Privacy Policy

How we handle your data — transparently and responsibly.

Last updated: August 2, 2026

Data Controller

The party responsible for data processing on this website is:

Alexander Fulst

Lehmkamp 1, 48161 Münster, Germany

[email protected]

Data We Collect

We collect and process the following personal data when you use our service:

  • Account InformationEmail address and encrypted password when you create an account.
  • Room ImagesRoom photos you upload are processed by our AI-powered room-analysis service and transmitted to the configured AI provider when needed for that analysis. They are stored in private Cloudflare R2 object storage so you can use your scan history, sharing features and ordering flow. Room photos are retained for up to 30 days and can be deleted earlier by you.
  • Order InformationName, shipping address, and email when you place an order for a print.
  • Usage DataTechnical request data such as browser, device and IP address. For rate limiting and abuse logs, the IP is hashed with a server-side pepper; the plain IP is not stored in the abuse tables.
  • Payment InformationPayment details are processed directly by Stripe and never stored on our servers.

Legal Basis for Processing

We process your personal data based on the following legal grounds (GDPR Art. 6):

  • Contract/service performance (Art. 6(1)(b))Room analysis, recommendation generation, private room-photo history for up to 30 days, user-requested artwork generation, checkout and fulfilment.
  • Legitimate interest (Art. 6(1)(f))Security, abuse prevention, operational reliability and support.
  • Legal obligation (Art. 6(1)(c))To comply with tax, commercial, and legal retention laws.

Third-Party Data Processors

We use trusted third-party service providers (data processors under GDPR Art. 28) to process data on our behalf:

Supabase

Supabase Inc. · USA

Authentication, account data, scan history, legal records and order data. Supabase hosts the database and authentication service.

View Privacy Policy

Vercel

Vercel Inc. · USA

Hosting and server execution. Vercel receives request metadata and may process IP addresses in technical logs for security, availability and abuse prevention.

View Privacy Policy

Google Cloud Vertex AI

Google Cloud EMEA Limited · Ireland

Google Cloud Vertex AI receives room images for requested room analysis and prompts for requested analysis or artwork generation. Artura does not use room photos or scan results to train its own models. Google processes data under the applicable Google Cloud Data Processing Addendum and service terms; provider-side logging, retention, processing locations and transfer safeguards depend on those terms and the account configuration.

View Privacy Policy

Stripe

Stripe Inc. · USA

Checkout, payment authorisation, billing address, fraud prevention and invoices. Stripe receives the payment and contact data needed to complete the purchase.

View Privacy Policy

Gelato

Gelato AS · Norway

Production, packaging and shipping of the ordered physical product. Gelato receives the recipient name, German delivery address, order details and print files.

View Privacy Policy

Cloudflare R2

Cloudflare Inc. · USA

Private object storage for room images, generated artwork and print files. Access is protected by short-lived signed URLs and server-side authorisation.

View Privacy Policy

Cloudflare Turnstile

Cloudflare Inc. · USA

Abuse and bot protection for public forms and sensitive API endpoints. Turnstile receives the browser challenge data and, where available, the client IP for verification.

View Privacy Policy

International Data Transfers: Some processors may process data outside the European Economic Area (EEA). Transfers use the safeguards applicable to the relevant service and agreement, such as an adequacy decision, EU Standard Contractual Clauses (SCCs) or another legally recognised mechanism. For Google Cloud Vertex AI, the applicable Data Processing Addendum, contracting entity, configured processing location and account settings govern the details. We do not claim zero provider-side retention.

Cookies & Local Storage

The following strictly necessary cookies and local-storage keys are used. No analytics, advertising or cross-site tracking is enabled.

Cookie / KeyPurposeType
NEXT_LOCALEKeeps the selected language and supports locale routing (one year).Strictly necessary
NEXT_CURRENCYStores your preferred currency (EUR/USD) for correct pricing display.Strictly necessary
sb-*Supabase authentication session storage/cookies (including the project-specific sb-* key).Strictly necessary
postair_referral (cookie)Stores an explicitly shared referral or promotion code for up to seven days; it is removed after checkout.Functional, user-initiated
artura_cart (localStorage)Stores the local shopping cart in the browser. It is not sent to a server until you start checkout.Strictly necessary
postair_referral (localStorage)Stores an explicitly shared referral or promotion code for up to seven days; it is removed after checkout.Functional, user-initiated
artura_measurement_systemStores the optional metric/imperial display preference.Strictly necessary

We do not use analytics, advertising or tracking cookies. Cloudflare Turnstile is a security service, not an advertising tracker.

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access — obtain a copy of your personal data (Art. 15 GDPR)
  • Right to rectification — correct inaccurate personal data (Art. 16 GDPR)
  • Right to erasure — request deletion of your data (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability — receive your data in a machine-readable format (Art. 20 GDPR)
  • Right to object — object to processing based on legitimate interest (Art. 21 GDPR)

You also have the right to lodge a complaint with a supervisory authority. The competent authority for North Rhine-Westphalia is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).

Data Retention

Retention is separated by data category: account and scan-history data remain until account deletion or the user deletes the scan; room photos in private Cloudflare R2 storage are retained for up to 30 days and can be deleted earlier. Generated artwork, prompts and scan metadata remain while the scan history is retained and are deleted with the scan where the stored object is linked. Order, invoice, tax and payment records are retained for 10 years under § 147 AO and § 257 HGB. Withdrawal declarations and their email-outbox audit data are retained for the applicable statutory limitation and proof periods. Security rate-limit and abuse records are retained for up to 90 days. Email delivery logs are retained for up to 90 days after successful delivery, unless a longer legal proof period applies. Technical deletion-failure logs are retained for up to 90 days after successful resolution. Artura does not use room photos or scan results to train its own models. Any provider-side logging or retention is governed by the applicable Google Cloud terms and account settings.

Data Protection Contact

For any questions about data protection or to exercise your rights, please contact us: