Effective September 19, 2026
Privacy policy
Send Artifact is operated by Earl Lee. The service (sendartifact.com, with published pages served from sendartifactusercontent.com) publishes web pages to access-controlled links and shows publishers who viewed them. That second part is the product, so this policy is blunt about it: if you open an artifact that asks for your email, the person who published it will see that you read it.
What we collect
- Publisher accounts — your email address, your handle, and API keys (stored only as hashes; we cannot read a key back). A reviewer-only demo account uses a generated password stored only as a one-way scrypt hash; ordinary customer accounts do not use passwords.
- Content — the artifacts you publish, every version of them, and comments left on them.
- Viewer emails — when a publisher gates a link, the email you enter. If you verify it with a one-time code or Google, it is marked verified; otherwise it is stored as self-reported.
- View events — which artifact and version was opened and when, tied to your email if you provided one, or otherwise to a session cookie. We store the IP address the request came from, which we use to tell repeat readers apart, to work out the approximate location of a read for the publisher, and to shut down abuse. The page also reports back how long it was open and in front of you, and how far down the page you scrolled, so the publisher can tell a read from a glance. Nothing about what you typed into an artifact is reported — the page cannot send that anywhere, and we never share view records with anyone but the artifact's own publisher.
- Sign-in and assistant connections — one-time email codes, which expire in minutes. If you choose Google sign-in, Google tells us your email address and nothing else. For OAuth connections we store the assistant-supplied client name and callback address, the permissions and publishing handle you approve, connection and last-used times, and hashed access and refresh tokens.
- Connector requests — when an assistant such as Claude or ChatGPT calls Send Artifact, we receive only the tool name, the tool inputs needed for that request, and ordinary security metadata such as time and network address. We do not request or receive your full conversation or raw chat transcript. Content you explicitly ask the assistant to publish is sent as a tool input and stored as described above.
How we use it
To run the service: authenticate you, connect assistants you authorize, execute the tool requests you approve, enforce each artifact's access rules, deliver one-time codes, and prevent abuse. And to do the product's one analytical job: show a publisher how their artifact is being read. We do not sell personal information, show ads, or use third-party analytics or advertising trackers.
What publishers see about viewers
If you view an artifact whose publisher requires an email, that publisher sees your address, whether it was verified, when you first and last viewed, and your view count. Comments you leave are attributed to your email. If you open an ungated artifact, the publisher sees only anonymous counts.
Cookies
Functional cookies only: one keeps publishers signed in, one remembers that a viewer verified an email (about 30 days), and short-lived cookies protect OAuth connection and form flows. There are no advertising or cross-site tracking cookies.
Who processes data for us
Render (US) hosts the service and its database. Resend delivers one-time code emails. Google is involved only if you choose to sign in with Google. If you connect Send Artifact to an assistant, that assistant provider processes your conversation and relays the tool requests you authorize under its own privacy terms; Send Artifact does not receive the rest of the conversation. Data is processed and stored in the United States; by using Send Artifact from elsewhere you consent to that transfer.
Retention and deletion
Account data lasts while your account does. OAuth authorization requests and codes expire within minutes; access tokens expire within an hour; refresh tokens expire within 30 days, and connected grants are removed after their tokens expire or are revoked. Unused OAuth client registrations are removed after 90 days. View events last while the artifact they belong to does — publishers can delete artifacts, which removes their analytics. Email us to access, correct, export, or delete your data, including view records tied to your email, and we will act on it. If you are in the EU/EEA, UK, or California, these are your statutory rights (access, rectification, erasure, portability, objection) and we honor them without discrimination. We do not sell or share personal information as those terms are defined by the CCPA.
Security
Everything travels over TLS. API keys and OAuth tokens are stored only as hashes. Network addresses are retained only for the view-location, reader-counting, and abuse-prevention purposes described above. Published pages run in a sandboxed frame on a separate domain so they cannot reach account sessions. No system is perfect; if a breach affects your data we will tell you.
Children
Send Artifact is not directed at children under 13 and we do not knowingly collect their data.
Changes and contact
If this policy changes materially, the date above changes with it and the current version always lives at this URL. Questions or requests: support@sendartifact.com.