ArtCrew
Support Terms

Privacy policy

ArtCrew privacy policy

Version 2026-09-01 · Last updated: September 1, 2026

Privacy at a glance

  • ArtCrew is cloud-first for signed-in covered data. The App keeps local cache and offline working copies, but a selectable local-only mode may not be available.
  • We do not sell personal data, run third-party behavioural advertising, or use User Content to train an ArtCrew general-purpose AI model.
  • Optional PostHog product analytics is off unless you actively enable it. Sentry reliability diagnostics is separate and is configured to exclude default personal-information collection, replay, screenshots, and broad logs.
  • Artwork images, contact records, sales, documents, public websites, social posts, and AI requests can contain sensitive information. You control what you enter and publish.
  • You may request access, correction, deletion, restriction, portability, or objection and may complain to the UK Information Commissioner or an EEA supervisory authority.

Contents

  1. Scope
  2. Controller and contacts
  3. When ArtCrew is controller or processor
  4. Personal data we process
  5. Sources of personal data
  6. Purposes and lawful bases
  7. Feature-specific processing
  8. Device permissions and local data
  9. Children and sensitive data
  10. Cookies, SDKs, and similar storage
  11. Recipients and service providers
  12. Public disclosure and independent controllers
  13. International transfers
  14. Retention
  15. Security
  16. Automated processing and AI
  17. Your data-protection rights
  18. Export, unpublishing, and deletion
  19. Objection and consent withdrawal
  20. Complaints
  21. Policy changes
  22. Contact us

1. Scope

1.1 Services covered

This Policy explains how Nouille Studio Limited processes personal data through the ArtCrew mobile App, dashboard, ArtCrew public site, artist websites hosted through ArtCrew, cloud sync and media storage, billing, account management, website imports, AI suggestions, social publishing, documents, notifications, diagnostics, optional analytics, and support.

1.2 People covered

It applies to Account holders, trial and paid users, support requesters, visitors to ArtCrew and ArtCrew-hosted artist websites, people identified in studio records, social-account holders, rights claimants, and other people whose personal data reaches ArtCrew. If an artist or studio entered your data, that user may be the controller and should give you its own privacy information.

1.3 Other notices

Just-in-time notices shown when a permission, AI request, import, publication, social connection, payment, or other feature is used supplement this Policy. A connected platform, payment provider, identity provider, app store, domain registrar, or artist website may be an independent controller under its own notice.

2. Controller and contacts

ControllerNouille Studio Limited, trading as ArtCrew
Company number17136168, registered in England and Wales
Registered officeFlat 86, Vanbrugh Court, Wincott Street, London, United Kingdom, SE11 4NR
Privacy contactsupport@artcrew.io
Data Protection OfficerNo DPO contact was identified in the materials used for this draft. Before publication, ArtCrew must confirm whether a statutory DPO is required or has been designated and publish the contact if applicable. Privacy enquiries are currently routed through the privacy contact.
UK regulatorInformation Commissioner’s Office (“ICO”), ico.org.uk/make-a-complaint

EEA launch item: ArtCrew is established in the United Kingdom. Before offering covered Services to people in the EEA, ArtCrew must appoint and publish the name, postal address, and contact details of an EEA representative where Article 27 GDPR applies. A Digital Services Act representative may also be required for hosted public content. Those appointments cannot be replaced by this Policy.

3. When ArtCrew is controller or processor

3.1 ArtCrew as controller

ArtCrew determines purposes and means, and acts as controller, for Account registration and authentication; Plan eligibility and entitlement; billing and tax administration; security, abuse prevention, and fraud; service diagnostics; optional ArtCrew analytics; support and complaints; legal compliance; app-store reporting; public-site request logs; and ArtCrew’s own communications.

3.2 ArtCrew as processor

When an Account holder subject to controller duties determines why and how to process personal data about contacts, collectors, customers, staff, or other people and ArtCrew merely stores, syncs, publishes, exports, or transmits it on that user’s instructions, that user is normally controller and ArtCrew is processor. The Data Processing Terms in Schedule 1 of the Terms of Service apply. Purely personal or household processing may fall outside those controller duties where the legal exemption applies.

3.3 Mixed roles

The same dataset can involve different roles. For example, a collector’s details in a user’s private sales record may be processed by ArtCrew as processor, while security logs recording access to that record are processed by ArtCrew as controller. Stripe, Apple, Google, Meta, a registrar, or a social platform may separately determine its own purposes and act as an independent controller.

