Privacy Policy

Last updated: July 28, 2026. The prior public label read “Last updated: July 25, 2026.”

1. Who We Are

ArtDrop is software developed and sold by StanHattie LLC ("we," "us," "our"). Our website is getartdrop.com. Contact: support@getartdrop.com

2. How ArtDrop Runs (Web vs Mac)

Mac app ($399 one-time). ArtDrop installs and runs on your Mac. Its local save path can copy sensitive values to the system keyring when available and also writes the complete configuration object to a local JSON file. When you run a normal Mac workflow, the worker sends the artwork, product data, credentials, and related business data needed for that route from your machine to the services you configured, including Shopify or Etsy, compatible print providers, Anthropic, and supported storage services. The Mac app separately sends license activation and validation data to the ArtDrop license server.

Web app ($39/mo). ArtDrop runs as a hosted web application on infrastructure operated by StanHattie LLC (currently Railway). Your account configuration is stored as a retrievable PostgreSQL JSON value so the server can run drops on your behalf. Within that JSON, hosted credential and connection-token values are encrypted at rest in AES-256-GCM envelopes before database storage. This credential-leaf protection does not claim that non-credential settings or identifiers are encrypted. The application masks credential-shaped values in browser views and removes or redacts recognized credential fields in its exports, but those export filters remain incomplete as described below. Uploaded artwork and derived files are processed in per-account filesystem areas and may be transferred to configured storage and providers. The source contains no account-erasure step for those files and no automatic cleanup deadline for archived copies. The login and claim templates load the consent script; after analytics consent, that script can load Google Analytics and Microsoft Clarity on those pages. The main dashboard defines a Clarity loader but does not load the consent script that invokes it.

Both tiers: the source includes administrator and support access paths, account and event records, and connected-service transfers described below. As a company policy, we do not sell personal data or use artwork for model training.

3. What We Actually Receive

For Mac licensing and purchase delivery, StanHattie LLC can receive and store:

License activation

Web app, additionally, we receive and store:

Purchase information (via Stripe)

Affiliate and referral information

These are the principal categories ArtDrop receives directly. Connected services also receive the workflow data described in Sections 5 and 6.

4. Your API Keys

Mac app. When you connect services like Anthropic, Gelato, Printful, Printify, Shopify, Etsy, or a supported storage service, the local save path attempts to copy recognized sensitive values into the system keyring when available and also writes the full configuration object to the local JSON configuration file. Normal worker calls use those credentials from your machine to authenticate to the connected service. License activation separately transmits the license fields listed in Section 3 to StanHattie LLC's license server.

Web app. Your API keys and connection tokens are stored as AES-256-GCM-encrypted credential leaves inside the hosted PostgreSQL configuration JSON. The backend decrypts a credential only for an authorized workflow that needs it. Browser views mask credential-shaped values, and self-service exports remove or redact fields recognized by their credential-name filters. Encryption at rest and export redaction are separate controls: the filters miss LULU_CLIENT_KEY and GOOTEN_PARTNER_BILLING_KEY, and the settings download appends three legacy template arrays without applying the main-config redaction to them. Treat every downloaded settings or account-data file as sensitive. A credential is transmitted to the relevant connected service when authentication requires it. The current self-service erase function deletes matching configuration rows only when its database operations succeed; Section 12 describes the records and files it does not remove.

Pinterest OAuth in the Web app. If direct organic Pinterest publishing is approved and enabled, Pinterest returns an access token and a rotating refresh token after you authorize ArtDrop. ArtDrop stores the complete token bundle in an AES-256-GCM encrypted envelope that is cryptographically bound to your ArtDrop account and selected ArtDrop store. The database does not store the tokens as plaintext, and the browser does not receive them. The backend decrypts them only when it must call Pinterest for that connection.

5. Copy Generation (Third-Party Processor)

When you use ArtDrop's copy generation, your artwork image and your voice/copy rules are sent to a third-party language-model provider (Anthropic), which analyzes the image and generates product titles, descriptions, SEO fields, and alt text. Product tags are assembled separately by ArtDrop from configured and analyzed metadata sources. How that request reaches Anthropic depends on your tier:

What gets sent to Anthropic:

What does not get sent:

We do not sell your data, and we do not train any models on your artwork. The only StanHattie systems involved are described in Section 2 (How ArtDrop Runs) and Section 6 (Subprocessors).

Anthropic says commercial API inputs and outputs are not used for model training by default; explicit feedback or another opt-in can be an exception. Its standard API policy deletes inputs and outputs within 30 days, except where different terms apply or longer retention is needed for Usage Policy enforcement or legal compliance. Review Anthropic's current commercial training policy and API retention policy for the complete exceptions.

If you prefer, you can turn copy generation off and write product copy manually. ArtDrop can then use seller-supplied titles, descriptions, and tags while attempting the configured file, provider, and storefront routes.

