This policy explains how Artisan AI, Inc. collects, uses, discloses, and retains personal information in connection with Artie, artie.ai, and related applications and services. Artie provides AI workers called Artisans for business use. Some capabilities described here apply only when they are available and enabled.
1. Who is responsible for your information
Artisan AI, Inc. is responsible for personal information we process for our own business purposes, such as website operation, account administration, billing, security, marketing, and managing our relationship with users and business contacts. Our address is 2261 Market Street, STE 62890, San Francisco, CA 94114, United States. Contact hello@artisan.co about this policy or a privacy request.
When a business customer uses Artie to process information in its workspace or connected accounts for its purposes, that customer generally acts as controller or business, and we act as processor or service provider under our agreement and the applicable Data Processing Agreement, as extended to Artie by the Artie terms. If the customer is itself a processor, we may act as its subprocessor. These roles depend on the actual processing, not merely the labels in a contract.
The customer's privacy notice and instructions govern its use of your information. If your information appears in an employer's workspace, a customer's workflow, or a meeting an organization arranged, direct requests about that organization's use to it. We will assist and respond as required by our role and applicable law. This policy does not give customers unlimited rights over other people's information or waive any individual's rights.
2. Information we collect and its sources
Account and business information
We collect information supplied during signup, purchase, onboarding, administration, and contact with us. This may include names, work email addresses, telephone numbers, business and billing addresses, employer, role, workspace membership, account identifiers, authentication information, preferences, plan choices, and communications with our team. We may receive related business-contact information from colleagues, customers, referral partners, public business sources, and providers used to support business outreach.
Customer work and connected accounts
When a customer supplies content or connects a supported source, we process information within the authorized scope. This may include prompts, messages, email, calendars, meeting details, contacts, documents, files, attachments, CRM records, project and task information, repositories, business records, and information returned by research services, APIs, browsers, or other tools. The content may concern the customer's workers, customers, prospects, vendors, collaborators, and other people who do not have an Artie account.
We also process generated documents, code, messages, task results, tool responses, and other Outputs. Artisans can process information and perform tasks proactively under the customer's standing delegation, including when no user is actively chatting. Relevant information may be sent to connected accounts or recipients as part of those tasks.
Memory and derived information
Artie may extract or infer facts, preferences, relationships, work context, summaries, task history, and reusable procedures or skills. We may create indexes, embeddings, retrieval records, and other representations that help Artisans locate and reuse permitted information. Such information can still be personal information even when it is summarized, transformed, or stored as an embedding. An inference may be incomplete or inaccurate.
Execution and authentication information
We process connection and account identifiers, granted permissions, tool requests and responses, execution records, logs, error information, access decisions, timestamps, task status, and usage measurements. Browser or computing environments may process screenshots, visible page content, downloaded files, generated code, temporary working files, and session state needed for authorized tasks.
Dedicated connection and secrets flows may process passwords, API keys, OAuth credentials, and related authentication information. Usable credentials or browser cookies may exist within trusted authentication components or authorized browser sessions when needed. Do not include credentials in ordinary chat, prompts, shared files, or support messages. If they are disclosed accidentally, we may process the affected material to contain the incident and help arrange rotation or removal.
Voice and video and device activity
When relevant features are used, we process live audio or video, speech-to-text data, meeting participant details, telephone or messaging metadata, transcripts, summaries, and notes. Saved audio or video recordings are separate from live processing and text transcripts. Section 6 explains those choices.
Authorized device observation or teaching may process selected screen images, visible text, application events, task steps, and separately enabled narration. This can include information about others visible in the selected work. We do not treat an organization's account ownership as unlimited permission to observe someone's device or personal activity.
Payments and purchases
We collect billing contacts, transaction and invoice details, subscription status, credit purchases and consumption, payment-method references, tax information where needed, and payment-provider results. Designated payment providers handle payment credentials for service billing; we may receive limited card details such as brand and last digits.
