Privacy Policy
This policy explains what Artwello collects, why, who we share it with, and how you can get your data out or delete it. We have tried to write it in plain language and to describe what our software genuinely does.
Who is responsible for your data
The controller of your personal data is Kostiantyn Holub, Jednoosobowa działalność gospodarcza (sole proprietorship registered in Poland). Our registered address, tax numbers and postal contact details are on the Imprint page.
For any privacy question or request, write to [email protected]. We answer within 30 days, as required by the GDPR.
What we collect
We collect only what the service needs to function. There is no advertising network, no data broker, and no tracking pixel on this site.
- Account data: your email address, and, if you sign in with Google, the name and profile picture Google returns. Passwords are stored only as a salted hash; we never see the plaintext.
- Images you upload: the photos you submit to be turned into a pattern, and the files we generate from them.
- Prompts: the text descriptions you write when generating from a prompt instead of a photo.
- Generation settings: the tool, format, complexity, palette and style options attached to each pattern.
- Billing records: your plan, credit balance, and the full history of credits granted and spent. Card numbers never reach our servers; they go straight to Stripe.
- Technical data: IP address, browser and device information, and server logs, which we need to operate the service and to stop abuse. This includes error reports when something breaks, and visit counts from our cookieless analytics.
- Correspondence: anything you send us by email, and anything you write in the support chat. If you are signed in when you open the chat, we attach your email address, display name, plan and credit balance to the conversation so that whoever answers already has the context.
Your images and prompts
This is the part of the policy most people care about, so we are being specific.
The photos you upload and the prompts you write are used for one purpose: producing the pattern you asked for. To do that, they are stored in our private cloud storage and sent to the AI provider we use for image generation. Those providers are named individually on our Subprocessors page.
We do not sell your images. We do not publish them. We do not use them to train AI models of our own, and we do not licence them to anyone for training. We do not run face recognition, biometric identification, or any attempt to work out who is in your photo.
Your patterns stay private to your account unless you publish one to our catalogue yourself. Publishing is off by default and is currently limited to administrators.
We keep a record of the prompts submitted to the service. We need it to investigate abuse and to answer a complaint if one arrives (see our Acceptable Use Policy).
One thing we cannot control: our AI providers apply their own safety filters to what passes through them, and they keep their own operational logs under their own terms. We link to their policies on the Subprocessors page.
Why we are allowed to process it
Under the GDPR every use of your data needs a legal basis. Ours are:
- Performance of a contract: creating your account, generating and storing your patterns, taking payment, and providing support. Without this data there is no service to give you.
- Legitimate interests: keeping the service secure, preventing abuse and fraud, enforcing rate limits, and understanding aggregate usage so we can improve the product. We balance this against your rights and keep the data minimal.
- Consent: nothing in the service currently depends on it. We set no analytics or advertising cookies. If we ever add optional analytics that does, it will load only after you agree in a cookie banner, and you will be able to withdraw that consent at any time.
- Legal obligation: retaining accounting and tax records for the period Polish law requires.
Who we share it with
We share your data only with the providers that make the service work: cloud storage, AI processing, payments, email delivery, error monitoring, analytics and hosting. Each one is named, together with what it receives and where it is located, on our Subprocessors page. They act on our instructions and may not use your data for their own purposes.
We may also disclose data where the law requires it: a valid court order, a lawful request from an authority, or where disclosure is necessary to establish or defend a legal claim. If our business is ever sold or transferred, your data may transfer with it, and this policy continues to apply until you are told otherwise.
Our support chat is run by Crisp IM SAS in France; it receives what you write to us, but only once you open the chat window and start a conversation. Crisp retains the IP address a conversation was started from.
We do not sell personal data, and we do not share it with advertisers.
Where your data is stored
Uploaded photos and generated patterns are stored in Amazon S3 in the us-west-2 region (Oregon, United States). Several of our providers are based in the United States.
This means your data is transferred outside the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with the data processing agreements we have in place with each provider.
Support-chat conversations are the exception: they are held in the European Union (messages in the Netherlands, the rest in Germany) and do not leave the EEA.
How long we keep it
- Account data: for as long as your account exists. Delete the account and it goes, along with your patterns and your credit history.
- Patterns you delete: moved to your trash and permanently erased, including the files in cloud storage, 7 days later. You can restore them or empty the trash yourself before then.
- Payment and accounting records: retained for the period Polish tax law requires (currently 5 years from the end of the accounting year), even after your account is deleted. This is a legal obligation we cannot waive at request.
- Server and security logs: a short rolling window, typically weeks rather than months.
- Support-chat conversations: kept in our support inbox until we delete them, because a returning question is usually easier to answer with the previous one in front of us. Deleting your account does not automatically erase them; ask us and we will remove the conversation and the contact profile behind it.
- Backups: deleted data may persist in encrypted backups for a short period before those backups rotate out.
Your rights
If you are in the EEA or the UK, you have the right to access your data, correct it, erase it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. These rights apply to everyone who uses Artwello, wherever you live. We did not want two classes of user.
Two of them are self-service and instant. From your data and privacy settings you can download a complete JSON export of your profile, every pattern with its settings, and your whole credit history. You can also delete your account outright, which removes your data from our database and your files from cloud storage, and cancels any running subscription.
For anything else, email [email protected]. If you believe we have handled your data badly, you may complain to your local supervisory authority. In Poland that is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa.
If you are in California
California residents have the right to know what personal information we collect and why, to request its deletion, to correct it, and not to be discriminated against for exercising those rights. The categories we collect and the parties we share them with are the ones described above and on the Subprocessors page.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Requests go to the same address as every other privacy request.
How we protect it
All traffic to and from Artwello runs over TLS. Your files live in a private storage bucket that is not publicly listable; the app hands your browser short-lived signed links that expire, rather than permanent public URLs. Access to production systems is restricted to the people who operate the service.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal data, we will notify the supervisory authority and, where the risk to you is high, notify you directly.
Automated processing
Artwello generates images automatically. That is the product. But we make no automated decisions that produce legal effects for you or similarly significantly affect you. Nothing about your pricing, your access, or your rights is decided by an algorithm without a human being able to review it.
Our AI providers apply automated safety filters, which occasionally refuse a perfectly innocent prompt. If that happens your credits are returned automatically, and you can write to us.
Children
Artwello is not intended for children under 16, and accounts may only be created by people aged 16 or over, as set out in our Terms of Service. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
Cookies
We set no cookies for analytics or advertising. The only things stored in your browser are what keeps you signed in and, if you use it, the support chat. Our visit counter works without cookies. The full list is on our Cookie Policy page.
Changes to this policy
We may update this policy as the service changes. The date at the top always reflects the current version. If a change materially affects your rights, we will tell you by email or in the app before it takes effect, so you have a chance to read it and, if you disagree, to delete your account.
Contact
Questions, requests, or complaints: [email protected]. If you would rather write on paper, our postal address is on the Imprint page.