6. Subprocessors and Third-Party Services

ArtDrop relies on the third-party services below to operate. Each service has its own privacy policy and acts as a subprocessor for the limited data described:

We disclose data to the subprocessors and connected services above for the stated purposes and as otherwise required by law. We do not sell personal data. We use analytics cookies only after consent and a first-party referral-attribution cookie when a visitor uses an affiliate link; we do not use cross-site behavioral advertising cookies.

6a. Pinterest Direct Organic Publishing (Approval-Gated)

Availability. Direct organic Pinterest publishing is not generally available. Pinterest must grant ArtDrop Standard API access before ordinary customers can use it, and that approval is pending and not guaranteed. The planned workflow uses ArtDrop Web's hosted credential vault and PostgreSQL records; it is not an ArtDrop Mac feature. Pinterest Product Pins through Shopify are a separate current route and are not evidence that this direct organic workflow has been approved.

Identity and owned boards. You authenticate and authorize on Pinterest. ArtDrop does not collect your Pinterest password or ask you to create a developer app or paste a token. ArtDrop stores the Pinterest account ID and username returned for the authenticated user inside the encrypted credential bundle. When you open the board picker, ArtDrop reads the current account and board list from Pinterest and displays only boards whose owner matches that authenticated username. Collaborative boards and boards without a matching owner are excluded. Board names are not retained as a cached Pinterest board list; the chosen board identifier is recorded with the publication review and ledger.

Exact consent, delivery, and readback. You choose one eligible ArtDrop product source and review the exact board, image URL, Shopify destination link, title, description, and alt text. Preparing the review stores those values, but does not publish. A separate Publish click is the immediate timing decision for one Pin; ArtDrop does not schedule, batch, or background-post direct organic Pins. The delivery ledger stores the ArtDrop account and store, source event and review ID, selected board identifier, exact reviewed content and URLs, status, Pinterest Pin ID when returned, verification result, bounded error code, and created, claimed, updated, and completed timestamps. After creation, ArtDrop reads the exact returned Pin ID and marks success only when the available provider fields match the reviewed record. An ambiguous write or mismatched readback is marked unknown for manual review and is not retried automatically. Raw Pinterest response bodies are not stored in the publication ledger.

Disconnect and provider-side retention. Disconnecting Pinterest deletes the local encrypted credential for that ArtDrop store. Pinterest does not provide the end-user token-revocation call this workflow would need, so disconnecting in ArtDrop does not by itself revoke the remote authorization; you must also remove ArtDrop in Pinterest security settings. Disconnecting does not delete Pins already created on Pinterest and does not erase the ArtDrop delivery ledger. ArtDrop account erasure deletes the active local Pinterest credential, pending authorization state, and publication ledger, subject to the backup, security, and legal limits in Section 12. Pinterest may retain and use Pins, account activity, and related data under Pinterest's Privacy Policy; ArtDrop cannot erase those provider-side copies for you.

7. Website Analytics

After you accept analytics cookies, the getartdrop.com website uses Microsoft Clarity to understand how visitors interact with marketing pages. Clarity processes pseudonymous identifiers, page and device metadata, interaction events such as clicks and scrolls, performance/diagnostic events, DOM/layout information for session playback, and IP-based location signals. Input fields are masked. Microsoft may set first- and third-party cookies described in its documentation. We use the resulting data for product and website analytics, not to sell personal data or target ads.

The shared consent script loads Google Analytics and Microsoft Clarity after consent. It is included on the marketing site and on the hosted login and claim templates, so prior consent can load those services on those application entry pages. The main dashboard defines a Clarity loader, but its source does not include the consent script that calls the loader. Independently of third-party analytics, the hosted app records the first-party account, authentication, security, feature-usage, performance, drop, provider, store, and diagnostic data described in Sections 3 and 10.

You can learn more about Clarity's data practices at clarity.microsoft.com/terms.

8. Cookies

Mac app. The Mac app runs a local Flask server and opens http://localhost:5100 in the default browser. Routes that write Flask session state can set ArtDrop's signed first-party session cookie. The shared configuration marks that cookie HttpOnly, Secure, and SameSite=Lax even though the local URL uses HTTP, so the source does not guarantee that every browser will persist or return it. Running the local UI does not by itself invoke the hosted login and claim analytics-consent path.

Web app. When you sign in to hosted Web, ArtDrop sets a strictly necessary HttpOnly, Secure, SameSite=Lax session cookie. The source defaults to a 30-day maximum session age, a 30-minute inactivity timeout, and 3 concurrent sessions. Those server-side controls fail open when the session database is unavailable or its validation raises a transient error. The login and claim templates also include the consent script, which can set or load consented analytics cookies as described in Section 7.

Marketing website. The getartdrop.com website can receive functional delivery cookies from Cloudflare and, after you opt in through the consent banner, analytics cookies for Google Analytics and Microsoft Clarity as described in Section 7. We do not use those analytics for targeted advertising.