If a customer enables purchasing assistance, we also process the authorized vendor, card or payment-account reference, spending mandate, purchase details, receipts, subscriptions, and related correspondence. A separate customer-authorized card or credential used for external purchasing is distinct from the payment method used to buy Artie credits. Optional outside-provider engagements may involve business contact, contract, and payment information for those providers.
Website and service activity
We and our providers collect device and browser information, IP addresses, approximate location derived from IP, online identifiers, referral sources, page views, clicks, events, session and interaction information, and diagnostic or security records. Cookies, pixels, tags, SDKs, and similar technologies may be involved. Product analytics and, where enabled, session replay may show how people interact with the interface. Capture settings and permissions determine the information included. Section 8 explains analytics, advertising, and choices.
Sensitive information
The Services are not intended as a general repository for sensitive or specially regulated information. However, users may inadvertently or deliberately include it in content or connected sources, and private communications and authentication information can themselves receive special legal protection. Depending on the content, we may receive health information, financial details, government identifiers, information revealing protected characteristics, or other sensitive information.
Do not submit such information to an unsupported workflow. Receipt does not mean the workflow has been approved for regulated processing, or that we may use the information for unrelated purposes. We limit processing to applicable service instructions, incident handling, legal duties, and other permitted purposes and apply additional safeguards or consent where required. General voice or video processing does not by itself mean we create biometric identity templates; any separate biometric identification or cloning feature requires an appropriate notice and legal basis before use.
3. Why we use information
We use information for the following purposes, subject to our role, the applicable agreement, source restrictions, and law:
- Provide accounts, workspaces, Artisans, integrations, memory, communication, research, code execution, hosted work, and other enabled features; carry out authorized instructions and standing delegation.
- Authenticate users and accounts, manage roles and permissions, maintain connections, and route tasks and information to appropriate tools and providers.
- Operate subscriptions, payments, credits, purchasing mandates, invoices, usage metering, and financial records; prevent billing abuse and resolve disputes.
- Maintain reliability, diagnose failures, provide support, assess the quality of the service delivered to a customer, and protect people, accounts, systems, and information against misuse and security incidents.
- Communicate about the Services, changes, support, purchases, and the business relationship; send marketing and measure advertising subject to applicable choices.
- Understand service usage and improve our products, including eligible anonymous-data research and training under section 4. The scope and permissions differ from customer-specific memory and operational quality review.
- Meet legal and contractual obligations, respond to lawful requests, establish or defend claims, enforce agreements, and manage a business reorganization or transaction.
We do not use private workspace content, connected email or documents, transcripts, credentials, or private Outputs to select advertisements for unrelated third-party products. Website and account-interaction information may be used for marketing as explained in section 8. We do not treat permission for one purpose as unrestricted permission for all of these purposes.
4. AI processing and improvement
Models and inference
Providing AI features requires sending relevant prompts and context to model and infrastructure providers. This may include customer content, retrieved material, task instructions, and tool results needed to generate an answer or complete work. We use OpenRouter to access model providers. The downstream provider and processing location depend on the permitted route and feature.
Our agreements and routing restrictions must support the commitments in this policy and the DPA. We do not authorize general-purpose model training by downstream providers on identifiable or confidential Customer Content merely because it passes through inference. Limited provider processing needed to serve requests, prevent abuse, or comply with law may still occur under the applicable terms. Inference, provider logging, retention, and training are distinct practices; use of OpenRouter does not itself establish zero retention or processing only in the United States.
Customer memory and operational quality
Using information to answer a customer's requests, maintain its workspace memory, develop its work procedures, troubleshoot its tasks, and assess the service supplied to it is part of providing the service. This is different from using customer information to improve a model for unrelated customers. Turning off optional anonymous-data improvement does not disable necessary processing for the customer's own features or eliminate necessary support and security access.
