Effective date: September 8, 2026.
1. Who we are and what this policy covers
Luxel Publishing LLC ("Luxel", "we", "us") provides software and hosted services for creative work. These include studio workspaces, booking tools, Prism galleries and asset management, Slate projects and documents, Crewlist profiles and collaboration, and account and subscription services.
This policy describes how we handle personal information when you visit luxel.studio, hold a Luxel account, use our hosted services, contact us, or connect an external account to a supported feature. Our privacy contact is Peter Holme at luxelpublishing@gmail.com.
A studio or other business using Luxel has its own relationship with its clients, staff, and collaborators. It decides matters such as what a booking requires, who may access its workspace, and how it uses its customer records. For information we handle on that business's instructions, the business's own privacy notice and our agreement with it also apply. Luxel remains responsible for its own account administration, security, billing, and other purposes it determines. Using Luxel does not make every studio and user part of the same business.
2. Information we handle
The information involved depends on the features you use and the permissions you grant.
- Account and profile information: your name, email address, account identifiers, authentication status, profile details, preferences, and workspace roles. Google sign-in can provide your Google account identifier, name, email address, and profile image. Authentication is handled through our authentication providers; Google sign-in does not give us your Google password.
- Workspace and transaction records: booking details, availability, contacts, project schedules, invitations, messages, contracts, signatures or acceptance records, invoices, support requests, and associated history.
- Files and creative work: photographs, other uploaded files, file metadata, gallery selections, comments, delivery settings, and information you include in documents or messages. Luxel stores and processes hosted content to provide these features.
- Payment and fulfillment information: order details, amounts, payment and refund status, billing or shipping details, and provider identifiers. Payment providers handle payment credentials through their payment flows. A studio or seller may receive information needed to administer the transaction, and a fulfillment provider may receive the details needed to deliver an order.
- Connected-service information: access credentials and the account, calendar, message, or other records that you authorize a supported integration to access. Connecting an integration is separate from simply signing in with Google.
- Technical and usage information: browser and device information, network information such as IP addresses, service activity, security events, and diagnostic records. Cookies and similar storage support sessions, preferences, and optional analytics or marketing features where enabled.
- Information provided by others: a studio, colleague, client, or collaborator may supply your contact details or include you in a project, booking, document, or invitation.
Please do not upload information you are not entitled to share. Avoid including unnecessary sensitive information in files, messages, or support requests.
3. Why we use information
We use information to provide the features requested, authenticate users, apply workspace permissions, store and deliver work, coordinate projects and bookings, process transactions, provide support, investigate abuse, maintain service reliability, and comply with legal obligations. We also use appropriate service information to understand and improve the product.
Service notices, security messages, and transaction communications are different from promotional messages. Optional promotional communications and optional tracking are subject to the choices and permissions applicable to them. Declining optional marketing does not itself cancel your account or a booking.
Where a law requires a legal basis for processing, the basis depends on the activity: performing an agreement or taking requested steps before an agreement, complying with a legal obligation, pursuing legitimate interests such as security and support where permitted, or obtaining consent where required. A studio may rely on its own basis for the processing it directs.
4. Google sign-in and connected Google services
Google sign-in identifies and authenticates your account. It does not, by itself, authorize Luxel to read your Gmail messages or calendars.
If an authorized user connects Google Calendar, we access calendar and event information for availability and booking coordination. The requested permissions can allow us to create, update, and delete events on accessible calendars. If an authorized user connects Gmail, we read message headers, sender and recipient details, snippets, message bodies, and labels for the connected inbox and booking-reply workflows. Some supported booking workflows extract customer, event, and pricing details from messages, including AI-assisted extraction when configured. These integrations are separate from sign-in and are not enabled for every user.
We store connection credentials, including access and refresh tokens, in the connected workspace integration configuration. Authorized calendar and message information can also be stored in booking records, inbox snapshots, and related operational records in our Google Cloud/Firebase infrastructure.
You can review and revoke access through your Google Account connections. Revocation prevents continued access under that authorization but does not automatically delete information already copied into a project or business record. Contact us about deleting retained integration information; records a studio controls may require that studio's instructions and consideration of applicable retention obligations.
Luxel follows the Google API Services User Data Policy when handling Google API information, including its Limited Use requirements. Google Workspace data is used for the disclosed, user-facing integration functions. It must not be used for advertising, sold to data brokers, used to determine creditworthiness, or used to train generalized artificial intelligence or machine-learning models. Human access to restricted Google user data is limited to the circumstances permitted by Google's policies, such as your specific authorization, necessary security investigation, legal compliance, or permitted aggregated internal operations.
