Privacy Policy

Last updated: July 14, 2026

1. Who We Are

ArtDrop is software developed and sold by StanHattie LLC ("we," "us," "our"). Our website is getartdrop.com. Contact: support@getartdrop.com

2. How ArtDrop Runs (Web vs Mac)

Mac app ($399 one-time). ArtDrop installs and runs on your Mac, where its configuration and credential files are stored. When you run a workflow, the artwork, product data, credentials, and related business data needed for that workflow are sent directly from your machine to the services you configured (Shopify, your print providers, Anthropic, Backblaze). The Mac app sends license activation and validation data to the ArtDrop license server; the hosted ArtDrop workflow backend does not process normal Mac-app drops.

Web app ($39/mo). ArtDrop runs as a hosted web application on infrastructure operated by StanHattie LLC (currently Railway). Your account configuration, including credentials and connection tokens, is stored in our database so the server can run drops on your behalf. Uploaded artwork and derived files are processed in per-account work areas and may be transferred to your configured storage and providers; copies can remain in processing, archive, connected-storage, or backup locations until cleaned up or deleted under the retention process in Section 12. We do not intentionally load the marketing site's Google Analytics or Microsoft Clarity scripts in the authenticated app. The app does collect first-party account, security, performance, drop, provider, store, and diagnostic records needed to operate its features.

Both tiers: no public dashboard, no admin login that lets third parties see your account, no resale of your data, and no use of your artwork for model training, ever.

3. What We Actually Receive

Mac app, the only data StanHattie LLC receives is:

License activation

Web app, additionally, we receive and store:

Purchase information (via Stripe)

Affiliate and referral information

These are the principal categories ArtDrop receives directly. Connected services also receive the workflow data described in Sections 5 and 6.

4. Your API Keys

Mac app. When you connect services like Anthropic, Gelato, Printful, Printify, Shopify, or Backblaze, ArtDrop stores your API keys in a local configuration file on your computer. These keys are never transmitted to StanHattie LLC. All API calls go directly from your machine to the service you configured.

Web app. Your API keys and connection tokens are stored in the hosted application database with application access controls and used to execute the workflows you configure. Values are masked in browser views and portable exports; that masking is a display and export control, while the backend must be able to retrieve and use the stored value for a requested workflow. Credentials are not sold or exposed through a public dashboard. A credential is transmitted to the relevant connected service when authentication requires it. If you cancel your subscription, you can request deletion of stored credentials at support@getartdrop.com, subject to the retention limits in Section 12.

5. Copy Generation (Third-Party Processor)

When you use ArtDrop's copy generation, your artwork image and your voice/copy rules are sent to a third-party language-model provider (Anthropic), which analyzes the image and generates product titles, descriptions, and SEO tags. How that request reaches Anthropic depends on your tier:

What gets sent to Anthropic:

What does not get sent:

We do not sell your data, and we do not train any models on your artwork. The only StanHattie systems involved are described in Section 2 (How ArtDrop Runs) and Section 6 (Subprocessors).

Anthropic says commercial API inputs and outputs are not used for model training by default; explicit feedback or another opt-in can be an exception. Its standard API policy deletes inputs and outputs within 30 days, except where different terms apply or longer retention is needed for Usage Policy enforcement or legal compliance. Review Anthropic's current commercial training policy and API retention policy for the complete exceptions.

If you prefer, you can turn copy generation off and write all product copy manually. ArtDrop will still handle file processing, product creation, and publishing, you just provide the titles, descriptions, and tags yourself.

6. Subprocessors and Third-Party Services

ArtDrop relies on the third-party services below to operate. Each service has its own privacy policy and acts as a subprocessor for the limited data described:

We disclose data to the subprocessors and connected services above for the stated purposes and as otherwise required by law. We do not sell personal data. We use analytics cookies only after consent and a first-party referral-attribution cookie when a visitor uses an affiliate link; we do not use cross-site behavioral advertising cookies.

7. Website Analytics

After you accept analytics cookies, the getartdrop.com website uses Microsoft Clarity to understand how visitors interact with marketing pages. Clarity processes pseudonymous identifiers, page and device metadata, interaction events such as clicks and scrolls, performance/diagnostic events, DOM/layout information for session playback, and IP-based location signals. Input fields are masked. Microsoft may set first- and third-party cookies described in its documentation. We use the resulting data for product and website analytics, not to sell personal data or target ads.

We configure Google Analytics and Microsoft Clarity for consented use on the getartdrop.com marketing website and do not intentionally load those services in the authenticated ArtDrop application. That separation does not mean the application collects no data: the hosted app records the first-party account, authentication, security, feature-usage, performance, drop, provider, store, and diagnostic data described in Sections 3 and 10. We use those application records to provide, secure, measure, reconcile, and improve the service, not for cross-site behavioral advertising.

