Privacy policy
Last updated: 24 July 2026
artifacted stores as little about you as it can get away with. This page lists everything we keep, why we keep it, and how to get it deleted — in plain language.
Who is responsible
artifacted is operated by [FOUNDER: full name], [FOUNDER: street and number], [FOUNDER: postal code and city], Germany (see the imprint). For anything privacy-related, email [FOUNDER: contact email].
What we store, and why
- Your account. When you sign in with Google we receive your email address and name — nothing else. We use them to identify your account and to show app owners who has access to their apps. Legal basis: performing our contract with you (Art. 6(1)(b) GDPR).
- Your apps. The code you deploy is stored in its sandbox on Cloudflare's network so we can run it and serve it back. Legal basis: contract (Art. 6(1)(b) GDPR).
- Visit events. Because every app is private, we check who is asking on every request — and we record who opened which app, and when (sampled to at most one entry per visitor, app, and hour). These records power the access checks, the usage statistics app owners see, and our own understanding of whether artifacted is useful. Legal basis: our legitimate interest in running a private-by-default service securely and improving it (Art. 6(1)(f) GDPR).
- Sharing records. Which emails or company domains an app is shared with, so we can enforce access. Legal basis: contract (Art. 6(1)(b) GDPR).
- Secrets. API keys you add for your apps are stored only in Cloudflare's encrypted secret store and injected into your app at runtime. Our database stores the key names only — never the values. Secret values never appear in our logs, API responses, or dashboard.
What we don't do
No advertising, no selling or renting data, no third-party analytics or tracking scripts. We set one cookie: the session cookie that keeps you signed in. It is strictly necessary to provide the service, so there is no cookie banner to click.
Who else processes your data
- Cloudflare — hosting, database, and secret store. Everything artifacted runs on lives on Cloudflare's global network.
- Google — sign-in only. Google tells us your email address and name when you sign in; we send nothing about your usage back to Google.
How long we keep things
Account data, apps, and sharing records are kept for as long as your account exists. Visit events are kept for as long as the app they belong to exists, so its owner can see usage over time. Delete an app and new visit records stop immediately; delete your account (email us) and we remove your account data, your apps, and their secrets.
Your rights
Under the GDPR you can ask us for a copy of your data (access), ask us to correct or delete it, restrict or object to processing, and take your data elsewhere (portability). Email [FOUNDER: contact email] and we'll handle it — no forms, no hoops. You can also complain to a data protection supervisory authority; in Germany that is the authority of your federal state.