Privacy policy

Last updated: October 7, 2026

1. Who we are and when this policy applies

Viewst, Inc. (“Viewst,” “we,” “us”) provides a creative production and design platform. This policy explains how we handle personal information through our website, application, customer support, business communications, and related services. Personal information means information that identifies, relates to, or can reasonably be linked to an individual.

For account administration, billing, website operations, and our own business communications, Viewst generally determines how and why information is processed and acts as a controller or equivalent business under applicable law. When we process personal information in an organization's workspace on its behalf, we generally act as its processor or service provider. In that situation, the organization's instructions and applicable data processing agreement govern that processing. Contact your organization about its own practices and decisions; you may also contact us, and we will help route your request.

This policy explains our privacy practices. Our Terms of Use govern use of the service. Signed customer agreements and applicable data processing agreements may provide additional protections; this policy does not reduce those protections or your rights under applicable law.

2. Information we collect

Account and business contact information
Examples and sources: Name, email, organization, workspace membership, role, login credentials, and contact details supplied by you or your organization.

Workspace content and collaboration
Examples and sources: Designs, images, videos, text, uploaded files, comments, sharing settings, and related metadata supplied by users. Content may contain personal information about other people.

AI feature information
Examples and sources: Prompts, selected media, instructions, context submitted with a request, generated results, and request metadata when you use an AI feature.

Billing and transactions
Examples and sources: Billing contacts, addresses, subscription selections, invoices, payment status, transaction identifiers, and payment information handled through Stripe. Stripe also handles information under its own applicable privacy terms.

Support and communications
Examples and sources: Requests, correspondence, attachments, feedback, and information you supply when working with our team.Usage, device, and security informationIP address, browser and device information, activity timestamps, pages or features used, error reports, and security logs generated through use of the service.

Analytics, interaction, and marketing information
Examples and sources: Browser or device identifiers, referral information, pages viewed, feature-use events, interaction timestamps, preferences, and campaign interactions. Google Analytics, Hotjar, and Amplitude help us understand use of the website and service. Where session replay, heatmaps, or feedback features are enabled, this may include clicks, scrolling, page interactions, and feedback you submit. Section 6 explains these activities and your choices.

Connected services

Examples and sources: Information and access permissions provided by services you or your organization connect, limited by the integration and permissions selected.

Account credentials and some customer content may be sensitive personal information under applicable law. Please provide only information necessary for your work and that you are authorized to process.

Some account and payment information is necessary to create an account, deliver a requested service, or complete a purchase. Without it, we may be unable to provide that function. Optional marketing consent is separate from access to the purchased service.

3. Why we use information

We use information to create and administer accounts; deliver requested design, collaboration, export, integration, and AI functions; process payments; answer support requests; investigate errors; maintain and secure the service; prevent misuse; communicate about accounts and service changes; and comply with legal duties or handle disputes. We also use service usage information to understand performance and improve usability. Our use of customer content for model training is addressed separately below.

We may send product news or offers, subject to applicable marketing rules and your choices. Marketing messages are distinct from necessary account, billing, and security communications. We may use aggregated or de-identified information for operational analysis only where it no longer identifies individuals under the applicable legal standard. We treat information that can still reasonably identify an individual as personal information.

4. AI processing and any future training program

Viewst does not currently use customer workspace content, including uploaded media and AI inputs and outputs, to train or fine-tune AI models. We use that content to deliver the functions you request and for the support and security purposes described in this policy and our agreements.

Viewst uses business APIs provided by OpenAI, Anthropic, Replicate, and fal.ai. Depending on the feature and routing, a request may be processed by one of these platforms and its relevant model or infrastructure providers. We submit the information needed for the requested function through Viewst's integrations; this does not require a personal account with each provider.

Provider retention, abuse monitoring, human review, and processing locations depend on the specific service, model, settings, and applicable agreements. Using an API does not mean that data is never retained. These arrangements are separate from Viewst's own model-training practices. Contact us for information about a feature's processing arrangements. Additional restrictions in a signed customer agreement remain applicable.

Future training would be a separate choice. If we introduce a voluntary model-improvement program, we will explain the specific content, purposes, models, participating providers, retention, and withdrawal arrangements before asking for affirmative authorization. Participation will be off by default. Acceptance of general terms, use of an AI feature, payment, renewal, or public sharing of a design does not enroll you or authorize use of historical workspace content.

Participation requires appropriate authority, content rights, and a lawful basis for any personal information involved. Customer authorization alone does not replace any additional consent or other legal requirement relating to individuals whose information appears in the contributed content.

Declining optional training will not remove access to the service you otherwise purchased. You may withdraw by the same channel used to enroll or by contacting hello@viewst.com. Withdrawal stops new use under that authorization; applicable erasure and other privacy rights continue to apply. Before enrollment, we will explain the effects on training data and already-trained models, including any technical limitations. Any retention or technical limitation remains subject to applicable privacy law. This policy does not itself enroll anyone in a training program.

5. Who receives information

We disclose information as needed to the following recipients:

  • Infrastructure and service providers: Google Cloud for live application hosting; Stripe for payments; the AI platforms described above for selected features; and providers supporting communications, diagnostics, and service operations.

