Privacy Policy
ArtDrop™ ships in two tiers, a hosted web app at $39/mo and a native Mac app at $399 one-time, and the privacy posture differs between them. We do not sell personal data or use your artwork for model training. We disclose limited data to processors and the connected services needed to provide the workflows you request, as detailed below.
1. Who We Are
ArtDrop is software developed and sold by StanHattie LLC ("we," "us," "our"). Our website is getartdrop.com. Contact: support@getartdrop.com
2. How ArtDrop Runs (Web vs Mac)
Mac app ($399 one-time). ArtDrop installs and runs on your Mac. Its local save path can copy sensitive values to the system keyring when available and also writes the complete configuration object to a local JSON file. When you run a normal Mac workflow, the worker sends the artwork, product data, credentials, and related business data needed for that route from your machine to the services you configured, including Shopify or Etsy, compatible print providers, Anthropic, and supported storage services. The Mac app separately sends license activation and validation data to the ArtDrop license server.
Web app ($39/mo). ArtDrop runs as a hosted web application on infrastructure operated by StanHattie LLC (currently Railway). Your account configuration is stored as a retrievable PostgreSQL JSON value so the server can run drops on your behalf. Within that JSON, hosted credential and connection-token values are encrypted at rest in AES-256-GCM envelopes before database storage. This credential-leaf protection does not claim that non-credential settings or identifiers are encrypted. The application masks credential-shaped values in browser views and removes or redacts recognized credential fields in its exports, but those export filters remain incomplete as described below. Uploaded artwork and derived files are processed in per-account filesystem areas and may be transferred to configured storage and providers. The source contains no account-erasure step for those files and no automatic cleanup deadline for archived copies. The login and claim templates load the consent script; after analytics consent, that script can load Google Analytics and Microsoft Clarity on those pages. The main dashboard defines a Clarity loader but does not load the consent script that invokes it.
Both tiers: the source includes administrator and support access paths, account and event records, and connected-service transfers described below. As a company policy, we do not sell personal data or use artwork for model training.
3. What We Actually Receive
For Mac licensing and purchase delivery, StanHattie LLC can receive and store:
License activation
- Machine fingerprint hash, a persistent SHA-256-derived identifier made from the Mac hostname, architecture, processor string, and MAC-address integer, used to bind machine slots. The server stores the hash, not those source components.
- License key, the activation key issued to you at purchase
- Platform and app version, sent during activation or revalidation
- Network and event data, including the request IP address, activation and last-seen timestamps, and license event details
- Purchase identity, including buyer name, email, order identifier, plan, status, and any recorded expiry
Web app, additionally, we receive and store:
- Your account email, magic-token records, authenticated-session identifiers, hashed session IP, session-security records, and passkey credential public-key information if you enroll a passkey. ArtDrop does not receive the biometric used by your device to unlock a passkey.
- The configuration you save (API keys and connection tokens, voice/copy rules, store and provider connections, template settings)
- Artwork uploads and derived files while they are held in per-account processing or archive areas and configured storage. The source does not define an operational-backup policy
- Operational records needed to run and reconcile drops: a drop/event ID, store and product-line destination, provider and resulting product references, status, timestamps, and bounded error details
- Deferred per-store release copies and scheduling records, including the selected destination and release time, while a scheduled drop is waiting
- If you use the direct Pinterest workflow after it is approved and enabled, the connected Pinterest account identity, encrypted OAuth credential bundle, selected board identifier, exact reviewed Pin data, and delivery/readback ledger described in Section 6a
- A perceptual fingerprint of the processed listing image used to reconcile a product outcome with its ArtDrop drop. The fingerprint is not the image, cannot recreate the artwork, and is not used for advertising, cross-site tracking, or model training
- Demo-use counters, copy-credit balances and ledger entries, and an audit trail for actions such as export, erasure, credential changes, and license binding
Purchase information (via Stripe)
- Name and email, provided at checkout, used to deliver your license key or provision your web subscription and to provide support
- Transaction references, including the Stripe customer and subscription identifiers recorded on a license and payment, charge, invoice, or checkout references used by purchase and affiliate webhooks. ArtDrop does not store the payment-card number
Affiliate and referral information
- If you follow an affiliate link, the affiliate code and first-touch timestamp in a signed first-party referral cookie
- If a purchase is attributed, the referring affiliate, purchase/customer identifiers, purchase amount, commission status, and refund or dispute status
- For an accepted affiliate, name, email, referral code, agreement version and acceptance-evidence reference, parent-affiliate relationship if any, payout account identifier/status, clicks, referral and commission ledger, payout history, tax-related account status, and administrative notes
These are the principal categories ArtDrop receives directly. Connected services also receive the workflow data described in Sections 5 and 6.