4. Personal data we process

CategoryExamplesRequired?
Account and authentication Account UUID, email, password-verifier and authentication state held by Supabase, session and refresh tokens, login method, Apple or Google subject identifiers, name shared by an identity provider, account creation and update times, QR or browser-handoff state, acceptance timestamps and policy versions. Core identifiers and authentication state are required for a signed-in Account. Social or Apple/Google sign-in is optional where alternatives exist.
Profile and onboarding Legal name, artist or display name, aliases, role, age or age attestation, date of birth if entered, gender if entered, nationality, city, country, email, phone, website, social links, practice, media, styles, techniques, hashtags, language, currency, measurements, and field preferences. Only fields identified in the interface as necessary are required. Many artistic and demographic fields are optional.
Artwork and gallery records Artwork IDs, titles, descriptions, medium, dimensions, creation dates, images, video or audio references, variants, editions, categories, galleries, tags, notes, status, location, condition, provenance, exhibitions, valuation, insurance, availability, custom fields, deletion and sync metadata. Chosen by you. A minimal identifier may be needed to create and sync a record.
Media and metadata Original and derived files, filename, MIME type, dimensions, byte size, object path, thumbnail, upload state, hashes, and embedded EXIF/IPTC/XMP metadata such as capture time, device details, creator data, and possibly precise GPS coordinates. Required only for media functions. Remove metadata before upload if you do not want it processed or potentially preserved in a derivative.
Contacts and relationships Names, organisation, role, postal address, email, phone, website, social links, notes, relationship type, interaction history, tags, imported contact identifiers, and links to artworks, galleries, sales, or documents. Optional. The Account holder is responsible for lawful collection and use.
Sales and commercial records Buyer or collector, artworks, amounts, currency, taxes or VAT fields, dates, payment or sale status, discounts, insurance, consignment, shipping, invoice and document links, internal notes, and transaction history. ArtCrew does not receive full card details for ArtCrew subscriptions. Optional for studio sales; required particulars depend on a document or workflow you choose.
Documents Templates, document content, versions, recipient and issuer details, artwork and sale fields, signatures or signature placeholders, generated PDFs, export history, and document metadata. Optional.
Website and public publishing Public profile, artwork selections, navigation, blocks, rich text, galleries, links, contact details, website slug, snapshots, publication versions, public URLs, custom hostname, DNS verification and certificate status, publish attempts, errors, and public asset manifests. Required only if you use website functions. Published fields become public.
Website import Submitted source URL, resolved host and network-safety data, pages fetched, response metadata, image source URLs, candidate images and previews, ranks, approvals, job state, attempt and error records, quotas, IP-derived abuse controls, and promotion identifiers. Required only for an import you request.
Social accounts and posts Instagram or Facebook platform, provider account ID, display name, encrypted access token, token expiry, connection state, candidate pages or accounts, captions, hashtags, schedule and timezone, media, target state, provider post ID, delivery attempts and errors, rendered media, cancellation, and publication time. Required only for social functions you choose.
Music Jamendo track ID, title, artist, licence name and URL, preview and share URLs, attribution, duration, artwork, saved preferences, and tracks attached to a draft or render. Optional.
AI request data The selected artwork image encoded for transmission, requested field, model and operation, generated suggestion, safety moderation outcome, pseudonymous user/network quota keys, request fingerprint, idempotency key, provider request ID, token counts, timing, status, and error class. Required only when you actively request an AI suggestion.
Subscription and billing Stripe customer, checkout, subscription, invoice, payment-intent, price, plan, billing interval, status, service period, billing address, country, tax treatment, VAT evidence, last-four/brand where Stripe returns them, refund, dispute, cancellation, entitlement, trial, adult-attestation, and reconciliation records. A restricted owner-only migration archive may also contain legacy native-store or RevenueCat billing rows if any existed at the Stripe-only cutover. Necessary to start a trial or paid Plan and to administer payment and legal obligations.
Apple/Google external-purchase reporting Encrypted or hashed attribution tokens, app-store territory and program context, provider series and report identifiers, transaction amount/currency/service period, renewal, cancellation, plan change, and refund reporting state. After Account deletion, retained records are designed to be pseudonymised. Required where a purchase begins under the applicable EU/EEA app-store program.
Device, app, and notifications Platform, OS and app version, build and release, device class, locale, timezone, permission state, Expo push token, push platform, notification payload and delivery/read state, secure local owner key, sync cursor, storage usage, and connectivity or failure state. Some technical data is necessary; notifications and device permissions are optional.
Diagnostics Privacy-filtered Sentry event, stack trace, app release, OS/device context, error class, performance trace, failure stage, and sanitised technical breadcrumbs. Default PII, session replay, screenshots, view hierarchy, touch tracing, and diagnostic logs are disabled in the current configuration. Necessary legitimate-interest processing for reliability where Sentry is enabled.
Optional product analytics A random installation identifier, platform, app version, build environment, access-mode category, and a strict allowlist of milestones: onboarding start/completion, first artwork creation, cloud-sync completion, website publication, paywall view, and subscription result. No Account ID, name, email, content, price, filename, URL, free text, error, or replay is intentionally sent. No. Disabled unless you opt in and the preview/beta configuration is enabled.
Support and complaints Name, email, subject, topic, message, website or Instagram handle, optional app/device context, app version, page URL, source, browser user-agent, attachments or filenames you provide, ticket and response history, and a salted hash of the request IP where configured. Contact details and message are needed to answer a request.
Security and operations IP address or pseudonymous hash, request headers, timestamps, user-agent, authentication events, rate-limit keys, audit trail, ownership and version metadata, upload queues, abuse signals, content reports, moderation decisions, legal requests, and incident evidence. Usually necessary for security, integrity, compliance, and claims.

