Privacy policy
What we collect, what we do with it, and how to make us delete it. Written to be read, not to be survived.
- We do not sell your data.
- We do not use it for advertising.
- We do not train AI models on it.
- Google data is read only to perform the action you asked for, and is not retained afterwards.
Who we are
Backslash Studio is a technology consulting studio. This policy covers backslashstudio.com and the internal tooling we operate for our own team. Where this policy says "we", it means Backslash Studio.
What we collect
From the website, only what you volunteer:
- Contact and enquiry forms — your name, email address, and whatever you write in the message.
- Booking a call — handled by Google Calendar's scheduling pages, under Google's own terms.
We do not run advertising trackers, and we do not build behavioural profiles of visitors.
From our internal tooling, for the small number of people with access to it:
- Your email address and name, from signing in with Google.
- Credentials you explicitly connect — API keys, and OAuth tokens for services you authorise.
- Operational records of which connections exist and when they were made.
Google user data
Our tooling can connect to Google services on behalf of the account holder. Each service is a separate, individually revocable authorisation — connecting one never implies access to another. You choose which to connect, and you can disconnect any of them at any time.
Gmail, Google Drive and Google Calendar are accessed on a read-only basis: we can list and read, and we cannot send, create, modify or delete anything. Google Docs, Search Console, Analytics and Tag Manager are accessed on a read and write basis, and any write happens only as the direct result of an action the account holder asked for.
What we store is the authorisation itself — an OAuth refresh token per connected account — held in AWS Secrets Manager, encrypted at rest, isolated per account so that one account's credentials cannot be read while acting for another.
What we do not store is the content. Messages, files, documents, and reports are fetched from Google at the moment you ask for them, returned into your session, and not copied into a database, index, log, or training set of ours. Operational logs record that a tool ran and for which account — never the content it returned, and never the credential.
Backslash Studio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generative AI or machine learning models.
How we use it
- To perform the specific action requested by the account holder, or by software acting on their behalf.
- To operate, secure, and debug the service.
- To reply to you when you contact us.
- To meet legal obligations where they apply.
We do not use your data for advertising, we do not sell or rent it, and we do not use it to train generative AI or machine learning models.
Who else touches it
We keep the list of third parties deliberately short. Today it is:
We may disclose information if legally required to. If Backslash Studio is ever acquired, the acquirer would be bound by this policy until you are given notice of a change.
Retention and deletion
Disconnecting a service deletes the stored credential immediately and irreversibly, and withdraws it everywhere it was in use. There is no recovery window.
You can also revoke our access from Google's side at any time, independently of us, at myaccount.google.com/permissions. Doing so stops the connection working at once.
Website enquiries are kept only as long as needed to answer them and maintain a normal business record. Ask us to delete yours and we will.
Security
Credentials are encrypted at rest and in transit, and are isolated per account by access controls enforced by our cloud provider rather than by application logic alone — a request for another account's credential is refused at the infrastructure layer, not merely avoided by our code. Access to the systems holding them is limited to the two of us.
No system is perfectly secure. If we ever become aware of a breach affecting your data, we will tell you.
Your choices
You can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Email us and we will action it — we are a two-person studio, so it reaches a human directly. Depending on where you live, you may have these rights under the GDPR, the CCPA, or similar law; we apply them to everyone regardless.
Children
Our services are not directed to anyone under 16, and we do not knowingly collect their data.
Changes to this policy
If we change how we handle data, we will update this page and move the effective date at the top. Material changes affecting connected accounts will also be surfaced in the product.
Contact
Questions about this policy, or about data we hold: hello@backslashstudio.com.
Backslash Studio · backslashstudio.com · Effective September 10, 2026