ArtSleuth

Privacy Policy

Last updated: June 15, 2026
This policy applies to visitors and users worldwide, including residents of the European Economic Area (EEA), the United Kingdom, Switzerland, the United States and other regions. Region-specific addenda for the EU/UK and for U.S. states appear at the end.

Quick Summary

  • We collect what we need to run the service: account, artwork uploads, payment, basic device data.
  • We do not sell your personal information for money.
  • We do not use your uploaded artwork to train AI models.
  • Analytics and advertising cookies load only after you click Accept in our cookie banner.
  • You can access, correct, delete or export your data by emailing us at info@artsleuthstudio.com.

Who is Responsible

The data controller for personal data processed through the ArtSleuth Studio website and mobile app is:

ArtSleuth Studio
Operated from Germany.
Email: info@artsleuthstudio.com
Website: https://artsleuthstudio.com

Our full legal entity name and postal address are listed in our site imprint / Impressum.

Information We Collect

Information You Provide to Us

  1. Account information: username, email address, hashed password. Email verification is required to unlock free analyses.
  2. Profile preferences: chosen AI model, search-engine preference, marketing opt-out flag.
  3. Artwork images: photos you upload for analysis. Processed by Google's Gemini AI (see "Service Providers / Sub-processors" below). We do not use your artwork to train AI models.
  4. Certificate & analysis history: reports you generate, the certificate IDs we mint and any project notes you save in your gallery.
  5. Forum & blog posts: any content you publicly post in our community sections (visible to other users).
  6. Communications you send: the content of support requests, contact-form submissions and emails to us.
  7. Payment information:
    • Web subscriptions / pay-per-use: handled by Stripe (we never see or store full card numbers).
    • Mobile app purchases: handled by Google Play or Apple App Store.

Information Collected Automatically

  1. Usage data: which pages and features you used, the timestamps and result of analyses you ran.
  2. Device & connection information: IP address, user-agent string, device type, OS, approximate location derived from IP (country/region only).
  3. Service diagnostics: server-side performance data and error logs. These are first-party only and not shared with advertisers.
  4. Anti-abuse signals: per-IP rate-limit counters used to stop automated bots from farming free trials.
  5. Analytics (only with your consent): if you accept the analytics cookie category, we use Google Analytics 4 with IP anonymisation and Google Signals disabled to measure aggregated traffic. See the Cookies section.
  6. Marketing measurement (only with your consent): if you accept the marketing cookie category, Google Ads receives conversion signals.

Information from Third Parties

  1. Google Sign-In (if used): we receive your name and email.
  2. Stripe webhooks: subscription / payment status updates.
  3. Mobile in-app advertising: Google AdMob on the mobile app only, if enabled by you.

We do not intentionally collect "sensitive" categories of personal information (such as racial or ethnic origin, political opinions, religious beliefs, biometric identifiers, health data, sexual orientation, precise geolocation, or government identifiers). Please do not submit sensitive data through the analysis form or community posts.

How We Use Your Information — Purposes & Legal Bases

The "legal basis" column below applies under the EU/UK GDPR. Outside those regions, we rely on equivalent grounds permitted by your local law (e.g. contract performance, our legitimate interest, your consent, or legal obligation).

Purpose What we use Legal basis (GDPR)
Provide the analysis service & account Account, artwork uploads, history Art. 6(1)(b) — performance of contract
Email verification at sign-up Email address, verification token Art. 6(1)(b) and Art. 6(1)(f) — legitimate interest in stopping fraud / abuse
Process payments and run subscriptions Email, Stripe customer ID, transaction data Art. 6(1)(b)
Tax, accounting and legal record-keeping Invoice / payment data Art. 6(1)(c) — legal obligation (e.g. German HGB §257)
Service security, abuse prevention, rate limiting IP address, basic device info, request logs Art. 6(1)(f) — legitimate interest
Service diagnostics & debugging Error logs, anonymised performance data Art. 6(1)(f)
Aggregated analytics (Google Analytics 4) Hashed identifiers, page views, country Art. 6(1)(a) + §25(1) TTDSG — your consent
Advertising measurement (Google Ads) Conversion signals Art. 6(1)(a) + §25(1) TTDSG — your consent
Service emails (transactional) Email address Art. 6(1)(b)
Marketing emails (newsletters) Email address, opt-out flag Art. 6(1)(a) — your consent (unsubscribe in every email)

Cookies and Similar Technologies

ArtSleuth uses cookies and equivalent browser storage. In line with the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TTDSG §25) and Art. 6(1)(a) GDPR, anything that is not strictly necessary is loaded only after you give your explicit consent in our cookie banner.

