◇ The Artifacts Lab
Legal

Privacy Policy

Last updated: 1 October 2026 · Applies to theartifactslab.com and The Artifacts Lab Android app.

The Artifacts Lab (“we”, “us”) makes simple tools for money, health, fitness and daily life. This policy explains what data we collect, why, who processes it for us, how long we keep it, and how you can delete it.

Who is responsible for your data: The Artifacts Lab is operated by Claudio Avallone. For the purposes of applicable data-protection laws, Claudio Avallone is responsible for the processing of personal data described in this Privacy Policy. Contact: support@theartifactslab.com.

1. The short version

2. What we collect

Account data (only if you sign up)

Data you enter in the tools

Depending on the tools you use, this can include: budgets, expenses and imported bank-statement lines (Expense Tracker); retirement savings and projections; goals, habits and to-do items; workout plans and logged sessions; meal plans, recipes and grocery lists; pregnancy dates, appointments and notes (Pregnancy Roadmap); and your daily Pulse/You check-ins.

AI features (optional)

When you use an AI feature (e.g. AI goal plans, workout or meal import from a photo, receipt scanning, bank-statement import, quick expense entry), the text or image you submit is sent through our server to Google’s Gemini API to generate the result. We keep a count of AI uses per account to apply plan limits. We do not use your AI submissions to train our own models; the AI provider processes submitted content solely to generate the requested result.

Reminders (push notifications, optional)

If you enable reminders, we store a push-notification token for your browser or phone (web push subscription, or a Firebase Cloud Messaging token in the Android app) and your time zone, plus a small daily summary used to write the reminder.

Usage and analytics

Payments

Paid plans are bought on our website through Stripe. Stripe processes your card details; we never see or store them. We receive your email, the plan and its status.

Emails

We send account emails (sign-up confirmation, password reset) and a small number of product emails (welcome, tips). Product emails can be unsubscribed from at any time.

Shared links

If you use “Share”, a snapshot of that result (title, summary and the numbers shown) is stored so anyone with the link can view it.

Households (optional)

If you create or join a household, its members can see the household’s name, its member list and the people without an account added to it. Each member decides, tool by tool, what to share. Members see only what others have chosen to share, never anyone’s full tool data:

Pregnancy and food-profile information is health-related. It is shared with your household only if you choose to share it, and you can stop at any time in your household settings. Turning sharing off, leaving the household or deleting your account deletes what you shared.

People without an account. A household member can add someone they cook for who doesn’t have an account, such as a child. We store only what the member enters: a nickname, an age band, and optionally sex, activity level, diet, allergies and calorie targets. We never ask for a date of birth, photo or contact details. Only that household’s members can see this information. Only add someone if you are allowed to do so on their behalf (for a child, as their parent or guardian).

Invites. If you invite someone by email, we use their email address to send the invite and to let them accept it. Invites work once and expire after 72 hours. Content you add to a household, such as shopping-list items or tasks, stays with the household if you leave.

3. Why we use it

Lawful basis (for EEA/UK users)

For users in the European Economic Area, the United Kingdom and similar jurisdictions, we process personal data under one or more of the following legal bases:

4. Who processes data for us

ProviderPurposeData
SupabaseAuthentication and databaseAccount data, tool data, reminders, events
VercelWebsite hosting and our APIRequests (IP, device), API inputs
Google (Gemini API)AI featuresText/images you submit to an AI feature
Google AnalyticsWebsite analyticsUsage, device, approximate location
Google Search ConsoleSearch-performance analytics for our websiteAggregated search queries and click data
Google Firebase Cloud MessagingAndroid remindersPush token, reminder text
StripePaymentsEmail, payment details (held by Stripe)
ResendSending emailsEmail address, email content
Google Fonts, jsDelivr, cdnjs, Google TranslateFonts, code libraries, optional page translationIP address and browser details when loaded

Some providers are located outside your country (including the United States). Where required by applicable law, we rely on appropriate safeguards and contractual protections designed to protect personal data during international transfers.

5. How long we keep it

6. Your choices and rights

7. Security

Data is encrypted in transit (HTTPS/TLS). Our database enforces per-user access rules so you can only read your own data and, if you are in a household, what its members chose to share with it. In the Android app your sign-in session is stored encrypted with the Android Keystore. No system is perfectly secure; please use a strong, unique password.

8. Children

The Artifacts Lab is not directed at children under 13, children cannot create an account, and we do not knowingly collect their data. The only exception is the limited information a parent or guardian chooses to enter about a child as a person without an account in their household (see “Households” above), which they can edit or remove at any time.

9. Changes

We will update this page when our practices change and change the “Last updated” date. Significant changes will be announced in the app or by email.

10. Data & compliance summary (Google Play Data Safety)

Kept in sync with the Play Console Data Safety form — the two must match.

Data typeCollectedPurposeShared*Optional
Email addressYes (account; and the address of anyone you invite to a household by email)Account management, communications, household invitesNoYes — only with an account or a household invite
Health & fitness (pregnancy, workouts, meals, check-ins, household food profiles and people without an account)Yes (if you use those tools or households with an account)App functionalityNoYes
Financial info (budgets, expenses, retirement figures)Yes (if you use those tools with an account)App functionalityNoYes
Photos / files you submit to AI importProcessed, not stored by usApp functionality (AI)NoYes
App interactions (product events)YesAnalyticsNoCollected for all users; linked to your account after sign-in
Device or other IDs (random device ID, push token)YesAnalytics, remindersNoPush: yes
Purchase historyPlan status only (purchase happens on the website)Account managementNoYes

*“Shared” in Play’s sense excludes service providers processing data on our behalf (section 4) and household sharing that you turn on yourself (a user-initiated transfer to people you choose).

The Artifacts Lab · Terms of Service · Delete your account