Privacy Policy

Last updated: 8 August 2026

1. Information We Collect

We collect information you provide directly: account details (email, name), artwork data, artwork images and videos, related media metadata, and contact information you enter into the platform.

If you use the optional Selling tools, we store your setup progress, seller name, country, private buyer-message notification email, policy additions, public Selling page, selected artworks, prices, edition or online quantities, and activation state. If online payments become available and you choose to use them, we will also store the public seller and delivery details you enter, plus limited Stripe or PayPal connection and status information. We do not store your provider password.

If you send an enquiry, we collect your name, email address, message, and, when needed for a delivery quote, country and postcode. If you start or complete an online payment if that option becomes available, we may also collect your delivery country or region, postcode, shipping or service address, and phone number where the delivery service requires it. We store the order, quoted price and delivery, seller-policy snapshot, fulfilment and tracking information, and limited provider transaction identifiers and status needed to reconcile payment, refund, reversal, or dispute events. Stripe or PayPal collects and processes payment-card, bank, or wallet details; Artwork Codex does not receive or store full payment credentials or ask for marketing consent during checkout.

Payment-provider connection records use security references rather than provider passwords or payment details. Expired connection attempts are removed after 30 days. If a seller disconnects, we retain only the provider information needed to protect and reconcile existing orders. Disconnecting stops new online payments through Artwork Codex but does not close the seller's separate Stripe or PayPal account.

When you sign in with Google OAuth, Google shares your email address and basic profile information (name and profile picture) with us. We use this solely to create and authenticate your account.

For eligible Free accounts, we keep when setup-email delivery started or was turned off, whether the account has reached a first artwork or first professional output, and limited delivery, unsubscribe, and suppression status. These records contain no artwork title, image, note, contact, sale, or billing information.

For visitors to our United States Google Search advertising campaign, we record limited first-party campaign information, such as campaign, keyword, ad, device, and match-type identifiers and, when supplied by Google, a Google click identifier. We use this information only for private campaign reporting about whether the campaign leads to demo use, account creation, artwork creation, subscription trials, and paid web subscriptions. We do not send account activity back to Google. No Google or Meta advertising tags are installed.

2. How We Use Your Information

Your data is used to provide the Artwork Codex service: storing and displaying your artworks, generating PDFs, and enabling features you use. We do not sell your personal information.

Buyer enquiry data is used to deliver the requested message to the artist, keep a private enquiry record in that seller's account, prevent abuse, and support deliberate follow-up such as creating a contact. Submitting an enquiry does not enrol the buyer in marketing and does not automatically create a contact or sale.

Online-payment data is used to calculate the exact price and delivery total, reserve one inventory unit for a limited period, create the seller's Stripe or PayPal checkout, verify and reconcile provider events, prevent duplicate or conflicting orders, create the seller's order, buyer contact and Sales record after confirmed payment, send transactional messages, support fulfilment and tracking, and show confirmed refund, reversal, or dispute status. A provider success page or browser message is not treated as proof of payment.

We use seller country, buyer destination, currency and complete-total information to apply provider, territory, eligibility and per-order limits. We retain bounded provider-event and order history to reconcile payments, investigate abuse or disputes, and meet legal obligations. Stripe and PayPal apply their own risk controls. Online payment remains unavailable until any additional Artwork Codex financial-crime controls required for an enabled territory have been reviewed and implemented. Unsupported or over-limit transactions fall back to an enquiry.

Signed Stripe and RevenueCat billing notifications may record the first time an account starts a trial or paid subscription, together with the plan and billing platform. We use these records only for private aggregate product reporting. They do not contain names, email addresses, artwork or contact data, advertising identifiers, or payment transaction identifiers, and they are removed when the account is deleted.

Eligible Free accounts may receive no more than two setup messages if the account has not yet reached a first artwork or a first professional output. Eligibility is checked from those generic outcomes rather than the content of your records. You can turn setup emails off at any time in Settings or from any setup message. This does not affect essential account, security, billing, export, artist-enquiry, or connected-order email.

