Your work stays yours. Your data stays where you can see it.
This page covers two things: what this site collects when you read it, and how the studio handles client material, including the one rule for AI tools.
- This site collects nothing about you on its own. No analytics, no cookies, no tracking scripts.
- We take intellectual property very seriously. Client material is used for your engagement and for nothing else.
- Client material is never fed into an AI model that was not designed for data sovereignty. Today that means European providers hosted in Europe, or models run on hardware the studio controls.
1. Who we are
Known, and (the studio, we) is the design and development studio of Josie Rigali. The studio is the data controller for the personal data described here. Reach us at rigaliresearchdevelopment@gmail.com.
2. What this site collects
knownand.com is a static site. It has no accounts, no forms that post to a server, no analytics and no advertising. Its Content Security Policy allows scripts from knownand.com only, so no third-party script runs on it. What does happen when you visit:
- Hosting
- The site is served by GitHub Pages. GitHub records ordinary server logs, including your IP address, under the GitHub privacy statement. We do not receive or read these logs.
- Fonts
- The type (Archivo, Inter) loads from Google Fonts. Your browser sends a request, including your IP address, to Google's servers. Google states that it does not use these requests for tracking or profiling; see the Google Fonts privacy FAQ.
- Dark or light mode
- Your choice is stored in your own browser (
localStorage, keyknown-theme) so the site remembers it. It never leaves your device and it is not a cookie. - Weekly sign-up
- The sign-up form opens your own mail app with a ready-made email. Nothing leaves the page until you send that email. Your address is then kept for the weekly and removed when you reply asking to stop.
- Project updates
- The Get updates pill on a project opens your own mail app the same way, with the project named in the subject. Your address is kept for updates on that project only and removed when you reply asking to stop.
- Booking a meeting
- The Book a meeting button opens Calendly, a separate service with its own privacy policy. We receive the name, email address, time and notes you enter there.
- If you write to us, we keep the correspondence as ordinary business email, for as long as the conversation or the working relationship needs it.
We do not sell personal data, and we do not share it with anyone except the services above, which are needed to run the site and the studio.
3. Intellectual property
We take intellectual property very seriously. When you work with the studio:
- What you bring stays yours. Brand assets, source files, data, documents, credentials, product ideas and unreleased work are used for your engagement and for nothing else.
- What we make for you becomes yours on final payment, as set out in the terms of service.
- Nothing you give us trains a model. Not the studio's tools, and not any provider's. The rule below is how that is enforced.
- Nothing is shown without permission. Your work is named, quoted or listed as a case study only with your written agreement, or with names and figures withheld.
- Access is limited to the people working on your engagement. Credentials go into a password manager and are never sent by chat, email or prompt.
- At the end, it comes back. On request we return or delete what you gave us and confirm in writing. We keep the final deliverables and the contract for our own records.
4. AI tools and data sovereignty
AI tools are part of how the studio works: research, drafting, design and code. Client material is handled under one rule:
Client material is never fed into an AI model, directly or through a tool that calls one, unless that model was designed for data sovereignty.
"Designed for data sovereignty" means all four of the following, checked before the first prompt:
- European jurisdiction. The company operating the model is headquartered in the EU, the EEA or Switzerland and answers to European data-protection law, so no authority outside Europe can compel it to hand over your data.
- European hosting. Inference runs in European data centres. Hosting alone does not qualify: a US-owned provider running servers in Frankfurt or Paris stays subject to the US CLOUD Act.
- No training, no retention. The plan in use excludes your data from model training and, where the provider offers it, keeps zero data retention. Free tiers that train by default do not qualify.
- A written agreement. The provider's data-processing terms are on file before any client material is used.
Where each model sits
Three tiers, by how much of your material a provider could see, keep or be made to hand over. Colour runs from least exposure to most. The tier decides what goes in. Only the first two ever see client material. Checked 30 September 2026.
On the studio's hardware
What goes inClient material, yes.
- Open-weight models, run locally
- Mistral open weights today
- Nothing leaves the machine, whatever country the model came from.
- No provider account, so nothing to train on, retain or subpoena.
- What remains is the studio's own machine, covered in section 5.
European provider, contract on file
What goes inClient material, only through the models named in your proposal.