Anonymous information for improvement and training
Where law, contracts, and source restrictions permit, we may use eligible information to create genuinely anonymous data for evaluation, research, system improvement, and model training. For eligible data, this improvement use is enabled by default where lawful. A workspace administrator can turn it off in the workspace's privacy or data settings or by contacting hello@artisan.co. Where prior consent or a separate opt-in is legally required, we obtain it before the relevant processing; a default setting is not a substitute.
Anonymous data must not reasonably identify or be linkable to an individual or customer, taking account of available means of reidentification. Removing names, hashing identifiers, redacting a few fields, aggregation, or creating embeddings does not automatically meet that standard. Creating anonymous data is itself processing and must have a lawful basis. We exclude restricted source data and protected confidential business information; we do not use anonymization as a way to disclose trade secrets or bypass source restrictions.
An opt-out prevents new selection of eligible workspace data for this optional improvement use after it takes effect. We will also stop using identifiable source material held solely for that purpose and handle it under applicable deletion requirements. The opt-out does not necessarily allow us to identify and remove a contribution already irreversibly anonymized or undo a model update already lawfully completed. We do not reidentify anonymous data to reconnect it to a customer, and we require appropriate recipients to preserve its anonymous status. Any remaining personal information is subject to applicable rights and obligations.
This setting does not authorize us to train general models on identifiable Customer Content. A broader research or contribution program, if offered, requires its own clear purposes and valid permissions. Customers cannot grant rights they do not hold, and a customer opt-in cannot override a provider prohibition.
Google and other restricted sources
Artie complies with the Google API Services User Data Policy, including its Limited Use requirements, for information received from Google APIs. Under the Google Workspace developer policy, covered Workspace data, including derived or anonymized forms, is excluded from generalized model training. Human access to covered data is limited to Google's permitted cases: affirmative agreement for specific data, security needs, legal compliance, or qualifying aggregated and anonymized internal operations. A general training setting does not replace those conditions.
Other connectors may impose narrower purposes, retention, caching, or learning restrictions. We apply the relevant source rules, including restrictions on Slack data and particular API routes. Permission to connect a source is not a blanket right to retain it indefinitely, train on it, or expose it to another audience.
5. Workspace visibility and human access
Workspace owners and authorized administrators may manage users, settings, billing, and shared resources and view information made available to their roles. Other members and Artisans may use permitted shared content and company knowledge to perform work. Connected tools and recipients may receive information when the customer authorizes actions or communications to them.
Ordinary nonsensitive business facts explicitly shared in a direct message may enter shared company memory. This allows authorized Artisans or workspace members to reuse relevant company context. Raw direct-message conversations and member-private preferences remain restricted to their appropriate scope. We do not treat sensitive or restricted matters as ordinary shared knowledge simply because a user mentioned them privately. Users should consider the relevant sharing scope before providing information, and customers must give their users appropriate notice.
Our authorized employees and contractors may access relevant content, task records, and diagnostic information when reasonably needed to operate the Services, troubleshoot, provide support, investigate abuse, maintain security, or review the quality of work delivered to a customer. Separately ordered managed operations may require people to perform authorized work. Access is limited by purpose, role, confidentiality obligations, applicable agreements, and source restrictions; it is not permission for unrestricted browsing of customer work.
Necessary operational human review is not controlled by the optional training switch and is not offered as a blanket account-level opt-out. We consider requests to restrict processing where required by law and may offer alternative arrangements by agreement. Optional unrelated research cannot be relabeled as necessary service review to avoid a choice or legal requirement. Human access does not mean every task is reviewed or that intervention is guaranteed. Credentials are handled through designated trusted processes, not routine support disclosure.
Public sharing, deployment, or publication intentionally enabled by a customer can make selected material available outside the workspace. Other people may download, forward, index, or copy it. Removing the original does not necessarily delete those copies. Workspace transfers or organizational changes must preserve applicable source permissions and individual privacy restrictions.
