Legal
Privacy Policy
1. About this Privacy Policy
This Privacy Policy explains what personal data Artor ("Artor", "we", "us") collects
about the people who use the Artor service — designers, developers, and reviewers who hold
accounts and the organizations they belong to — and how we use, share, and protect it. It
applies to the Artor dashboard, the artor command-line tool, the preview and sharing
infrastructure, and our websites and APIs (the "Service").
Artor is a tool for hosting and reviewing web prototypes against staging and mock data. A core rule of the Service (see the Terms and Acceptable Use Policy) is that you must not put real production data or the personal data of real end users into prototypes, environment variables, or mock datasets. Because of that rule, this policy is about your data as an account holder — not the personal data of any end users, which the Service is not designed to process. Because the Service is built only for staging and mock data, we do not scan or index prototype contents for personal data. If, contrary to the rule, real personal data is placed into the Service anyway, we still handle it only as described here, you remain responsible for it, and — if you tell us it is there — we will remove it through the manual deletion process in Section 9.
Where your data lives. Artor is hosted in the United States, so your information is stored and processed there. US courts and government authorities may be able to require access to it under US law, which differs from the law of your country. See Section 7.
2. Who is responsible for your data (controller)
The data controller is Alexandre Schrammel Tecnologia da Informação LTDA (CNPJ 37.609.214/0001-70), Avenida Paulista 171, Bela Vista, São Paulo/SP, CEP 01311-904, Brazil, which operates the Artor service. You can reach us at the contacts in Section 13. We intend not to offer the Service to the public in a given region until the items that region's law requires (see Section 9) are in place; in particular, we will appoint and name our EU and UK representatives (and any Data Protection Officer) before serving users in those regions.
3. Personal data we collect
We collect only what we need to run the Service:
- Account data — your name and email address, and (for organizations) your organization membership and role. Providing account data is necessary to use the Service: without it we cannot create your account.
- Authentication data — a securely hashed password (we never store your password in plain text) and, for the CLI, access tokens stored only as a hash (the token itself is shown to you once and never stored in a readable form).
- Sign-in provider data (if you use Google or GitHub sign-in) — if you choose to sign in with Google or GitHub instead of a password or email link, that provider sends us the basic profile it holds for you (your name, email address, and account identifier, and where available a profile picture) so we can create or match your Artor account. We request only this basic profile, not your contacts or other data, and we receive it only when you choose that sign-in method. Your use of Google or GitHub is governed by their privacy policies.
- Billing and payment data (paid plans only) — if your organization subscribes to a paid plan, the payment is handled by Stripe (Section 6), and Artor never receives or stores your card number. Stripe collects what it needs to take the payment — typically your name, email address, billing address, and card details — and gives us back only what we need to run the subscription: an identifier for you as a Stripe customer, your plan, billing interval, publisher-seat count, renewal or cancellation dates, and your invoice and payment history (including whether a payment failed). Stripe's billing portal also lets you add a billing address and a tax ID if you choose to; Stripe stores those on your customer record. We do not currently collect tax and we do not read those fields.
- Product-analytics data in the dashboard (only if you consent) - if you opt in through the cookie banner, our analytics provider (PostHog) records how the dashboard is used: pages viewed, actions taken, technical details such as your browser/device type and approximate location derived from your IP address, and a session replay of your activity in the dashboard, associated with an opaque account identifier and your organization's id and slug. We do not place personal data such as names or email addresses in page addresses. A replay can show Artor's own dashboard interface plus organization, project, and prototype names and comment text that were already visible on screen; it never shows what you type, because every input and text field is masked before capture. Declining the banner, or simply ignoring it, means the analytics script is never downloaded, and your analytics identifier is stored in your browser's local storage, not a cookie. None of this loads or is sent until you accept, and you can withdraw at any time (see Sections 4 and 9 and the Cookie Notice).