We do not use your artwork for model training or sell your account data. We disclose data to the processors and connected services listed below to provide the service, secure it, process payments, communicate with you, and complete workflows you request. Authorized personnel may access hosted account data when needed for security, operations, legal compliance, or support.
4. Your API Keys
Mac app. When you connect services like Anthropic, Gelato, Printful, Printify, Shopify, Etsy, or a supported storage service, the local save path attempts to copy recognized sensitive values into the system keyring when available and also writes the full configuration object to the local JSON configuration file. Normal worker calls use those credentials from your machine to authenticate to the connected service. License activation separately transmits the license fields listed in Section 3 to StanHattie LLC's license server.
Web app. Your API keys and connection tokens are stored as AES-256-GCM-encrypted credential leaves inside the hosted PostgreSQL configuration JSON. The backend decrypts a credential only for an authorized workflow that needs it. Browser views mask credential-shaped values, and self-service exports remove or redact fields recognized by their credential-name filters. Encryption at rest and export redaction are separate controls: the filters miss LULU_CLIENT_KEY and GOOTEN_PARTNER_BILLING_KEY, and the settings download appends three legacy template arrays without applying the main-config redaction to them. Treat every downloaded settings or account-data file as sensitive. A credential is transmitted to the relevant connected service when authentication requires it. The current self-service erase function deletes matching configuration rows only when its database operations succeed; Section 12 describes the records and files it does not remove.
Pinterest OAuth in the Web app. If direct organic Pinterest publishing is approved and enabled, Pinterest returns an access token and a rotating refresh token after you authorize ArtDrop. ArtDrop stores the complete token bundle in an AES-256-GCM encrypted envelope that is cryptographically bound to your ArtDrop account and selected ArtDrop store. The database does not store the tokens as plaintext, and the browser does not receive them. The backend decrypts them only when it must call Pinterest for that connection.
5. Copy Generation (Third-Party Processor)
When you use ArtDrop's copy generation, your artwork image and your voice/copy rules are sent to a third-party language-model provider (Anthropic), which analyzes the image and generates product titles, descriptions, SEO fields, and alt text. Product tags are assembled separately by ArtDrop from configured and analyzed metadata sources. How that request reaches Anthropic depends on your tier:
- Mac app. The request goes directly from your machine to Anthropic. It does not pass through StanHattie LLC servers.
- Web app. The request is made by our backend on your behalf so that drops can run server-side, using ArtDrop's managed copy-engine integration (or, if you have supplied your own copy-engine key, the credential saved in your account). The image and voice rules are processed through our backend for that request. The source image or derived files may also remain in per-account processing or archive areas and configured storage as described in Section 12.
What gets sent to Anthropic:
- Your artwork image (for visual analysis)
- Your voice rules (so the copy sounds like you)
- Basic context like your artist name and artwork type
What does not get sent:
- Your payment card details
- Financial data
- Customer information
- Store analytics or sales data
We do not sell your data, and we do not train any models on your artwork. The only StanHattie systems involved are described in Section 2 (How ArtDrop Runs) and Section 6 (Subprocessors).
Anthropic says commercial API inputs and outputs are not used for model training by default; explicit feedback or another opt-in can be an exception. Its standard API policy deletes inputs and outputs within 30 days, except where different terms apply or longer retention is needed for Usage Policy enforcement or legal compliance. Review Anthropic's current commercial training policy and API retention policy for the complete exceptions.
If you prefer, you can turn copy generation off and write product copy manually. ArtDrop can then use seller-supplied titles, descriptions, and tags while attempting the configured file, provider, and storefront routes.
6. Subprocessors and Third-Party Services
ArtDrop relies on the third-party services below to operate. Each service has its own privacy policy and acts as a subprocessor for the limited data described:
- Stripe (stripe.com/privacy), processes customer payments. If you are accepted as an affiliate and onboard for payouts, Stripe Connect also processes your identity, contact, bank/payout, verification, and tax-form information. StanHattie LLC remains responsible for configuring, reviewing, filing, and delivering any required information returns; Stripe provides tooling and delivery options.