Strictly necessary (always active)

  • Login session, CSRF protection, rate-limit / abuse protection.
  • Remembering your cookie-consent choice itself (as_cookie_consent_v1 in your browser's local storage).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the service) and §25(2) Nr. 2 TTDSG (strictly necessary technical storage).

Analytics — opt-in

  • Provider: Google Ireland Limited / Google LLC (Google Analytics 4, property G-NW6K8PPLEY).
  • Purpose: Aggregated, pseudonymised traffic measurement (page views, country, device class, referrer).
  • Configuration: IP anonymisation enabled, Google Signals disabled, ad-personalisation signals disabled. Loaded only after you accept this category.
  • Storage: Cookies _ga, _ga_NW6K8PPLEY (up to 24 months).
  • Data transfer: Data may be processed by Google in the United States. We rely on Google's EU–U.S. Data Privacy Framework certification and the EU Standard Contractual Clauses.

Legal basis: Art. 6(1)(a) GDPR + §25(1) TTDSG (your consent).

Marketing — opt-in

  • Provider: Google Ireland Limited / Google LLC (Google Ads conversion measurement via the same gtag).
  • Purpose: Attribute conversions to our advertising campaigns and measure ad performance.
  • Storage: Cookies _gcl_* (up to 90 days).

Legal basis: Art. 6(1)(a) GDPR + §25(1) TTDSG (your consent).

Withdrawing consent. Your consent is voluntary and can be revoked at any time without giving reasons and with effect for the future. Use the Open cookie settings link to change your choices, or click the small Cookie settings button visible in the bottom-left corner of every page after you have made an initial choice. You may also delete the as_cookie_consent_v1 entry from your browser's local storage to be re-prompted.

Service Providers / Sub-processors

We work with a small number of service providers ("processors" under GDPR / "service providers" under CCPA) that handle limited personal data on our behalf and only on our written instructions:

Provider Role Country / data flow
Google Ireland Limited / Google LLC Gemini AI inference for artwork analysis; Google Analytics 4 (opt-in); Google Ads conversion (opt-in); AdMob on mobile only. EU + USA. Transfers covered by EU Standard Contractual Clauses and Google's certification under the EU–U.S. Data Privacy Framework.
Stripe, Inc. / Stripe Payments Europe Ltd. Payment processing for web subscriptions / pay-per-use. USA + EU. Transfers covered by EU Standard Contractual Clauses + Stripe's DPF certification.
Apple Inc. / Google LLC (mobile) In-app purchases on iOS / Android. USA. Governed by their respective developer agreements.
SMTP / email relay provider Sends transactional emails (verification, receipts) and any newsletters you opt into. EU.
Mullvad VPN AB VPN egress for our reverse-image-search lookups (audited no-logs). Does not see your account or upload identity. Sweden.
TinEye Inc. Reverse image search to look for online appearances of your uploaded image. Your image is fetched once via a 5-minute one-time URL and the URL then expires; TinEye may cache images they index per their own retention policy. Optional — opt out at upload time (see "Your choices" below). Canada (PIPEDA).
Hosting / infrastructure Runs our servers and stores the database. EU.

Online provenance check (TinEye)

When you upload an artwork for analysis, we run an automated check to see whether the same image already appears elsewhere on the public web (auction houses, museums, social media, AI-art platforms). The check is run via SearXNG, a privacy-respecting metasearch engine we host on our own servers, and uses the TinEye reverse-image index. All outbound traffic from our SearXNG instance is routed through a Mullvad WireGuard tunnel so that TinEye never sees our origin IP, and never sees your account identity.

To make this work, we briefly publish your image at an unguessable, signed URL (/r/<token>) that expires after 5 minutes and can only be fetched once. The URL carries an X-Robots-Tag: noindex header so honest crawlers will not store it. After the one fetch, the URL returns 404 forever.

Your choices: the upload form has a "Skip online provenance check" checkbox. Tick it before submitting an analysis to disable this step entirely; in that case neither the one-time URL nor the TinEye query is created. We honour the choice on a per-upload basis (no account-wide setting needed).

Other disclosures. We may also disclose information when we are legally required to (e.g. valid court order, German law-enforcement request, official tax audit), or in connection with a merger, acquisition, or sale of substantially all of our assets, in which case we will notify users in advance and ensure equivalent protections apply.

We do NOT:

  • Sell your personal information for money.
  • Use your uploaded artwork to train AI models.
  • Share your private analyses or certificates with anyone outside the providers above.
  • Run advertising or analytics scripts before you give consent.