3. Third-Party Services

We use or connect with the following service providers. A connected payment provider also supplies services directly to the seller and buyer under its own terms and privacy policy, and may act independently for identity checks, payment, fraud prevention, disputes, and legal compliance:

  • Vercel — Web hosting and privacy-focused aggregate web analytics. Analytics uses no cookies; before events are sent, Artwork Codex removes query strings and replaces user- or record-specific path values.
  • Supabase — Database, authentication, and file storage
  • Cloudinary — Image storage, delivery, and optimization (images are automatically resized and format-converted for performance)
  • Stripe — Payment processing and subscription management for Artwork Codex web subscriptions, and optional Standard connected accounts and direct artwork payments for sellers. Stripe receives the seller onboarding and buyer payment information needed to provide those services. Artwork Codex receives limited account capability, checkout, transaction, refund, dispute and verified event information needed to operate Selling. See stripe.com/privacy.
  • PayPal — Optional seller business-account onboarding and direct artwork payments through PayPal's multiparty services. PayPal receives the seller, buyer and payment information needed to provide those services. Artwork Codex receives limited merchant capability, order, capture, refund, reversal, dispute and verified event information needed to operate Selling. See paypal.com/privacy.
  • Apple App Store — In-App Purchase processing for iOS subscriptions. Apple receives your Apple ID and purchase information per their privacy policy (apple.com/legal/privacy).
  • RevenueCat — Subscription receipt validation and entitlement state for the iOS app. RevenueCat receives your account identifier (Supabase user ID), purchase events, and basic device metadata (iOS version, country code, store identifier). See revenuecat.com/privacy.
  • Resend — Transactional email delivery, including signup confirmations, password resets, artist enquiry notifications, and connected-order messages to the buyer and seller. For an enquiry or order, only the contact, artwork, price, delivery, policy, fulfilment and secure action-link information needed for that message is included; recipients are not added to Resend marketing contacts. For eligible account setup guidance, Resend receives only the delivery email address, fixed Artwork Codex message copy and links, and limited delivery and suppression identifiers. It does not receive artwork details, account or billing IDs, plan data, or personalised message content for this guidance.
  • Google — OAuth authentication (if you choose to sign in with Google)
  • Apple Sign in with Apple — OAuth authentication (if you choose to sign in with Apple). You may opt to share a private relay email instead of your real Apple ID email; in that case, we never see your real email address.
  • Meta / Instagram — Optional Instagram import. If you connect an Instagram Creator or Business account, Meta shares your Instagram account ID, username, selected media metadata, captions, and temporary media URLs so we can copy selected posts into your private Artwork Codex archive. We store imported images in Cloudinary and captions in your artwork notes.

3a. Instagram Import

Instagram import is optional. When you connect Instagram, we store an encrypted access token so you can review and import your eligible image and carousel posts. We do not scrape Instagram, we do not post to your account, and we do not request messaging, publishing, comments, or insights permissions for the import feature.

If you disconnect Instagram or Meta sends us a deauthorization or data deletion request, we remove the stored Instagram connection token. Artwork records and images you already chose to import remain in your Artwork Codex account unless you delete them or request full account deletion.

3b. iOS App — Permissions and Data

The Artwork Codex iOS app requests these device permissions, each only when you take an action that requires them:

  • Camera — to photograph artworks for your inventory.
  • Photo Library (read) — to import existing photos of artworks or videos of artworks from your library.
  • Photo Library (add) — to save generated PDFs and selected artwork media to your library when you choose to share them.
  • Contacts — only when you explicitly initiate a contact import. We never read your contacts in the background.

When you add artwork media in the iOS app, we process only the images, videos, and media metadata you select or create, such as file type, file size, upload status, and display order. This information is used to store, sync, display, and manage your artwork archive across Artwork Codex.

The iOS app does not collect device identifiers (IDFA, device fingerprints) for tracking purposes. We do not include third-party analytics, advertising, or attribution SDKs in the iOS build. Crash and diagnostic information is collected only via Apple's standard App Store Connect tooling, which is governed by Apple's privacy policy.

Anonymous accounts (created via the “Get Started” button on the iOS sign-in screen) do not collect any personal information. If you later upgrade an anonymous account to a real account via Sign in with Apple, Google, or email, we collect only the email address provided by your chosen sign-in method.

4. Cookies

We use essential cookies for authentication. We do not use third-party tracking or advertising cookies.

On the website, Vercel Web Analytics records anonymous aggregate page views and limited funnel events. These events contain fixed labels such as plan, interval, currency, sign-in method, and whether an artwork was the account's first record. They do not contain names, email addresses, account or artwork IDs, artwork titles, media, contact data, or advertising identifiers.

If you arrive via a referral link, we set a temporary first-party cookie containing the public referral code. This cookie expires after 30 days and is readable by our pages so we can show referral messaging and credit the referring user if you subscribe. It is not a third-party advertising cookie.

