Türkçe

Privacy

Last updated 23 September 2026

Short version: we keep as little as we can, and protect what we keep. If you sign in, we keep your email address, encrypted, and nothing else about who you are: no name, no photo. There are no ads, and nothing follows you to other sites. You can take everything we hold about you with you, or delete it, whenever you like.

If you just use the studio

Your browser gets a cookie with a random number in it. That’s how we know it has already had its free performance. The number isn’t linked to you, your device or anything else.

To stop one person from taking endless free performances, we also count free performances per network each day. We never store your address. It gets scrambled together with a secret and the date into a code that can’t be turned back into an address or matched with the next day’s codes, and yesterday’s codes are deleted.

Cloudflare’s Turnstile check runs once, the first time a new browser asks for a performance, to tell people from bots.

If you sign in with your email

We send a six-digit code to your address. When you sign in, we keep the address so we know it’s you next time, can join this sign-in to a Google sign-in with the same address, and can help if something goes wrong with your coins. It is stored encrypted, with a key kept apart from the database, so a copy of the database alone doesn’t reveal it. Only the person who runs the site can see it, only to help you, and every time it’s looked at is recorded. We never use it for marketing without asking, and we never sell or share it. The email itself goes out through Cloudflare’s email service.

If you sign in with Google

We ask Google for the sign-in and your email address, not your name or picture. We keep the address only if Google has verified it, encrypted in the same way and for the same reasons as above (a Google sign-in and an email sign-in with the same address are one account). Of the account number Google gives us, we keep only a scrambled version that works for recognising you when you sign in again.

If you delete your account, your address is deleted with it. We still keep a scrambled code of it (and of the Google account number), only to remember that it already got its sign-in bonus. It can’t be turned back into the address or used for anything else.

Your ideas and performances

What you type is sent to the AI model that writes the performance, and which one depends on the kind you pick. Quick uses DeepSeek V4 Flash, running on Cloudflare Workers AI. Thoughtful and the Premium kinds use OpenAI’s GPT models, reached through Cloudflare’s AI Gateway. Before that, the words alone (nothing about you) go to TypeSafe’s Jev model, which picks the mood for the music and whether the painting gets a stone ground. We keep what you type for 90 days, encrypted like your email, so we can stop abuse and sort out problems (a painting that failed, coins that went missing); then it’s deleted automatically, or straight away if you delete your account. Only the person who runs the site can read it, only for those reasons, and every look is recorded. We never use it to train anything.

If you’re signed in, each performance is saved to your account so you can replay it anywhere. Saved performances are encrypted with a key that belongs to your account alone. If you’re not signed in, they aren’t kept.

Keeping it friendly

Ebru Studio is for everyone, kids too. So before the AI paints, what you type goes through a word filter and through Llama Guard, a safety model that also runs on Cloudflare Workers AI. If a request gets blocked, we count that, and only that: a number for the day, kept under your browser’s random number (or your account’s) and the scrambled network code above. Too many in one day and AI painting pauses until tomorrow. What you typed is kept for 90 days like any other request (above); each day’s counts are deleted the next day.

Your paintings, and sharing them

If you’re not signed in, nothing you paint is kept, not by us and not in your browser. Sign in and your paintings are saved to your account, encrypted with a key that belongs to your account alone, so they’re with you on any device you sign in on. Your browser keeps a working copy only while you’re signed in, and signing out removes it.

If you share a painting, we keep a copy of what’s on the tray and the name you gave it, and anyone with the link can see it. The link is long and random, search engines are asked not to list it, and it doesn’t say who made it. Stop sharing, delete the painting, or delete your account, and the copy is gone and the link stops working.

Buying coins

Coins are sold through Stripe, which is the seller: it takes the payment, handles tax and receipts, and keeps your card details, email and address under its own privacy policy. We never see your card. For each order we keep only what we need to add the coins and to handle a refund: the order number, the pack, the number of coins, the amount and currency, and the date. If you delete your account, those order rows are deleted too; Stripe keeps its own records of the payment.

Invites

If you share your invite link, we keep your invite code, and for each friend who signs in through it, a note linking their account to yours and whether they got their coins. To catch fake invites, we also keep the scrambled network code from the last day you used the studio (see above; it changes every day and can’t be turned back into an address). Neither of you sees the other’s email or anything else. Delete your account and all of this goes with it.

How we learn what’s working

To see which parts of the studio people use and where they get stuck, the site counts a few things: that a visit started (and roughly where it came from, like search or a shared link), which tools and demos get used, whether an AI performance worked, sign-ins, shares, and how smoothly the tray runs on your device. These counts go through our own server to PostHog, our analytics provider. They carry a random id kept in a cookie, never your name, email, IP address, what you type or what you paint. If you’re signed in, they also carry a scrambled code for your account, so we can tell when someone comes back on another device. It can’t be turned back into your email or your Google account. PostHog is in the US, and we’ve told it not to store IP addresses. If your browser sends Do Not Track or Global Privacy Control, none of this happens.

Cookies

That’s all of them. No ads and no third-party trackers: no analytics script runs in the page.

Your data, your call

Signed in, tap your avatar next to the ebru logo, then More. Download my data gives you everything we hold about your account as one file, and Delete account erases your account, your email address, your saved performances, your coins and your order history right away.

Who runs this

Ebru Studio is made by Meriç Dağlı. It runs on Cloudflare: their servers deliver the site, and their database stores what’s described above. If we ever change how any of this works, this page changes first.