5. Sources of personal data

We obtain personal data:

  • Directly from you when you register, enter records, upload media, publish, contact support, order, or exercise a right.
  • From your device through local files, selected photos, selected contacts, camera input, notification state, device/app context, embedded media metadata, and technical requests, subject to platform permissions.
  • From identity providers such as Apple or Google when you choose that sign-in method.
  • From service and payment providers including Supabase, Stripe, Apple, Google, Cloudflare, app stores, and notification infrastructure.
  • From connected social and music providers including Meta and Jamendo when you connect, search, import, render, or publish.
  • From publicly accessible websites only when an authorised Account holder submits a source URL for import or when public content is needed to resolve a report.
  • From another ArtCrew user where that user enters you as a contact, collector, buyer, collaborator, rights holder, or other person in its records.
  • By inference or generation when we derive entitlement, sync, security, quota, publication, moderation, or AI-output data from the preceding information.

5.1 Privacy information for indirectly obtained data

Where we receive your data from an ArtCrew user or another source and ArtCrew is the controller, we provide the information required by Article 14 GDPR within the applicable period—ordinarily within one month, at first communication, or before first disclosure—unless you already have it, providing it is impossible or would involve disproportionate effort under a lawful exception, obtaining or disclosure is expressly required by law with safeguards, or professional secrecy law applies. Where ArtCrew is only the user’s processor, the user remains responsible for its controller notice and we assist as required.

6. Purposes and lawful bases

The lawful bases below refer to Article 6 GDPR and corresponding UK law. More than one basis may apply. “Legitimate interests” means the specified interest only after considering necessity, proportionality, and your rights; it is not a licence for unrelated use.

PurposeTypical dataLawful basis
Create and secure the AccountIdentity, email, authentication, sessions, acceptance, device owner state.Contract or steps requested before contract; legitimate interests in account security and continuity; legal obligation where verification is required.
Supply cloud sync, storage, offline continuity, documents, websites, imports, social delivery, and requested AIUser Content, identifiers, device and service state, instructions, provider results.Contract; for third-party data under a Business User’s control, processing on the controller’s documented instructions.
Publish or send ContentSelected public profile, website, social, media, document, and recipient data.Contract and your explicit instruction; legitimate interests in secure delivery. Consent is used where a separate law requires consent.
Operate trials and paid PlansAge attestation, territory, Order, Stripe and entitlement state.Contract and pre-contract steps; legal obligations for consumer, tax, accounting, sanctions, and app-store rules; legitimate interests in fraud prevention and debt administration.
Report qualifying external purchasesApple/Google attribution context and transaction reports.Contract; legal obligation where applicable; legitimate interests in complying with platform programs necessary to offer the selected purchase route.
Provide support and handle complaints, rights, withdrawal, and disputesContact, Account, message, transaction, logs, evidence.Contract or pre-contract steps; legal obligation; legitimate interests in service quality and establishing, exercising, or defending claims.
Protect the Services and othersAuthentication, access, IP/hash, rate limit, abuse, content reports, audit and incident records.Legitimate interests in security, integrity, fraud prevention, rights protection, and business continuity; legal obligation; vital interests in rare safety emergencies.
Diagnose reliability with SentrySanitised crash, error, release, device/OS, and performance context.Legitimate interests in detecting and repairing defects and protecting data. We minimise event content and disable replay and default PII.
Optional PostHog product analyticsRandom installation ID and allowlisted milestone data.Your consent. Core access does not depend on consent and withdrawal is available in Privacy & Legal settings.
Send service communicationsEmail, Account, Plan, security, policy, transaction, and support state.Contract; legal obligation; legitimate interests in operating and securing the Account. Marketing, if introduced, will use consent or another basis permitted for the specific audience with an opt-out.
Comply with law and corporate obligationsRelevant Account, transaction, tax, report, complaint, consent, and legal-request data.Legal obligation; legitimate interests in governance, audit, and legal claims.
Improve ArtCrew without identifying peopleAggregated or irreversibly anonymised statistics and technical learnings.Not personal data once genuinely anonymised; before anonymisation, legitimate interests or consent as appropriate.

6.1 Contractual and statutory requirements

Account email and authentication state are contractually necessary for signed-in Services. Accurate billing address, age attestation, and transaction information may be contractually and legally necessary for a trial or purchase. If you do not provide required information, the affected Account, payment, publication, support, or provider function may not be available. Optional profile fields, contacts, analytics, social connections, device permissions, and AI requests are not required for core account administration.

6.2 No sale, targeted advertising, or ArtCrew model training

ArtCrew does not sell personal data, exchange it for advertising value, build third-party advertising profiles, or show third-party behavioural advertisements. ArtCrew does not use User Content to train its own general-purpose AI model. We will not introduce a materially incompatible purpose without the notice, lawful basis, and consent required by law.

