Back to Gesso

Gesso · Meridian Studios

Privacy

A clear account of what stays local, what optional services receive, and what we do not use for training.

Last updated: August 23, 2026

Counsel review is required before commercial publication.

Service providers

These companies support specific Gesso features. Opening this page does not contact them.

Resend

A configured deployment may use Resend to deliver account messages, feedback receipts, incorrect-label report replies, and internal report alerts.

OpenAI Codex

sends text and shapes to OpenAI

Turn this on to let Codex read your work and suggest changes. Gesso sends the text and shapes you select, your brand rules, details about your document, and stock photo searches to Codex, using your own Codex account. Codex runs on your computer and talks to Gesso over standard input and output, but what it reads can still go on to OpenAI.

Anthropic Claude Code

sends text and shapes to Anthropic

Turn this on to let Claude Code read your work and suggest changes. Gesso sends the text and shapes you select, your brand rules, details about your document, and stock photo searches to Claude Code, using your own Claude Code account. Claude Code runs on your computer and talks to Gesso over standard input and output, but what it reads can still go on to Anthropic.

Anthropic Claude Code

sends your image to Anthropic

Turn this on to let Claude Code clean up a cutout or a vector trace. Gesso sends the image you selected to Anthropic, through your own Claude Code account. Claude Code runs on your computer, but your image doesn't stay here.

Subject isolation and incorrect-label reports

Forma’s subject isolation uses Apple Vision and runs locally on your device. It separates pixels already present in the image from the background. It does not upload the image or generate replacement people, objects, scenery, or text.

Sending an incorrect-label report is a separate, voluntary hosted action. A report can collect report answers, a reply email when you include evidence and give contact consent, selected evidence, evidence metadata, technical app and release context, and abuse and security records.

Meridian uses this information to investigate the report, respond to the reporter, improve Forma’s export safeguards, and protect the upload service. Submitted evidence is not used for model training, advertising, sale, unrelated product work, or public reuse.

This approach follows data minimization, purpose limitation, transparency, access, and deletion principles reflected in current European Union and California guidance. It does not claim certification, universal legal coverage, or legal advice.

  • Access is limited to authorized Meridian operators. Supabase hosts private report records and evidence. Resend receives the email address and message content needed to deliver report receipts and replies.
  • Evidence uploaded to an unfinished report and its draft metadata are scheduled for deletion after 24 hours.
  • Evidence is deleted seven days after a report is marked Addressed. Report narrative and encrypted contact data are deleted 30 days after Addressed.
  • The report status link lets a reporter delete uploaded evidence earlier. A verified privacy request can also ask Meridian to delete the report and contact data earlier.
  • Forma cannot automatically identify or redact personal information in uploaded evidence. Review visible content and hidden metadata before sending anything.

EU and California privacy choices

Meridian Studios is the controller for information submitted through the hosted report flow. Where European Union law applies, Meridian processes it to provide the requested investigation and for legitimate interests in understanding Forma exports and protecting the report service. A reply email is used only with contact consent. You can withdraw reply consent by writing to legal@meridianproject.studio.

Depending on the circumstances, European rights can include access, correction, deletion, restriction, objection, and portability. You may also complain to your local supervisory authority. Withdrawing reply consent does not affect processing that already occurred and may prevent Meridian from emailing an outcome.

California rights can include the rights to know, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive non-discrimination for exercising a right. Meridian does not sell or share incorrect-label report information for cross-context behavioral advertising.

  • Supabase, Vercel, and Resend may process hosted-service information outside the European Economic Area. Where required, Meridian will use a lawful transfer mechanism; request information about applicable safeguards from the privacy address below.
  • To make an access, correction, deletion, restriction, objection, portability, consent-withdrawal, or California privacy request, email legal@meridianproject.studio. Meridian may need limited information to verify and fulfill the request.
  • These rights depend on the law and circumstances. This notice does not claim that every law applies to Meridian or that every right applies to every request.

Your creative work stays local by default

Gesso is local-first. In the current web app, projects, documents, imported assets, drafts, and interface preferences are stored in browser-managed storage on your device.

Exported SVG, PNG, and JPG files are prepared and downloaded in your browser. Ordinary local editing and export do not upload those files to Meridian. Export important work before clearing site data or removing the browser profile that contains it.

  • You can use the web app without an account.
  • Signing in does not automatically upload, move, or delete projects already stored in this browser.

Meridian does not operate AI models

Meridian does not provide, operate, or train AI models. Gesso does not send your creative work, documents, imported files, exports, prompts, or account information to a Meridian model-training pipeline.

Supported native releases may use Apple Intelligence for narrow, optional suggestions such as proposed names. You choose whether to use and accept a suggestion. Results can be incomplete, inaccurate, or unavailable and should be reviewed before use.

  • Apple Intelligence availability depends on supported hardware, operating-system version, language, and region.
  • When possible, Apple Intelligence runs on the device. Apple may use Private Cloud Compute for some requests, subject to Apple’s settings and privacy information.
  • The web product-event boundary excludes document contents, imported bytes, pixels, filenames, free-form text, and export contents.