If our hosting provider identifies your advertising visit as originating in the United States, we set a first-party, httpOnly campaign attribution cookie namedacq_touch for up to 30 days. It contains only a random opaque token; we store only a cryptographic hash of that token. If you create or sign in to an account in the same browser, the campaign visit may be connected to that account and the cookie is then cleared. The cookie is not available to advertising scripts and is not sent to Google.

If you choose Keep my artworks before a temporary web demo ends, we set an essential first-party, HttpOnly cookie for no longer than the fixed 24-hour transfer window. It contains a versioned opaque transfer reference and a cryptographic signature, not your artwork, account, or provider identifiers. Page scripts and analytics cannot read it. It works only in the same browser and is cleared or expires after completion, cancellation, or expiry.

To understand which product experiences are useful, we may set a signed, first-party, HttpOnly cookie for up to 30 days. It contains only fixed, allowlisted experience versions and exposure times. It does not contain URLs, paths, referrers, names, email addresses, account or artwork IDs, or file details. If you create and verify a permanent account in the same browser, those versions may be associated with that account and the cookie is then cleared.

4a. Browser Storage

During a confirmed Quick Add retry, this tab may temporarily keep the selected filenames, reviewed titles and basic file attributes with random operation references so it can match the same local files after a refresh without creating duplicates. The files themselves remain on your device until upload, these details are not sent to analytics or attribution, and the recovery entry is cleared when the import is completed or dismissed.

If you choose “Create your first artwork with this price” in the public artwork pricing calculator, we store a small, temporary draft in this browser that the app will use for no more than 24 hours. It contains only the artwork dimensions, unit choice, currency, rounded price, expiry details, and, once you are signed in, a limited marker that binds the draft to your profile. It does not contain your name, email, artwork title, pricing formula, baseline, materials, studio time, commission, market adjustments, files, or media.

The draft stays on this device and cannot follow you to another browser. Nothing is added to your Artwork Codex account until you review the prefilled artwork form, add the required title, and explicitly save it. We attempt to remove the draft after the artwork is successfully saved. An expired draft is never used and is removed the next time it is checked if the browser permits deletion.

If you choose “Save these artworks” in the public catalogue maker, we can keep up to three prepared JPEG copies, up to 1.2 MB each and 4 MB altogether, with their artwork details in this browser for up to 24 hours. They stay on this device while you create your account. When you open each prefilled artwork, its image is prepared for your account and attached when you save the artwork. We attempt to remove each browser copy after the matching artwork is saved; unused copies expire and are removed when this browser next checks them, where browser storage permits.

These temporary catalogue copies stay on this device and cannot follow you to another browser. Clearing browser data can remove them before you finish, in which case you can add the image again from the artwork form.

The optional calculator continuation analytics events contain only fixed tool, version, and step or decision labels plus a redacted route without query strings or record identifiers. They do not contain the price, currency, dimensions, draft or account identifiers, or a raw URL.

5. Public Content

Portfolios, custom selling pages, and viewing rooms you publish may be accessible through their unique URLs. Artwork titles, images, videos, media metadata, dimensions, and other details you include in these features are visible to anyone with the link. You control which artworks are included and can remove them at any time.

Selling is off by default. A saved setup draft remains private until the artist completes setup and turns Selling on. Published artwork pages can then show the seller name and country, price, delivery information, returns and cancellation policy, sales terms, and the selected buyer action. If Buy now becomes available, it will also display the legal seller identity, public business email, principal business address, and service address where different before payment. The private email used for buyer-message notifications can be different and is not shown publicly. We do not automatically copy a private identity-check address from Stripe or PayPal into the public seller fields.

For collection, the seller provides a broad public collection area and may add public collection instructions. Sellers should not put a private exact handover address or access details in those fields; exact arrangements are shared privately after purchase. The area, instructions, and readiness timing shown before payment are saved with the order so a later delivery-profile edit does not change the buyer's record. This is separate from public legal seller addresses required for online payment.

Private enquiries, buyer and shipping details, orders, Sales records, payment identifiers, provider-account information, account review information, and unselected inventory are not shown on public pages. After an online payment, order information is available only through a secure buyer link and the authenticated seller account.

A published portfolio can remain available to anyone with its link while the owner asks search engines not to index it. Search engines may take time to recrawl and remove a page after that choice changes.

6. Media Processing

Images and videos you upload are stored and processed by our media storage and delivery providers. Images may be resized, reformatted, and optimized for display. Videos may be processed for playback in the app and on the web. Original-resolution media is preserved where the feature and your plan support it.