International Data Transfers

ArtSleuth is operated from the European Union. Some of our service providers are located in the United States. When personal data is transferred outside the EEA / UK, we rely on:

  • EU Standard Contractual Clauses (SCCs, Module 2 controller-to-processor); and
  • The processor's certification under the EU–U.S. Data Privacy Framework where applicable; and
  • Supplementary technical measures such as TLS encryption in transit and pseudonymisation of analytics identifiers.

You can request a copy of the SCCs we rely on by emailing us.

Data Security

We implement reasonable technical and organisational measures to protect your information — appropriate to the risk — including:

  • HTTPS/TLS in transit, with HSTS;
  • Salted password hashing;
  • Role-based access control on the production database;
  • Per-IP rate limiting and email-verification gates against bot abuse;
  • Least-privilege access to production servers, MFA on admin accounts;
  • Regular dependency and security review.

No internet service is 100 % secure; if a breach affecting your personal data occurs, we will notify you and the relevant supervisory authority as required by Art. 33–34 GDPR or applicable U.S. state law.

Data Retention

Data category Retention
Account data (username, email, password hash) Kept while your account is active. Deleted on request, normally within 30 days.
Uploaded artwork images Kept for 7 days after the analysis. If you issue a signed certificate within that window, the images are retained permanently so the certificate's verification page can display them. Otherwise they are automatically deleted; the analysis text remains in your dashboard, but a certificate can no longer be issued (we need the source images to sign and verify it). See below.
Analysis history & certificates Until you delete them or close your account.
Server logs & security signals Up to 90 days, then anonymised or deleted.
Analytics cookies (Google Analytics 4) Up to 24 months, only if you consented.
Marketing cookies (Google Ads) Up to 90 days, only if you consented.
Invoices, receipts, payment records Up to 10 years (German tax law / U.S. statutory equivalent).

Image retention (7-day window)

Source images you upload for analysis are kept on our servers for 7 days. Within that window you can issue a signed certificate by clicking the Issue Certificate button on the analysis page. Issuing the certificate copies the images into the permanent certificate bundle so the public verification page (/verify/<cert-id>) can render them.

After 7 days, if you have not issued a certificate, the source images are automatically deleted from our servers by an internal sweeper process. The text of the analysis stays in your dashboard, but a certificate cannot be issued retroactively because the cryptographic signing process needs the original image bytes. To re-enable a certificate after that point, simply re-upload the artwork as a fresh analysis.

This 7-day rule applies only to source images. Analysis text and metadata are retained as described in the table above. If you would like us to delete all data tied to a specific analysis — text included — use the “Delete project” button on your dashboard or write to us (see Contact).

You can choose to publish certified artworks to a public page at /g/<your-slug>. The slug is a short handle you pick yourself in your profile (different from your login username), and the gallery is opt-in: until you set a slug AND mark individual certificates as published, no public page exists for your account.

The public gallery shows, per published item: the artwork image, its title (taken from your analysis), an optional caption you write, and a link to the certificate's verification page. It does not show your email, your other certificates, or any internal analysis details beyond what you explicitly publish.

You can unpublish individual items, change your slug, or remove your slug entirely (taking your gallery offline) at any time from /gallery/me. Unpublishing removes the item from the public page immediately; your underlying certificate is unaffected.

Your Rights — Universal Baseline

Regardless of where you live, you can ask us to:

  1. Access a copy of the personal data we hold about you;
  2. Correct inaccurate or incomplete information;
  3. Delete your account and associated data;
  4. Export your data in a portable format (JSON / CSV);
  5. Withdraw consent for analytics, marketing or newsletters at any time.

Email info@artsleuthstudio.com from the address on file for your account, or use the in-app "Delete account" / "Cookie settings" controls. We respond within 30 days (45 days for U.S. CCPA / state-law requests, with one possible 45-day extension if needed). The service is free.

Children's Privacy

ArtSleuth is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we have inadvertently collected information from a child under 16 (or under 13 in the U.S. under COPPA), we will delete it. Parents or guardians can contact us at the email above.

Third-Party Privacy Notices

Changes to This Policy

We may update this Privacy Policy. We will post the revised version here, update the "Last updated" date and — for material changes that affect your rights — email registered users at least 30 days before the change takes effect.

Contact Us

For privacy questions or to exercise your rights:


Notice for EEA, UK and Switzerland (GDPR)

If you are in the European Economic Area, the United Kingdom or Switzerland, the General Data Protection Regulation (GDPR), the UK GDPR and the Swiss FADP apply to our processing of your personal data. The data controller is the entity identified in the "Who is Responsible" section above.

