How we handle your data.
This site collects as little as a website can, and this page says exactly what happens to the little it does collect. No cookies, no ad trackers, no analytics vendors.
1 · What sovereign means here
On this site, sovereign describes you, not our servers. It is our fourth principle turned on ourselves: any system, at any time, must preserve your right to keep control of your own data.
Here that comes to three things. We hold nothing that identifies you unless you send it: no cookies, no browser storage, and visits counted as daily totals. To send a form you tick a consent sentence first; without the tick, it cannot be sent. And you can take it back: email our contact address with the subject “Withdraw consent” and we delete your record within 30 days.
It does not mean your data stays on our own machines, or in your country. Your request passes through a small service we run on Amazon Web Services in Oregon and is kept in HubSpot, a US company that processes it for us. GitHub serves the pages, Google the typefaces, and cdnjs one library on the home page. Nor is it a certification.
If a sentence isn't true on the page, it isn't true in the system either. So check it.
2 · What the contact forms collect
When you send one of our three request forms (a 30-minute call, an introductory call, or a memo request), we receive only what you type:
- your first name, surname, and email address;
- your phone number and company or organization, if you choose to add them;
- your answers to the form's questions — the question you'd like answered, what you're building, team size, timeline, preferred timing, goals, today's workflow, and any notes;
- the consent sentence you ticked before sending (see Consent).
The submission also carries the address and title of the form page you sent it from, so we know which request you made. The page adds no IP address, no device fingerprint, and no identifier of any kind. Optional fields left blank are not sent at all.
3 · Where it goes
When you press send, your browser sends the form to a small service we run ourselves on Amazon Web Services in Oregon, US. It does one job: it checks that the request is not automated spam and passes it to HubSpot, the customer relationship system we use to keep track of conversations. Our service keeps none of what you typed, and it does not log your IP address or your browser details. It keeps two small things: a log line saying that a request arrived, when, and whether it went through; and, for up to two days, a marker that the spam check behind your request was used, so that it cannot be used twice. Neither says anything about you. HubSpot processes the data on our behalf and hosts it in the United States.
The spam check is automatic. Your browser does a short calculation, usually a second or less, and our service verifies the result. There is no puzzle to solve, no cookie, and no outside company involved in it.
We use what you send for one purpose: to reply to your request and follow up on the conversation you started. We do not sell it, rent it, share it with anyone else, or add you to a marketing list. If you would like it corrected, email our contact address and we will do so and confirm. To have it deleted, see how to withdraw consent below.
If a submission cannot be delivered, the page offers a pre-filled email containing the same answers instead — nothing is silently lost, and nothing is stored anywhere else.
4 · Consent and how to withdraw it
Each request form ends with a checkbox that must be ticked before the form can be sent. The sentence next to it reads:
I agree to allow GNStudio.AI to store and process my personal data so it can reply to this request.
Ticking it gives GNStudio.AI your consent to keep what you typed in our CRM and to use it to answer the request you sent and follow up on that conversation. It is not consent to marketing: we do not subscribe you to a newsletter or any mailing list. When you send the form, that exact sentence and the time you sent it are recorded with your request. If the box is not ticked, nothing is sent.
You can withdraw your consent at any time, without giving a reason. Email our contact address with the subject “Withdraw consent”, from the address you used on the form (or tell us which address it was). We will permanently delete your record from our CRM within 30 days and confirm to you that it is done.
Withdrawing consent does not undo what was done before you withdrew it, such as a reply we had already sent. Once your record is deleted, our CRM holds nothing about you.
6 · Telemetry
To know roughly how many people read each page, the site sends a tiny beacon to a service in
our own AWS account (Oregon, US). The beacon contains the page path, the host name of
the site that referred you (not the full address), a coarse device size (mobile, tablet, or
desktop), and, if you open a request form, the event names contact_start and
contact_submit. The page adds nothing else. Like every web request, the beacon
also arrives with your IP address and your browser's identification string; the next
paragraph says what happens to them.
On our service, your IP address is truncated (the last part is discarded), combined with your browser's identification string and a random salt that changes every day, and turned into a one-way hash. That hash is kept for at most two days, next to that day's salt, for one purpose: so the same visitor is not counted twice in a day. Then both are deleted, and what remains is daily totals. Raw IP addresses and browser strings are never stored or logged, and because the salt changes daily, nothing links one day to the next.
If your browser sends a Do Not Track or Global Privacy Control signal, the beacon is not sent at all.
7 · Third-party requests
Your browser contacts three outside services while using this site:
- GitHub Pages — the host. It serves the pages themselves, on every visit, from this site's own address, through the delivery network GitHub uses (Fastly).
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — the typefaces, loaded on every page.
- cdnjs (Cloudflare) — the Three.js library that draws the decorative globe on the home page; skipped on small screens.
Each of these sees your IP address in the ordinary course of serving a request, as any web host or server does. None of them sets a cookie on this site.
When you submit a contact form or load a page, your browser also contacts our own service on
Amazon Web Services (an address ending in amazonaws.com). Your browser never
contacts HubSpot; our service passes your request on.
8 · Check it yourself
The footer of every page says trust can be checked, not just claimed. So here is how, in any desktop browser.
- No cookies, no storage. Open developer tools (F12, or right-click and Inspect; Safari needs its Develop menu switched on first), then Application (Chrome, Edge) or Storage (Firefox, Safari). Cookies, Local Storage, Session Storage and IndexedDB for this site are empty, before and after sending a form.
- Who your browser talks to. Open the Network tab and reload. You will see
this site, Google Fonts (two addresses,
fonts.googleapis.comandfonts.gstatic.com), cdnjs on the home page (in a wide window), and one address containingus-west-2.amazonaws.com, which is our own service in Oregon. No HubSpot, no analytics company, no CAPTCHA company. - The visit counter. In the Network tab, with the filter on All, click the
request named
collect(Chrome lists its type as ping) and read what it sent: the wordpageview, the page path, the site you came from (or the worddirect), and whether your browser window is phone, tablet or desktop size. On a request form there is a second one, carrying only the event namecontact_startand the form's short name. Turn on Global Privacy Control, or Do Not Track where your browser still offers it, reload, and these requests are gone. If one of the two was already on, they were never sent.
Two limits, stated plainly. What a browser cannot show you is what our service does after it receives a request; for that you have this page and our word.
And the “Human / AI-assisted” split on the card is our own estimate of how each page was made, not something you can measure from outside.
9 · Questions and changes
Anything unclear, or a request about your data: write to our contact address. The address is kept out of this page's source so that spam harvesters cannot collect it, which is why it appears only with JavaScript turned on. If this page changes, the effective date above changes with it. Effective 5 October 2026.