7. Referral Program

When you participate in the referral program, we store your unique referral code on your profile and track referral relationships (referrer and referred user IDs, referral status, and conversion date). When a referred user makes their first payment, a credit is applied to the referrer's Stripe account balance.

8. Data Retention & Account Freezing

If your paid subscription is cancelled, your account enters a frozen read-only state. Your data, including artworks, images, videos, media metadata, contacts, Sales records, seller settings, enquiries and connected orders, is preserved — nothing is deleted merely because the subscription ended. You can continue to view and export the data available through the account. If you resubscribe, full access is restored immediately.

An artist may delete an enquiry from the dashboard. If its artwork is deleted first, the enquiry keeps a title snapshot so the artist can understand the earlier message, but the live artwork link is removed. Connected orders retain the seller, artwork, price, delivery, terms, cancellation form and returns snapshot shown at the time of checkout, together with inventory-claim, transaction, provider-event and fulfilment history needed to understand and reconcile the order. Removing a public listing or changing a current policy does not rewrite that historical snapshot. Abuse-prevention keys are short lived and contain a server-generated digest rather than a raw IP address.

If a checkout expires, is cancelled, or fails without payment and remains abandoned, we reduce its direct buyer and delivery details after 30 days once there is no Sales record or unresolved provider payment. Paid, refunded, reversed, disputed, and review-needed orders keep the contract, transaction, delivery, and fulfilment evidence needed for the transaction, legal obligations, disputes, and claims under the retention period that applies to those records.

If you request account deletion, we will permanently remove all your data, including product-email preferences and media stored with our storage and delivery providers, from active systems within 30 days, except where we must retain limited information for a legal obligation, fraud prevention, dispute, or legal claim. Restricted disaster-recovery backups age out on their existing retention schedule, currently no more than 90 days. They are restored only into an isolated recovery environment and are not used to recreate a deleted account or restart withdrawn email consent.

Deleting an Artwork Codex account does not delete the seller's separate Stripe or PayPal account or records those providers retain under their own terms, privacy policies, financial-services duties, and retention periods. Buyers and sellers may also retain order emails and their own transaction records.

A normal web demo remains temporary for 10 minutes. If you prepare Keep my artworks before that timer ends, only the protected demo source and its eligible transfer scope are held for up to 24 hours while you create and verify a new account on the Free plan in the same browser. A successful copy follows the normal retention and deletion rules for that new account. Completed, cancelled, or expired transfer mappings and their source and destination identity snapshots are removed within 30 days after the required cleanup and recovery checks finish.

Advertising attribution remains available for account matching for up to 30 days. Unclaimed campaign records are automatically deleted no later than 90 days after arrival. Attribution linked to an account is automatically deleted no later than 18 months after arrival, or earlier when that account is deleted.

Product-experience versions and limited completion milestones remain linked to a retained account so later results can be reported only in protected aggregate cohorts. They are deleted with the account. Aggregate reports contain no account identifiers, omit or suppress small groups, and round released counts down in groups of five.

9. Your Rights

You may export your data at any time using the export feature in Settings. You may request deletion of your account and all associated data by contacting us.

You may turn optional setup emails off at any time in Settings or through the unsubscribe control in any setup message. Opting out is free, does not require contacting support, and does not affect access to Artwork Codex.

Under GDPR and CCPA, you have the right to access, correct, or delete your personal data. You may also request a portable copy of your data.

A buyer who wants to access, correct, or delete enquiry or connected-order information can contact us using the address below. We may need enough information to identify the relevant request and protect it from disclosure to the wrong person. We will also tell the artist or payment provider where their action or separately controlled record is needed to complete the request.

9a. Data Deletion Requests

To request deletion of your account and all associated data, email hello@artworkcodex.com with the subject "Data Deletion Request" and include the email address associated with your account. We will process your request within 30 days and confirm deletion by email. This includes all artwork records, images, videos, media metadata, contacts, Sales records, seller settings, private enquiries, connected order and provider-linking data, and profile information held by Artwork Codex, subject to the limited legal-retention exceptions above. Artwork Codex does not own or delete a seller's separate Stripe or PayPal account or the records held by that provider.

10. Security

We use industry-standard security measures including encrypted connections (HTTPS), row-level security policies, and secure authentication. However, no system is completely secure.

11. Changes to This Policy

We may update this policy from time to time. We will notify users of significant changes via email.

12. Contact

Questions about privacy? Contact us at hello@artworkcodex.com.

Back to home