Privacy Policy
Last updated: July 30, 2026
Table of Contents
- 1. Introduction and Scope
- 2. Privacy Summary
- 3. Information We Process
- 4. How and Why We Use Information
- 5. Optional Cloud Storage Integrations
- 6. Google API Limited Use Disclosure
- 7. Service Providers and Disclosure
- 8. Cookies, Local Storage, Analytics, and Advertising
- 9. Retention and Deletion
- 10. Security
- 11. International Data Transfers
- 12. Your Choices and Privacy Rights
- 13. Children's Privacy
- 14. Changes to This Privacy Policy
- 15. Contact Information
1. Introduction and Scope
ArtistAssistApp ("ArtistAssistApp", "we", "us", or "our") is operated by Yevhen (Eugene) Khyst, a sole trader based in Ukraine. ArtistAssistApp provides browser-based tools for artists, account and membership authentication, and an optional feature for synchronizing app data through Google Drive, Microsoft OneDrive, or Dropbox.
This Privacy Policy applies to the ArtistAssistApp website, progressive web application, authentication service, and related services. It explains what information is processed, why it is processed, where it is stored, when it is disclosed, and the choices available to you. It also specifically explains how ArtistAssistApp accesses and uses information received from Google APIs, Microsoft Graph, and the Dropbox API.
2. Privacy Summary
- Image processing and most app functions run locally on your device. Images are not sent to our servers for image processing.
- If you sign in, we process limited account and Patreon membership information needed to authenticate you and provide Premium Features.
- Cloud sync is optional. Deletion is limited to the provider-specific app folder and its remaining contents. Files moved outside that folder are not deleted. Google Drive disconnection moves the folder to Trash; server-data deletion requests permanent folder deletion.
- Synchronized files are transferred directly between your browser and your chosen cloud provider. Our servers do not receive or store their contents.
- We do not sell personal information, use cloud-storage data for advertising, use it to determine creditworthiness, or use it to train general-purpose artificial intelligence or machine-learning models.
- We do not use third-party behavioral analytics, tracking cookies, device fingerprinting, or behavioral advertising.
3. Information We Process
3.1 Data Stored Locally on Your Device
ArtistAssistApp stores app settings and user-created app data in your browser's local storage technologies, primarily IndexedDB and browser caches. Depending on the features you use, this can include selected or saved images, image metadata, custom color brands, custom color sets, saved color mixtures, preferences, authentication session data, and cloud synchronization metadata. This local data normally remains on your device unless you choose to export it or enable cloud sync.
3.2 Account, Login, and Membership Data
When you sign in or use Premium Features, we may process:
- Patreon user and membership identifiers, membership status, and related membership information needed to confirm that you have an eligible membership;
- the email address associated with your Patreon account or the email address you enter to request a one-time login code;
- a keyed, one-way representation (HMAC) of your normalized email address, rather than your plain email address, in our membership and login-code database;
- a keyed, one-way representation of the one-time login code, its expiration time, and the number of verification attempts; and
- short-lived OAuth state, login-completion data, signed session tokens, and an essential secure authentication cookie.
We do not process payment-card details. Patreon handles memberships and payments under its own terms and privacy policy. We use your plain email address to verify current Patreon membership and, when requested, to instruct our email provider to deliver a one-time login code. We do not retain the plain email address in our account database.
3.3 Cloud Connection and Authorization Data
If you connect a cloud-storage account, we process and store:
- the selected provider and a provider-issued account identifier;
- an internal ArtistAssistApp connection identifier and your account identifier;
- OAuth access and refresh tokens, token expiration information, connection timestamps, and short-lived authorization state; and
- on your device, identifiers and revision information for ArtistAssistApp's cloud folder and state file, plus the time and status of synchronization.
OAuth refresh tokens are stored, encrypted at rest, by our authentication service at auth.artistassistapp.com. They are used only to request new short-lived access tokens from the selected provider. Our authentication service does not use them to list, read, download, upload, or delete your cloud files. A short-lived access token is delivered to ArtistAssistApp in your browser so the browser can communicate directly with the provider. The browser keeps that access token in memory only and requests another token when necessary.
3.4 Cloud-Synchronized Content and Metadata
If you enable cloud sync, the synchronized data may include custom color brands, custom color sets, saved color mixtures, reference photos, and image metadata. ArtistAssistApp also accesses limited metadata about its own cloud items, such as file and folder identifiers, names, types, modification times, revisions, hashes, and deletion status. We use this information only to create, synchronize, download, verify, or delete your ArtistAssistApp data.