  • Security support: our engineering team manages security, supported by Beagle Security and Sprinto. Information made available for security support depends on the task and the access needed to perform it.

  • Your organization and collaborators: workspace administrators and people with whom you share content, according to their permissions and your organization's arrangements.

  • Connected services and public recipients: recipients you select through integrations or publication. Shared links and exported materials can be copied by their recipients.

  • Analytics providers: Google Analytics, Hotjar, and Amplitude, for traffic measurement, product analytics, and user-experience analysis described in section 6, subject to applicable choices.

  • Professional advisers, authorities, and transaction parties: where necessary to comply with law, protect rights or security, obtain professional advice, or evaluate or complete a business transaction, with safeguards appropriate to the circumstances.

When providers process personal information on our behalf, applicable processing restrictions govern that use. Some recipients, including payment providers for certain activities and services you independently connect, act as separate controllers. Their notices explain their own processing; that does not remove Viewst's responsibilities for its disclosures.

6. Cookies, analytics, and marketing choices

Viewst does not sell personal information for money. We use Google Analytics, Hotjar, and Amplitude to understand website and product use and improve the service. We have removed Facebook/Meta and LinkedIn tracking tools from our website.

Google Analytics
Purpose and information: Website traffic and usage measurement, such as pages viewed, referral sources, browser/device information, and interaction events. The information collected depends on our configuration. Google's explanation of partner-site data processing.

Hotjar
Purpose and information: User-experience analysis. Depending on the features enabled, this can include heatmaps, session replays of website interactions, and feedback or surveys. Replays can reconstruct activity within the monitored page, including clicks and scrolling; they are not a general recording of your device. Hotjar privacy information.

Amplitude
Purpose and information: Product analytics, such as feature-use events, navigation paths, and usage patterns. Event data may be associated with a device or account identifier where configured. Session replay, if enabled, also captures interactions within monitored pages. Amplitude privacy information.

These tools may use cookies, local storage, or similar technologies. Data linked to a device or account is not necessarily anonymous. Collection varies by the page, selected features, settings, and your consent choices. Where applicable law requires consent for nonessential tracking, that consent is required before the relevant collection. You may withdraw consent without affecting the lawfulness of processing before withdrawal.

Essential cookies and similar technologies support functions such as authentication and account security. Analytics technologies support measurement and service improvement as described above. Cookies may expire when your browser closes or remain until their configured expiry or deletion. You may use the privacy controls displayed on the website, where available, adjust browser settings, or contact hello@viewst.com about analytics processing, consent withdrawal, and applicable access or deletion rights. Browser controls may apply only to that browser or device and do not necessarily remove previously collected information. Blocking essential cookies may affect functions such as sign-in.

You may unsubscribe from marketing emails or contact hello@viewst.com to object to direct marketing. Necessary account, billing, and security messages may continue. We may retain a minimal suppression record to honor your choice. Cookie consent, email marketing consent, and permission to train on content are separate choices.

Some privacy laws define “sale” more broadly than a payment and separately regulate “sharing” for cross-context behavioral advertising. Where a disclosure is treated as a sale, sharing, or targeted advertising under applicable law, the relevant opt-out rights apply even if no money changes hands. Where applicable, you may opt out of sale, sharing, or targeted advertising by contacting hello@viewst.com or using available website privacy controls. Where applicable law recognizes an opt-out preference signal, including Global Privacy Control, that signal is a request to opt out of the processing covered by the law. These rights do not require closing your account.

7. Legal grounds where required

Where European or other applicable law requires a legal basis, the basis depends on the activity and our role:

  • Contract: processing necessary to provide a service you personally contract for or take requested steps before that contract.

  • Legitimate interests: proportionate business account administration, service reliability, security, fraud prevention, support, and lawful business communications, after considering the effect on individuals. Where the customer is your employer, this basis may apply instead of a contract with you personally.

  • Consent: optional activities for which consent is required, including relevant tracking, marketing, and any future training participation that relies on consent. A reasonable expectation is not a substitute for consent.

  • Legal obligation: necessary accounting, compliance, and legally required disclosures.

When we act as a processor, the customer determines the legal basis for its processing and we act on its documented instructions. Sensitive information requires any additional conditions prescribed by law.

You may object to direct marketing at any time. You may also object to processing based on legitimate interests, and withdraw consent without affecting the lawfulness of processing before withdrawal. Contact hello@viewst.com.

8. Location and international transfers

Viewst hosts its live application on Google Cloud in the United States. AI processing, other providers, and authorized support access may involve other countries. US hosting is not a promise that every copy or processing activity remains in the United States.

International transfers are subject to applicable data protection requirements. Where required, those requirements include an applicable adequacy decision or appropriate transfer safeguards, such as standard contractual clauses, relevant UK transfer terms, and supplementary measures. Contact hello@viewst.com for information about the arrangements applicable to your data and how to obtain a copy or description of relevant safeguards, subject to protection of confidential information. Use of the service does not constitute blanket consent to international transfers.