7. Feature-specific processing

7.1 Cloud sync and storage

For signed-in covered data, Supabase Postgres and object storage may be canonical while local SQLite and files are an offline cache and pending-mutation outbox. Sync uses owner IDs, versions, cursors, deletion markers, timestamps, upload states, quotas, and conflict information. Private artwork and document media is stored under owner-scoped paths. Do not assume that content remains only on your device.

7.2 Public websites and custom domains

When you publish, selected snapshots and assets are intentionally public through Cloudflare and may be indexed, cached, archived, copied, or linked. Custom-domain processing includes hostname, DNS verification, certificate status, and routing identifiers. Visitors disclose routine network data such as IP address, user-agent, requested URL, timing, and security signals to Cloudflare and ArtCrew. The artist whose site you visit may be a separate controller for its content and any direct enquiries.

7.3 Website imports

An import request directs Cloudflare infrastructure to fetch up to the configured limits from an authorised public website, inspect static pages, discover image candidates, and re-encode accepted images into private WebP previews. Source hosts receive routine request data. Imported source bytes are discarded after sanitisation; candidates and job records normally expire after approximately 30 days, subject to active approval and manual-review safeguards.

7.4 Social publishing and imports

Meta authorisation returns account identifiers, available Instagram/Facebook destinations, display name, access tokens, permissions, and expiry. Tokens are encrypted before persistence and decrypted only at trusted provider-call boundaries. Posts and media are sent when you instruct immediate or scheduled publication. Provider errors and remote post IDs are stored to show status and prevent duplicate actions. Disconnecting stops future use but does not erase content already held by Meta.

7.5 Music search and rendering

Search terms and routine request metadata may be sent to Jamendo through an ArtCrew function. If you attach a track, licence, attribution, preview, and provider identifiers are stored with the draft. Social rendering may create temporary composite media in cloud storage. Provider and platform rules determine their own logs and retention.

7.6 AI artwork suggestions

Only when you request the feature, ArtCrew retrieves an owned artwork image and sends an encoded copy to OpenAI’s moderation and Responses APIs. The provider receives the image, a tightly scoped instruction, model parameters, and routine API metadata. ArtCrew does not intentionally send your name, email, artwork price, contacts, or unrelated records. The suggestion can be saved to the artwork only through the product workflow. ArtCrew’s cached response patch is designed to clear after 24 hours and pseudonymous request/quota metadata after 30 days when the scheduled cleanup is active. OpenAI’s independent service-side retention follows the applicable API agreement and configured controls.

7.7 Billing and external-purchase programs

Stripe receives payment and billing data directly and returns customer, subscription, invoice, refund, dispute, and limited payment-method information. ArtCrew uses this to project entitlement in Supabase. A client payment result does not itself grant access. Where an iOS or Android purchase begins under an EU/EEA alternative-payment program, Apple or Google may issue attribution tokens and receive required initial purchase, renewal, plan-change, cancellation, and refund reports. Those providers do not determine ArtCrew entitlement.

7.8 Diagnostics and product analytics

Sentry is configured for privacy-filtered reliability telemetry. URLs, tokens, authentication data, query strings, user content, and sensitive breadcrumbs are sanitised; broad logs, replay, screenshots, view hierarchy, touch tracing, and default PII are disabled. PostHog is a separate optional beta signal, hosted at its EU endpoint, with no person profiles, replay, autocapture, lifecycle capture, surveys, remote flags, or Account IDs. Enabling or disabling PostHog does not affect Sentry’s necessary reliability role.

7.9 Support

Support requests are stored in Supabase and may be proxied through Cloudflare. We use the information to respond, troubleshoot, identify abuse, maintain a record of commitments, and improve support. Do not put passwords, full card data, private keys, recovery codes, or unnecessary third-party data in a support message.

8. Device permissions and local data

Permission or storageUseChoice and consequence
Photos and mediaSelect artwork images and other instructed media. The App may copy originals and derivatives into persistent local files.Denying prevents import from the library; other entry methods may remain.
CameraCapture artwork images or supported visual material.Denying prevents in-App capture but does not prevent use of an existing permitted file.
Contacts — read accessShow device contacts so you can select records to import. ArtCrew is not intended to write to the phone address book.Optional. You can enter contacts manually. Only select contacts you may lawfully import.
NotificationsRegister an Expo/Apple/Google push token and deliver website or social status notifications.Optional and revocable in OS settings. In-App status may remain available.
LocationOnly for a clearly identified location-aware feature or where location already exists in selected media metadata.Optional. Precise location is not needed for ordinary account use. Remove GPS metadata from images if it should not be processed.
Audio playbackPreview licensed music and play supported media. ArtCrew’s release configuration does not request microphone recording permission for this purpose.Playback may not work if device audio is unavailable.
SQLite, files, AsyncStorage, SecureStoreOffline cache, content, preferences, consent state, pending mutations, owner binding, and limited entitlement evidence.Necessary for App operation. Clearing storage or uninstalling may remove local copies; OS backups may retain them.

