Privacy Policy
Studio Makker LLC
Last updated: June 16, 2026
Introduction
Studio Makker LLC ("Studio Makker," "we," "us," or "our") operates the websites tryempress.dev (https://tryempress.dev) and app.tryempress.dev (together, the "Site") and the Empress software-as-a-service platform (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Empress is currently offered as an invite-only testing (beta) service. It is not yet a generally available commercial product, and the tenants and sites created on it during this period are testing instances. By accessing the Site or using the Service you agree to this Privacy Policy and to our Terms of Use .
Our technology and how data flows
Empress is a multi-site operating layer: one application where a business operator can see, talk to, and operate across all of their websites. Understanding where data lives is the most important part of this policy, so we state it plainly.
The Service runs on the customer's own cloud account. When you connect Empress to your Cloudflare account, Empress provisions and operates your sites and their databases, storage, and supporting resources inside your own Cloudflare account under permissions you grant. The content, end-user records, and operational data for your sites are stored in cloud resources that belong to you — not in a central Studio Makker database. We hold only the limited information needed to run the orchestration layer itself (described below).
During the current testing phase, some sites and resources may be operated on Studio Makker–managed cloud infrastructure rather than your own account; in all cases the data-handling commitments in this policy apply.
We process customer data only to provide the Service. We use the data you and your end users put into Empress solely to operate the sites and features you direct us to operate, and to keep the Service secure and working. We do not sell customer data, we do not share it except as needed to provide the Service, and we do not use customer data to train artificial-intelligence or machine-learning models.
Information we collect
We keep collection to what the Service actually needs.
Operator account information. Empress is currently allowlist-gated and uses passkeys rather than passwords. When an invited operator registers, we collect their name and email address, and we store the public-key credential created by their passkey. We do not collect or store passwords.
Connected cloud-account information. When you connect your Cloudflare account, we receive, through Cloudflare's OAuth authorization, your account and membership details and the scoped permissions needed to provision and operate Workers, databases (D1), storage (R2), and key-value namespaces on your behalf, and read-only access to your account's analytics data so we can show you your sites' traffic dashboards. We use these to run your sites and for no other purpose.
Content and instructions you provide. This includes the messages you send to the Empress chat/orchestration assistant, the brand and content settings you configure, and the site content you create or edit through the Service.
Early-access and contact information. If you join a waitlist or contact us, we collect the email address (and any message) you provide.
End-user data on your sites. Sites you run through Empress may collect information from their own visitors and readers (for example, an email address used for reader sign-in via passkey, magic link, or an optional Google sign-in you enable). For that data, you are the controller and we act as your processor; this data resides in your connected cloud account.
Automatically collected operational data. Like any web service, we log technical and security information such as IP address, timestamps, request and error logs, and basic device or browser information. We use this to keep the Service secure, debug problems, and prevent abuse.
We do not knowingly collect special categories of data or biometric identifiers, and we do not collect more personal information than is described here.
How we use information
We use the information above to:
- provide, operate, and maintain the Service and the sites you run through it;
- authenticate operators and protect accounts (passkey registration and sign-in);
- provision and operate resources in your connected cloud account at your direction;
- communicate with you about your account, including service and security notices;
- maintain the security of the Service, prevent fraud and abuse, and debug errors; and
- comply with applicable law and respond to lawful requests.
We do not use customer data for advertising, to build marketing profiles, or to train AI models. Because Empress is in a testing phase, we do not currently process payments or collect billing or credit-card information.
How we share information
We do not sell, rent, or trade personal information. We share information only in these limited ways:
- Service providers (subprocessors). We use a small number of vendors to host and run the
Service. They may process data only to provide services to us and must keep it confidential. Our current subprocessors are listed below.
- At your direction. Where the Service connects to a third party you choose to enable
(for example, Google sign-in for your site's readers), data flows to that third party according to your configuration and their terms.
- Legal and safety. We may disclose information if required by law or legal process, or
where we believe in good faith it is necessary to protect the rights, property, or safety of Studio Makker, our users, or the public.
- Business transfer. If Studio Makker is involved in a merger, acquisition, or sale of
assets, information may be transferred under the same commitments described in this policy.
Subprocessors
- Subprocessor — Purpose — Data processed
- Cloudflare, Inc. — Hosting and compute (Workers), database (D1), object storage (R2), key-value storage, transactional email, browser rendering, image handling, and AI inference (Workers AI) — Operator account data, connected-account data, content and chat instructions, site content, operational logs
- Zhipu AI (GLM model, served via Cloudflare Workers AI) — Powers the Empress chat/orchestration assistant; runs as a model on Cloudflare's Workers AI infrastructure — The prompts and context you send to the assistant. Inputs are processed to generate responses and are not used to train models.
- Google LLC — Optional reader sign-in (OAuth) for customer sites that choose to enable it — Reader email/profile for sites where the operator turns this on
We keep this list current and review the security practices of vendors that handle customer data. Studio Makker does not host customer site data in its own infrastructure; that data lives in the customer's connected Cloudflare account.
Data security
We maintain reasonable administrative, technical, and physical safeguards appropriate to a testing-stage service, including:
- Encryption in transit and at rest. All traffic uses HTTPS/TLS, and data stored in our
cloud provider's databases and object storage is encrypted at rest by the provider.
- Phishing-resistant authentication. Operator access uses passkeys (WebAuthn) rather than
passwords, and operator registration is gated by an explicit allowlist.
- Least-privilege access. Access to systems and data is limited to what is needed to
operate the Service, and privileged actions are logged.
- Tenant isolation. Each customer's sites and data run in that customer's own cloud
account, providing strong separation between customers by design.
No system is perfectly secure, but we work to protect your information and to respond quickly if something goes wrong.
Data breach notification
If we become aware of a security incident affecting personal information, we will promptly investigate, take steps to contain and remediate it, and notify affected customers and, where required, regulators, in the manner and within the timeframes required by applicable law.
Data retention
We retain personal information only as long as needed for the purposes described here or as required by law. As general guidance: operator account records are kept for the life of the account and for a limited period after closure; operational and security logs are kept for a limited period appropriate to security needs; and content and end-user data in your connected cloud account are retained according to your own configuration and are removed when you delete them or close your account. Because your site data resides in your own cloud account, you retain direct control over much of its retention and deletion.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain uses. We honor these rights as required by applicable law, including the California Consumer Privacy Act. Because Empress acts as a processor for the data on your sites, the Service is designed so you can export, correct, and delete that data directly; for the limited operator-account data we hold, contact us using the details below and we will respond as required by law.
We may decline a deletion request only where the law allows — for example, where we must keep information to complete a transaction you requested, detect or prevent security incidents or fraud, fix errors, or comply with a legal obligation.
Marketing email. If we send promotional email, you can opt out at any time using the unsubscribe link. We will still send necessary service and security messages about your account.
Children
Empress is a business tool and is not directed to children. We do not knowingly collect personal information from children under 13 (or the equivalent age of digital consent in your jurisdiction). If you believe a child has provided us information, contact us and we will delete it.
International users
We operate from the United States, and information we process may be stored and processed in the United States and other countries where our service providers operate. We rely on our providers' safeguards for cross-border transfers where applicable.
Changes to this policy
We may update this Privacy Policy from time to time — for example, when the Service changes, our data practices change, or the law changes. When changes are significant, we will provide notice by updating the "Last updated" date above and, where appropriate, by a notice in the Service or by email. Your continued use of the Service after an update means you accept the revised policy.
Contact us
Questions or requests about this policy or your information:
Studio Makker LLC Oakland, California, USA Email: privacy@tryempress.dev