- Website-analytics data on artor.app (unless you opt out) - on our public website (the marketing pages, docs, blog, and changelog) we use Google Analytics and PostHog to understand how the site is used: pages viewed, clicks and scrolling, referring site, technical details such as your browser/device type, and approximate location derived from your IP address. PostHog may also record a session replay of your visit; every input field is masked before capture. These run by default when you visit, a notice bar tells you so on your first visit, and you can opt out at any time via Cookie settings in the footer. A Global Privacy Control browser signal is treated as an opt-out. You are never identified to either provider by name or email; the website has no accounts. Google Analytics runs with all advertising signals denied and does not set advertising cookies.
- Never on prototype previews. The separate preview origin that serves your prototypes loads no analytics at all, so a prototype's own contents are never recorded by either kind of analytics.
- Technical and security data — your IP address and browser/user-agent string, recorded with sessions and used for security, rate-limiting, and audit logging. Operator audit logs (used only by platform operators for safety and abuse handling) may record the same technical data alongside the action taken; these logs are append-only and are an explicit exception to deletion (see Section 8).
- Collaboration data — review comments you write and the author name shown next to them.
- Content you provide — the prototypes, source code, configuration, environment variables, and mock datasets you upload. This is your content, processed to provide the Service; under the staging-and-mock-data-only rule it must not contain real personal data.
- Communications — messages you send us (for example, support or deletion requests).
Data we receive about invited members. When someone invites you to an organization, we receive your email address from the inviting organization to send the invitation. The category is your email/contact data and the source is the organization that invited you; this policy, provided with the invitation, is your notice of that processing.
Apart from the product and website analytics described above, we do not use third-party advertising or cross-site tracking technology; we do not build advertising profiles; we do not sell your data; and we do not knowingly collect special categories of personal data. Our analytics are used only to understand and improve the Service. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated security measures (such as rate-limiting) may briefly restrict access, but they do not profile you, and a person decides any account suspension or termination.
4. How and why we use your data, and our legal bases
For each purpose we give the plain-English reason and, in brackets, the legal basis under the main data-protection laws (the EU/UK General Data Protection Regulation, "GDPR"; Brazil's General Data Protection Law, "LGPD"). In Canada, we rely on consent (express or implied as appropriate to the sensitivity of the data) where Canada's federal privacy law (PIPEDA) requires it, and on PIPEDA's exceptions to consent (such as ss. 7.2–7.3) for security, fraud and abuse handling, audit logging, and legal compliance — processing for which consent is not the basis and which therefore continues even if you withdraw consent for other purposes.
| What we do | Why | Legal basis |
|---|---|---|
| Run your account, host and serve prototypes, store comments, authenticate the CLI | It is necessary to provide the Service you signed up for | Performance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7, V) |
| Send account email (verification, password reset) | It is necessary to operate your account | Performance of a contract |
| Take payment for a paid plan through Stripe, keep the subscription and seat count accurate, and send the billing email that confirms each change | It is necessary to provide and bill the plan your organization chose | Performance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7, V) |
| Keep invoices and payment records | Tax and accounting law require us to keep them | Legal obligation (GDPR Art. 6(1)(c); LGPD Art. 7, II) |
| Send organization invitations | A member invites you on their own initiative; the email carries sender identification and a way to decline | Our and the inviting member's legitimate interest (in Canada, in reliance on the CASL referral exemption) |
| Send opt-in share-expiry warnings | To help you avoid losing access by surprise | Our legitimate interest (GDPR Art. 6(1)(f); LGPD Art. 7, IX) |
| Keep the Service secure (rate-limiting, audit logs, abuse prevention, incident response) | To protect the Service and its users from fraud and abuse | Our legitimate interest in security (GDPR Art. 6(1)(f), Recital 49; LGPD Art. 7, IX) |
