Privacy Policy
Last updated October 2, 2026
Who we are
23artifacts is operated by 23made LLC, 1905 Sherman St, Ste 200, Denver, CO 80203, United States — the data controller for the personal data this policy describes. Questions about this policy go to privacy@23artifacts.com.
What we collect
Account data: your email, name, and sign-in method (password hash or emailed codes/links). Content: the artifacts you publish and their version history. Organization data: memberships, roles, teams, and invitations. And, for each artifact, its log: a record of everything that happens to it — publishes and settings changes, who reached it, each page served, comments and recordings, and the software that acted on it. What a log entry holds is described in the next two sections.
Signing in with Apple or Google
If you sign in with Apple or Google, the provider tells us your name, your email address and an identifier for your account with them, and Google also sends your profile picture. We ask for nothing else — no contacts, files, calendar or any other data in your Apple or Google account — and we use what we receive only to create your account, sign you in and show who you are in the product. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We never sell it, never use it for advertising, and never use it to train AI models.
Why we're allowed to use it
Where the GDPR applies, our legal grounds are these. We process account, content, and organization data because it takes that data to provide the service you signed up for (performance of a contract). Dashboard analytics and session replay run only with your consent, which you can withdraw at any time via "Cookie settings" in the footer. And we keep the artifact log in our legitimate interests and those of the artifact's owner: to know who reached a gated artifact, and to recognise and stop abuse and spam.
What the artifact log records about a visit
When someone opens a published artifact, or is admitted or refused at its gate, the log records the page, the referrer domain, the time, and — judged at our network edge from the request — an estimate of where the visit came from (country, region, city, postal code, coordinates, time zone) and what class of device made it. It records the network the request came from, never the full address: an IPv4 address is kept to its first three groups and an IPv6 address to its first three, enough to recognise a spam wave and nothing about which household or device on it. The full address is used only while the request is being served, to limit abuse, and is not stored. The browser's user-agent string is classified into a device class and, for bots and link previewers, a name (for example "Slackbot"), and then discarded. The visitor identifier is a one-way hash that rotates daily and cannot be linked across days or reversed to an address. No cookie is set for any of this.
Who the log names depends on how the visitor is known: someone admitted at the gate by their email address, someone who arrived by share link by the link's name, someone signed in by their account, and software acting for someone (an agent or app) by its own name and version alongside the person's. When a gated artifact refuses someone, the log records the address they tried, so the owner knows who asked. Anyone else is anonymous. Location and device are best-effort estimates and are shown to the owner as such.
Cookies we do set
Session cookies on 23artifacts.com to keep you signed in, and a per-artifact grant cookie on gated artifact pages so approved viewers aren't re-challenged on every visit. No advertising or cross-site tracking cookies. With your consent, the 23artifacts.com dashboard also uses PostHog for product analytics and session replay (to understand how the dashboard is used and to diagnose errors); you can decline, and this never applies to published artifacts, whose analytics stay cookieless. If your browser sends a Global Privacy Control signal, we honour it and treat it as declining analytics — and we don't sell your data or share it with advertisers either way.
Who else touches the data
Infrastructure providers process data on our behalf: our hosting providers (servers in the EU and United States), Cloudflare (DNS, routing/CDN, object storage for artifact files, and page-preview rendering), Resend for transactional email (verification codes, invitations, password resets), PostHog for dashboard product analytics (hosted in the United States), Backblaze for encrypted backups, Deepgram for voice transcription (only when you make a recording), Stripe for payments (card details go to Stripe and never reach us; we keep only the customer and subscription it gives us), Apple and Google when you choose to sign in with them, GitHub for feedback you or your assistant send us about the product (kept in a private repository, without your name, your email address or anything your artifacts contain), and Anthropic for the AI features you invoke — summaries of comments and recordings, and descriptions written from the pixels of images you upload to an asset library. We don't sell your data or share it with advertisers. Where these providers process data in the United States, transfers from the EU or UK rest on safeguards such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses, depending on the provider.
Retention and deletion
Artifacts and their versions are kept until you delete them or your account. Deleting an artifact — or your account (Settings → Delete account, confirmed by email) — takes it offline immediately and starts a 30-day grace window, after which it is permanently removed. In the artifact log, entries about visits — pages served, grants, refusals and arrivals by link — are kept for up to 12 months and then deleted. If a specific visit record is needed for an open abuse report or a legal claim, or the law requires us to keep it, we keep that record until the matter is resolved. Entries about the artifact's own history (publishes, settings, comments, recordings, agent sessions) are kept for as long as the artifact exists. The log is deleted with the artifact. Feedback you or your assistant send us about the product is kept with your account and deleted with it. On the documentation, whether a page helped is counted per page and day with nothing about who answered; a note you add is feedback like any other, kept with your account if you are signed in and for one year if you are not; and a search that found nothing is counted by its words and day, with nothing about who searched, for ninety days. While answering, your network address is held in memory for an hour to limit how many answers come from one place, and never stored.
Some artifacts collect shared state — a poll, a shared canvas, a collaborative board — written by the people who view them rather than by the owner. That content belongs to the artifact: it is visible to the artifact's owner, who can inspect or wipe it at any time, and it is deleted outright when the artifact is deleted, without the 30-day grace period that applies to the owner's own files. Comments left on an artifact are kept while the artifact exists; the change history behind them is retained for 180 days. Don't put anything sensitive into an artifact's shared state: anyone who can view the artifact can write to it and read what others wrote.
Your rights
You can access, correct, or delete your data — most of it directly in the product. Where the GDPR applies you can also object to our processing, ask us to restrict it, receive a copy of your data in a portable format, withdraw consent at any time (via "Cookie settings" in the footer), and lodge a complaint with your local data protection supervisory authority. The portable copy needs no request: Export now, in the Backups card of your account settings, makes a zip of your personal workspace — every artifact, version, comment, asset and theme — with your account details and everything you wrote on other workspaces' artifacts, and emails you when it is ready. For anything else, including access and deletion requests and questions about this policy, email privacy@23artifacts.com.