Paper 03 ยท Studio OS

The Privacy Doctrine

Photos that destroy themselves, data that belongs to the shop, and why holding less makes the product worth more.

The ID that dies on verification

Shops must check ID. Most digitize this by hoarding license photos โ€” a filing cabinet of passports waiting for a breach. The machine does it differently: the artist's phone shoots the ID through a signed, single-sitting link; it appears at the desk; the desk taps 'checks out'; the attestation stamps the record โ€” and the photo is deleted in the same transaction. A 24-hour purge catches strays. What survives is the fact of the check, which is all the release ever needed. We never store licenses is a sentence a shop can say to customers and mean.

Share links are credentials

Every link the machine hands out โ€” a customer's ticket, an artist's shot link, a check-in QR โ€” is a signed credential scoped to exactly one thing and, where it matters, one sitting. A shot link dies when the chair empties. A ticket opens one walk-in's thread and nothing else. There are no passwords for customers because there are no accounts to breach โ€” the link IS the key, and it opens one door.

The shop's data is the shop's

The model is explicit: your book, your clients, your money, your numbers. Nightly database dumps ride with the shop's own stack. If a shop leaves, their data leaves with them โ€” including the texting number their clients know, which ports out on churn. Software that holds data hostage is charging rent on fear; software that hands it back charges rent on being good.

Financial sight-lines

Money is visible to exactly who should see it: owners see the whole house, artists see only their own line. Rate cards, drops, splits โ€” none of it leaks sideways across the roster, and none of it appears on any public surface, ever. The public wall knows who's free; it does not know what anyone makes.

Next paperOne Line, One Brand โ†’ โ† the library