| Sign you in with Google or GitHub, if you choose that option | It is necessary to authenticate you and provide the Service | Performance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7, V) |
| Understand how the dashboard is used, to improve it (product analytics via PostHog) | To measure and improve the Service | Your consent (GDPR Art. 6(1)(a); LGPD Art. 7, I) — off until you opt in, and you can withdraw at any time |
| Understand how the public website artor.app is used, to improve it (website analytics via Google Analytics and PostHog) | To measure and improve the website | Legitimate interest (GDPR Art. 6(1)(f); LGPD Art. 7, IX) in understanding aggregate site usage, with an opt-out available at any time; where local law requires prior consent for analytics storage, your continued use after the notice bar and your ability to opt out are relied on [confirm with counsel for EU/UK/BR visitors] |
| Comply with law | To meet legal and regulatory obligations | Legal obligation (GDPR Art. 6(1)(c); LGPD Art. 7, II) |
Apart from member-initiated organization invitations, we send only transactional email needed to operate the Service. Organization invitations are sent at a member's initiative to the person they invite, include sender identification and a way to decline, and we rely on the applicable consent or exemption (such as the CASL referral exemption in Canada). We do not send marketing email, so there is no marketing list to opt out of today. If we ever introduce marketing email, we will obtain any consent the law requires (including under the UK Privacy and Electronic Communications Regulations ("PECR"), Canada's Anti-Spam Legislation ("CASL"), and the LGPD) and provide an unsubscribe option and sender identification.
Where we rely on legitimate interests, we balance those interests against your rights and freedoms and will record that assessment before launch; you can object as described in Section 9, and (for Brazil) request a report on the legitimate-interest processing under LGPD Art. 10 §3.
5. Cookies
The Service uses a small number of strictly necessary cookies for sign-in sessions and secure prototype previews, and no advertising or cross-site tracking technology. In the dashboard it also offers optional product analytics that load only after you opt in through the cookie banner. On the public website artor.app, website analytics (Google Analytics and PostHog) run by default and you can opt out at any time. Both can be changed via Cookie settings. Full details, including how to change your choice, are in the Cookie Notice.
6. How we share your data — service providers (subprocessors)
We do not sell your personal data and do not share it for advertising. We share it only with the service providers ("subprocessors") that help us run the Service. Before they process your personal data, we will engage them under a written contract that requires them to protect it and use it only on our instructions (including, for international transfers, the clauses described in Section 7); under the California Consumer Privacy Act ("CCPA") that contract engages them as "service providers" (independently of the EEA-specific clauses in Section 7).
| Provider | Purpose | Processing location |
|---|---|---|
| Hostinger | Application and database hosting | United States |
| Cloudflare, Inc. — R2 | Object/blob storage for prototypes and artifacts | United States (bucket region) |
| Cloudflare, Inc. | DNS, TLS termination, and content delivery (edge) | Global edge network, incl. United States |
| Resend | Sending transactional email | United States |
| Stripe, Inc. | Payment processing and subscription billing — paid plans only | United States |
| PostHog, Inc. | Product analytics in the dashboard (only if you opt in) and website analytics on artor.app (unless you opt out) | United States (PostHog Cloud US) |
| Google LLC | Website analytics on artor.app via Google Analytics (unless you opt out); advertising features disabled | United States |
Sign-in providers. If you choose to sign in with Google or GitHub, you authenticate directly with that provider and it returns your basic profile to us (Section 3). These providers act as independent controllers of your use of their own services, under their own privacy policies; they are not our subprocessors, and you only involve them if you pick that sign-in method.
We may also disclose data if required by law or valid legal process, to enforce our Terms, to protect the rights, safety, or property of Artor or others, or in connection with a merger, acquisition, or sale of assets (in which case we will require the recipient to honor this policy or notify you). We will update this list before adding a provider that processes your personal data.
