Confidentiality
Data Handling
Agencies bring other people's brands in here. This is exactly what happens to that material — in plain language, with the controls you can set yourself.
Last updated August 2026
Your workspace is a closed set
Every Brand DNA, brief, take and campaign belongs to the workspace that created it. Nobody outside that workspace can read it — not another customer, not another agency, not another account on the same plan.
Access is enforced in the database itself with per-workspace rules, not only in the interface. A request that isn't from a seat in your workspace returns nothing.
Within your workspace, you decide who sees what by handing out Director and Performer seats.
We do not train models on your work
Your briefs, Brand DNA and generated narratives are never used to train, fine-tune or improve any model — ours or a provider's.
Content is sent to the model provider only to produce the output you asked for, and only for the length of that request. It is not retained by us for training, benchmarking or examples.
We never use client work in marketing, demos or case studies without written permission.
Who processes what
Hosting and database: the infrastructure that stores your workspace content.
Model providers: receive the brief and Brand DNA needed to generate a take, under agreements that forbid training on the content.
Payment processing: handles cards and subscriptions. Card numbers never touch our servers.
That's the full list. We do not sell data and we do not share it with advertisers.
Retention you control
Directors can set a workspace-level rule: do not retain generation history beyond 7, 30, 90 or 180 days. It lives in the studio under Account → Privacy & retention.
When the rule is on, a daily purge permanently deletes generations, takes, review notes and comments older than the window for every seat in the workspace, and writes the purge to your workspace log.
Retention is off by default, so nothing disappears unless you ask for it. Brand DNA profiles are never purged automatically — those are your character files.
Shared links
Share links are public while they are live, because that is their job. You choose when to create one, when it expires and when to revoke it.
Downloads from a share link are watermarked and delivered through short-lived signed URLs.
Deletion and export
Delete any take from the library and it is gone. Close the account and profiles, generations and share links go with it.
For a full export or a documented deletion for a specific client, write to hello@pesavie.com and we act within 30 days.
Questions
Security or confidentiality review before you bring a client on: hello@pesavie.com.
See also our Privacy Policy and Terms of Service.