Evokativ Creative Workspace
Privacy Policy
Last updated: 6 October 2026
Evokativ operates Evokativ Creative Workspace, a local image and video creation workspace for assigned creators. Quiet Flow AI develops the workspace and hosts these public information pages. The current local pilot stores workspace data on the operator's computer. This policy explains how the workspace and its public information pages handle personal data. For support or privacy requests, contact ocean@evokativ.io.
1. Google sign-in data
We request only the Google permissions openid, email and profile. We receive a verified email address, a stable Google account identifier and identity-verification claims. Basic profile information, such as a name or profile picture, may be included by Google; the current workspace does not save Google's profile name or picture. The display name in the workspace is managed by its administrator.
We store your assigned email address, the linked Google account identifier, the time of linking, and authentication and access records. We use this information to match you to an assigned workspace user, authenticate you, protect access and support your use of the app. Unassigned or disabled accounts cannot enter.
Google authorization codes and identity tokens are processed during sign-in. The current app does not retain Google access or refresh tokens for continuing Google API access. It creates its own session, which expires after eight hours. We do not request access to Gmail messages, Google Drive files, calendars or contacts, and we do not ask for your Google password.
Google sign-in data is not sold, used for advertising or used to train AI models. We use it for the sign-in and access purposes described here. Our use of information received from Google APIs follows the Google API Services User Data Policy, including applicable Limited Use requirements.
2. Creative content and workspace records
The workspace stores prompts, uploaded image references, settings, drafts, generation status, generated images and videos, revisions and linked source jobs. It also stores creator identity and access settings, allowances, accepted credit estimates, reservations, calculated usage and accounting evidence when available.
These records support media creation, history, downloads, routing, allowance enforcement, troubleshooting and accounting review. Calculated usage is based on accepted estimates. A provider charge is treated as verified only when supporting evidence can explicitly link it to the job.
Creators can access their own workspace records and files. Authorized workspace administrators can review creators' outputs, prompts, references, identities, access and usage records to operate the service.
3. Sharing and service providers
Google: Google processes your sign-in and supplies identity information under its own Privacy Policy. The workspace does not send creative prompts or media to Google as part of sign-in.
Higgsfield: To quote and generate media, we send the selected model, prompt, settings and necessary reference images to Higgsfield through administrator-connected subscription accounts. Higgsfield processes generation requests and returns results. Your Google sign-in tokens and linked Google account identifier are not included in these generation requests. Personal data you put in a prompt or reference will be sent with that content. Higgsfield's own data practices and terms apply to its processing; see Higgsfield's website.
Public page hosting: Quiet Flow AI hosts these information pages using Cloudflare Pages. Cloudflare processes technical request information, such as IP address and browser/request metadata, to deliver and secure the pages under its Privacy Policy. Workspace identities, credentials, prompts, media and the local database are not part of this static website deployment. These pages contain no analytics scripts, advertising trackers, sign-in form or upload form.
We may disclose relevant information where needed to investigate security incidents or comply with applicable legal obligations. This policy does not promise or describe public sharing of creator media. Downloading and publishing your own outputs is a separate action under your control and your organization's instructions.
4. Storage, security and retention
The current pilot stores workspace records, media, reference images and provider credentials on the operator's computer and in operator-managed backups. Browser local storage keeps draft and recovery copies on the browser profile you use. Workspace administrators separately authorize Higgsfield connections; creators do not receive those credentials.
The app uses authenticated access, ownership checks and session controls. Connections to Google and Higgsfield use HTTPS; the current workspace browser connection uses the local computer's loopback address. Local files and backups depend on the operator's device security and access controls. We do not represent this pilot as a publicly hosted or fully encrypted-at-rest service.
The pilot has no automatic deletion schedule for saved creative content and history. Records remain until an administrator performs an approved cleanup or handles a valid removal request. Audit and accounting history is preserved; some records may need to remain for security, financial integrity or applicable obligations. Backup copies are handled separately and may retain earlier records until those copies are replaced or removed. No specific deletion deadline or backup-retention duration has yet been established for this pilot.
5. Your choices and requests
You can stop using the workspace, sign out, ask an administrator to disable your access, and remove the app's Google connection through your Google Account connections settings. Removing Google's connection does not by itself erase stored workspace history or end an already-issued workspace session. Ask the administrator to revoke workspace access as well.
Contact ocean@evokativ.io to request access to, export of, correction of or removal of your personal data and creative content. Include the Google email assigned to your workspace and the request you want us to review; do not send passwords, tokens or private media unless a secure channel has been arranged. We may verify your identity. Requests are handled manually. We will explain any records that cannot be removed and any backup or provider-processing limitations. Data already sent to a provider is also subject to that provider's processes.
Draft copies on your device can remain after sign-out. On a shared device, use a separate browser profile and clear its workspace site data when appropriate. Clearing browser data does not delete server records.
6. Intended users and policy changes
This workspace is intended for assigned professional creators and administrators, not as a service directed to children. If we change the information we access or the purposes for which we use Google data, we will update this policy and provide any notices and renewed consent required before the new use. Review the date above for the current version.