Security
How Desu Studio protects your work
Effective July 24, 2026 · Last updated July 26, 2026
On-device by design
Editing, effects, and AI background removal all run in your browser. Your images are not uploaded, because Desu Studio has no cloud storage, so your work can't be leaked, subpoenaed, or trained on from our side. The only data that reaches our servers is your account basics: who you are and your subscription status.
No passwords
Desu Studio has no passwords to steal. Sign-in is handled by Google, so your account inherits the protections on your Google account, including two-factor authentication if you use it. We never see or store credentials.
Data in transit and at rest
All connections to desustudio.com and our backend use TLS. Account data is encrypted at rest on our infrastructure provider (Supabase, on AWS).
Access controls
Every cloud record, meaning your profile and any synced account data, is scoped to your account with row-level security enforced at the database layer, not just in application code. Server-side credentials never ship to the browser.
Payments
Checkout happens on Paddle, our PCI-DSS-compliant merchant of record. Your card details are entered on Paddle's systems and never pass through desustudio.com.
Account deletion
You can delete your account yourself, from inside the app. Deletion is immediate and complete: your account record and any synced account data are removed, and any active subscription is canceled. Everything on your device stays exactly where it is.
Reporting a vulnerability
If you believe you've found a security issue, email support@desustudio.com with “[security]” in the subject. We'll acknowledge within 72 hours, keep you informed as we fix it, and credit you if you'd like. We won't pursue legal action against good-faith research that respects user data and privacy.