6. Meetings and device observation
Audio and video recording are off by default. When Artie participates in a meeting or call, live audio or video processing, transcription, summaries, or retained notes may still occur without saving an audio or video recording, where disclosed and lawful. A transcript may be retained as customer content and used in permitted workspace memory. The fact that an audio recording is off does not mean no text record exists.
Required notices and permissions apply separately to the relevant processing. Where the law requires consent to transcription, a customer cannot bypass it by calling the feature live processing or by disabling only the audio recording. If required permission is absent or withdrawn, the affected processing must stop or remain disabled. Customers must address their obligations to participants and nonusers, including required notices of AI participation.
Where device observation or teaching is enabled, the participant's setup and permissions determine the selected scope and session. Observation may continue within that authorized scope until paused, stopped, or otherwise ended. It does not require approval of each individual event, but new purposes or a broader scope may require new permission. Customers and participants must use available exclusions and avoid capturing credentials or unrelated private activity.
A workplace administrator's approval alone may not establish a lawful basis for employee monitoring. Customers must consider employment rules, notice, proportionality, and any consultation or consent requirements. Consent to capture work for a customer's task does not automatically authorize public release or unrelated training. Deleting a recording, transcript, learned procedure, and memory item may involve separate records and controls.
7. Recipients and service providers
We disclose information only for the purposes and subject to the protections described in this policy and applicable agreements. Recipient categories include:
- Infrastructure and execution providers. Hosting, storage, databases, computing environments, file handling, delivery, and related operations. Our primary hosting is on Amazon Web Services in the United States.
- AI and related providers. OpenRouter and permitted downstream model providers; supported research, speech, transcription, video, and other specialist processing providers used by a feature.
- Connection and credential providers. Integration services, authentication providers, designated secrets custody, and permitted tools. Our architecture uses Pipedream for supported managed integrations and Infisical for designated secrets custody, with separate protected handling for browser sessions. The particular custody route depends on the connection.
- Business operations providers. Payment, billing, tax, support, communication, security, diagnostics, analytics, and professional advisory services. Analytics providers include PostHog and Google; advertising-related recipients are addressed in section 8.
- Customer-authorized recipients. Workspace users, connected applications, message recipients, meeting participants, vendors, outside service providers, and audiences to which the customer instructs or delegates disclosure.
- Authorized personnel. Employees and contractors supporting the purposes described in section 5, including separately ordered human operations.
- Legal and transaction recipients. Authorities, courts, advisers, insurers, or others where disclosure is required by law or reasonably necessary for security, rights, or claims; and potential or actual transaction counterparties under appropriate confidentiality and legal safeguards during a merger, acquisition, financing, or sale of relevant assets.
Providers acting on our behalf receive appropriate contractual restrictions and safeguards. Customer-selected services may act independently under their own notices for their own activities. We do not treat that distinction as removing our responsibility for providers we appoint as subprocessors. Applicable subprocessor details and change procedures are available through the Artisan trust center, the DPA, or hello@artisan.co. A provider list may change as supported features and infrastructure change; contractual notice and objection rights remain effective.
8. Cookies and advertising
We use essential technologies for sign-in, security, account state, billing flows, and site functionality. We also use analytics and, where permitted by applicable choices, advertising technologies to understand visits, measure campaigns, build or reach business audiences, and show relevant advertisements across websites or services. PostHog and Google tools are part of our analytics stack; Google and other advertising partners may receive information through the advertising tools we deploy. With your visitor-identification choice enabled, Artisan uses Vector and Demandbase to match website visits with professional contact or company information for relevant sales outreach. Visitor identification is optional and separate from analytics and session recordings. You can decline it or withdraw your choice through Privacy settings.
Information involved may include online identifiers, IP addresses, approximate location, browser or device information, referral information, page visits, events, and interactions. Some disclosure to advertising partners may constitute a sale or sharing of personal information or targeted advertising under state privacy laws, even without a monetary payment. This is distinct from private workspace content, which is subject to the restrictions in section 3.
