Updated Sep 23, 2026
Privacy policy
Studio Insights ("we", "us") publishes game development news for Roblox Studio, Unreal Engine, and Unity at studioinsights.net. This page explains what we collect, why, and what you can do about it. Questions go to hello@studioinsights.net.
What we collect
- Email address when you subscribe to the posts. That is all the free tier needs.
- Discord profile when you sign in: your Discord ID, username, avatar, and the email address on your Discord account. Of those, only the Discord ID is written to our database, and only so we can give and take away the members-only role in our server. Your username, avatar, and the email address stay in the session cookie your browser holds while you are signed in. We do match that email against our subscriber list to find your row, and the moment you start checkout it is stored as your subscriber address, the same field the signup form writes, and goes to Stripe along with the display name on your Discord account to create your customer record there. That happens when you begin paying, not when the payment succeeds, so it is stored even if you close the Stripe page without buying anything. We use Discord sign-in only to identify members. We never post to Discord or read your servers or messages.
- Billing records when you become a member. Stripe processes your payment and stores your card details. We store only your Stripe customer ID, subscription ID, and subscription status so we know which tier you are on.
- Advertiser details: company, email, and the headline, copy, and link you submit through the advertise form, plus Stripe's record of the payment.
- Interview requests: the name or studio, email address, Roblox game link, and optional note you send through the be-interviewed form. We keep them in our database and also email a copy to ourselves, with your address as the reply-to, so we can write back.
- Email delivery records: whether a message bounced or was reported as spam, reported by Resend when it carries our mail. A permanent bounce or a spam complaint stops mail to that address. We do not track whether you open a post or which links you click: open and click tracking are switched off at our email provider, so nothing reports them to us.
- Post ratings: the great, fine, or meh link at the bottom of a post records that rating against your email address in our own database, one row per post, so we can see which posts land. Clicking again replaces your earlier answer.
- Site analytics: page views and web performance through Vercel Web Analytics and Speed Insights, only after you accept them in the notice at the bottom of the page. These are aggregate and do not use advertising cookies. Your choice is stored in your browser; clear site data to be asked again.
- Channel code: links we post sometimes carry a short code in the address, like ?src=discord. Your browser remembers it for the rest of the visit and sends it along if you subscribe, so we can see which link brought you. It is kept with your subscription and says nothing about you beyond where you arrived from.
- Bot protection: five things you can submit are checked by Vercel BotID before we act on them, to tell people apart from automated submissions: the subscribe form, the be-interviewed form, the advertise form, the form on studioinsights.net/unsubscribe that emails you your unsubscribe link, and the buttons that start a membership or open the billing portal. A check like that weighs device and behavioural signals: how the browser making the request is put together, and how the submission was made. They are collected by Vercel's script in your browser and judged on Vercel's side when our server asks for a verdict, so we never see them. What reaches us is one yes or no, which we act on and do not store. While the site is closed to the public, the two forms on the holding page are not covered by it: they are limited by a count of recent attempts from the same IP address, held in the server's working memory the same way the ad count below is, and never written to our database.
- Advertising: free-tier pages carry ads, and all of them are our own. We sell them directly, there is no advertising network involved, and an ad is a plain link: no script of an advertiser's runs in your browser and no advertising cookie is set. So we can tell an advertiser what their pack delivered, we count how often an ad was seen and how often it was clicked. To stop one reader counting twice, we ignore a repeat view from the same IP address for an hour. That note lives in the server's working memory only: it is never written to our database, it never goes to the advertiser, who sees only totals, and it goes when the server process recycles. Ads never appear in the email, and neither an ad nor a sponsor mention inside a post appears for a member.
How we use it
- To send you the posts you signed up for.
- To provide membership features and know who is a member.
- To review, run, and report on ads.
- To arrange interviews with the developers who volunteer for one.
- To keep the site secure, to stop mailing an address that bounces or reports us, and to see how readers rate a post.
Confirming your address is how you consent to the email. Signing up sends one confirmation request and nothing else; the posts start when you click the link in it, along with messages about your account or membership if you have one. Starting a membership with an address, or asking to be told when we launch, is the same consent given a different way. As the Spam Act 2003 (Cth) requires, every post and marketing email identifies us as the sender, carries our postal address, comes from an address you can reply to, and has an unsubscribe link.
