Data location
Written for the person at your institution who has to sign off on this. If they need it in a different form, ask.
Your recordings
| Where | The machine you installed on, and nowhere else |
|---|---|
| Transmitted | Never. There is no code path that uploads a recording |
| Cached remotely | No |
| Verifiable | Yes. All network code is in the Python scripts under Resources/scripts/, readable in the installation |
The same holds for pipeline files, results, figures and anything derived from a recording, unless you deliberately publish it to the marketplace.
Account and website data
| Data | Service | Stored in | Controller |
|---|---|---|---|
| Account, sign-in, sessions | Clerk | United States | Clerk Inc. as processor |
| Catalogue, forum, reviews | Cloudflare D1 | Created in the ENAM region (eastern North America), replicated by Cloudflare | NeuraCrypt |
| Published files, icons, images | Cloudflare R2 | Automatic placement, primarily North America | NeuraCrypt |
| Installers you download | GitHub Releases | United States, served by CDN | GitHub Inc. |
| Request logs | Cloudflare | Edge, short retention | Cloudflare as processor |
Using it with no data leaving at all
You can install Signal Studio, run every pipeline, and never create an account. In that mode the only outbound request is the daily update check, which carries your version number and platform.
To remove even that, block eeg.studio at your firewall. The
application handles the failure silently and keeps working. Update by
downloading installers manually from
the archive.
This is the configuration we would expect a hospital network to want, and it is supported rather than merely tolerated.
Retention
| Item | Kept |
|---|---|
| Account and profile | Until you delete it |
| Published entries | Until you delete them; your choice on account deletion |
| Forum posts | Kept, detached from you on account deletion |
| Install and vote records | Deleted with the account |
| Moderation log | Kept, since it is the record of accountability |
| Cloudflare request logs | Per Cloudflare's own retention, not under our control |
Sub-processors
Cloudflare (hosting, database, storage), Clerk (authentication), GitHub (installer distribution). No analytics vendor, no advertising network, no data broker. Changes to this list are announced on the forum before they take effect.
If you need more
Institutions often need a completed security questionnaire, a data
processing agreement, or a statement on a letterhead. Ask on the
forum or at privacy@eeg.studio.
We would rather answer honestly than have someone guess.