You can learn more about Clarity's data practices at clarity.microsoft.com/terms.

8. Cookies

Mac app. The Mac app runs locally and does not use cookies.

Web app. When you sign in to the hosted web app at app.getartdrop.com, we set a strictly necessary session cookie to keep you logged in. It is not used for advertising or cross-site tracking.

Marketing website. The getartdrop.com website uses a small number of functional cookies from our hosting provider (Cloudflare) required for site delivery, and, only after you opt in through our consent banner, analytics cookies for Google Analytics and Microsoft Clarity as described in Section 7. We do not use advertising cookies or cross-site tracking cookies.

Affiliate referrals. When you intentionally follow an ArtDrop affiliate link or use a URL containing a referral code, ArtDrop may set a signed first-party cookie named artdrop_ref. It records only the referral code and first-touch time, is HttpOnly and SameSite=Lax, is not readable by page scripts, and normally expires after 90 days. It is used to attribute an eligible purchase and prevent the referral timestamp from being altered; it does not follow you across unrelated websites. You can remove it through your browser settings, but doing so may prevent attribution.

9. Email Communications

When you purchase ArtDrop, we send transactional messages and may send occasional product updates to the email address used at checkout. Marketing messages include an unsubscribe link. We do not sell or rent your email address; email processors receive it as needed to deliver authorized messages.

10. How We Use the Data We Have

We do not use personal data for targeted advertising or sell it.

11. Where Your Data Is Stored

License activation data and hosted web account, configuration, credential, file, and operational data are stored on infrastructure hosted by Railway in the United States. Data sent to connected services is stored and processed under those services' locations and policies. If you are outside the United States, your data may be transferred to and processed in the United States and other locations used by those services.

12. Data Retention

We retain license data while the license is active. Hosted account, configuration, credential, and operational drop records are retained while the account is active and then deleted or de-identified on request or under our operational deletion process, subject to legal, security, backup, and accounting needs. Operational logs are retained as reasonably needed for security, reconciliation, and diagnosis. Uploaded artwork and derived files may remain in per-account processing or archive areas, configured storage, provider systems, and operational backups until cleanup, account deletion, or another applicable retention process removes them. ArtDrop does not offer those files as a permanent user-facing artwork library, but we do not promise zero or instantaneous retention. If you request license-data deletion, we will remove your name, email, and machine fingerprint within 30 days and deactivate the license. Referral, commission, payout, tax, refund, dispute, and related audit records are retained as needed to administer the program, prevent duplicate payment/fraud, resolve disputes, and satisfy tax, accounting, and legal obligations; deletion requests may be fulfilled by de-identifying non-required personal fields while preserving required financial records. Transaction records may be retained for at least 3 years or longer when tax, accounting, dispute, or legal rules require it.

13. Reddit Community Monitoring

StanHattie LLC uses Reddit's API to read public posts in a small set of print-on-demand and art-business subreddits, solely to find discussions relevant to ArtDrop and inform our product roadmap. We access only public content via OAuth2, read-only. We do not store Reddit content, usernames, or user identifiers; matching happens in memory and the only output is a link to the public thread. Because we retain no copies, content a user deletes on Reddit stops appearing on our next read, satisfying Reddit's 48-hour deletion requirement by design. We never use Reddit data for model training, never sell or share it, and never use it to identify individuals.

14. Your Rights

You can request:

Email support@getartdrop.com with the subject "Privacy Request." We will respond within 30 days.

15. Children

ArtDrop is not directed at children under 13. We do not knowingly collect personal data from children.

16. Changes to This Policy

If we update this policy, we will post the revised version here with a new "Last updated" date. Continued use of ArtDrop after an update constitutes acceptance.

17. SMS / Text Messaging

If you opt in by texting ArtDrop first at (833) 278-5080, we collect and use your phone number solely to reply within the support conversation you initiated. We do not collect phone numbers through a web form for this program and do not send proactive account notifications, promotional messages, or marketing texts.

18. Affiliate and Referral Data

Participation in the affiliate program is optional and subject to the Affiliate Program Agreement. Affiliate statistics links are access-controlled capability links; anyone who possesses an unexpired link may be able to view the affiliate's aggregate clicks, conversions, commissions, and payout history, but not referred-customer personal details. Affiliates should keep those links private and contact us if one should be replaced. We may review referral and transaction signals to enforce program rules, investigate self-referral, fraud, duplicate attribution, prohibited traffic, refunds, disputes, and payment errors.

19. Contact

Privacy questions or requests: support@getartdrop.com

Postal mail:
StanHattie LLC
731 SE Alices Rd PMB 1035
Waukee, IA 50263
United States