7. International data transfers
The Service is hosted in the United States. If you are in the EEA, the United Kingdom, Switzerland, Brazil, Canada, or elsewhere, your personal data is transferred to and processed in the United States. This is a standard situation for any US-hosted service — but it means your data may be subject to access by US government authorities, courts, and law enforcement under US legal process, which differs from the law of your country. We do not transfer the personal data of users in a given region until that region's transfer safeguard below is in force; offering the Service in a region is conditioned on it (see Section 2). To protect your data we encrypt it in transit and encrypt secrets and credentials at rest, and we rely on the legally recognized transfer protections below (each marked where it is still to be put in place):
- EEA: the European Commission's Standard Contractual Clauses ("SCCs", the EU's approved data-transfer contract), concluded with each US service provider, supported by a transfer impact assessment. This includes PostHog for the optional analytics you consent to (under PostHog's data processing agreement and SCCs). [SCCs with each provider, including PostHog, to be put in place before EEA launch and before analytics is enabled for EEA users.]
- United Kingdom: the UK International Data Transfer Addendum to those SCCs. [To be put in place before UK launch.]
- Switzerland: the SCCs with the Swiss (FDPIC) amendments. [To be put in place before Swiss launch.]
- Brazil: because our controller is established in Brazil, the LGPD already governs this processing today. Transfers to our US service providers currently rely on the transfer being necessary to perform your contract — an international-transfer basis permitted by the LGPD (Arts. 33–36) — and we are putting the ANPD standard contractual clauses (Resolution CD/ANPD No. 19/2024) in place as the standing mechanism. [ANPD SCCs to be executed with each US provider.]
- Canada / Quebec: contractual measures requiring comparable protection. For Quebec, a privacy impact assessment under Quebec's privacy law ("Law 25") s.17 is required before serving Quebec users. [To be completed before launch in Quebec.]
We rely on the Standard Contractual Clauses (and their UK and Swiss equivalents) as our transfer mechanism rather than the EU–US, UK, or Swiss Data Privacy Framework ("DPF", a US self-certification program); where a provider is also DPF-certified, the SCCs still apply as a backstop. You may request a copy of the relevant safeguards using the contacts in Section 13. Note that Cloudflare terminates the secure (TLS) connection at its global edge — at locations that may be inside or outside the EEA and the US — before re-encrypting to our origin; the transfer impact assessments we complete for each region before launch will address this, and the safeguards above cover edge processing in any country without an adequacy decision.
8. How long we keep your data (retention)
We keep personal data only as long as we need it for the purposes above, then delete or anonymize it. The periods below are indicative operational targets for our systems (not yet verified against the final production setup); they describe how long we hold data and do not override your legal rights or the response deadlines in Section 9. A deletion target runs after we verify and action a request under Section 9 — it is distinct from the deadline to respond to that request:
| Data | Target retention |
|---|---|
| Account data (name, email, membership) | For the life of your account, then deleted after a verified deletion request (we aim for ~30 days), subject to the exceptions below |
| Authentication/session records | For the session lifetime; security logs typically a short rolling window (we aim for ≤ ~90 days) |
| Operator/abuse audit logs | Retained under our legal obligations and legitimate interest in abuse handling, then deleted; these survive ordinary account deletion |
| Content you upload | Until you or your organization delete it; immutable storage blobs are reclaimed by a routine clean-up process |
| Billing and invoice records (paid plans) | Kept for as long as tax and accounting law requires us to keep them — generally five years in Brazil, and longer in some countries; these survive ordinary account deletion. Stripe keeps its own copy under its retention rules |
| Product-analytics data (dashboard, only if you opt in) | Held by PostHog for their standard analytics retention window; capture stops and your browser-side analytics storage is deleted as soon as you decline or turn analytics off. [Confirm the configured PostHog retention period before enabling analytics in production.] |
| Website-analytics data (artor.app, unless you opt out) | PostHog: as above. Google Analytics: held for the retention period configured in our Google Analytics property (default 2 months for event-level data, extendable to 14 months) [confirm the configured GA4 retention period]; the _ga cookies expire after ~2 years or when you delete them. Opting out stops further collection. |
| Backups | Overwritten on a rolling cycle (we aim for within ~35 days) |
Erasure exceptions. Because backups are overwritten on a cycle rather than surgically edited, a deleted item may persist in backups until the cycle completes. Abuse and operator audit records are retained where the law allows or requires it, and invoices and payment records are kept for the statutory tax and accounting period even after the account they belong to is deleted. For Brazil, post-purpose retention is limited to the grounds in LGPD Art. 16.