We do not sell personal information. We use no third-party advertising network, so no ad platform and no advertiser receives your email address or account details.
Who processes it for us
These are the companies that hold or handle reader information for us. Each receives only what it needs to do its job, and each has its own privacy policy covering what it does with it.
| Company | What it does for us | Based in |
|---|---|---|
| Vercel | Hosts the site and runs its server code, so every request to studioinsights.net passes through it | United States |
| Vercel BotID | Checks the submissions listed above for automation | United States |
| Vercel Web Analytics and Speed Insights | Counts page views and measures how fast pages load, only after you accept analytics | United States |
| Supabase | Our database: your subscription, your issue ratings, bounce and complaint records, advertiser records, and interview requests | United States |
| Stripe | Takes payments and holds the billing record: your card details, your customer record, and its invoices | United States |
| Resend | Sends our email, tells us when a message bounces or is reported as spam, and forwards mail sent to our address | United States |
| Discord | Sign-in, and the members-only role in our server | United States |
No advertising network is on that list, because we do not use one.
How long we keep it
For as long as you are subscribed or a member. An address that is signed up but never confirmed is kept unused, so the same signup is not counted or mailed twice. When you unsubscribe, we keep your address on a suppression list so we do not email you again by mistake. Ask us to delete it entirely at any time, or do it yourself from the dashboard once you have signed in (members cancel first, so billing records stay consistent). That clears our copy, including your votes, delivery events, and any ads or interview requests under your address. Stripe and Resend keep records of their own that we cannot erase for them: Stripe's invoice and tax history for a payment it processed, and Resend's log of mail it delivered, each for as long as their own legal obligations require.
Advertiser records are separate from all of that, because an advertiser is usually not a subscriber. What an ad leaves behind is the company, the email address, the headline, the copy, and the link submitted through the advertise form, plus how many times the ad was shown and clicked. We keep that while the pack is running, and afterwards only for as long as we need it to answer a question about a campaign and match it to the payment behind it. We clear finished, declined and abandoned ad records at least once a year, and we will not hold one longer than 24 months. Ask sooner and we delete it sooner: email hello@studioinsights.net, and if the same address has an account here, deleting that account from the dashboard clears ads booked with it as well. The one part that is not ours to delete is Stripe's: it keeps its own record of the payment for its invoicing and tax obligations, whatever we do with ours.
Your choices and rights
- Unsubscribe at any time with the link at the bottom of every post, your mail app's own unsubscribe button, or studioinsights.net/unsubscribe. It takes effect immediately, well inside the five working days the Spam Act allows.
- Cancel membership at any time from your dashboard.
- Ask us to access, correct, export, or delete your personal information by emailing hello@studioinsights.net, and we answer within 30 days. We do that for every reader, wherever you live and whether or not a privacy law requires it of a publisher our size; we do not ask which country you are in before answering. Where such a law does apply to you, like the GDPR in the EEA and the UK or the CCPA in California, it adds to what is offered here and takes nothing away from it.
Cookies
Signing in sets a session cookie so you stay signed in, plus the handful of short-lived ones our sign-in library uses to carry out the Discord handshake safely; those clear themselves once you are through it. While the site is closed to the public, entering the access code sets one more cookie so that browser is not asked for the code again for thirty days. We set no advertising or tracking cookies, and nobody else sets any either: the ads on free-tier pages are plain links rather than embedded code, so there is no third party in a position to set one. Your analytics choice and your light-or-dark preference are not cookies at all; they sit in your browser's local storage and never reach our servers. Clear site data to be asked again. One stored value does reach us: a channel code from a link that carries one, which every page keeps in your browser's session storage for the rest of the visit and the subscribe form sends with your email address.
Children
The newsletter is for developers aged 13 and up. We do not knowingly collect information from anyone under 13. If you think we have, email us and we will delete it.
Changes
The date at the top of this page shows the latest version. For material changes we will tell subscribers by email.