- Anthropic (anthropic.com/policies), copy generation, as described in Section 5 above.
- Gelato, Printful, Printify, if you configure a compatible print-on-demand route, the provider receives the artwork file or hosted-artwork reference, product configuration, and listing data needed to create the requested product. That transfer goes from your machine on Mac or from our backend on Web.
- Shopify (shopify.com/legal/privacy), if you connect a Shopify storefront, receives product and listing data. Shopify also receives artwork files when you select Shopify Files as the storage route.
- Pinterest (policy.pinterest.com), if the approval-gated direct organic workflow becomes available and you connect it, receives the authenticated authorization and each image, title, description, alt text, destination link, board identifier, and publication request you explicitly approve.
- Etsy (etsy.com/legal/privacy), if you authorize an Etsy shop, receives OAuth and shop identifiers plus the listing fields and files needed for a direct digital listing. Physical Etsy products use the compatible Etsy-connected provider route you select.
- Backblaze B2 (backblaze.com), if you select Backblaze for image hosting, receives files from your machine on Mac or from our backend on Web.
- Dropbox (dropbox.com/privacy), if you select Dropbox storage, receives the files and connection data needed to store the requested artwork.
- Google Drive (policies.google.com/privacy), if you select Google Drive storage, receives the files and connection data needed to store the requested artwork.
- Railway (railway.com), hosts the ArtDrop web application backend and the license activation server in the United States.
- Cloudflare (cloudflare.com), serves the getartdrop.com marketing site and provides DNS, TLS termination, and DDoS protection. Cloudflare may set functional cookies required to deliver the site. If you select Cloudflare R2, it stores the requested artwork files. If a Turnstile challenge is presented during sign-in, Cloudflare processes the challenge and related request data for abuse prevention.
- Resend (resend.com), delivers transactional email (license keys, magic-link sign-in, account notifications) on our behalf.
- Migadu (migadu.com), hosts the support@getartdrop.com and hello@getartdrop.com mailboxes used for customer email.
- Google Analytics 4 (policies.google.com), loads after analytics consent on pages that include the shared consent script, including the login and claim templates.
- Microsoft Clarity (microsoft.com/privacy), loads after analytics consent on pages that include the shared consent script, including the login and claim templates, as described in Section 7.
We disclose data to the subprocessors and connected services above for the stated purposes and as otherwise required by law. We do not sell personal data. We use analytics cookies only after consent and a first-party referral-attribution cookie when a visitor uses an affiliate link; we do not use cross-site behavioral advertising cookies.
6a. Pinterest Direct Organic Publishing (Approval-Gated)
Availability. Direct organic Pinterest publishing is not generally available. Pinterest must grant ArtDrop Standard API access before ordinary customers can use it, and that approval is pending and not guaranteed. The planned workflow uses ArtDrop Web's hosted credential vault and PostgreSQL records; it is not an ArtDrop Mac feature. Pinterest Product Pins through Shopify are a separate current route and are not evidence that this direct organic workflow has been approved.
Identity and owned boards. You authenticate and authorize on Pinterest. ArtDrop does not collect your Pinterest password or ask you to create a developer app or paste a token. ArtDrop stores the Pinterest account ID and username returned for the authenticated user inside the encrypted credential bundle. When you open the board picker, ArtDrop reads the current account and board list from Pinterest and displays only boards whose owner matches that authenticated username. Collaborative boards and boards without a matching owner are excluded. Board names are not retained as a cached Pinterest board list; the chosen board identifier is recorded with the publication review and ledger.
Exact consent, delivery, and readback. You choose one eligible ArtDrop product source and review the exact board, image URL, Shopify destination link, title, description, and alt text. Preparing the review stores those values, but does not publish. A separate Publish click is the immediate timing decision for one Pin; ArtDrop does not schedule, batch, or background-post direct organic Pins. The delivery ledger stores the ArtDrop account and store, source event and review ID, selected board identifier, exact reviewed content and URLs, status, Pinterest Pin ID when returned, verification result, bounded error code, and created, claimed, updated, and completed timestamps. After creation, ArtDrop reads the exact returned Pin ID and marks success only when the available provider fields match the reviewed record. An ambiguous write or mismatched readback is marked unknown for manual review and is not retried automatically. Raw Pinterest response bodies are not stored in the publication ledger.