Affiliate referrals. When you follow an ArtDrop affiliate link or use a URL containing a referral code, ArtDrop can set a signed first-party cookie named artdrop_ref. It records the normalized referral code and first-touch time, is HttpOnly, Secure, and SameSite=Lax, and is not readable by page scripts. Its lifetime follows the affiliate setting, whose seeded default is 90 days. The first marker wins even if its code does not match an active affiliate, so an earlier invalid marker can prevent a later referral from being captured until the cookie is removed. You can remove it through your browser settings, but doing so may prevent attribution.

9. Email Communications

When you purchase ArtDrop, we send transactional messages and may send occasional product updates to the email address used at checkout. Marketing messages include an unsubscribe link. We do not sell or rent your email address; email processors receive it as needed to deliver authorized messages.

10. How We Use the Data We Have

We do not use personal data for targeted advertising or sell it.

11. Where Your Data Is Stored

License activation data and hosted web account, configuration, credential, file, and operational data are stored on infrastructure hosted by Railway in the United States. Data sent to connected services is stored and processed under those services' locations and policies. If you are outside the United States, your data may be transferred to and processed in the United States and other locations used by those services.

12. Data Retention

The source does not implement a general automatic expiry or cleanup deadline for license records, hosted configuration, drop and audit records, affiliate ledgers, or per-account processing and archive files. A deferred release keeps its scheduled copy while it waits. After release, the worker can archive the source file and describes that archive as permanent. Copies sent to connected storage, storefronts, or providers remain subject to those services and are not removed by ArtDrop's account route.

The current self-service erase function attempts to delete matching hosted configuration rows, passkeys, magic tokens, hosted session rows, and the hosted user row, then inserts the raw email address into the email-suppression table. It does not delete license-server records, drop records, credit balances or ledger entries, audit records, Shopify app-account rows, affiliate records, or per-account filesystem data. The following audit write also stores the raw email in its entity identifier. The route does not cancel a subscription or revoke a license.

If the database is unavailable or a deletion operation raises an exception, the erase function returns a zero or partial summary. The API still clears the session and returns ok: true, so that response is not proof that every attempted deletion succeeded. License-server deletion is a separate administrator-only operation and accepts only a license already marked revoked.

For the approval-gated direct Pinterest workflow, disconnecting removes the local encrypted token bundle but does not remove the publication ledger or any Pin and related activity retained by Pinterest. ArtDrop removes the active Pinterest credential, pending authorization state, and publication ledger through account erasure, subject to the limits above. You must separately manage or delete provider-side Pins and revoke remote access in Pinterest.

13. Reddit Community Monitoring

The repository contains a separate operator-run Reddit launch module. Its command-line interface defaults to dry-run mode, but its live option authenticates with Reddit account credentials and can publish posts, scan posts and top-level comments for keywords, and check engagement. When live monitoring finds a match, the module writes a local JSON file containing fields that can include the subreddit, Reddit post or comment ID, post title, up to 500 characters of a matching comment, author name, public URL, matched keywords, scores, timestamps, and other engagement metrics. The module contains no deletion or expiry sweep for that file. Whether this module is operated live, and the operational retention and Reddit-approval status, cannot be determined from the source alone.

14. Your Rights

You can ask support to review a request for:

The self-service JSON export is not a complete account export. It includes the basic hosted user row, the main configuration JSON with credential-shaped values removed or redacted, and the plan and purchased balance from the current credit row. It omits the separate template columns, authentication rows, credit ledger, audit trail, drop records, affiliate records, per-account files, and the separate license-server database. If the database is unavailable or a query fails, the route still downloads an empty or partial JSON structure.

The self-service erase route has the limits in Section 12 and does not deactivate a license. Email support@getartdrop.com with the subject "Privacy Request" for any broader request. The source does not implement or measure a support-response deadline.

15. Children

ArtDrop is not directed at children under 13. We do not knowingly collect personal data from children.

16. Changes to This Policy

If we update this policy, we will post the revised version here with a new "Last updated" date. Continued use of ArtDrop after an update constitutes acceptance.

18. Affiliate and Referral Data

Participation in the affiliate program is optional and subject to the Affiliate Program Agreement. Affiliate statistics links are signed capability links with no timestamp or expiry in the token. Anyone who possesses a valid link can view that affiliate's aggregate clicks, conversions, commissions, override earnings, and payout history, but the page does not return referred-customer personal details. Affiliates should keep those links private. There is no per-link expiry or revocation field. Changing the server secret invalidates every existing stats token, and removing the affiliate record makes its page unavailable. We may review referral and transaction signals to enforce program rules, investigate self-referral, fraud, duplicate attribution, prohibited traffic, refunds, disputes, and payment errors.

19. Contact

Privacy questions or requests: support@getartdrop.com

Postal mail:
StanHattie LLC
731 SE Alices Rd PMB 1035
Waukee, IA 50263
United States