Your GDPR rights

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure / "right to be forgotten" (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21) — including objection to processing based on legitimate interests
  • Withdrawal of consent (Art. 7(3)) at any time, without affecting the lawfulness of processing already carried out
  • Right not to be subject to a decision based solely on automated processing producing legal effects (Art. 22). Our AI generates an analysis report — it does not make legally binding decisions about you.

Right to lodge a complaint

If you believe we have not handled your personal data lawfully, you have the right to complain to a supervisory authority. As we are based in Germany, the lead authority is typically the data protection authority of the German federal state in which we are established. You can find your local authority via the German Federal Commissioner (BfDI) or the EDPB members directory. You can also complain to the authority of your own EU member state (Art. 77).

Cookies & TTDSG

Storage of, or access to, information on your device that is not strictly necessary requires your consent under §25(1) TTDSG. See the Cookies and Similar Technologies section above. You can change your choices at any time via the Cookie settings control in the bottom-left corner of every page.


Notice for U.S. Residents

This section provides additional disclosures for residents of California (CCPA/CPRA), Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA) and any other U.S. state granting equivalent rights.

"Notice at Collection" categories (CCPA)

In the past 12 months, we have collected the following CCPA categories of personal information:

CCPA category Examples we collect Source Purpose
A. Identifiers Email, username, IP address, device ID You; automatically Run the service, prevent abuse
B. Customer records (Cal. Civ. Code §1798.80) Name (if provided), email, billing data via Stripe You; Stripe Process payments
F. Internet / network activity Pages visited, features used, error logs, opt-in analytics Automatically Improve service, security
G. Geolocation Approximate location from IP (country/region only) Automatically Anti-fraud, language hints
K. Inferences Aggregated traffic patterns (with consent) Analytics Service improvement
L. Sensitive personal information None intentionally collected. Account login uses email + password only.

"Sale" / "Sharing" disclosure

We do not sell personal information for money in the past 12 months and we will not do so in the future without first updating this notice and offering you a clear opt-out.

Under the CPRA, "sharing" includes disclosing personal information for cross-context behavioral advertising. We only "share" a small amount of advertising-measurement data with Google Ads, and only when you have opted in to the Marketing cookie category. If you live in a state with an opt-out right (CA, CO, CT, VA, UT, TX, OR, MT), you can exercise it in two equivalent ways:

  • Click Cookie settings in the bottom-left of any page and switch off the "Marketing" category. (Recommended — instant.)
  • Send a signed Global Privacy Control (GPC) signal from your browser. We treat a recognised GPC header on your visit as a valid request to opt out of "sale/sharing" for that browser, persisted via our consent cookie.
  • Email us at info@artsleuthstudio.com with the subject line "Do Not Sell or Share My Personal Information".

Limit the use of my sensitive personal information

We do not use sensitive personal information to infer characteristics about you, beyond what is strictly necessary to provide the service you have requested. As a result there is nothing to limit, but you can still send a request to the same email above and we will confirm.

Your CCPA / state-law rights

  • Right to know what personal information we have collected, used, disclosed and "shared" about you;
  • Right to delete personal information (subject to legal exceptions, e.g. records we must keep for tax);
  • Right to correct inaccurate personal information;
  • Right to opt out of "sale" or "sharing" for cross-context behavioral advertising (see above);
  • Right to limit the use of sensitive personal information;
  • Right to non-discrimination — we will not deny you the service, charge you a different price, or give you a lower-quality experience because you exercised any of these rights;
  • Right to data portability — export of your data in a structured, machine-readable format;
  • Right to appeal a denial of any of the above (CO/CT/VA/TX/OR/MT) — reply to our denial email and we will reconsider within 60 days.

How to submit a request — including via authorised agent

Send your request to info@artsleuthstudio.com from the email address on file for your account, telling us which right you want to exercise. We will verify your identity by matching the request to your account email; for sensitive requests we may also ask you to confirm one or two account-related details. If you use an authorised agent, please include a signed permission letter or a power of attorney with the request.

Children under 16 (CCPA)

We do not knowingly sell or share the personal information of consumers under 16. The service is not directed to children, and you must be at least 16 to create an account.

California Shine the Light (Civ. Code §1798.83)

California residents may request a list of categories of personal information we have shared with third parties for those parties' own direct-marketing purposes in the previous calendar year. We do not share personal information for that purpose, so the answer is: none.

Notice of financial incentives

We do not currently offer financial incentives or price differences in exchange for personal information.


This notice is provided for informational purposes and does not constitute legal advice. Specific contractual terms with our service providers (DPAs, SCCs) are available on request.

© 2026 ArtSleuth. All rights reserved.