Platform permission prompts control technical access but are not necessarily the GDPR lawful basis for every related processing. We still need a lawful basis and must use data only for disclosed purposes.

9. Children, special-category data, and data about others

9.1 Adults only

ArtCrew Accounts and paid Services are intended for people aged 18 or older. We do not knowingly offer Accounts to children or intentionally profile them. If you believe a child’s data was provided improperly, contact us so we can investigate and delete or restrict it as appropriate.

9.2 Special-category and criminal-offence data

ArtCrew does not ask for health, biometric, racial or ethnic origin, political opinion, religious belief, trade-union membership, sex-life or sexual-orientation, genetic, or criminal-offence data as a normal feature. Free-text, images, provenance, contacts, or support messages may nevertheless reveal such data. Do not submit it unless necessary, lawful, and appropriately safeguarded. Where a Business User chooses to submit it, that user is responsible for an Article 9/10 condition and any impact assessment; ArtCrew processes it only as instructed unless law requires otherwise.

9.3 Third-party transparency

If you enter another person’s data, you must provide this Policy or your own compliant notice as appropriate, identify the controller, explain purposes and recipients, and respect the person’s rights. ArtCrew may not have a direct relationship with that person and may refer a request to the relevant Account holder.

10. Cookies, SDKs, and similar storage

ArtCrew uses the term “cookies” broadly here to include browser cookies, local and session storage, mobile identifiers, SDK storage, secure tokens, and equivalent device technologies.

TechnologyPurposeStatus
Authentication and security storageMaintain Supabase sessions, protect handoffs, bind a local cache to an owner, prevent replay, apply rate limits, and retain security state.Strictly necessary for the requested signed-in service.
Dashboard local/session storageLanguage, theme, dismissed onboarding, notification cache/read state, import onboarding, and one-time recovery after a failed dynamic load.Necessary or low-impact functional storage. Controls are available in the dashboard or browser storage settings.
Billing context and StripePurpose-limited billing handoff, checkout, fraud prevention, payment, Strong Customer Authentication, and portal operation. Stripe may set its own necessary cookies on hosted interfaces.Necessary when you request billing. Stripe’s notice applies to its independent processing.
PostHog mobile SDKAllowlisted beta product milestones under a random installation ID.Non-essential and disabled until you opt in. Withdrawal opts out and resets the identifier.
Sentry SDKPrivacy-filtered crash, error, release, and performance diagnostics.Reliability processing based on legitimate interests; configured without replay, screenshots, or default PII.
YouTube privacy-enhanced embedsDisplay a user-selected video through youtube-nocookie.com. Google/YouTube may receive network data and may place storage when the embed loads or is used.Third-party content. Artist-site owners must provide any consent mechanism required for their visitors.
Remote media, fonts, and CDNsLoad content selected by a user or needed for a web interface. The remote host receives routine network request data.Used only where configured or embedded. Non-essential tracking is not authorised by these functions.

The core ArtCrew public pages do not use advertising cookies. A “Cookie Preferences” control may explain current storage even where there are no optional browser cookies to toggle. Global Privacy Control or “Do Not Track” does not change our behaviour because we do not sell data or perform cross-site behavioural advertising; applicable consent and objection controls remain available directly.

11. Recipients and service providers

We disclose only data reasonably needed for the purpose, subject to contracts and access controls where ArtCrew appoints a processor. A named provider may be a processor for one activity and an independent controller for another.

RecipientPurpose and dataTypical role
Supabase and infrastructure affiliatesAuthentication, Postgres databases, realtime sync, Edge Functions, storage metadata, Account, Content, support, entitlement, and security data.Processor for ArtCrew-controlled processing; subprocessor for Customer Personal Data.
CloudflareDNS/CDN, Pages, Workers, APIs, D1, R2, Queues, Images, Browser Rendering where enabled, custom domains, published sites, import jobs, media, request and security data.Processor/subprocessor; may independently process limited network/security data under its terms.
Stripe and payment partnersCheckout, PaymentSheet where enabled, cards, Apple Pay, Link, SCA, billing address, tax, subscription, invoices, refunds, disputes, fraud, and portal.Processor for some functions and independent controller for regulated payment, fraud, and legal obligations.
OpenAIArtwork image and scoped instruction submitted only for a requested AI suggestion; provider response and safety result.Processor/subprocessor under the configured API arrangement, with any independent legal processing described by its terms.
Sentry (Functional Software)Sanitised crash, error, release, device/OS, and performance diagnostics.Processor/subprocessor.
PostHogConsent-gated random installation ID and allowlisted beta milestone properties through the EU host.Processor/subprocessor when enabled.
AppleApp distribution, Apple sign-in, Apple Pay through Stripe, push delivery, device/platform services, and EU alternative-purchase disclosures, tokens, reports, and notifications.Usually independent controller for Apple services; processor-like role for limited developer-directed services where its terms provide.
GoogleGoogle sign-in, Play distribution, push transport, EU/EEA external-offer tokens and reporting, YouTube embeds, Google-hosted fonts or APIs where selected.Usually independent controller for Google services; processor-like role where its terms provide.
Expo / 650 IndustriesBuild/update infrastructure where used and Expo push-token routing, including device token, platform, and notification payload needed for delivery.Processor/subprocessor or independent platform provider depending service.
Meta PlatformsInstagram/Facebook connection, account selection and import, media, captions, schedules, and publication results.Independent controller for its platforms; recipient acting on your instruction.
JamendoMusic search terms, track metadata, preview playback, licensing and attribution links, and routine request data.Independent controller/provider.
Domain registrars, DNS operators, and certificate authoritiesCustom-domain verification, DNS records, certificate issuance, hostname, and routine network data.Independent controllers/providers chosen by you or technically necessary recipients.
Professional advisers, auditors, insurers, and acquirersLimited data needed for confidential advice, audit, insurance, financing, reorganisation, or a genuine business transfer.Processor or independent controller under confidentiality and law.
Authorities, courts, rights holders, and safety recipientsData legally required for tax, regulatory, court, law-enforcement, rights, fraud, safety, or legal-claim purposes.Independent recipients. We assess validity and disclose only what is required or lawfully justified.