You can use the site's cookie or privacy choices to control nonessential categories and opt out of sale, sharing, or targeted advertising. Where consent is required for nonessential storage, access, or related processing, those technologies remain inactive until valid consent is obtained. You may withdraw that consent through the same choices. We honor Global Privacy Control and other legally recognized opt-out preference signals where required, including for applicable sale and sharing choices. Traditional Do Not Track signals may not be treated as equivalent to a recognized legal opt-out signal.
You can also contact hello@artisan.co for assistance. Browser controls and vendor opt-outs may offer additional choices, but blocking cookies alone may not control every advertising use or data disclosure. Choices may apply to a browser or device; signed-in account choices are applied more broadly where supported or required. Opting out does not remove essential processing or mean you will see no advertising.
Marketing emails include an unsubscribe method. You can also ask us to stop marketing to you. We may still send necessary account, security, billing, and service communications. Our use of a customer's business name and logo is subject to the marketing opt-out in the Terms; that permission does not authorize an individual's endorsement or disclosure of private work.
9. Retention and deletion
We retain personal information for the period reasonably needed for the purpose for which it was collected, considering the customer's instructions, account status, feature settings, source restrictions, contracts, legal duties, security needs, and the nature and sensitivity of the information. Where a specific duration is not reasonably fixed in advance, these criteria determine it. We do not apply an unlimited retention rule merely because Artie supports persistent memory.
- Workspace content and derived memory. Retained while needed to provide the customer's continuing service, subject to deletion requests, source permissions, and the DPA. Canceling a paid plan may leave an available account or separately continuing service; canceling renewal and requesting deletion are different actions.
- Recordings and observation evidence. Retained according to the enabled feature's disclosed settings, purpose, and applicable source limits. Transcripts, notes, Outputs, and derived skills are separate records and may have different purposes and retention periods. Raw capture is not retained solely because a later summary remains useful.
- Credentials and sessions. Retained only while needed for authorized access and associated security requirements. Disconnecting a connection requires withdrawal of usable access within its scope; provider-side revocation and externally completed actions may require separate handling. We do not retain live secrets as ordinary business history.
- Execution and diagnostic records. Kept for a proportionate period to operate, meter, troubleshoot, secure, and substantiate the service and resolve disputes. Restricted source content is subject to any shorter applicable retention or caching limit.
- Account and commercial records. Kept for the relationship and as needed for accounting, tax, fraud prevention, contracts, legal claims, and legally required records. An applicable legal hold may require longer restricted retention of relevant information.
- Analytics and advertising records. Retained according to the technology's purpose, configured lifetime, applicable consent and opt-out choices, and law. Necessary suppression records may be kept to continue honoring an opt-out.
When the relevant service ends, Customer Data is returned or deleted according to the DPA, including its ordinary outer limit of 90 days and its limited exceptions for legally required retention and protected backup copies. Shorter legal deadlines or source requirements control where applicable. This period is not permission to delay a valid privacy request beyond the applicable legal deadline.
Deletion from live systems may precede expiration of protected backup copies. Retained backups are restricted from ordinary use and are deleted under the applicable backup lifecycle; restoration must not reintroduce information that should remain deleted. We may retain limited information needed for legal obligations, security, or claims, with restricted access and use. We cannot delete a separate copy controlled by a customer, recipient, or independent provider merely by removing our copy, but will take required processor and recipient-notification steps.
Irreversibly anonymous information may be retained for permitted purposes because it is no longer personal information. This exception does not cover merely pseudonymous records, restricted source data, or information subject to a continuing contractual deletion duty.
10. Your controls and requests
Depending on the feature and your role, available controls may let you manage account details, workspace membership, permissions, connections, tasks and recurrences, spending, recording and observation, memory, shared links, optional anonymous-data improvement, and account closure. Disconnecting an app, stopping work, disabling training, withdrawing cookie consent, and deleting stored information have different effects; one does not automatically perform all the others.
