Privacy and data processing


This page says what AI on Artur.Work does with your data, in the order that matters: what we hold, who we send it to, how long we keep it, and what you can make us do about it.

Who is responsible

The controller is the one-person business that operates https://ai.artur.work. Write to [email protected] about anything on this page, including a request to see, correct or delete your data.

What we hold, and why

  • Your account - e-mail address, name, optional picture, interface language, and the identifier of any social login you connect. Needed to give you an account at all.
  • What you send and get back - prompts, uploads, generated images, audio and text. Needed to do the work you asked for and to show it back to you.
  • Usage and billing - which model ran, when, what it cost, your balance and its history, and your country and VAT ID if you gave one. Needed to charge correctly and to keep the books.
  • Card details - only the brand, the last four digits, the issuing country and the result of the check. The card number never reaches us; it goes straight to our payment provider.
  • Technical records - IP address, browser, and server logs of requests. Needed to keep the service standing up and to spot abuse.

The legal grounds are: performing our contract with you (your account, your generations, your payments), our legitimate interest (preventing abuse, keeping our records, answering refund questions), a legal obligation (invoices and tax records), and your consent where you opt into something, such as connecting a chat bot.

Where your requests go

When you run a model, the request is sent to the provider that serves it. The provider receives what the request contains - your prompt and any file you attached - and not your name, e-mail or account identity. Which provider will serve a request is shown before you send it.

The providers currently reachable from here are: Anthropic, BlackForestLabs, GoApi, Google, Ideogram, Luma, Mesh, NanoBananaApi, OpenAi, OpenRouter, Recraft, Runware, Runway, XAi.

What each provider’s terms say about training on what it receives, as we last read them. Where a provider lets us ask per request, we ask on every request unless you untick “Ask not to train” for it on your profile.

ProviderTrainingTerms
Anthropic Does not train on API data Reviewed 2026-09-27
BlackForestLabs Trains, no opt-out Reviewed 2026-09-27
GoApi Not yet reviewed
Google Does not train on API data Reviewed 2026-09-27
Ideogram Does not train on API data Reviewed 2026-09-27
Luma Not yet reviewed
Community computers (Mesh) Community computers: cannot be enforced; use trusted rigs
NanoBananaApi Not yet reviewed
OpenAi Does not train on API data Reviewed 2026-09-27
OpenRouter Trains unless asked not to Reviewed 2026-09-27
Recraft Does not train on API data Reviewed 2026-09-27
Runware Not yet reviewed
Runway Does not train on API data Reviewed 2026-09-27
XAi Does not train on API data Reviewed 2026-09-27

Each provider has its own terms and its own privacy policy, and some of them are outside the European Union. We rely on the data-protection terms in each provider agreement for those transfers. If that matters to you, restrict your account to providers that do not train on user input, in your profile settings, and check the provider before you send.

Decisions (/v1/decisions) are answered by TypeSafe's Jev model, which we reach through OpenRouter: both receive the text and questions of the request, nothing else. We ask OpenRouter to route only to endpoints that do not keep or train on what they receive (data_collection: deny). We do that unless you untick “Ask not to train” for OpenRouter on your profile. When you leave the model on Auto, the words of your request also go to Jev the same way, to tell what kind of work it is - never your files, only measurements taken from them, such as text found in an image. Those calls always ask not to keep or train, and are not made at all when your settings exclude OpenRouter.

If you send work to the peer network, it runs on another user's computer. That person's machine receives the prompt and produces the result. Turn the network off in your profile settings if you would rather not.

Where generated files live

Generated and uploaded media is stored on our content network and served from an address derived from the contents of the file. Such an address cannot be guessed, but it is not protected by a login: anyone you give the link to can open the file, and so can anyone they pass it on to, until the file is deleted.

Who else touches it

  • Hetzner Online GmbH - servers and file storage, in Germany and Finland.
  • Stripe - card payments. They receive your card details and your billing country directly.
  • Our mail provider - the e-mails the service sends you.
  • Telegram and Slack - only if you connect one of them, and only for the messages you exchange with the bot.

We do not sell your data, we do not share it for advertising, and we do not use it to train models.

Cookies

Two cookies: one that keeps you signed in for the session, and one that remembers you if you asked to stay signed in. There is no advertising or analytics tracking on this site.

How long we keep it

You choose how long your messages and images are kept, including keeping nothing at all. The full table, and what stays behind whatever you choose, is on What we keep, and for how long.

What you can ask for

  • A copy of everything. Your profile has a button that builds one archive with your account, your payments, your history and every file you own.
  • Deletion. Also a button on your profile; it runs automatically. See Deleting your account for exactly what goes and what stays.
  • Correction of anything wrong, and objection to processing we do on the grounds of legitimate interest.
  • A complaint to a data protection authority - in Slovakia, the Office for Personal Data Protection - if you think we have it wrong.

Changes

This page changes when the service does. Changes are published here rather than e-mailed, so that using the service does not mean agreeing to receive mail you did not ask for.


Last updated: 2026-09-23. The English version of this page is the one that governs. The other languages are translations offered for convenience; where they differ, the English text applies. Questions about this page: [email protected].