Provider identity, region, and role can change as infrastructure evolves. We will update this list or a linked subprocessor list before a material new disclosure and give Business Users any notice required by the Data Processing Terms.

12. Public disclosure and independent controllers

Data becomes public when you publish an artist website, use a public profile or URL, or direct a social post. Public data may be indexed, cached, archived, copied, downloaded, re-shared, or processed by visitors, search engines, AI crawlers, archives, social networks, and other independent recipients. ArtCrew cannot identify or control every recipient and cannot guarantee recall after unpublishing.

When ArtCrew sends data to Stripe, Apple, Google, Meta, Jamendo, a bank, a registrar, or another provider that determines its own purposes, that provider’s policy applies. Exercising an ArtCrew deletion right does not automatically delete data in an independent provider account or a post already delivered there.

13. International transfers

ArtCrew is established in the United Kingdom, so EEA personal data may be processed in the UK. Providers and support personnel may also process data in the EEA, United States, or another country. Data-protection laws and government-access rules can differ from those in your country.

For a restricted transfer, we use a mechanism recognised by applicable law, such as an adequacy regulation or decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard. We assess provider and transfer risk and use supplementary technical or organisational measures where appropriate. You may request information about the applicable safeguard or a redacted copy by emailing the privacy contact.

Publication to the internet and a user-directed transfer to a connected social platform may necessarily make Content accessible internationally. We will distinguish those instructions from ArtCrew’s own processor transfers.

14. Retention

We keep personal data only for as long as reasonably necessary for the stated purpose, contract, security, legal obligations, disputes, and rights. We consider account status, user instructions, sensitivity, risk, backup cycles, statutory tax/accounting periods, limitation periods, provider requirements, and technical deletion dependencies. Current operational expectations are:

DataTypical retention or criterion
Local App dataUntil you delete the record, clear App storage, complete device cleanup, or uninstall. Device or cloud OS backups may retain copies under Apple/Google settings and schedules.
Account and cloud ContentFor the Account term and until valid deletion, plus a limited period for sync tombstones, recovery, secure backup overwrite, disputes, or law. Soft-deleted content remains marked while deletion propagates.
Private mediaUntil the associated record or Account is deleted and storage cleanup completes, subject to queue retries, orphan detection, backup cycles, incident preservation, and lawful holds.
Published websites and assetsUntil unpublishing, Plan downgrade, or deletion, plus reasonable CDN, DNS, version, rollback, and cache expiry. Third-party search/archive copies are outside our control.
Website-import jobs and private candidatesNormally 30 days; private quarantine storage has a 31-day lifecycle backstop. Active approvals or unresolved manual-review records may outlive normal job retention to preserve integrity, but source bytes may still expire.
AI suggestions and security ledgerA saved suggestion follows the artwork record. Cached response patches are designed to clear after 24 hours; pseudonymous request, quota, and abuse metadata after 30 days, when scheduled cleanup is active. Provider-side API retention follows the applicable provider arrangement.
Social tokensUntil disconnect, expiry, revocation, replacement, or Account deletion, plus short failure/retry and security handling. Posts and delivery history remain until deleted under Account/content retention.
Rendered social mediaUntil associated post deletion or an operational lifecycle expires it, subject to retry, provider delivery, incident, and backup requirements. A separate platform retains delivered media under its own policy.
Push tokens and notificationsUntil token invalidation, disabling, Account deletion, or operational cleanup. Stored notification history remains until deleted or the Account/content retention period ends.
Stripe and entitlement recordsFor subscription administration, then for applicable tax, accounting, refund, fraud, dispute, audit, and limitation periods. Stripe keeps its own legally required records.
Pseudonymised billing and Apple/Google reporting tombstonesThe current deletion design permits retention up to seven years for refund, fraud, audit, accounting, and platform-reporting purposes, subject to a maximum configured legal period and earlier deletion where no longer necessary.
Legacy native-store/RevenueCat migration archiveThe 2026 Stripe-only migration created an owner-only restricted archive capable of holding legacy rows. Before production launch, ArtCrew must verify whether it is populated, remove data not required, document the lawful retention criterion for any remainder, and implement expiry. RevenueCat is not an active billing provider under the current design.
Billing API and operational job recordsShort-lived claims and completed/failed jobs are cleaned on schedules commonly ranging from 7 to 180 days, while canonical transaction records follow the longer legal criterion above.
Support and formal complaintsUntil the request is resolved and then for the period reasonably needed for follow-up, quality, commitments, legal complaints, and limitation periods. Messages containing unnecessary secrets may be redacted or deleted earlier.
Sentry diagnosticsUnder the shortest practical configured project retention consistent with detecting release regressions and investigating incidents. The exact production setting must be verified and recorded before launch and is reviewed at least quarterly.
PostHog analyticsUnder the shortest practical configured EU beta retention. Opting out stops new events and resets the local identifier; historic anonymous events may be difficult to locate without the random identifier and expire under provider configuration.
Policy acceptance and security evidenceFor the Account term and the applicable claims or regulatory period so we can establish the accepted version, investigate abuse, and defend rights.
Backups and incidentsUntil overwritten under rolling provider schedules. A narrowly isolated copy may be retained longer under a documented security incident or legal hold and is access-restricted.

