Privacy Policy
Arteur turns one photo of your room into an AI redesign. This policy explains, in plain English, exactly what we collect, why, who else touches it, and the choices you have. Arteur, the operator of arteur.app, is the “data controller” responsible for your data. You can reach a human at hi@arteur.app.
- We collect little: your email (to send your renders and a receipt), the room photo you upload, your payment (handled entirely by Stripe — we never see your card), and first-party, aggregate usage counts.
- We don’t sell or rent your data, run advertising trackers, or use your photos to train AI models.
- There’s no account — your checkout email is how we recognize a request.
- You can ask us to access or delete your data any time by emailing us from your checkout address.
What we collect, and what we don’t
We only collect what the product actually needs:
- Your email address — entered in the upload form. It leaves your browser when you submit, even if you don’t go on to pay, so we can send your finished renders and so Stripe can email your receipt.
- Your room photo — uploaded to generate the redesign. Your browser also keeps a copy on your own device (see §07) so you can re-render the room without re-uploading.
- Your payment — collected on Stripe’s secure checkout page. Your card details never reach our servers. We keep only a record of the payment: the amount, the style, the traffic source, and the domain of your email (e.g. “gmail.com”), never the full address.
- Aggregate usage analytics — first-party counts of page views and button clicks (e.g. how many people uploaded a photo or reached checkout), tagged with the site that referred you and the style chosen. In our database these are stored only as running totals, not as a profile of you — though, as noted below, individual events do pass through our server logs. When you complete a purchase, one of these events carries your Stripe payment reference so we can confirm the sale.
- Basic technical details — like your browser type and the page that referred you are present in our server logs and, if you submit the form, are saved alongside your email in our contact list. We do not log or store your IP address in our own database.
What we don’t do: we don’t sell or rent your personal information; we don’t run third-party advertising or tracking pixels; we don’t build cross-site profiles; and we don’t use your photos to train AI models.
Why we use it (and our legal basis)
If you’re in the EU or UK, the law asks us to name a “legal basis” for each use. Here it is:
| What | Why | Legal basis |
|---|---|---|
| Room photo | Generate and deliver your redesign | Contract — it’s what you asked us to do |
| Email address | Send your renders and your Stripe receipt | Contract |
| Payment record | Take payment, prevent double-charges, keep tax/accounting records | Contract + legal obligation |
| Aggregate analytics & abuse prevention | Understand which content is useful and stop payment/render abuse | Legitimate interests — running and improving the service |
Providing your photo and email is necessary to use Arteur — without them we can’t generate or send a redesign. We don’t make any decision about you by automated means that has a legal or similarly significant effect; generating a decorative image isn’t that kind of decision.
International transfers
The providers above are based in the United States, so wherever you use Arteur from — the EU, UK, or elsewhere — your data is transferred to and processed in the US. Where a provider is certified under the EU–US Data Privacy Framework (Stripe is), that certification covers the transfer; otherwise we rely on the Standard Contractual Clauses in that provider’s data-processing agreement. You can ask us for details of the safeguard used for a given provider by emailing hi@arteur.app.
Retention
- Your uploaded photo is not stored on our servers after your redesign is generated — it’s processed and discarded. The only lasting copy is the one your own browser keeps on your device, which you control (see §07).
- Your generated renders are kept so you can revisit them from the private link in your results email (treat that link like a key — anyone who has it can view your renders). We keep them until you ask us to delete them — one email (see §08) and we remove the stored images and links.
- Your email and contact-list entry are kept until you ask us to remove them.
- Payment records (amount, style, email domain) are kept as long as needed for accounting and tax obligations.
- Aggregate analytics are not tied to you and are kept as running totals.
Copies held by our providers (for example, your receipt at Stripe or the delivery record at Resend) follow their own retention schedules and are outside the deletion we can do directly — but we’ll always help you request removal.
Photos of your space
Your room photo is analyzed by AI systems only to produce your redesign. To keep your and other people’s privacy simple:
- Please don’t upload photos with people in them. Crop or clear the room first. If someone incidentally appears, we treat that image as their personal data too.
- We do not use your photos for facial recognition, and we don’t try to identify anyone in them.
- Your photo is not reviewed by a person in the ordinary course — it’s processed automatically.
- We do not use your photos or renders to train AI models, and we don’t publish them or use them in our marketing without your permission.
Cookies, local storage, and why there’s no banner
Arteur sets no cookies and runs no third-party advertising or tracking scripts, which is why you won’t see a cookie-consent banner — consent is only required for non-essential storage, and we don’t use any.
- Local storage on your device: while you go through the flow, your browser keeps a temporary copy of your photo, email, and chosen style so they survive the trip to the checkout page; that copy clears when you close the tab. After you buy, your browser also stores your unlock (your room photo plus your payment reference) so you can return and render more styles without paying again. Both are strictly necessary for the service — no consent banner is needed for them. The unlock stays until you clear your browser’s site data for arteur.app; clearing it removes that local copy of your photo.
- Analytics: our usage counts are first-party and aggregate, collected without cookies.
- Fonts: our typefaces are self-hosted — pages make no automatic third-party requests at all.
Your choices and rights
You can ask us to: access the data we hold about you, correct it, delete it, restrict or object to how we use it, or receive a copy to take elsewhere. Where we rely on your consent (for example, marketing email), you can withdraw it at any time.
Because there are no accounts, the simplest way to prove a request is yours is to email hi@arteur.app from the address you used at checkout. We’ll respond within the time the law allows (a month under GDPR).
If you’re in the EU or UK and think we’ve mishandled your data, you can also complain to your local data-protection authority — in the UK, the Information Commissioner’s Office (ICO). We’d appreciate the chance to fix it first.
California residents
The categories of personal information we collect are described in §01 (identifiers such as your email; the photo you upload; payment records; and coarse technical log data), and the categories of third parties we share it with are in §03. To review or request changes to your information, email us as described in §08.
Do Not Track: because we don’t track you across other websites, a “Do Not Track” signal changes nothing about how we operate. We do not sell or share your personal information as those terms are defined under California law.
Children
Arteur isn’t directed to children (under 13 in the US, and up to 16 in parts of the EU/UK), and we don’t knowingly collect their data. If you believe a child has given us personal information, email hi@arteur.app and we’ll delete it.
Security and changes to this policy
We protect your data in transit with encryption (HTTPS), limit internal access to it, and keep as little as we can for as short as we can. Your finished renders are served from an unlisted web address that acts like the private results link itself — hard to guess, but not password-protected, so anyone you give the link to can view them. No method of transmission or storage is ever perfectly secure, but we take reasonable steps to protect your data.
If we make a material change to this policy, we’ll update the date at the top and, where appropriate, tell you by email. Continuing to use Arteur after a change means you accept the updated policy.
Contact
Arteur · hi@arteur.app
See also our Terms of Service.