- Mistral AI, Paris (paid API)
- Aleph Alpha, Heidelberg
- The provider sees the prompt for the length of the request. No training, zero retention where offered, both in the written agreement.
- Headquartered and hosted in Europe, so no court outside Europe can compel a hand-over.
- What remains: a breach at the provider, or a change in their terms. The date above is re-checked for that.
Their terms, their jurisdiction
What goes inPrompts that name nothing. No client name, file, dataset, credential or unreleased work.
- Claude
- ChatGPT
- Cohere
- Qwen
- Kimi K3
- DeepSeek
- Any consumer chat app
- Consumer plans train on your chats unless you find the switch and turn it off. An idea typed in can surface in another user's answer.
- Deleted chats can still exist. In 2025 a US court ordered OpenAI to keep ChatGPT conversations, deleted ones included, as evidence in a lawsuit. Enterprise and zero-retention plans were exempt. Everyone else's chats were held for months.
- Intellectual property. ChatGPT is in court over copyright, and in 2026 OpenAI was ordered to hand 20 million user chats, de-identified, to the other side's lawyers. Research or code done in it can be read as evidence in someone else's IP case. OpenAI's terms add that the same output can go to other users, and in the US purely AI-generated work gets no copyright. A product researched or coded in ChatGPT carries all of that into any IP dispute of its own. And terms change: should a provider one day claim a share of what its model helped make, a product researched or coded inside it would have no clean line to draw.
- Headquartered outside Europe, so a court or agency there can compel a hand-over. The US CLOUD Act reaches US companies' servers in Europe too.
The plan decides the tier, and the same brand can sit in two. Mistral's open weights run locally sit in 01. Its paid API sits in 02. Its consumer chat app sits in 03 with every other consumer chat app.
The list changes as providers change. When it does, this page is updated and the date above moves.
When models are used
- Ideation, in the studio. The models shown on the home page (Claude, ChatGPT, Mistral, Aleph Alpha, Cohere, Qwen, Kimi K3 and DeepSeek) take part in the studio's ideation process: turning a question over, sketching directions, working through a craft problem. Prompts at that stage are nondescript. No client name, file, dataset, credential or unreleased work goes into them. Which model is used depends on the question, and each is used under its own terms. How and why is set out in Using AI as a digital artist and researcher: ethics, morals and honest representation of self-expression.
- Client material. Only models that pass the four tests above, and only the ones named in your proposal. You may ask for none.
- Review. AI output is reviewed by a person before it reaches you. AI-assisted code ships after an adversarial review and tests.
Products we design or build for you may call whichever AI provider you choose. That choice is yours, it is recorded in the proposal, and your customers' data then flows under your policies.
5. Security
Client files are kept per client, with backups. Accounts use multi-factor authentication. Credentials live in a password manager. Every client build starts from the same baseline: MFA and domain lock, SPF, DKIM and DMARC, per-client isolation, backups and a written incident plan. If we learn of a breach that affects your data, we tell you without undue delay and say what happened, what was affected and what we are doing.
Security researchers: see security.txt.
6. How long we keep things
- Client material: for the engagement, then returned or deleted on request. Final deliverables and contracts are kept for the studio's records.
- Email: for as long as the conversation or the working relationship needs it, then deleted on request.
- Weekly sign-up and project updates: until you reply asking to stop.
- Booking data: held by Calendly under its own retention rules; our copy follows the email rule above.
7. Your rights
Wherever you live, you can ask what personal data we hold about you, have it corrected or deleted, or object to how it is used. Write to rigaliresearchdevelopment@gmail.com and we answer within 30 days.
If you are in the EU, the EEA, the UK or Switzerland, you have the rights set out in the GDPR and its equivalents, including the right to complain to your data-protection authority. If you are in California, you have the rights set out in the CCPA; we do not sell personal data.
8. Children
The site and the studio's services are for adults and businesses. We do not knowingly collect personal data from anyone under 16. If you believe we have, tell us and we delete it.
9. Changes to this policy
We may update this policy. The date at the top is the current version. Material changes to how client material is handled are also sent to current clients by email.
10. Contact
rigaliresearchdevelopment@gmail.com. Postal address on request.