9. Your rights
Subject to your local law, you have some or all of these rights over your personal data: access; correction/rectification; deletion/erasure; restriction of or objection to processing (including processing based on legitimate interests); portability; withdrawal of consent where we rely on consent; the right to lodge a complaint with a supervisory authority; and the right not to be discriminated against for exercising your rights.
How to exercise them today. Self-serve account deletion and data export are not yet built. For now we handle these requests manually: email us (Section 13) and we will verify your identity and respond. The law sets maximum response times — generally one month (EEA/UK), 15 days for a simplified access request (Brazil, LGPD Art. 19), 30 days (Canada, PIPEDA), or 45 days, extendable by 45 (California). These are legal maximums; we aim to meet them, ask that you allow time for identity verification, and will tell you if we need a permitted extension. You do not need an account to make a request, and you may use an authorized agent (we will verify the authorization). If we deny a request, you may appeal by emailing us.
EEA / UK / Switzerland (GDPR, UK GDPR, Swiss FADP). You may complain to a supervisory authority. If you are in the UK, that is the Information Commissioner's Office (ICO), ico.org.uk. In the EEA, complain to your local authority; in Germany, that is your Bundesland's authority. If you are in Switzerland, you may complain to the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch. We will name our EU representative (GDPR Art. 27), UK representative, and (where required) Swiss representative (FADP Art. 14), and any Data Protection Officer, here before launch in those regions; designation is a launch precondition.
California and other US states (CCPA/CPRA and comparable laws). We do not sell or share personal information (and have not done so), and we do not use sensitive personal information to infer characteristics. Our sources are you (directly), your use of the Service (automatically), and — for paid plans — our payment processor (subscription and payment status); we disclose personal information for a business purpose only to the service providers in Section 6.
| Category of personal information | Examples | Business purpose | Retention |
|---|---|---|---|
| Identifiers | name, email, IP address, account/token identifiers | provide and secure the Service | see Section 8 (indicative) |
| Internet/network activity | user-agent, session and audit logs; product-analytics usage events with an opaque identifier (dashboard, only with your consent); website-analytics usage events (artor.app, unless you opt out) | security and rate-limiting; and, for analytics, to improve the Service | short rolling window for security/audit logs; provider retention windows for analytics events; see Section 8 (indicative) |
| Geolocation data (approximate) | coarse location derived from your IP address, for product analytics (dashboard, only with your consent) and website analytics (artor.app, unless you opt out) | to improve the Service | see Section 8 (indicative) |
| Commercial/financial information (paid plans) | plan, billing interval, publisher-seat count, renewal date, invoice and payment history, and an identifier for you as a Stripe customer — we never receive your card number | take payment for the plan and run the subscription | statutory tax and accounting period; see Section 8 |
| Other information you provide | prototype content and comments you create | provide the Service | until you delete |
You have the rights to know, access, delete, and correct your personal information and to not be discriminated against. We do not sell or share personal information and do not use sensitive personal information for inference. In the dashboard, product analytics run only if you opt in; on the public website artor.app, website analytics run unless you opt out. You can change either at any time via Cookie settings. We honor the Global Privacy Control ("GPC") browser signal: in the dashboard, analytics require your affirmative opt-in, so a GPC signal means they stay off with no action needed; on artor.app, a GPC signal is treated as an opt-out. The Cookie settings dialog reflects the current state. If we ever engage in an activity that counts as a "sale" or "share," we will honor GPC as an opt-out for that too and update this policy. Residents of Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana and other states with comprehensive privacy laws have analogous rights, including the right to appeal a denied request as described above.