AI and connected agent tools

AI and connected agent tools are Off by default. You must turn them on from your Account before Gesso can start or continue AI or MCP work for you. When they are Off, their controls are hidden and Gesso rejects direct or stale requests before it creates context or saves a change.

Gesso has five reviewed connections. Two are MCP connections, one for OpenAI Codex and one for Anthropic Claude Code, where a client you run on your own computer reads approved Gesso context and proposes changes. Two are visual-agent connections, again one for OpenAI Codex and one for Anthropic Claude Code, which send the image you selected to that provider for a cutout or vector refinement. The fifth is Ollama Local, which suggests text on your own device.

A connected agent may address a social campaign or a fixed canvas, may propose changes to your Brand Book, and may read your Work board without being able to change it. The minimum approved inbound context is limited to selected text, brand rules, document metadata, stock photo search results, the shared campaign headline, and — on a canvas only — the position, size and shape geometry of the blocks on it. Gesso does not expose raster or image data, image file identifiers, whole documents, credentials, local paths, or unrelated attachments through the MCP connections, and the visual-agent connections carry nothing but the bounded image projection for the refinement action they name.

Turning on this account control does not authorize every provider, connector, tool, document, or change. Each action remains subject to its own review, permission, and scope checks.

Turning the control Off stops running authenticated work and disconnects pending agent sessions. Accepted edits, local work, workspace sync, and document history remain. After approved context reaches OpenAI through Codex or Anthropic through Claude Code, Gesso cannot recall it; the person’s provider product, account, plan, settings, terms, privacy, retention, and training controls govern that side.

  • Gesso does not use this control as permission to send your whole document, browser storage, credentials, local paths, or unrelated attachments.
  • No hosted model or remote MCP connector is available in the current web V1. A future route must identify its provider and publish its applicable privacy information before release.

AI connection disclosures

This notice describes reviewed connections; it does not activate or connect a provider. AI and connected agent tools are Off by default and hidden. Turning on the master control reveals the individual connections but does not enable any provider; each connection requires its own opt-in and acknowledgement. Gesso sends only the approved data classes for a declared action.

Meridian is responsible for its own collection, authorization, minimization, security, and transfer boundary. Each provider's terms and privacy policy apply in addition to Gesso's, and handling may depend on the provider, product, account, plan, and settings. Model-improvement consent is separate from connection approval.

The reviewed inbound MCP connections authorize the shape geometry of a canvas — the position, size and path of the blocks on it — only where the connection names shape geometry above, and only while a canvas is the open document. The separately reviewed outbound visual-agent connections authorize only a bounded selected raster projection for their named refinement actions. No connection authorizes whole documents, credentials, local file paths, or unrelated attachments.

Inbound MCP connections do not authorize raster or image data, image file identifiers, whole documents, credentials, local file paths, or unrelated attachments.

Turning a connection off stops future processing. Gesso cannot control or recall data a third-party provider has already received.

  • The Codex and Claude Code MCP connections connect a locally started client process to Gesso’s MCP bridge over standard input and output; that client may then send approved context to its provider under the client’s applicable controls.
  • The Codex and Claude Code visual-agent connections reach Gesso’s signed gateway over an authenticated loopback connection, and the agent it starts sends only the authorized image projection for the named refinement action under the person’s provider account and settings; they are not local-model or no-upload routes.
  • Ollama Local processes approved selected text on this device. Model downloads, software updates, account activity, and cloud-model use are separate network paths.

Optional account and sign-in

You can use Gesso without an account. If you create an account or log in, Supabase Auth processes your email address and account session so Gesso can recognize you across sessions.

If you choose Google sign-in, Google and Supabase process the authentication request. Gesso receives the account identity information Supabase makes available for that sign-in, including the account email used by the current account screen, subject to the provider settings and policies.

Authentication emails use the email-delivery service configured for the Gesso deployment. That service receives the recipient address and the message information needed to deliver a confirmation or password-reset email. Do not put creative content in an authentication form.

  • Gesso’s authentication route receives your password only to send the authentication request to Supabase; Gesso does not retain plaintext passwords after that request.
  • Google sign-in is optional. You can use email/password authentication or continue without an account.
  • Logging out removes the account session from this browser but keeps local Gesso work here.
  • Account email and session data are not sent as Google Analytics product-event fields.

Optional web product measurement

The hosted Gesso deployment may enable Google Analytics 4 to help us understand whether people can complete core design tasks. It is optional to the local editor and can be disabled for the deployment.

When measurement is enabled, Gesso sends limited event categories about whether workflows start, reach an editable state, save, recover, import, export, or stop. The app does not send a Google Analytics User-ID or creative content as event fields.

  • Page context uses generic route names. Document and project route segments are replaced with [document] and [project].
  • Product events use categories such as surface, template, format, result, reason, and destination.
  • If measurement is not enabled, Gesso does not load the Google Analytics measurement script.

Product events we measure

The event names are designed to answer one product question: how quickly can someone get useful work done, and where does the workflow stop?

