1. Introduction and scope
Artfical ("Artfical," "we," "us," or "our") provides tAI, tCode, the Artfical API, and the related websites at tai.artfical.com, ai.artfical.com, and docs.artfical.com (together, the "Services"). This policy explains what personal data we collect in connection with the Services, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
This policy applies to visitors, registered users, and, where applicable, individuals whose information is processed on behalf of an organization with a commercial agreement with us. It does not apply to a third-party service you choose to connect to the Services, such as Gmail, Notion, GitHub, or Linear, which is separately governed by that provider's own privacy terms in addition to this policy.
This is the master privacy document for the Services. The privacy choices page is a practical, plain-language index of the controls described here, and the cookie policy covers cookies and similar technologies in full.
2. Definitions
- Personal data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
- Controller means the entity that determines the purposes and means of processing personal data. Artfical is the controller for the personal data described in this policy, except where a separate written agreement with your organization specifies otherwise.
- Processor means an entity that processes personal data on behalf of a controller, on the controller's documented instructions.
- Connector means an optional, explicit integration between the Services and a third-party account, currently Gmail, Notion, GitHub, or Linear.
- Usage data means data generated by your use of the Services, including feature usage, error logs, and performance metrics, as distinct from the content of your conversations.
3. Personal data we collect
The table below sets out the categories of personal data we collect, representative examples of each, and where it typically comes from. It does not list every possible field collected in every configuration of the Services, but it covers every category.
| Category | Examples | Source |
|---|---|---|
| Account information | Name, email address, authentication credentials | Provided directly by you |
| Conversation content | Messages, uploaded files, generated output | Provided directly by you |
| Connector activity | Requests made to a connected service, scoped to a given conversation | Generated by your use of a connector |
| Usage and diagnostic data | Feature usage, error logs, performance metrics | Collected automatically |
| Payment information | Billing name and address, payment method token | Provided directly by you, processed by our payment processor |
| Device and log data | IP address, browser type, access timestamps | Collected automatically |
4. How we use personal data
- To provide, operate, and maintain tAI, tCode, and the Artfical API.
- To authenticate your account and secure it against unauthorized access.
- To respond to a support request you've submitted.
- To improve future versions of tAI, limited to usage data and only where you have not opted out under privacy choices.
- To detect, investigate, and prevent activity that violates the usage policy.
- To process payment for a paid subscription or commercial agreement.
- To send a product, security, or billing notice, or, where you have not opted out, an optional product update.
- To comply with a legal obligation, or to establish, exercise, or defend a legal claim.
5. Cookies and similar technologies
The Services use cookies and similar technologies for authentication, security, and, on the marketing and documentation sites, aggregate analytics. We do not use cookies to build an advertising profile of you, and the Services do not run third-party advertising.
The full detail on categories of cookies used, their duration, and how to control them is in the cookie policy, which this section incorporates by reference rather than duplicating in full here.
6. How we share personal data
We do not sell personal data, and we do not share conversation content with advertisers or data brokers under any circumstance.
- Service providers. A provider bound by contract to data-protection terms consistent with this policy, engaged only for a specific operational purpose, such as payment processing or infrastructure hosting.
- Connector destinations. Where you've connected a third-party account, the specific action you requested is sent to that service, scoped to what the action actually requires, described in full in that connector's own documentation.
- Legal and safety disclosures. Where required by valid legal process, or where necessary to protect the rights, safety, or property of Artfical, our users, or the public, limited to what the specific request or circumstance actually requires.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy continuing to govern the transferred personal data, or you being given notice and a choice where required by law.
7. Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on one or more of the following legal bases: performance of a contract with you (providing the Services you've signed up for); our legitimate interests (securing the Services, preventing abuse, and improving the product), balanced against your rights; your consent (for example, an optional product update, or a training-data opt-in you've explicitly enabled); and compliance with a legal obligation.
8. Data retention
Account and conversation data is retained for as long as your account is active, and deleted on account closure subject to the bounded operational window described below, not retained indefinitely on the theory that it might become useful later.
A short operational retention window, generally not exceeding 30 days beyond the point of deletion, applies specifically for backup rotation and abuse prevention. Usage data eligible for training, described in Section 4, is retained under the same review process applied to the core training corpora, not treated as a separate, less-protected category once it enters that pipeline.
9. Security
Personal data is encrypted in transit and at rest. Infrastructure is operated directly by Artfical rather than a third-party cloud AI platform, described in full at docs.artfical.com/tai/en/security/infrastructure.
Internal access to production data is limited to what a given role actually requires to do its job, and is logged. No security measure is perfect, and if we become aware of a breach affecting your personal data, we will notify you and any relevant regulator as required by applicable law.
10. International data transfers
Artfical's infrastructure is operated across the regions described in our infrastructure documentation. Where personal data crosses a border as part of normal operation of the Services, it remains protected under this policy and, where the GDPR or UK GDPR applies, under an appropriate transfer mechanism such as the European Commission's Standard Contractual Clauses.
11. Your privacy rights
Depending on where you live, you may have some or all of the rights described below. We apply the fullest version of these rights to every user by default, rather than limiting them strictly to the jurisdictions that legally require them.
- Access. Know what personal data we hold about you and get a copy of it.
- Correction. Correct inaccurate or incomplete personal data.
- Deletion. Request deletion of your personal data, subject to the bounded retention window described in Section 8.
- Portability. Receive your data in a structured, commonly used, machine-readable format.
- Restriction and objection. Ask us to limit certain processing, or object to processing based on legitimate interests.
- Opt-out of certain uses. Opt out of usage-data-informed training and optional communications, as described in privacy choices.
- Non-discrimination. We will not deny you the Services, charge you a different price, or provide a different level of service because you exercised one of these rights.
Regional specifics
- EEA and UK (GDPR/UK GDPR). The rights above apply in full, along with the right to lodge a complaint with your local data protection authority.
- California (CCPA/CPRA). California residents have the rights above, plus the right to know the categories of personal data disclosed for a business purpose and the right to limit the use of sensitive personal information. We do not sell or share personal data as those terms are defined under the CCPA.
- Turkey (KVKK). Rights under KVKK Article 11, including the right to learn whether your personal data has been processed and to request correction or deletion, are honored in full through the same request process described below.
12. Automated decision-making
tAI can generate output that materially affects a decision, but the usage policy requires a qualified human to review that output before it is acted on for a high-risk use, such as an employment, credit, or housing decision. We do not use personal data to make a legal or similarly significant decision about you on a fully automated basis without human review.
13. Children's privacy
tAI and tCode are not directed at children under 13, and we do not knowingly collect personal data from anyone under that age. If we learn that we have collected personal data from a child under 13 without the consent required by applicable law, we will delete it.
14. Third-party links
The Services may link to a third-party website or service, including a connected account's own service. This policy does not apply to that third party's own data practices, and we encourage you to review its privacy terms separately.
15. Changes to this policy
Material changes are announced at tai.artfical.com/announcements ahead of taking effect. This page always reflects the current version; every prior version, with its own effective date, is preserved and linked from version history.
16. Contact us
Questions about this policy, or a request to exercise a right described in Section 11: [email protected].
See version history for prior versions of this document, and the other pages under Terms and policies in the footer below for related terms.