Brazil (LGPD). You have the rights under Art. 18: confirmation that we process your data; access; correction; anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; portability; deletion of data processed with your consent; information about the public and private entities with which we have shared data; information about the possibility of denying consent and its consequences; and revocation of consent. We currently fulfill these requests manually (see above). Our person in charge of data processing (encarregado) is Alexandre Schrammel, reachable at privacy@artor.app. We do not make decisions based solely on automated processing (Art. 20). You may contact the Autoridade Nacional de Proteção de Dados (ANPD). We will make a Portuguese-language version of these documents available before launch in Brazil; for Brazilian consumers it will prevail in case of conflict.
Canada (PIPEDA / Quebec Law 25). If you are in Canada, your main rights are to see and correct your information and to withdraw consent (subject to legal/contractual limits). Quebec residents additionally have rights to data portability and to de-indexing / cessation of dissemination under Law 25 (ss. 27, 28.1) where their conditions are met (public shares already default to unlisted, no-index, and short-lived), and are entitled to these documents in French and to a named person responsible for personal-information protection (Law 25 s.3.1) — we are finalizing both and will publish them before Artor is offered in Quebec. Your data is processed in the United States and may be accessible to US authorities, as noted in Section 7. You may complain to the Office of the Privacy Commissioner of Canada ("OPC") or, in Quebec, the Commission d'accès à l'information ("CAI").
10. Security
We protect your data with measures including: secrets (such as environment variables and stored
credentials) encrypted at rest with AES-256-GCM — note this protects secrets and credentials,
not every field in the database; passwords hashed by our authentication system; a closed-garden
access model where prototype content is limited to organization members; previews served from a
cookie-isolated origin; exclusion of .env and secret files from the source snapshots we
store; and rate limiting. The staging-and-mock-data-only design is itself a protection: by
forbidding real personal data, we keep it out of the system. No method of transmission or storage
is perfectly secure, but we work to protect your data and respond to incidents.
If a security incident affects your personal data, we will notify the relevant authorities and affected individuals as the law requires — for example, the relevant EEA/UK supervisory authority within the GDPR's 72-hour window where it applies; the ANPD and affected individuals for Brazil within the timeframe its rules set; the OPC and affected individuals for Canada where there is a real risk of significant harm (and we will keep the PIPEDA breach record); and the CAI and affected individuals for Quebec where an incident presents a risk of serious injury under Law 25. We will put the corresponding incident runbooks and confidentiality-incident register in place before launch in each region, and will notify affected residents under applicable US state breach-notification laws.
11. Children
The Service is a professional tool not directed to children and not likely to be accessed by children; with no advertising or cross-site tracking, and analytics that are optional, opt-in, and minimized, it is built to respect children's-privacy standards (such as the UK Children's Code). Eligibility is a contractual age requirement, not a consent mechanism:
- You must be at least 16 to use the Service. Some countries set a higher minimum age for online services; if yours does, that higher age applies to you.
- In Brazil, because the LGPD (Art. 14) gives special protection to children (under 12) and adolescents (12–17) that the Service does not implement, you must be at least 18.
We do not knowingly collect personal data from anyone below these ages; if we learn we have, we will delete it. If you believe a minor has provided us personal data, contact us (Section 13).
12. Changes to this Privacy Policy
We may update this Privacy Policy. If we make material changes, we will give reasonable notice (for example, by email or an in-product notice). The "last updated" date below always shows the current version.
13. Contact us
- Privacy and data-rights requests: privacy@artor.app
- General legal: legal@artor.app
- Controller: Alexandre Schrammel Tecnologia da Informação LTDA, CNPJ 37.609.214/0001-70, Avenida Paulista 171, Bela Vista, São Paulo/SP, CEP 01311-904, Brazil
- Encarregado (DPO): Alexandre Schrammel — privacy@artor.app
(Still to be appointed before we serve those regions: the EU and UK representatives and the Canadian/Quebec person in charge of the protection of personal information.)
Effective: September 8, 2026 · Version: 1.3