/EEA (including Norway), you have the following rights in relation to your personal data:

  • Access — to obtain a copy of the personal data we hold about you.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to have your personal data deleted ("right to be forgotten").
  • Restriction — to ask us to limit how we process your data.
  • Objection — to object to processing based on our legitimate interests.
  • Data portability — to receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller.
  • Withdraw consent — where processing is based on consent (for example the Google Calendar connection), you can withdraw it at any time without affecting prior processing.
  • Complaint — to lodge a complaint with a supervisory authority. In Norway this is the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no); if you live elsewhere in the EEA you may contact your local authority.

You can access and update your account information, and permanently delete your account and practice history, directly from your account settings in the app or on the website. Deleting your account removes your profile, practice history, subscription record, and any stored Google Calendar tokens. To exercise any other right, contact us at the email below — we respond within 30 days and never charge for these requests.

Deleting your account does not automatically cancel an active subscription: cancel web memberships from your account settings before deleting, and App Store memberships in your iOS subscription settings.

8. Contact us

Studio X ISH, operated by Inga Sand Holth, Oslo, Norway. If you have questions about this Privacy Policy or wish to exercise your rights, contact us at: inga.holth@gmail.com

9. Google user data & data protection

When you connect your Google Calendar, studioxish requests only the minimum scopes required to create, update, and remove the class events you schedule in the app (calendar.events), plus your email address so we can show which Google account is connected. We do not read any other events on your calendar, and we never use Google user data for advertising, resale, or training AI/ML models.

How we protect this sensitive data:

  • Encryption in transit: all communication with Google APIs and with our servers uses HTTPS/TLS 1.2+.
  • Encryption at rest: OAuth access tokens and refresh tokens are stored in our managed Postgres database (Supabase), which encrypts data at rest using AES-256. Tokens are held in a row-level-security protected table and are readable only by server-side code acting on your behalf.
  • Access control: tokens are scoped to your user account via row-level security policies and are never exposed to the browser, other users, or third parties. Only a small number of authorised administrators can access production infrastructure, and all access is logged.
  • Third-party sharing: we do not sell, transfer, or share Google Calendar tokens or any Google user data with any third party outside of the Google API calls needed to operate the calendar features you initiate.
  • Retention & deletion: you can disconnect Google Calendar at any time from your account settings, which immediately revokes the tokens with Google and deletes them from our database. Deleting your studioxish account also deletes any stored Google tokens. To request deletion of your Google-connected data, contact us at inga.holth@gmail.com and we will remove it within 30 days.
  • Security incidents: if we become aware of a breach affecting Google user data, we will notify affected users and Google without undue delay and in accordance with applicable law and our incident-response procedures.
  • Limited use: studioxish's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.