Subject to applicable law and exceptions, you may have rights to know whether we process your information; access and obtain a copy; correct inaccuracies; request deletion; restrict or object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; and receive appropriate safeguards concerning significant automated decisions. You may also have a right to appeal a refusal and complain to a regulator. We do not discriminate against you for exercising protected rights.
Submit requests to hello@artisan.co with enough detail to identify the information and relationship involved. Do not send passwords or complete sensitive identity documents in an initial email. We may seek proportionate verification for access, deletion, or similar requests and authority for an agent acting for you. We do not require identity verification or an account for an opt-out where law prohibits it. We respond within applicable deadlines and explain any permitted extension or refusal.
Where we act for a customer, we may direct or forward the request to that customer and assist under the DPA. We do not use that process to avoid duties we independently owe. Where a right of appeal applies, reply to our decision or email hello@artisan.co identifying the request and why you disagree. We will review and respond within the applicable deadline and provide available complaint options.
11. California and other United States rights
For California residents, the descriptions in this policy serve as a notice of the categories we collect, sources, purposes, disclosures, and retention criteria. Our practices depend on the relationship and features used. The categories include identifiers and account details; commercial and payment records; internet and device activity; professional or employment-related information; audio, visual, and electronic content; inferences; and sensitive personal information where supplied or involved in an enabled feature. They may also include personal-record categories and protected characteristics appearing in customer content. We do not claim every user supplies every category.
We disclose these categories as needed to the provider and recipient categories in section 7 for the purposes in sections 3 through 6. Website identifiers, internet activity, approximate location, and related marketing interactions may be disclosed to advertising partners in a way that constitutes sale or sharing. We do not sell or share private workspace content for cross-context behavioral advertising. Where we act as a service provider, we use customer personal information only as permitted by the applicable service-provider terms and law.
California residents may request access to categories and specific pieces of personal information, sources, business purposes, and recipient categories, including applicable collection or disclosure during the preceding 12 months; correction; deletion; and portability, subject to legal exceptions. You may opt out of sale or sharing through the site choices, a recognized preference signal, or hello@artisan.co. An authorized agent may act for you subject to applicable authorization rules.
We use sensitive personal information for necessary service, security, authorized communication, and other legally permitted purposes, not to infer personal characteristics for unrelated marketing. If an additional use triggers a statutory right to limit or a consent requirement, we will provide the required notice and choice before that use. We do not knowingly sell or share personal information of people under 16 and do not offer accounts to people under 18.
Other state laws may provide similar or additional rights, with different eligibility rules and business-context exemptions. Where applicable, you may opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects, exercise access, correction, deletion, or portability rights, and appeal a denial using section 10. We apply the protections required for your situation rather than assuming that all business information is exempt.
12. European and international legal bases
Where European Economic Area, United Kingdom, or Swiss law applies and we act as controller, we rely on the following legal bases as appropriate:
- Contract. Processing objectively necessary to enter into or perform a contract with you, where you are personally a party. Where the contract is with your employer or another organization, our business-contact processing generally relies on legitimate interests instead.
- Legitimate interests. Operating and securing a business service, maintaining business relationships, preventing fraud, troubleshooting, improving reliability, conducting proportionate service-quality review, and permitted business marketing, after considering your rights and reasonable expectations. Anonymization or improvement processing relies on this basis only where the processing and balancing assessment support it and no consent or other specific condition is required.
- Consent. Processing requiring valid consent, including relevant nonessential cookies, advertising technologies, and optional capture or other features where applicable. You may withdraw consent without affecting processing lawfully carried out beforehand. Workplace consent is used only where it is valid in the circumstances.
- Legal obligations. Records, regulatory compliance, lawful requests, and other duties we are required to meet.
Where special-category information is involved, we also require an applicable additional condition and safeguards. A customer's instruction, a contract, or a general legitimate interest does not alone meet that requirement. If we process information for a customer, the customer is responsible for its lawful basis and required notices, and we follow lawful instructions and our own applicable duties.
