ArtSeal
MarketplaceVerifyHow it worksAbout
Create a pageSign in

← All legal documents

ArtSeal Data Retention Policy

Beta v0.1 — pending attorney review; material changes will require renewed acceptance.

Effective 31 July 2026. Operator: Gimped Hero Games, LLC, doing business as ArtSeal. Contact: seth@gimpedherogames.com.

This is the published summary of ArtSeal's retention practice. It states what the systems actually do today, including where they do nothing yet.

In short

ArtSeal keeps data for different periods because the product has three different jobs:

  1. Studio Compute holds job files briefly. Completed job directories are swept about 24 hours after the job finishes, and a generation LoRA cache expires 24 hours after its most recent use and can be removed sooner.
  2. The marketplace keeps account data, public content, messages and encrypted model files until a deletion process runs. Several of those processes have no automatic time limit yet. ArtSeal will not claim a shorter period than its systems enforce.
  3. Evidence records are intentionally durable. Deleting an account can detach it from an off-chain record, but the record itself may remain, and hashes and IDs already written into public blockchain metadata cannot be erased by anyone.

The Privacy Policy explains how to make a request and the limits that apply to one.

The rules ArtSeal works to

  • Collect and keep only what a live product function, a security need, a legal obligation, or a documented evidence purpose requires.
  • A period is not in force until code or an assigned procedure enforces it.
  • A deletion covers database rows, storage objects, email copies and provider-side data where applicable — not only the row a user can see.
  • Legal hold, safety preservation, fraud prevention, accounting, dispute and valid legal-process needs can pause a deletion. The hold, its scope, its owner and its release are recorded.
  • Immutable records and blockchain metadata are exceptions to deletion, never a reason to keep unrelated data.
  • Backups expire on the provider's schedule. Restored data is re-checked against completed deletion requests before normal processing resumes.

What is kept, where, and for how long

DataWhere it livesHow long todayHow it goes away
Local training images, LoRA, manifest and outputsYour computerYou control it; ArtSeal sets no periodYou delete the files
Local generation LoRA, prompt and imagesYour computerYou control itYou delete the files
Local temporary manifest and diagnostic logsYour operating system's temporary directoriesDiagnostic output is overwritten on the next run; temporary files follow OS policyYour own or your OS's cleanup
Local Python environment and downloaded model cachesDesktop app data directory and provider cachesPersistent; no ArtSeal expiryYou remove the app data or model cache
Studio job inputs, outputs, manifest and error logStudio job directoryAbout 24 hours after the job finishesAutomatic sweep
Studio generation LoRA cachePer-artist studio cache24 hours after last use, slidingAutomatic sweep, or "Delete from studio now" in the Tester
Studio in-memory job status and parametersStudio process memoryUntil the service restartsProcess exit
Studio invite identity and passphrase recordOperator token fileUntil the operator revokes itOperator revocation
Your Studio address and passphraseYour operating system keychainUntil you clear it"Forget studio connection", or your OS credential manager
Account and authentication recordsAuthentication providerUntil deletion is requested and carried outOperator deletion; there is no self-service flow yet
Artist profile, listings, gallery items, tier text, prompts and settingsDatabase and public storageUntil you or the operator removes them; no age-based expiryListing and profile actions; storage pruning. Public caches can outlive removal briefly
Contact form name, email, topic and messageDatabase, plus an operator mailbox copyNo automatic expiry. The email provider advertises 30-day retention; the operator mailbox copy has its ownManual deletion, by request or by operator
Listing interest email and messageDatabase, plus an operator mailbox copyNo automatic expiry; removed if an unlicensed listing is deletedManual deletion or listing cascade
Rate-limit keyed hashesDatabaseNo automatic expiry; the query windows are 15 minutes and 24 hours, but rows remainNo deletion job today
Draft listing imagesPrivate storageUntil published, replaced, or the draft is deleted; no age sweepPublish, delete, or folder pruning
Published listing imagesPublic storage and CDNUntil removed, replaced, or the listing is deleted; the CDN may cache brieflyListing save or delete
Verified-original source uploadPrivate storageProcessing time onlyRemoved on every path, success or refusal
Verified-original display copy, digest, size and proofPublic storage and databaseUntil the item or listing is removedOwner delete action
Submitted manifest file listPrivate database tableTied to the listing record; no expiryNot deletable while the record stands; no browser role can read it
Model-file plaintext uploadPrivate inbox storageProcessing time onlyRemoved after encryption; the removal is retried and logged
Encrypted model master and header factsPrivate storage and databaseNo automatic expiry; needed for test deliveryNo complete expiry rule yet
Attestation assent evidence (IP, user-agent, time, statement, document, party)Private record columnImmutable record; no expiryNo deletion path; readable by no browser role
Checkout assent evidence (IP, user-agent, time, statement, document, purchase)Private record columnMoved onto the record when a test purchase completes; no expiryStaging copy cleared after the record is written
Account acceptance of these documents (version, hash, time, IP, user-agent)Private database tableNo automatic expiry; it is the evidence that acceptance happenedNo deletion path today; readable by no browser role
Parties and immutable listing, license and registration recordsDatabase and public verify pagesDesigned to remain; the account link is cleared on account deletionCorrections attach as addenda; nothing is edited or deleted
Cardano transaction metadataPublic test blockchainPermanent by network designNo deletion path anywhere
Test payment, payout and review referencesPayment provider and private tablesProvider and legal periods; no ArtSeal age-based sweepProvider tools and database cleanup
Bot-protection and tunnel network dataCloudflareProvider-controlledProvider controls its own service data
Blockchain read-API request logsBlockfrostProvider-controlledProvider account process
Server runtime and function logsVercelPlan-dependent, from one hour to 30 days: Vercel runtime logs ↗Provider expiry
Database backupsSupabasePlan-dependent: Supabase backups ↗. Storage objects are not inside database backupsProvider expiry
Outbound email logs and contentResend30 days on current plans: Resend pricing ↗Provider expiry

