AI Router · CLI · MCPCheapest eligible quotes before you create
commercial · decision

Data boundaries in hosted MCP media generation

Separate account storage, provider processing, analytics, logs, and owner-authorized delivery.

Compare Studio plans
FAQ interlock

Map the request across account, provider, and storage boundaries

OfflineCreator Studio is a cloud service. The live Privacy Policy is version 2.0, effective August 7, 2026. It says web, API, MCP, and CLI generations follow the same processing model: prompts, settings, and source media are associated with generation work, and fal.ai receives the prompt, settings, and source media needed to run the selected model. The current provider disclosure says the launch catalog is routed through fal, which may operate or broker the underlying model, while the product page distinguishes Studio from the on-device LocalForge path.

Account data, credit ledger entries, generation history, and private media are separate from provider execution but still part of the hosted service. Media remains private unless the account owner explicitly publishes a generation to the Community gallery. Do not describe this boundary as zero retention, end-to-end encryption, anonymous processing, or local generation.

The live policy identifies Cloudflare as the service used for private media storage. Cloudflare's current R2 documentation says buckets are not publicly accessible by default and require explicit permission to expose. Together, these sources support a bounded storage statement, not an independent audit of deployed bucket settings, object-key layout, access controls, or write verification.

Fit filter

Separate analytics and security metadata from creative content

The policy distinguishes first-party product events and optional Google Analytics from private generation content. It states that opted-in Google Analytics receives usage measurements, not prompts, uploads, generated media, or email addresses. It also describes sampled API security logs containing route, status, key identifier, and a truncated one-way network-address hash, while personal API key secrets are shown once and stored as hashes.

These details support a data inventory, not a universal privacy guarantee. Teams should review the effective policy, provider disclosure, cookie choices, and their own client logs before using sensitive material. Work that cannot leave the device belongs on the documented offline path.

Add the buyer's systems to the inventory. A client may preserve prompts in conversation history, a shell wrapper may write arguments to logs, and a downloaded output may move into a team drive even when Studio's own analytics excludes creative content. Approval should cover that complete chain rather than treating the Studio policy as a description of third-party clients and local destinations.

Related circuit

Signed download links expire quickly and require account authorization to mint. The policy lists generation history and media retention until deletion or account closure, temporary uploads and failed-job artifacts typically within seven days, sampled logs up to twelve months, and account or billing records up to seven years. Those categories have different purposes and should not be collapsed into one retention number.

Classify each deletion request by record. Deleting a Studio generation, removing a temporary upload, expiring a signed delivery URL, clearing client history, and addressing provider-held inputs are different operations. Require an owner and verification method for each one. A single “delete project” checkbox should not be assumed to cross every account, provider, client, and downloaded-copy boundary.