  • Starting and creating documents, projects, and organizations.
  • Opening a document, reaching editor-ready state, making a first modification, saving, and recovering a draft.
  • Importing assets and preparing or downloading SVG and PNG exports.
  • Using library search, universal search, and navigation between Gesso surfaces.

Data we do not put in product events

The analytics boundary removes undeclared fields and only forwards the small categorical schema needed for product decisions.

  • Document IDs, project IDs, organization IDs, names, filenames, or account identifiers.
  • Document text, imported image or SVG bytes, pixels, exported file contents, or other creative content.
  • Search queries, form values, email addresses, or other free-form user input.

Native macOS and iOS apps

The macOS and iOS apps keep core creative processing on the device. Vectorization and image handling do not require a Meridian server, Apple Intelligence, or web product analytics to edit and export work.

The Gesso macOS app can use Apple iCloud and CloudKit when the feature is available and you choose to use it. That path can synchronize document packages, revisions, embedded assets, and collaboration records through Apple. Sharing a document can make copies available to invited participants.

Some native features are explicitly online: Google Fonts browsing or installation can contact font catalog and download services, and iCloud sync or sharing can use Apple CloudKit. These requests are separate from local vectorization and creative editing. Any crash-reporting service added to a native release is a separate data path and must be described in that release’s privacy information.

  • CloudKit sync and sharing are separate from the local document-authoring path and follow Apple’s storage and provider policies.
  • Optional Apple Intelligence suggestions are not required for core editing and remain subject to your review.

Fonts and typography libraries

Gesso can use bundled fonts, fonts available on your device, Google Fonts, and font files you upload. The Google Fonts catalog request is made by Gesso’s server. When a Google font is selected, Google may receive the network information needed to deliver its font files.

Uploaded font files and library metadata stay in local browser or app storage unless you deliberately use a hosted synchronization or sharing feature that includes them. When organization or project font libraries and typography presets are available, they organize font choices for that scope; they do not change the storage or provider boundary by themselves.

  • Font files can contain names and licensing metadata supplied by their publisher.
  • You control which uploaded fonts and typography presets are assigned to an organization or project.
  • Meridian does not claim ownership of uploaded fonts, but you must have permission to use and share them.

Optional Pexels stock photos

If you use Pexels search, Gesso sends the normalized search terms, selected orientation or color filters, page number, and selected photo request through the deployment server. Pexels receives the server request under its own privacy policy. Gesso does not attach your document contents, exported pixels, account identifiers, filenames, or analytics identifiers to that request.

Preview thumbnails load directly from the exact Pexels image host without sending the page address as a referrer. Pexels can still receive network information from that browser request, such as your IP address and browser details. The selected full photo passes through the deployment server so the API key never becomes a browser credential. After import, the photo bytes and verified source details are stored locally with your other library assets. Editing or exporting an already imported photo does not contact Pexels.

Gesso displays “Photos provided by Pexels” and photographer attribution in Pexels-powered browsing, asset details, and Export Review when selected PNG files use those photos. If you choose a ZIP package, a separate manifest.json retains the credit, filenames, artboard names, document title, and export settings. It excludes image bytes and internal document or artboard identifiers. Gesso does not add a Pexels watermark or attribution layer to exported work. The Pexels License says attribution is not required, although credit is appreciated when practical.

  • Pexels browsing is optional and is unavailable when the deployment operator has not configured the provider.
  • Removing an imported photo from your local library removes Gesso’s usable local copy; Meridian does not keep a backup merely because you imported it.

What Google Analytics may collect

When the hosted measurement service is enabled, Google Analytics may use first-party _ga and related Google Analytics cookies to distinguish users and sessions. Google describes its default Analytics collection as including user counts, session statistics, approximate geolocation, and browser and device information.

Google also explains that IP addresses can be used at collection time for location and service operation, then discarded before the data is logged in Google Analytics. Google’s own processing and privacy terms apply to data it receives.

Storage, retention, and deletion

Gesso keeps local work in the browser profile until you remove it or clear the site’s browser storage. In the current build, deleting a document or project removes its catalog entry but does not guarantee removal of every saved or recovery record. To remove all local Gesso data, clear site data for the Gesso origin. Meridian does not have a copy of that local work simply because you used the editor.

Account information and authentication sessions are retained by the configured authentication service while needed to provide the account and protect it. To request help with account information, use the Meridian support page. We will review what can be identified and handled from the data available to us.

Analytics and any separately configured crash-report retention depend on the relevant property or provider configuration. We do not state a fixed period here because those settings must be verified for each production service and release.

Your choices

You can continue without an account, avoid optional hosted features, block third-party analytics scripts, or delete the _ga cookie through your browser controls. These choices can change measurement without changing local Gesso files.

You can log out of the web account, export local work before clearing browser storage, and contact support about information that may be associated with your account or visit. There is not currently an in-app consent panel or account-level analytics preference in this web build.

Questions

For support, contact support@meridianproject.studio. For legal or privacy questions, contact legal@meridianproject.studio. We will review what can be identified and handled from the data available to us.