Privacy Policy
Last updated
Artista is a design studio where an agent makes SVG designs with you, and where you can publish, remix and discuss designs with others. This policy says what we collect, why, and what you can do about it. It is written to be read.
"We", "us" and "Artista" mean Artista, the operator of artista.ai. You can reach us at hello@artista.ai.
What we collect
Your account. You sign in with Google. From Google we receive your email address, your name, your profile picture and a stable account id. We never see your Google password.
Your profile. What you add in Settings: a username, a display name, an "about" line, a website, a picture you upload, and whether your profile page is public.
Your designs and sessions. The SVGs the agent makes with you and their preview images, the prompts and instructions you type, the reference images, fonts and SVG assets you upload, the agent's notes about a design, and the design sessions that hold all of this together.
Your social activity. Albums, likes, bookmarks, comments, remixes (a remix records which design it came from) and the notifications these create.
Credits and purchases. Your credit balance and every credit movement: welcome credits, purchases, refunds, and one record per model call saying what it cost (the model, token counts, timing — never the text of your prompt). Payments go through Stripe. We store Stripe's customer id for you and the ids of your purchases. We never receive your card number.
Technical records. Our servers log requests: IP address, browser type, time, the page or endpoint, and errors. We use them to keep the service running and to investigate abuse.
Feedback and support. What you type in the feedback form, with the page you were on and your browser type, and anything you email us.
There are no analytics or advertising trackers on artista.ai.
How we use it
- To run Artista: sign you in, make and store your designs, show your portfolio, deliver notifications, run the model calls your designs need, and charge credits for them.
- To process payments and keep the records that tax and accounting law require.
- To keep the service safe: prevent abuse (one welcome bonus per person, write limits), debug failures, and protect other users.
- To talk to you about your account: a purchase receipt, a security notice, an answer to your feedback. We don't send marketing email.
If you are in the EU, the UK or a place with similar law: we process your data to perform our contract with you (running the service), for our legitimate interests (security, abuse prevention, improving the service) and to meet legal obligations (tax, accounting). Where we would need your consent, we ask for it first.
Who sees it
Other users and the public. A design, album or comment you make public is public: anyone can see it, search engines index it, and other users can remix it under the license in the Terms. Your username, display name and picture appear next to what you publish and comment. A design you keep private, or that lives only inside your Studio, is visible to you alone. You can hide your profile page in Settings; your public designs stay public.
The model providers. To make a design, the agent sends your prompt, your reference images, the current state of each canvas and the fonts in play to the model doing the work. Today those models are run by Anthropic (the Claude API) and Google (Vertex AI). They process this data as our service providers, under terms that do not allow them to use it to train their models. If you choose to use your own API keys in the Studio, your browser calls the vendor you chose directly, with your key, under the terms of your own account with that vendor — some vendors' free tiers do use data to improve their models, so read your vendor's terms. Your keys stay in your browser's session storage and never reach our servers.
Service providers. Google Cloud hosts Artista: the application, the database, file storage, logs and sign-in (Firebase Authentication). Stripe processes payments and handles card data. These providers act on our instructions under data-processing agreements.
The law. We disclose data when a valid legal request requires it, to protect someone's safety, or to enforce our Terms.
We don't sell personal data, and we don't share it for advertising.
Cookies and what stays in your browser
Artista sets one cookie, __session. It carries your sign-in token to the part of our service that serves your own private images, is sent only to that part, and goes away when you sign out. It is strictly necessary for signed-in use. Firebase keeps your sign-in state in your browser's storage. The Studio keeps a local copy of the canvases a run is working on, so a closed tab can recover them, and keeps your own API keys, if you use them, in session storage for the life of the tab. Stripe sets its own cookies when the payment form loads, for fraud prevention; its policy covers them.
We don't use cookies for tracking or advertising, so there is no cookie banner.
How long we keep it
- Your account, designs, sessions and social activity: until you delete them or your account.
- Payment and credit records: as long as tax and accounting law require. When you delete your account, these records are kept but detached from your identity.
- Server logs: about 30 days.
- Database backups: up to 14 days, after which deleted data is gone from backups too.
- After you delete your account we keep a one-way hash of your email address, so the welcome credits cannot be claimed twice by the same address. The hash cannot be turned back into your email.
Deleting your account
Settings → Delete account. It removes your profile, designs, sessions, albums, comments, likes, bookmarks and notifications right away, deletes your stored files, deletes your sign-in record, and asks Stripe to delete your customer record. Unused credits are forfeited (see the Terms). Designs others have remixed from yours stay theirs. What we keep is listed above.
Your rights
You can see and change your profile in Settings, download any of your designs as SVG or PNG, and delete your account yourself. Depending on where you live, you may also have the right to ask for a copy of your data, to correct it, to restrict or object to its processing, or to complain to your data protection authority. Email hello@artista.ai and we will answer within a month. We never treat anyone differently for exercising their rights.
Children
Artista is not for children under 13, or under the age your country sets for consenting to online services. We don't knowingly collect data from them; if you think a child has an account, tell us and we will delete it.
Where the data lives
Our servers are in the United States (Google Cloud, Iowa). If you use Artista from elsewhere, your data travels there. Our providers commit to standard contractual clauses and equivalent safeguards for those transfers.
Security
Everything travels over HTTPS. Access to production systems is limited to the people who run the service and goes through dedicated service accounts. Published SVGs are sanitized before they are stored. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.
Changes
When this policy changes we update the date at the top; for a change that matters we also tell you in the app or by email. The current version always lives at this address.