Account deletion

There is no self-service deletion flow yet. Write to seth@gimpedherogames.com and a person will handle it. ArtSeal will identify your account, profiles, listings, storage folders, messages, leads, test payout records, review records and model objects; suspend access and revoke Studio credentials; remove what is neither required nor designed to remain; detach your account identifier from the records that remain; ask providers to remove their copies where that is supported; and tell you which records remain and why.

ArtSeal will not tell you an account was fully deleted when immutable records or public blockchain metadata remain. You will be told what stayed.

Backups and restores

Backups are held by ArtSeal's hosting and database providers on their own schedules. After a restore, completed deletions and takedowns are re-applied before normal writes resume. A database backup is not a backup of stored files; they are separate.

Security incidents

ArtSeal maintains a private incident-response plan covering containment, credential rotation, preservation, provider notification, breach analysis under Michigan and other applicable law, and user communication. That plan is not published, because it would help an attacker.

Changes

Each version of this policy carries a version label, an effective date and a published hash of its text. Several periods above are marked as absent today. Once ArtSeal implements them, this policy will say so, in a new version.

Version beta-v0.1.1 · effective 2026-07-31 · sha256 83efb099fc7bffc32dede892774e147346029f479c190f13d2e8c66508460cc7
Every acceptance ArtSeal records names this hash, so what you accepted and what you are reading can be compared without taking ArtSeal’s word for it.

Verify a licenseManifest toolManifest tool source ↗Contact
Terms of ServicePrivacy PolicyAcceptable Use / Content PolicyData Retention PolicyArtist Pilot AgreementCopyright Complaint Policy

ArtSeal records attestations and verifies what is mechanically checkable. It never certifies what it can’t check.

The legal documents above are Beta v0.1 — pending attorney review. Gimped Hero Games, LLC · 901 Tower Drive, Suite 420D, Troy, MI 48098 · seth@gimpedherogames.com