I lost my project passphrase. Can you recover it?
No — and this is the one to read before you need it. Your Studio project is encrypted on your device, and any copy of it that leaves that device — a backup, a snapshot, a project handed to another machine — is sealed with a key wrapped under a passphrase you choose. We never receive that passphrase, we hold no copy of it, and there is no master key, no reset link, and no support path that opens a project without it. If you lose your passphrase, we cannot recover it for you, and the project it protects cannot be opened by anyone — including us.
That is a deliberate design decision, not a gap: Studio is used for facility topology, control-system architecture, device inventory, and site photographs, and a recovery path we could walk is a recovery path someone else could walk. Two habits make it a non-event — keep the passphrase wherever you keep your other credentials, and restore a backup once, on purpose, while nothing is wrong.
Where does my project actually live?
In one project package on your own device — the design database, every photo and datasheet you attached, and the previews, all encrypted at rest. It is a file you own, in a location you chose. Studio is local-first: it opens and edits that project with no network connection and no account, and nothing you author is uploaded to us.
The deliberate exception is what you generate to share. A documentation package exported as Markdown or PDF is something you decided to publish, so it leaves the encrypted container as a normal file — and from that point it is governed by wherever you put it.
How do backups and restore work?
A backup is a versioned, encrypted snapshot of the whole project, written to a destination you pick — a local file, your files app, or a folder you keep in a personal cloud drive. Studio tracks the snapshots it made so you can restore one, take an earlier version, or duplicate a project from a backup. Backing up is never required for Studio to work.
Because the archive is encrypted before it leaves the app, whichever service holds that folder holds ciphertext, not your design — and the passphrase above is what opens it. This release has no TameChaos-hosted backup and no cloud sync of your projects; what the app does and does not send us is set out in full in the Studio app privacy policy.
How do I move a project between my Mac and my iPad?
By snapshot. Studio packages the project into a single encrypted archive, and the other device opens it with the same passphrase — no account, no sync service, and no network in between. That is also why the passphrase matters even if you never back anything up: it is what makes a project portable at all.
The key for day-to-day use is held in your device’s own secure credential store and never leaves it, which is the flip side of the same design — an archive without its wrapped key can only be opened on the machine that wrote it. If a project opens on one device and reports a missing key on another, that archive is the one to check first. Studio is single-user with snapshot handoff; it has no live sync and no simultaneous multi-device editing.
Do I need an account to use Studio?
No. Every editor works signed out, nothing you author requires an account, and you can use Studio indefinitely without making one. Signing in does exactly one thing: it lets Studio pull the component catalog. Sign out and your projects are untouched — they were never tied to the account.
If you do sign in and want the account closed or the information behind it deleted, email support@tamechaos.com and we will handle it. The account details we hold, and why, are listed in the Studio app privacy policy.
Why is Studio asking for my location?
Only because you tapped “Set location from GPS” on a facility. Studio takes a single, one-shot fix while you are using the app, writes that coordinate onto that facility, and stops. There is no background location and no tracking of any kind, and the coordinate is stored in your own encrypted project on your device — it is never transmitted to us.
It is entirely optional. A facility’s location can be typed in as an address or dropped as a pin with no location permission granted at all, and declining the permission changes nothing else in the app. If you granted it and want it back, revoke it in your device’s privacy settings; the coordinates already saved stay in your project until you change them.
Studio doesn’t do the thing I need. Is that a bug?
Possibly not — some of it is deliberate. Studio designs and documents a system; a runtime executes it. It has no simulation engine, its HMI mockups are design artifacts rather than live dashboards, its comms topology is drafting only, and it has no quotes, purchase orders, or ordering rail. Those boundaries are set out one by one in what Studio is and isn’t on the Studio page.
If what you need is on the wrong side of one of those lines, tell us anyway — knowing what people reach for is how the roadmap gets decided. If it is on the right side and still doesn’t work, that is a bug, and the checklist above is how to report it.