9. Retention and deletion

We retain personal information only for as long as necessary for the relevant purpose, taking account of the type of information, account status, customer instructions, statutory recordkeeping, security needs, and specific legal claims. Cancellation of a subscription and a request to delete data are separate actions.

Workspace content and account records needed to provide service
Kept while needed for the account or agreed service, subject to your deletion rights and customer instructions. The deletion process below applies to a valid request.

Billing and transaction records
Kept for applicable tax, accounting, payment-dispute, and legal recordkeeping periods. This does not justify retaining all workspace content.

Analytics and interaction records
Kept for the period necessary for documented measurement and improvement purposes, based on the configured provider retention settings, applicable consent, and deletion rights. Identifiable event or replay data and genuinely anonymous aggregate reports may have different retention rules.

Support and security records
Kept only while needed to resolve the issue, investigate a specific security concern, or satisfy a documented legal requirement; access and scope are restricted.

Marketing preferences and request records
Minimal records may be kept to honor an opt-out, demonstrate handling of a request, or meet a legal recordkeeping requirement.

Backups
Deleted or overwritten through a bounded rotation cycle as described below, subject to a specific lawful preservation requirement.

To request deletion, contact hello@viewst.com. We may verify your identity and authority using proportionate measures. Where we act for an organization, we coordinate with that organization while addressing any separate obligations we have.

Live application: once the request is verified and its scope confirmed, we immediately remove the requested content from the live application, except for information we are legally required or otherwise legally entitled to preserve for a specific purpose. Save or request an export before deletion if you need a copy.

Other active systems: we complete deletion or irreversible anonymization of eligible information under our control within 30 calendar days of verification, and sooner where applicable law or a signed agreement requires. This includes related active storage, temporary files, caches, and searchable derivatives. We initiate deletion instructions to relevant processors promptly and track their responses. Their separate legal retention duties may affect completion.

Backups: residual copies are put beyond ordinary use and expire no later than 90 calendar days after deletion from active systems, unless a specific lawful preservation requirement applies or a shorter period is required. If a backup is restored for recovery, deletion instructions are reapplied before the affected data returns to ordinary service. Backup copies are not a source for marketing, analytics, or model training.

Exceptions and confirmation: if we retain anything, we explain the categories, reason, and applicable retention period or criteria unless prohibited by law. We distinguish live-system completion from pending backup or provider deletion. Copies that other users have independently downloaded or published may be outside our control; we take required steps to notify recipients or assist with removal. Deletion from our live application does not mean every independently retained third-party copy is erased at the same time.

We respond without undue delay and within the applicable legal deadline. Where a lawful extension is available and needed, we explain it within the initial deadline. Any earlier deadline under applicable law or a signed customer agreement remains applicable.

10. Security

We use administrative, technical, and organizational measures intended to protect personal information against unauthorized access, loss, and misuse. Our engineering team is responsible for security and uses external security support. No service can guarantee absolute security. If an incident requires notification under applicable law or a customer agreement, we provide the required notification. Send security concerns to hello@viewst.com, which is monitored daily.

11. Your rights and how to use them

Depending on your location and applicable law, you may request confirmation of processing, access, a copy or portable version, correction, deletion, restriction, withdrawal of consent, or an objection to processing. You may also have rights to opt out of sale, sharing, targeted advertising, or specified profiling, and to limit certain uses of sensitive information.

Email hello@viewst.com with your request and enough information to locate the relevant account or information. Do not send identity documents or sensitive information unless requested through an appropriate process. We use proportionate verification for requests that require it; a marketing or applicable sale/sharing opt-out is not subject to the same verification requirements as disclosure of account data. An authorized agent may act for you where permitted, with appropriate evidence of authority.

We do not unlawfully discriminate against you for exercising privacy rights. If we decline a request, we explain why, subject to lawful restrictions. Where you have an appeal right, email hello@viewst.com with “Privacy appeal” in the subject. You may complain to the regulator in your jurisdiction; EEA residents may contact their local supervisory authority and UK residents may contact the Information Commissioner's Office. You do not need to contact us first to use a right to complain.

US state notice: where state privacy laws apply, the categories, sources, purposes, and recipient categories in sections 2–6 describe our processing; section 9 explains retention. California rights include applicable access, correction, deletion, sale/sharing opt-out, sensitive-information limitation, and nondiscrimination rights. The sale/sharing distinction and applicable choices are explained in section 6; Viewst does not sell personal information for money. Contact us to exercise the rights applicable to you.

12. Children and third-party services

Viewst is a business-oriented service and is not directed to children. If you believe a child has provided personal information contrary to applicable requirements, contact us so we can investigate and take appropriate action. Account eligibility is governed by our terms and applicable law.

Third-party sites and services have their own privacy practices. Review their notices before connecting accounts or publishing content. This does not limit responsibilities we have for providers acting on our behalf.

13. Changes and contact

We will update the date when this policy changes and provide notice of material changes as required. Where a change requires consent, we will obtain it before the relevant new processing. A policy update alone does not enroll existing or former customers in model training or override signed customer restrictions.

Viewst, Inc.
541 Jefferson Ave., Suite 100
Redwood City, CA 94063, United States
Email: hello@viewst.com