Disconnect and provider-side retention. Disconnecting Pinterest deletes the local encrypted credential for that ArtDrop store. Pinterest does not provide the end-user token-revocation call this workflow would need, so disconnecting in ArtDrop does not by itself revoke the remote authorization; you must also remove ArtDrop in Pinterest security settings. Disconnecting does not delete Pins already created on Pinterest and does not erase the ArtDrop delivery ledger. ArtDrop account erasure deletes the active local Pinterest credential, pending authorization state, and publication ledger, subject to the backup, security, and legal limits in Section 12. Pinterest may retain and use Pins, account activity, and related data under Pinterest's Privacy Policy; ArtDrop cannot erase those provider-side copies for you.
7. Website Analytics
After you accept analytics cookies, the getartdrop.com website uses Microsoft Clarity to understand how visitors interact with marketing pages. Clarity processes pseudonymous identifiers, page and device metadata, interaction events such as clicks and scrolls, performance/diagnostic events, DOM/layout information for session playback, and IP-based location signals. Input fields are masked. Microsoft may set first- and third-party cookies described in its documentation. We use the resulting data for product and website analytics, not to sell personal data or target ads.
The shared consent script loads Google Analytics and Microsoft Clarity after consent. It is included on the marketing site and on the hosted login and claim templates, so prior consent can load those services on those application entry pages. The main dashboard defines a Clarity loader, but its source does not include the consent script that calls the loader. Independently of third-party analytics, the hosted app records the first-party account, authentication, security, feature-usage, performance, drop, provider, store, and diagnostic data described in Sections 3 and 10.
You can learn more about Clarity's data practices at clarity.microsoft.com/terms.
8. Cookies
Mac app. The Mac app runs a local Flask server and opens http://localhost:5100 in the default browser. Routes that write Flask session state can set ArtDrop's signed first-party session cookie. The shared configuration marks that cookie HttpOnly, Secure, and SameSite=Lax even though the local URL uses HTTP, so the source does not guarantee that every browser will persist or return it. Running the local UI does not by itself invoke the hosted login and claim analytics-consent path.
Web app. When you sign in to hosted Web, ArtDrop sets a strictly necessary HttpOnly, Secure, SameSite=Lax session cookie. The source defaults to a 30-day maximum session age, a 30-minute inactivity timeout, and 3 concurrent sessions. Those server-side controls fail open when the session database is unavailable or its validation raises a transient error. The login and claim templates also include the consent script, which can set or load consented analytics cookies as described in Section 7.
Marketing website. The getartdrop.com website can receive functional delivery cookies from Cloudflare and, after you opt in through the consent banner, analytics cookies for Google Analytics and Microsoft Clarity as described in Section 7. We do not use those analytics for targeted advertising.
Affiliate referrals. When you follow an ArtDrop affiliate link or use a URL containing a referral code, ArtDrop can set a signed first-party cookie named artdrop_ref. It records the normalized referral code and first-touch time, is HttpOnly, Secure, and SameSite=Lax, and is not readable by page scripts. Its lifetime follows the affiliate setting, whose seeded default is 90 days. The first marker wins even if its code does not match an active affiliate, so an earlier invalid marker can prevent a later referral from being captured until the cookie is removed. You can remove it through your browser settings, but doing so may prevent attribution.
9. Email Communications
When you purchase ArtDrop, we send transactional messages and may send occasional product updates to the email address used at checkout. Marketing messages include an unsubscribe link. We do not sell or rent your email address; email processors receive it as needed to deliver authorized messages.
10. How We Use the Data We Have
- Delivering your license key and download link via email
- Activating and validating your license
- Enforcing the machine limit on your license
- Providing customer support when you contact us
- Sending occasional product updates (with easy unsubscribe)
- Creating and authenticating hosted web accounts
- Storing hosted configuration and credentials
- Running requested drops, transferring files, and publishing product data
- Holding deferred per-store copies while they wait and releasing them at the selected time
- Fetching provider catalog and base-cost data for Provider Cost Comparison
- Completing and verifying each Pinterest Pin that you separately review and request, if the approval-gated direct workflow becomes available
- Protecting the service, maintaining operational logs, and diagnosing failures
- Recording referral attribution, calculating and auditing commissions, detecting abuse, and administering affiliate payouts
We do not use personal data for targeted advertising or sell it.
