ArtSeal Privacy Policy
Beta v0.1 — pending attorney review; material changes will require renewed acceptance.
Effective 31 July 2026. Operator: Gimped Hero Games, LLC, a Michigan single-member LLC, doing business as ArtSeal. Privacy contact: seth@gimpedherogames.com. Mail: 901 Tower Drive, Suite 420D, Troy, MI 48098, United States.
1. Scope
This policy describes the ArtSeal website, the desktop Trainer and Tester, and the optional Studio Compute service. It does not describe the data practices of a developer's own game, film, or other product made with a LoRA.
ArtSeal is a free beta. Payment, payout, identity and license-delivery machinery is limited to Stripe test mode and the Cardano Preview test network; the code refuses live Stripe keys. You must be 18 or older to use the Services.
2. Information ArtSeal handles
Accounts and profiles
- Email address, and the authentication and session records that go with it.
- Artist display name, handle, avatar, biography, influences, links, and profile status.
- Anything an artist chooses to publish in a profile or a LoRA listing.
- If payout onboarding is tested: the connected-account identifier, onboarding and payout status, identity-verification method, and the requirements or restriction state Stripe returns. Stripe, not ArtSeal, hosts that form.
- Private seller-review records, which may contain reviewer identifiers, reasons, evidence references and checklist results.
Messages and interest forms
- The contact form: optional name, email, selected topic, message, and submission time.
- A listing's interest form: email, optional message, the listing, and submission time.
- Both forms use Cloudflare Turnstile. ArtSeal sends the request IP address and the widget response to Cloudflare for bot detection.
- ArtSeal stores keyed hashes derived from IP addresses, email addresses and request context to enforce rate limits. The rate-limit table holds those hashes, not the raw values.
- Contact and interest messages are stored in the ArtSeal database and copied by email to an operator inbox.
Artwork, listings, and training-set commitments
- Listing text, license-tier previews, uploaded original and generated artwork, optional prompts and generation settings, image dimensions and storage URLs. Published profiles, listings and display images are public.
- A submitted training-set manifest holds file digests, byte sizes, a file count and a Merkle root. The format carries no names and no file paths. The browser manifest tool hashes files locally and uploads none of them.
- For a verified original, the exact source file is uploaded temporarily. The server hashes those bytes, checks membership in the committed set, makes a low-resolution display copy, and removes the source upload. ArtSeal keeps the display copy, the source digest, the source byte count, and the public membership proof.
Model files
- An artist may upload a LoRA model file to a private inbox. ArtSeal reads its size, digest and metadata header, encrypts the master with AES-256-GCM under a server-held key, stores the encrypted object in private storage, and removes the plaintext from the inbox. A failed removal is retried and logged.
- Test-mode delivery rebuilds a buyer-specific copy carrying a license ID in its header, and records that copy's hash and size. ArtSeal does not count downloads and does not store a last-download time.
Attestations, records, and test transactions
- Publishing a listing can record checkbox assent to an artist attestation. A test checkout can record assent to a license agreement. Creating an account, and accepting the Pilot Agreement, record assent to the documents named on those screens.
- Assent evidence includes the exact statement accepted, the document version and hash, the acceptance time, the action, the method, the party, and the relevant commitment or test purchase. It also includes the IP address and user-agent when available. The evidence body stays private; only its hash is public or anchored.
- Test transaction records can include legal and display names, account email, test payment references, tier, price, terms, record and party IDs, and delivery facts. Public verification pages show selected display identities and record facts — never legal names, email addresses, IP addresses, user-agents, a private assent body, or a payment reference.
Trainer and Tester
- In local mode, the images, LoRA files, prompts, style names, manifests, models and generated images you select stay on your computer. The desktop apps contain no advertising or analytics telemetry.
- Local processing also creates temporary diagnostic and manifest files, plus persistent Python environments and downloaded model caches. ArtSeal uploads none of those in local mode; their removal follows your own or your operating system's cleanup.
- The Trainer's ownership checkbox is held in screen state only. It is not stored and not transmitted.
- Your Studio Compute address and four-word passphrase are stored in your operating system's keychain until you choose "Forget studio connection."
Studio Compute
- Training sends the images you selected, the style name, and a manifest if one exists. Generation sends the LoRA and the prompt. The studio holds job parameters in memory and creates job or cache directories for the inputs, outputs, metadata and technical error logs.
- Completed job directories are swept about 24 hours after the job finishes.
- A generation LoRA is cached per invited artist and expires 24 hours after its most recent use. Each use restarts that period, and the artist can delete it sooner from the Tester.
- Job status and parameters, including a style name or prompt, stay in process memory and are lost when the service restarts; completed entries are not otherwise purged by age. Invite identity and passphrase records stay in the operator's token file until revoked.
Technical information
The service providers below may receive ordinary network and service information: IP address, user-agent, request time, diagnostics and security events. Server function logs may contain information ArtSeal deliberately logs. ArtSeal does not log message bodies or secrets.
3. Why ArtSeal uses information
ArtSeal uses information to create and secure accounts and recover access; host profiles, listings and display images; answer messages and record licensing interest; run local or optional remote training and generation; check file hashes and membership claims; record attestations and mechanically checkable facts; run test-mode payment, payout and delivery flows; prevent abuse, review sellers, enforce content rules and investigate incidents; maintain, debug and protect the service; and comply with law, including preserving or producing records when legally required.
