Privacy
Last updated 11 September 2026
The short version
OpenArtifacts stores your published artifacts, account information, and records needed to run the service and process payments. We do not sell your data or train models on your work.
What we store when you publish
- The artifact itself: its content, its title, and each version you push, until you unshare it.
- An account identifier, so your artifacts stay yours to list and remove.
- Timestamps for when an artifact was published and last updated.
What we store when you sign in
Google or GitHub provides your verified email and a provider-specific identifier. We store these with your OpenArtifacts account ID so your artifacts follow you across machines. We also keep token hashes, device labels, creation and usage times, and revocation records. Temporary approval and account-action records support sign-in and browser handoffs. Device polling secrets and one-use account handoff codes are stored as hashes; approval codes and handshake state are retained temporarily.
Product updates
At sign-up, you can choose whether to receive product updates through our newsletter. We store that choice with your account. Unchecking the box does not affect your free account or publishing access.
What we never store
- Passwords. We never see one.
- Full payment-card details. Payment details are handled by Stripe.
- Anything in your vault that you have not published.
Linking accounts and billing
Linking a Copilot for Obsidian license requires your explicit confirmation. The license key entered in that form is checked but not saved by the OpenArtifacts linking flow. License-key publishing keeps a hash and validation cache. We retain the confirmed association between account IDs so both accounts share a document collection; matching emails alone do not link accounts.
Browser account actions use a short-lived signed cookie containing your account ID, email, linked identity and expiry. Stripe stores payment and billing records. We keep your dedicated customer ID and the frozen request needed to recover an unfinished checkout. Publishing access is read from current provider and linked Copilot for Obsidian license state; we do not maintain a separate purchase ledger.
Reading an artifact
Reading needs no account. OpenArtifacts does not set account cookies on the document-serving domain. Published HTML may include its own scripts, external resources or cookies. Pages ask search engines not to index them.
This website
We use PostHog for website page views and explicit command-copy actions. Automatic event capture and session recording are off; anonymous visits do not create person profiles. Account-action pages are excluded from website analytics. Cloudflare serves requests and keeps operational logs.
Removing things
Unsharing withdraws the link and starts removal of its stored files. A permanent database tombstone keeps that link marked as withdrawn. Copies readers saved or cached cannot be recalled. Contact us to request account deletion. We may retain billing records required for bookkeeping and legal obligations, and records needed to prevent withdrawn links from being restored.
Self-hosting
OpenArtifacts is open source. Run your own and this policy does not apply to it, because we never hold the data.
Contact
Questions about any of this go to logan@brevilabs.com.