Privacy policy
Last updated: 2026-09-20. This service is pre-release.
Who we are
This service is operated as artefaktum.dev (“we”, “us”). Contact: support@artefaktum.dev.
What we store and why
- Account identity. Sign-in is handled by Clerk. We receive a user id, your email address, your name, and the organisation you belong to, so we can create and identify your tenant. We do not receive your password.
- Artifacts. Files you or your agents upload, plus the metadata you attach (title, description, tags, custom metadata) and derived data we compute from that metadata (search index, embeddings). Uploads and downloads go directly to our object-storage provider over short-lived signed URLs and never pass through our application servers — we do not read file contents at all.
- API keys. A one-way hash of each key, its name, scopes, and last-used time.
- Usage records. Request counts, bytes uploaded and downloaded, and storage size, per tenant, project and key, to show you your usage and, later, to bill.
- Error reports. When something breaks we record the request id, the error and a stack trace; these may include identifiers such as artifact ids, never file contents.
Processors
We use these providers to run the service. Each processes data on our behalf.
| Provider | Purpose | Location |
|---|---|---|
| Clerk | sign-in, organisations, sessions | processor based in the USA |
| Fly.io | application servers | EU (Frankfurt) |
| Neon | database | EU (Frankfurt) |
| Cloudflare | object storage for artifacts (R2); DNS; reverse proxy and CDN in front of the API and the website — TLS is terminated at Cloudflare, so every API request and response passes through it in readable form, including access tokens and artifact metadata; website hosting once connected | R2: Eastern Europe (location hint only, not a formal jurisdictional restriction); DNS and network: global |
| OpenAI | text embeddings of artifact metadata for search (never file contents) | processor based in the USA |
| Sentry | error reporting | EU |
| Grafana Labs, Better Stack | uptime and health monitoring (no personal data) | EU |
Transfers outside the EU rely on the provider’s standard contractual clauses.
Retention
Artifacts stay until you delete them or their expiry passes; deleted artifacts are removed from storage within hours and the record is kept as a tombstone with no content. Usage records are kept for 24 months. Error reports are kept for 90 days. Account identity is kept while your account exists.
Cookies
The public pages set no cookies. After you sign in to the console, Clerk sets cookies
that keep you signed in (__session, __client_uat and related). They are strictly
necessary for the service you asked for and need no consent. We use no analytics and
no advertising cookies.
Your rights
Under the GDPR you may ask for access to, correction of, deletion of, or restriction of processing of your personal data, receive a copy of it in a portable format (data portability), or object to processing, by writing to support@artefaktum.dev. You may also lodge a complaint with your local data protection authority.
Changes
We will post changes on this page and update the date above.