Legal
Privacy Policy
Last updated 21 July 2026
ArtifactsMCP ("we", "us") is an independent beta service that lets AI agents publish self-contained web pages to a shareable URL. This policy explains what we collect and your choices. Questions: privacy@artifactsmcp.com.
What we collect
- Account — your email address (from Google or GitHub sign-in), a username, a one-way hash of your API key (never the key itself), and the date you joined.
- Content you publish — the HTML and title of your artifacts, their visibility setting, and — only if you choose email- or domain-restricted sharing — the email addresses or domain you supply to grant access. Those belong to other people; you confirm you may share them with us for this purpose.
- Feedback — anything you send us, plus an optional contact email.
- Technical — standard request logs (IP address, browser/user-agent, timestamps) and rate-limit counters, used to run and protect the service.
- Analytics — aggregate page views and a few button events via PostHog, collected without cookies (see below).
How we use it
To provide and secure the service, authenticate you, prevent abuse, respond to support and feedback, and understand which features are used. We do not sell your data.
Analytics without cookies
We use PostHog (United States region) in a cookieless mode — it sets no cookies. It keeps only an anonymous identifier in your browser's local storage so repeat visits aren't counted as new people, and it honours your browser's "Do Not Track" setting. We use it only for aggregate product analytics — never session recording. Aggregate analytics data is processed in the United States.
Who processes data for us
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, sign-in (Cognito) | India (Mumbai) |
| Cloudflare | DNS, edge delivery, email routing | Global edge |
| Sign-in, Search Console | Global | |
| GitHub | Sign-in | Global |
| PostHog | Cookieless analytics | United States |
| Google (Gmail) | Support-email delivery | Global |
Where your data lives
Primary storage is AWS in India (Mumbai). Some processors operate outside India — notably PostHog (analytics) in the United States; where this involves an international transfer, we rely on the provider's safeguards.
How long we keep it
Artifacts are kept until you delete them. Account data is kept until you ask us to delete it. Technical logs are kept for about 90 days.
Your rights
You may access, correct, or delete your data, and withdraw consent. Delete artifacts yourself from your dashboard; for account deletion or any request, email privacy@artifactsmcp.com and we will act within a reasonable time. This service is provided under the laws of India (Digital Personal Data Protection Act, 2023 — "DPDP"). If you are in the EU/UK or California, we also honour the access/deletion rights the GDPR and CCPA give you.
Children
The service is for adults; you must be 18 or older to use it. It is not directed to children and we do not knowingly collect their data.
Security
Data is served over TLS, API keys are stored only as hashes, and access is restricted. No system is perfectly secure, but we take reasonable measures.
Changes
We will update this page and its "last updated" date when this policy changes.
Contact
Privacy questions and grievances: privacy@artifactsmcp.com.