11. Where Your Data Is Stored
License activation data and hosted web account, configuration, credential, file, and operational data are stored on infrastructure hosted by Railway in the United States. Data sent to connected services is stored and processed under those services' locations and policies. If you are outside the United States, your data may be transferred to and processed in the United States and other locations used by those services.
12. Data Retention
The source does not implement a general automatic expiry or cleanup deadline for license records, hosted configuration, drop and audit records, affiliate ledgers, or per-account processing and archive files. A deferred release keeps its scheduled copy while it waits. After release, the worker can archive the source file and describes that archive as permanent. Copies sent to connected storage, storefronts, or providers remain subject to those services and are not removed by ArtDrop's account route.
The current self-service erase function attempts to delete matching hosted configuration rows, passkeys, magic tokens, hosted session rows, and the hosted user row, then inserts the raw email address into the email-suppression table. It does not delete license-server records, drop records, credit balances or ledger entries, audit records, Shopify app-account rows, affiliate records, or per-account filesystem data. The following audit write also stores the raw email in its entity identifier. The route does not cancel a subscription or revoke a license.
If the database is unavailable or a deletion operation raises an exception, the erase function returns a zero or partial summary. The API still clears the session and returns ok: true, so that response is not proof that every attempted deletion succeeded. License-server deletion is a separate administrator-only operation and accepts only a license already marked revoked.
For the approval-gated direct Pinterest workflow, disconnecting removes the local encrypted token bundle but does not remove the publication ledger or any Pin and related activity retained by Pinterest. ArtDrop removes the active Pinterest credential, pending authorization state, and publication ledger through account erasure, subject to the limits above. You must separately manage or delete provider-side Pins and revoke remote access in Pinterest.
13. Reddit Community Monitoring
The repository contains a separate operator-run Reddit launch module. Its command-line interface defaults to dry-run mode, but its live option authenticates with Reddit account credentials and can publish posts, scan posts and top-level comments for keywords, and check engagement. When live monitoring finds a match, the module writes a local JSON file containing fields that can include the subreddit, Reddit post or comment ID, post title, up to 500 characters of a matching comment, author name, public URL, matched keywords, scores, timestamps, and other engagement metrics. The module contains no deletion or expiry sweep for that file. Whether this module is operated live, and the operational retention and Reddit-approval status, cannot be determined from the source alone.
14. Your Rights
You can ask support to review a request for:
- Access, a copy of the personal data we hold about you
- Correction, correction of inaccurate data
- Deletion, removal of eligible data
- Portability, your data in a portable format
The self-service JSON export is not a complete account export. It includes the basic hosted user row, the main configuration JSON with credential-shaped values removed or redacted, and the plan and purchased balance from the current credit row. It omits the separate template columns, authentication rows, credit ledger, audit trail, drop records, affiliate records, per-account files, and the separate license-server database. If the database is unavailable or a query fails, the route still downloads an empty or partial JSON structure.
The self-service erase route has the limits in Section 12 and does not deactivate a license. Email support@getartdrop.com with the subject "Privacy Request" for any broader request. The source does not implement or measure a support-response deadline.
15. Children
ArtDrop is not directed at children under 13. We do not knowingly collect personal data from children.
16. Changes to This Policy
If we update this policy, we will post the revised version here with a new "Last updated" date. Continued use of ArtDrop after an update constitutes acceptance.
18. Affiliate and Referral Data
Participation in the affiliate program is optional and subject to the Affiliate Program Agreement. Affiliate statistics links are signed capability links with no timestamp or expiry in the token. Anyone who possesses a valid link can view that affiliate's aggregate clicks, conversions, commissions, override earnings, and payout history, but the page does not return referred-customer personal details. Affiliates should keep those links private. There is no per-link expiry or revocation field. Changing the server secret invalidates every existing stats token, and removing the affiliate record makes its page unavailable. We may review referral and transaction signals to enforce program rules, investigate self-referral, fraud, duplicate attribution, prohibited traffic, refunds, disputes, and payment errors.
19. Contact
Privacy questions or requests: support@getartdrop.com
Postal mail:
StanHattie LLC
731 SE Alices Rd PMB 1035
Waukee, IA 50263
United States