Configuration disclosure item: exact Sentry, PostHog, support-ticket, backup, rendered-media, and any populated legacy-billing-archive production retention settings must be approved, configured, and inserted into this table before those production workflows process live user data. A policy cannot substitute for an implemented deletion schedule.

15. Security

We use risk-based technical and organisational measures designed to protect personal data. Measures in the current architecture include encrypted HTTPS transport; Supabase authentication and row-level access controls; owner-scoped records and object paths; private storage for non-public media; server-side entitlement checks; encryption of social-provider tokens and sensitive external-purchase tokens; bounded request and upload sizes; URL and network-safety controls for imports; idempotency and rate limits; sanitised telemetry; separation of public and private assets; least-privilege administrative access; and deletion and incident procedures.

Local working data uses ordinary Expo SQLite and persistent device files and is not represented as application-level field-encrypted in every location. It relies substantially on iOS/Android sandboxing, device encryption, passcode and biometric controls, and SecureStore for selected secrets. A rooted, jailbroken, unlocked, compromised, shared, or improperly backed-up device creates additional risk.

No method is completely secure. If a personal-data breach is likely to risk people’s rights, we will notify the competent authority without undue delay and, where required, within 72 hours after awareness. If it is likely to create a high risk, we will also notify affected people without undue delay unless a lawful exception applies.

16. Automated processing, eligibility controls, and AI

16.1 No solely automated significant decisions

ArtCrew does not currently use personal data to make a decision based solely on automated processing that produces legal or similarly significant effects about you within Article 22 GDPR. We do not score credit, employment, insurance, health, or artistic merit.

16.2 Deterministic service controls

Automated rules check authentication, ownership, age attestation, EU billing country, app-store eligibility, Plan entitlement, quotas, media status, provider state, rate limits, fraud indicators, and policy version. A failed rule may prevent purchase, upload, publication, AI generation, or other access, but a human review is available through support for a disputed result. Payment and entitlement decisions also depend on independent Stripe, bank, Apple, or Google systems.

16.3 AI output and moderation

OpenAI models analyse an image only when an Account holder requests an AI suggestion. Safety moderation may reject the request. The output is a draft title or enabled metadata suggestion and has no legal or similarly significant effect about a person. ArtCrew records the model and moderation result for security and accountability but does not infer sensitive traits or use the result to rank artists.

17. Your data-protection rights

Subject to conditions and exemptions, EEA and UK data-protection law may give you the right to:

  • be informed about processing;
  • access personal data and obtain a copy;
  • rectify inaccurate data and complete incomplete data;
  • erase data in applicable circumstances;
  • restrict processing while an issue is resolved;
  • port data you provided in a structured, commonly used, machine-readable format where processing is automated and based on consent or contract;
  • object to processing based on legitimate interests and to direct marketing at any time;
  • withdraw consent at any time, without affecting earlier lawful processing;
  • request safeguards used for a restricted international transfer;
  • not be subject to certain solely automated significant decisions and to request human intervention where that right applies; and
  • complain to a supervisory authority and seek a judicial remedy.

17.1 How to exercise rights

Email support@artcrew.io with “Privacy request”, the right, your Account email if applicable, and enough context to locate the data. Do not send a password or full identity document unless we specifically request a secure verification step. You may also use available Account export, correction, unpublish, disconnect, consent, and deletion controls. You may authorise another person to act for you; we may request proportionate proof of that authority and still verify your identity directly where necessary.