You may object to processing based on legitimate interests and to direct marketing. You may complain to a competent supervisory authority, including where you live or work or where an alleged infringement occurred. Our existing EEA and UK representative contact details are available in Artisan's privacy notice; you may also contact hello@artisan.co to reach the appropriate privacy contact. We will provide information about applicable transfer safeguards on request, with necessary confidential information protected.
13. Automated processing and decisions
Artisans use automated processing to generate content, infer context, select steps, prioritize work, and carry out delegated actions. Relevant inputs can include customer instructions, connected records, prior task history, and permitted memory. Model predictions and configured tools produce responses or external actions; results can be inaccurate or incomplete. Those actions can affect communications, records, purchases, and business workflows.
We do not use the general-purpose Services as our own system for deciding an individual's employment, credit, housing, healthcare, or comparable eligibility. A customer may propose a regulated use only where the relevant offering, providers, agreements, and law permit it and all necessary safeguards are in place. General autonomy settings do not establish compliance for a legally significant decision or waive a person's right to human involvement, explanation, contest, or other protection where applicable.
Where we determine the purpose of a legally significant automated decision and applicable law imposes additional obligations, we provide the required specific notice, lawful basis, and safeguards before that processing. When a customer is responsible for the decision, it must provide those protections and explain its specific decision process. Contact the responsible organization or hello@artisan.co for assistance identifying the appropriate route.
14. Processing locations and transfers
Our primary hosting is on AWS in the United States. Information may also be processed in other countries where permitted providers or authorized personnel operate. Model routing through OpenRouter, customer-selected integrations, support, and optional services may involve separate processing locations. United States hosting is not a promise that every copy, inference request, or human access remains in the United States.
Where a transfer is restricted by applicable law, we use an appropriate mechanism, such as an applicable adequacy decision or approved contractual safeguards, including relevant EU Standard Contractual Clauses and UK or Swiss adaptations, together with required assessments and supplementary protections. A user's acceptance of this policy is not treated as blanket consent replacing those safeguards. A particular regional hosting or routing commitment applies only if expressly agreed for the service.
15. Security
We use reasonable administrative, technical, and physical safeguards appropriate to the information and risks. These include access restrictions, protected credential handling, encryption for designated storage and transmission, and procedures for security and incident management. Our credential architecture separates secrets custody from the general agent execution environment and limits access to trusted components needed for authorized use. An authenticated browser still contains usable session information and needs separate protection.
No system or transmission is completely secure. We do not promise that plaintext never exists during authorized authentication, that a provider can never access information, or that every product has a particular certification or regulated-data qualification. Customers also need to manage permissions, protect credentials and devices, and use supported controls. We handle security incidents and required notices under applicable law and agreements.
16. Age and external services
Artie accounts are for business users aged 18 or older. We do not knowingly offer accounts to children or intentionally solicit their information. Customer content may nevertheless mention or include information about a minor; that possibility does not authorize a customer to use Artie for prohibited children's profiling or unlawful processing. Contact us if you believe a child has provided information inappropriately, and we will take the steps required by law.
External websites, connected services, and customer-published sites may have their own privacy notices. Where a customer uses Artie to publish an application or collect visitor information, the customer is normally responsible for that site's purposes and notices, and we process resulting information according to the actual arrangement. Our role in hosting does not automatically make us the controller of every customer workflow.
17. Changes and contact
We may update this policy as features, processing, or legal requirements change. We will update the effective date and provide notice of material changes through an appropriate method, such as account email or a prominent notice. Where a new purpose requires consent or another legal step, we complete that step before the new processing. Covering an optional feature in this policy does not mean the feature is already available or excuse a required notice when it is introduced.
Contact Artisan AI, Inc. at hello@artisan.co or 2261 Market Street, STE 62890, San Francisco, CA 94114, United States, for privacy questions, requests, complaints, or assistance reaching the responsible customer or privacy representative.
