Privacy Policy
LAST UPDATED · MAY 1, 2026
The short version
Artico is an AI museum companion. We collect the minimum data needed to identify the artwork in your photo, deliver an explanation, and let you find your scans again later. We do not sell your data, do not run third-party advertising, and do not share your scans with anyone but you.
What we collect
- THE PHOTO YOU SCANSent to OpenAI's vision API for identification, then stored in our private object storage so you can revisit it across devices. Only you see your scans.
- APPROXIMATE LOCATION AT SCAN TIMEUsed to match your scan to a museum or place (e.g. Louvre / Paris). Resolution is roughly city-scale; we don't track movement between scans.
- ACCOUNT EMAILFrom Sign in with Apple or your email address — used solely to authenticate. We don't market to it.
- SCAN HISTORY AND CONVERSATIONSYour scans, your saved visits, the chat history with each artwork. Stored under your account so you can pick up where you left off on another device.
What we don't collect
- CAMERA ROLL ACCESSWe only see the single photo you choose to scan, never your library at large.
- CONTINUOUS LOCATIONLocation is read at scan time only — we do not run a background tracker.
- CONTACTS, CALENDAR, MICROPHONENot requested, not used.
- CROSS-SITE ADVERTISING IDENTIFIERSWe don't run third-party ad SDKs.
How we use AI
Each scan is processed by OpenAI to identify the work and generate the explanation. Per OpenAI's API policy, your inputs are not used to train their models. We do not retain the OpenAI request beyond what's needed to deliver the response back to you. The summary, keywords, and follow-up questions are stored in your account so the page renders identically when you reopen the scan.
Where data lives
- AUTHENTICATIONSupabase (US-East). Stores your account record and session tokens.
- DATABASENeon Postgres (US-East). Stores scan metadata, visits, places, and chat history.
- PHOTOSSupabase Storage (private bucket). Scan images are accessible only via short-lived signed URLs that we generate per request.
- AIOpenAI (United States). Receives the photo + your audience-mode and language preferences for that single request.
Your controls
- DELETE A SINGLE SCANFrom the scan's detail page → trash icon. We delete the database row, the conversation, and the stored image. Visits become detached and may also be removed if they had no other scans.
- DELETE YOUR WHOLE ACCOUNTEmail contact@artico-x.com from the address on your account. We delete all associated scans, visits, conversations, and the account record itself within 7 days.
- EXPORTEmail the same address and we'll send you a JSON archive of your scans and visits within 14 days.
Children
Artico is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has signed up, email contact@artico-x.com and we'll remove the account.
Changes to this policy
If this policy changes, we'll update the "last updated" date at the top and, for material changes, send a notice to the email on your account. Past versions are kept in our git history at github.com/adamkzh/artico-v2 if you want to compare.
Contact
Questions, deletions, exports, or anything else — contact@artico-x.com. A real person reads it.