17.2 Verification and response

We may ask for proportionate information to verify identity, authority, and Account ownership, especially where disclosure could expose other people. We ordinarily respond without undue delay and within one month under EU GDPR, subject to a lawful extension for complexity or volume. We do not charge unless a request is manifestly unfounded or excessive and law permits a reasonable fee or refusal. We will explain a refusal and complaint options.

17.3 Limitations

Rights are not absolute. We may retain or withhold data to protect another person’s rights, comply with law, preserve legal privilege, prevent fraud, establish or defend claims, or meet tax and platform-reporting duties. An export excludes passwords, private keys, provider tokens, internal fraud logic, temporary signed URLs, other users’ data, and material whose disclosure would undermine security or rights.

17.4 Data controlled by an ArtCrew user

If your data appears only in a studio’s private contacts, sales, documents, or User Content, direct the request to that studio where possible. We will assist the controller as required and may forward your request, but will not disclose another user’s private records without verification and lawful authority.

18. Export, unpublishing, and deletion

18.1 Export

Available Account export can include profile, cloud settings, sync history, content tables, private and public media manifests, website, social, notification, artwork, contact, sale, and document records. It intentionally excludes payment-provider secrets, dashboard authentication material, push tokens, OAuth sessions, encrypted social tokens, temporary object credentials, worker leases, and internal security/billing ledgers. A manifest may identify owned object paths without minting a private download credential.

18.2 Unpublish and disconnect

Unpublishing removes ArtCrew’s active public publication and begins cache cleanup, but search engines, archives, recipients, and third parties may retain copies. Disconnecting a social account stops new ArtCrew calls after queued work settles; it does not delete provider-side posts. Delete those directly with the provider.

18.3 Account deletion

A verified Account deletion is designed to cancel eligible recurring Stripe resources, fence new billing writes, remove the Stripe customer where permitted, delete eligible Supabase authentication and Account rows, remove owned private and public cloud objects, unpublish websites, revoke or delete eligible social and push state, and clear local ArtCrew owner data on the requesting device. A deletion may remain pending while a payment dispute, provider report, in-flight import approval, ambiguous object promotion, legal hold, or security incident requires safe resolution.

18.4 Data retained after deletion

We may retain minimised tax, invoice, refund, fraud, dispute, consent, complaint, and app-store reporting records where required or reasonably necessary. Current billing deletion hardening replaces direct Account and transaction identifiers in retained tombstones with keyed pseudonymous hashes and excludes raw provider tokens where the purpose permits. Pseudonymised data remains personal data if re-identification is reasonably possible and stays protected until expiry.

18.5 Local, backup, and public copies

Account deletion does not necessarily erase an old offline device, exported file, recipient copy, OS backup, search cache, archive, or social post. You must clear other devices and exports you control. Restricted backup copies are deleted through ordinary overwrite and are not restored except for disaster recovery, after which the deletion instruction remains applicable.

19. Your right to object and withdraw consent

You have the right to object at any time to direct marketing. ArtCrew will stop it for the relevant address, except to keep a minimal suppression record so the opt-out is respected.

You may also object to processing based on legitimate interests. Tell us your situation and the processing you oppose. We will stop unless we demonstrate compelling legitimate grounds overriding your interests, rights, and freedoms, or the processing is needed for legal claims.

Withdraw optional PostHog consent in Settings → Privacy & Legal. Withdrawal stops new allowlisted analytics, opts the SDK out, and resets the random installation identifier. You may revoke camera, photo, contacts, location, or notification permission in device settings. Revocation does not make prior lawful processing unlawful and may prevent the associated feature.

20. Complaints

20.1 Complain to ArtCrew

Email support@artcrew.io with “Data protection complaint”. We will acknowledge the complaint, investigate it through a documented procedure, keep you informed where appropriate, and provide an outcome without undue delay. Using our procedure does not prevent you from contacting a regulator or court.

20.2 Supervisory authorities

Because ArtCrew is established in the United Kingdom, you may complain to the UK Information Commissioner’s Office. If EU GDPR applies, you may also complain to the supervisory authority where you habitually reside, work, or believe an infringement occurred. The European Data Protection Board maintains a list of EEA supervisory authorities. You may seek a judicial remedy and compensation where law provides.

21. Changes to this Policy

We review this Policy when the product, providers, law, or processing changes. The version and date identify the notice in force. We will notify Account holders before a material new purpose or materially reduced protection, using email, an in-App notice, or another durable method where required. We will request renewed consent where the new processing relies on consent. Historic versions will be retained or made available on request where reasonably necessary to establish what notice applied.

22. Contact us

Privacy — ArtCrew / Nouille Studio Limited
Flat 86, Vanbrugh Court
Wincott Street
London SE11 4NR
United Kingdom
Company number 17136168
support@artcrew.io

Use the Help Center for a support request. For privacy, put “Privacy request” or “Data protection complaint” in the subject so it is routed correctly.

Contact ArtCrew

Support Terms of Service Report Security Issues Privacy Policy © 2026 Nouille Studio Limited. ArtCrew is a trading name.