ArtSeal Data Retention Policy
Beta v0.1 — pending attorney review; material changes will require renewed acceptance.
Effective 31 July 2026. Operator: Gimped Hero Games, LLC, doing business as ArtSeal. Contact: seth@gimpedherogames.com.
This is the published summary of ArtSeal's retention practice. It states what the systems actually do today, including where they do nothing yet.
In short
ArtSeal keeps data for different periods because the product has three different jobs:
- Studio Compute holds job files briefly. Completed job directories are swept about 24 hours after the job finishes, and a generation LoRA cache expires 24 hours after its most recent use and can be removed sooner.
- The marketplace keeps account data, public content, messages and encrypted model files until a deletion process runs. Several of those processes have no automatic time limit yet. ArtSeal will not claim a shorter period than its systems enforce.
- Evidence records are intentionally durable. Deleting an account can detach it from an off-chain record, but the record itself may remain, and hashes and IDs already written into public blockchain metadata cannot be erased by anyone.
The Privacy Policy explains how to make a request and the limits that apply to one.
The rules ArtSeal works to
- Collect and keep only what a live product function, a security need, a legal obligation, or a documented evidence purpose requires.
- A period is not in force until code or an assigned procedure enforces it.
- A deletion covers database rows, storage objects, email copies and provider-side data where applicable — not only the row a user can see.
- Legal hold, safety preservation, fraud prevention, accounting, dispute and valid legal-process needs can pause a deletion. The hold, its scope, its owner and its release are recorded.
- Immutable records and blockchain metadata are exceptions to deletion, never a reason to keep unrelated data.
- Backups expire on the provider's schedule. Restored data is re-checked against completed deletion requests before normal processing resumes.
What is kept, where, and for how long
| Data | Where it lives | How long today | How it goes away |
|---|---|---|---|
| Local training images, LoRA, manifest and outputs | Your computer | You control it; ArtSeal sets no period | You delete the files |
| Local generation LoRA, prompt and images | Your computer | You control it | You delete the files |
| Local temporary manifest and diagnostic logs | Your operating system's temporary directories | Diagnostic output is overwritten on the next run; temporary files follow OS policy | Your own or your OS's cleanup |
| Local Python environment and downloaded model caches | Desktop app data directory and provider caches | Persistent; no ArtSeal expiry | You remove the app data or model cache |
| Studio job inputs, outputs, manifest and error log | Studio job directory | About 24 hours after the job finishes | Automatic sweep |
| Studio generation LoRA cache | Per-artist studio cache | 24 hours after last use, sliding | Automatic sweep, or "Delete from studio now" in the Tester |
| Studio in-memory job status and parameters | Studio process memory | Until the service restarts | Process exit |
| Studio invite identity and passphrase record | Operator token file | Until the operator revokes it | Operator revocation |
| Your Studio address and passphrase | Your operating system keychain | Until you clear it | "Forget studio connection", or your OS credential manager |
| Account and authentication records | Authentication provider | Until deletion is requested and carried out | Operator deletion; there is no self-service flow yet |
| Artist profile, listings, gallery items, tier text, prompts and settings | Database and public storage | Until you or the operator removes them; no age-based expiry | Listing and profile actions; storage pruning. Public caches can outlive removal briefly |
| Contact form name, email, topic and message | Database, plus an operator mailbox copy | No automatic expiry. The email provider advertises 30-day retention; the operator mailbox copy has its own | Manual deletion, by request or by operator |
| Listing interest email and message | Database, plus an operator mailbox copy | No automatic expiry; removed if an unlicensed listing is deleted | Manual deletion or listing cascade |
| Rate-limit keyed hashes | Database | No automatic expiry; the query windows are 15 minutes and 24 hours, but rows remain | No deletion job today |
| Draft listing images | Private storage | Until published, replaced, or the draft is deleted; no age sweep | Publish, delete, or folder pruning |
| Published listing images | Public storage and CDN | Until removed, replaced, or the listing is deleted; the CDN may cache briefly | Listing save or delete |
| Verified-original source upload | Private storage | Processing time only | Removed on every path, success or refusal |
| Verified-original display copy, digest, size and proof | Public storage and database | Until the item or listing is removed | Owner delete action |
| Submitted manifest file list | Private database table | Tied to the listing record; no expiry | Not deletable while the record stands; no browser role can read it |
| Model-file plaintext upload | Private inbox storage | Processing time only | Removed after encryption; the removal is retried and logged |
| Encrypted model master and header facts | Private storage and database | No automatic expiry; needed for test delivery | No complete expiry rule yet |
| Attestation assent evidence (IP, user-agent, time, statement, document, party) | Private record column | Immutable record; no expiry | No deletion path; readable by no browser role |
| Checkout assent evidence (IP, user-agent, time, statement, document, purchase) | Private record column | Moved onto the record when a test purchase completes; no expiry | Staging copy cleared after the record is written |
| Account acceptance of these documents (version, hash, time, IP, user-agent) | Private database table | No automatic expiry; it is the evidence that acceptance happened | No deletion path today; readable by no browser role |
| Parties and immutable listing, license and registration records | Database and public verify pages | Designed to remain; the account link is cleared on account deletion | Corrections attach as addenda; nothing is edited or deleted |
| Cardano transaction metadata | Public test blockchain | Permanent by network design | No deletion path anywhere |
| Test payment, payout and review references | Payment provider and private tables | Provider and legal periods; no ArtSeal age-based sweep | Provider tools and database cleanup |
| Bot-protection and tunnel network data | Cloudflare | Provider-controlled | Provider controls its own service data |
| Blockchain read-API request logs | Blockfrost | Provider-controlled | Provider account process |
| Server runtime and function logs | Vercel | Plan-dependent, from one hour to 30 days: Vercel runtime logs ↗ | Provider expiry |
| Database backups | Supabase | Plan-dependent: Supabase backups ↗. Storage objects are not inside database backups | Provider expiry |
| Outbound email logs and content | Resend | 30 days on current plans: Resend pricing ↗ | Provider expiry |
Account deletion
There is no self-service deletion flow yet. Write to seth@gimpedherogames.com and a person will handle it. ArtSeal will identify your account, profiles, listings, storage folders, messages, leads, test payout records, review records and model objects; suspend access and revoke Studio credentials; remove what is neither required nor designed to remain; detach your account identifier from the records that remain; ask providers to remove their copies where that is supported; and tell you which records remain and why.
ArtSeal will not tell you an account was fully deleted when immutable records or public blockchain metadata remain. You will be told what stayed.
Backups and restores
Backups are held by ArtSeal's hosting and database providers on their own schedules. After a restore, completed deletions and takedowns are re-applied before normal writes resume. A database backup is not a backup of stored files; they are separate.
Security incidents
ArtSeal maintains a private incident-response plan covering containment, credential rotation, preservation, provider notification, breach analysis under Michigan and other applicable law, and user communication. That plan is not published, because it would help an attacker.
Changes
Each version of this policy carries a version label, an effective date and a published hash of its text. Several periods above are marked as absent today. Once ArtSeal implements them, this policy will say so, in a new version.