These restrictions apply to the Google data involved even when another section of this policy describes a broader use of information from other sources.
5. Who receives information
We disclose information as needed for the service and the choices you make:
- Your workspace and collaborators. Authorized studio staff, invited collaborators, clients, and other intended recipients can receive the information their permissions and the relevant workflow allow. A public profile, published gallery, or shared link can expose information to a wider audience. A recipient may retain an authorized download or copy after access changes.
- Service providers. Infrastructure, authentication, storage, payment, messaging, printing, monitoring, and other providers process information needed for their functions. The service uses Google Cloud/Firebase infrastructure and supports providers such as Stripe, Resend, Quo, Prodigi, and Sentry where the corresponding feature is enabled. Not every provider receives every user's information.
- Connected services you select. An enabled integration may exchange information with the service you connect. Its own terms and privacy practices also apply to the account you maintain there.
- Optional analytics and marketing providers. Where enabled and permitted by your choices and applicable law, these tools may receive online activity or campaign-related information. Google Workspace information subject to the restrictions above is excluded from advertising uses.
- Legal, safety, and business circumstances. We may disclose information when required by law, to respond to a valid legal process, to address fraud or a security incident, to protect rights or safety, or as part of a business transaction subject to appropriate confidentiality and applicable law.
We do not treat uploading creative work as permission to publish it publicly or use it in advertising. Feature-specific sharing and permission settings matter.
6. AI-assisted features
Some supported workflows use automated analysis or AI-assisted processing. When such a feature processes your selected content, the content and instructions needed for that function may be sent to the configured processing provider. Supported processing includes image tagging, assistant conversations, and booking information extraction. The service uses Google Gemini for these functions. Processing can include image content, conversation history, workspace or booking context, and relevant message text. Diagnostic and monitoring systems can also receive personal information associated with service activity. Provider and feature settings affect processing and retention.
AI output can be inaccurate. Review extracted booking details, generated text, and other suggestions before relying on them. The Google-data restrictions above continue to apply to AI-assisted workflows.
7. Retention and deletion
Retention depends on the purpose of the record, the workspace's instructions, your account or subscription, and applicable obligations. Hosted files and active project records may be needed while the service is being used. Transaction, agreement, security, and dispute records can require different retention periods.
Closing an account, revoking Google access, cancelling a subscription, removing a workspace member, and deleting a file are different actions. One does not necessarily perform all the others. We may retain information needed for legal obligations, fraud prevention, dispute resolution, or enforcement of an agreement. Backups and recovery systems may retain copies temporarily after removal from active systems. Copies already delivered to another person are outside Luxel's direct control.
Contact luxelpublishing@gmail.com to request access, correction, export, or deletion and to ask what records can be removed in your situation. We may need to verify your identity or authority over a workspace. If a studio controls the records, we will explain the appropriate route for its involvement. We respond to requests within the period required by applicable law.
8. Your choices and rights
You can use available account, sharing, notification, and cookie controls, revoke a connected account's authorization, and contact us with a privacy request. Unsubscribing from marketing does not stop necessary service or transaction notices.
Depending on where you live and which law applies, you may have rights to access, correct, delete, receive a copy of, restrict, or object to processing of personal information; withdraw consent; or complain to a supervisory authority. Some rights have exceptions. Contact us if you need help exercising an applicable right or using an authorized representative. We will not require you to give up an applicable legal right to use the request process.
9. Security, international processing, and children
We use technical and organizational measures intended to protect information, including access controls and security monitoring. No service can guarantee that every transmission or storage system is completely secure. Protect your login credentials and review who has access to your workspace and shared links.
Our service providers may process information in the United States and other countries. Applicable agreements and legal requirements govern transfers; this policy does not promise that all information remains in a particular country.
Luxel is designed for creative and business workflows, not services directed to young children. If you believe a child has provided personal information inappropriately, contact us so we can investigate and take appropriate action.
10. Changes and contact
We will identify the effective date of the published policy. Material changes will be communicated through an appropriate service notice or other channel, with additional consent where required. The policy in force and the context in which information was collected matter; publication of a revision is not permission to ignore applicable consent requirements.
Luxel Publishing LLC
Privacy contact: Peter Holme