4. Public information
Published artist profiles, listings, display images, listing text and verified-original proofs are public. A public verify page may show record IDs, display identities, record facts, hashes, timestamps and a test-network transaction link. Search engines, archives, recipients and caches may keep copies after ArtSeal removes the source page.
The fact that ArtSeal recorded an attestation or verified a hash match is not a finding that a person owns artwork. The absence of an ArtSeal record is not a verdict about a license or a work.
5. Service providers and disclosures
ArtSeal does not sell personal data and does not use it for cross-context behavioral advertising.
| Provider | Role and information involved |
|---|---|
| Vercel | Hosts the website and server functions; receives requests, diagnostics and function logs. |
| Supabase | Provides email authentication, the database and file storage for accounts, profiles, messages, records and uploads. |
| Cloudflare | Provides Turnstile bot protection and the HTTPS tunnel for Studio Compute; processes network and security signals, and Studio traffic in transit. |
| Resend | Sends account and transactional email, and copies contact or interest messages to the operator. |
| Stripe | In test mode, hosts Checkout and Connect onboarding and processes test payment, payout, identity and connected-account information. If enabled for live service, Stripe receives personal data and processes it under Stripe's Privacy Policy ↗. |
| Blockfrost | Reads Cardano Preview transaction metadata for verify pages, and receives those server requests. |
ArtSeal may also disclose information to professional advisers and to authorities where reasonably necessary to obtain advice, comply with law, protect users or the service, or respond to valid legal process.
Public blockchain metadata is a disclosure to the public, not to a revocable processor. Section 7 explains its narrow content and its permanence.
6. Cookies and similar technologies
- Authentication cookies keep and refresh a signed-in session. They are necessary for account-only pages.
- Cloudflare security technology processes browser and network signals for bot detection. Optional or challenge-dependent Cloudflare security cookies may be set. Cloudflare describes these as security cookies, not advertising cookies: Cloudflare cookies ↗.
- There is no analytics SDK, advertising pixel, or cross-site ad tracker on this site.
ArtSeal therefore does not present an advertising-cookie consent banner. If that changes, this policy changes first.
7. Permanent records and deletion limits
ArtSeal's evidence records are designed to be immutable. Deleting an account can detach the account identifier while leaving the party and record rows needed to render the historical record.
Cardano Preview metadata contains record IDs, hashed party identifiers, amounts, currency and rail, and content, contract and assent hashes. It contains no names, email addresses, IP addresses, user-agents or payment references, and an automated check inspects the serialized payload for personal data before anything is submitted.
Once included in a blockchain transaction, that metadata cannot be erased by ArtSeal, by Gimped Hero Games, by a service provider, or by an account-deletion request. Hashing narrows what is disclosed; it does not make the transaction erasable. Mainnet anchoring is not enabled. Preview is a public test network.
8. Retention
Periods and current gaps are set out in the Data Retention Policy. The facts that matter most:
- Studio job directories: about 24 hours after the job finishes.
- Studio generation LoRA cache: 24 hours after last use, or sooner on request.
- Verified-original source uploads and model-file plaintext: removed after processing. Display copies, proofs and encrypted model masters remain.
- Contact messages, interest leads, rate-limit rows, assent evidence, profiles, listings and encrypted model masters: no automatic expiry today. ArtSeal states this plainly rather than promising a period its systems do not enforce. Choosing those periods is one of the questions ArtSeal's attorney is being asked.
- Immutable database records and public blockchain metadata: not deleted with an account.
9. Security
ArtSeal uses HTTPS in transit, row-level and column-level access controls, private storage buckets, application-level encryption for model masters, keyed hashes for rate-limit identifiers, and restricted server credentials.
Studio Compute files are protected in transit but are not separately end-to-end encrypted and are not documented as encrypted at rest. No method of storage or transmission is completely secure.
10. Choices and requests
Subject to applicable law, you may ask ArtSeal to provide information about the data associated with your account; correct account or profile information; remove content that can be removed; delete your account and the data that is not required or designed to remain; object to or restrict particular processing; or appeal a content or account decision.
Send requests to seth@gimpedherogames.com. ArtSeal may need to verify your identity. Immutable records, backups pending expiry, legal holds and public blockchain data are real limits: ArtSeal will tell you which limit applies to your request rather than claim that everything was erased.
There is no self-service deletion or export flow today. Requests are handled by a person, by email.
11. Age
The Services are for adults: you must be 18 or older. ArtSeal is not designed for children, does not knowingly collect personal information from anyone under 18, and will close an account and address deletion if it learns otherwise.
12. United States service and state-law posture
ArtSeal is operated by a Michigan LLC for a United States beta. It is below the current California CCPA/CPRA applicability thresholds and derives no revenue from selling or sharing personal data. Applicability can change with volume, revenue, geography or law, and ArtSeal will reassess before the beta widens.
13. Changes
Each version of this policy carries a version label, an effective date and a published hash of its text. ArtSeal will give notice of material changes and ask for renewed acceptance where the change warrants it. A repository edit alone is not notice.
14. Contact
Privacy questions and requests: seth@gimpedherogames.com, or Gimped Hero Games, LLC, 901 Tower Drive, Suite 420D, Troy, MI 48098, United States.