The synchronized content is stored in your own cloud-storage account and is transferred directly between your browser and the provider. It is not routed through or stored on our servers. For Google Drive, the app uses only files and folders it creates. For OneDrive and Dropbox, provider-enforced app-folder permissions limit access to the app folder.
3.5 Network, Operational, and Security Data
When you request a page or use an online feature, ordinary network information such as your IP address, user agent, request time, requested URL, and security-event information is necessarily transmitted to and may be processed by Cloudflare and the relevant service endpoint. We and our infrastructure providers may process limited error, abuse-prevention, rate-limit, and security logs to operate and protect the service. We do not use this information to build advertising profiles.
4. How and Why We Use Information
We process the information described above to:
- provide the app and its user-requested features;
- authenticate users and confirm Patreon membership eligibility;
- send requested one-time login codes;
- connect, maintain, refresh, and disconnect an optional cloud-storage integration;
- synchronize, download, verify, and delete ArtistAssistApp data;
- maintain security, prevent abuse, apply rate limits, and diagnose failures;
- comply with applicable law and enforce our Terms of Use; and
- maintain and improve user-facing features without using cloud-storage content for unrelated purposes.
Where applicable law requires a legal basis, we rely on performance of our agreement with you or steps taken at your request, your choice to enable an optional integration, compliance with legal obligations, and our legitimate interests in operating, securing, and improving ArtistAssistApp. You may withdraw a provider authorization at any time as described below.
5. Optional Cloud Storage Integrations
Connecting Google Drive, Microsoft OneDrive, or Dropbox is optional and requires your affirmative action through that provider's authorization screen. ArtistAssistApp uses the minimum provider permissions designed for an application-specific storage area. It uses those permissions only for the visible cross-device synchronization features you request.
5.1 Google Drive
ArtistAssistApp requests only the Google Drive https://www.googleapis.com/auth/drive.file scope. Our authentication service uses the Google Drive API to obtain an opaque Drive account identifier for the connection. We do not request Google OpenID, profile, or email scopes for the cloud connection.
Apart from obtaining this identifier, ArtistAssistApp uses drive.file only to create and manage a visible ArtistAssistApp folder and the files and folders it creates there. Reference photos are stored in ArtistAssistApp/Photos with recognizable names, standard file extensions, and their original image content, so you can open and use them outside the app. A single ArtistAssistApp Data.json file stores custom color brands, color sets, mixtures, photo references, and other synchronization state. Stable content identifiers are stored in private Google Drive appProperties, not in photo filenames.
ArtistAssistApp does not offer a Google Drive picker or an "open with" integration, does not request access to existing Drive files, and does not query or list unrelated Drive files. It can access only Google Drive files it creates. You may view, open, move, or delete those files in Drive, and you may rename reference photo files. Folder synchronization and deletion do not follow files moved outside ArtistAssistApp. Shared drives are not supported.
5.2 Microsoft OneDrive
ArtistAssistApp requests openid, offline_access, and Files.ReadWrite.AppFolder. openid is used only to obtain a stable Microsoft account identifier, and offline_access permits the connection to continue until you disconnect or revoke it. Files.ReadWrite.AppFolder limits file access to ArtistAssistApp's folder in your OneDrive Apps folder. ArtistAssistApp can create, list, read, download, update, and delete items in that app folder. If you manually add another file to that folder, the permission also permits ArtistAssistApp to access that file, and it will be deleted with the app folder during disconnection unless you move it out first. Reference photos are stored in a Photos subfolder as standard image files named <SHA-256>.<extension>.
5.3 Dropbox
ArtistAssistApp is configured for Dropbox App Folder access and requests files.content.read, files.content.write, and files.metadata.read, together with offline access. These permissions allow ArtistAssistApp to create, list, read, download, update, and delete items only within its Dropbox app folder. If you manually add another file to that app folder, ArtistAssistApp can access that file as permitted by the granted scopes, and it will be deleted during disconnection unless you move it out first. Reference photos are stored in a Photos subfolder as standard image files named <SHA-256>.<extension>.
5.4 Your Cloud-Storage Controls
Cloud-data deletion follows the provider's app-storage model:
- Google Drive: Routine synchronization manages obsolete or duplicate reference photos only while they remain inside
ArtistAssistApp/Photos. On a successful disconnection, ArtistAssistApp moves the completeArtistAssistAppfolder to Google Drive Trash. The in-app server-data deletion control instead requests permanent deletion of the folder. Permanent folder deletion also deletes all user-owned descendants still inside it, including files and subfolders the user added. Files moved outsideArtistAssistAppare not deleted. - Microsoft OneDrive: On a successful disconnection, ArtistAssistApp deletes its app folder with a single Microsoft Graph folder-deletion request. The folder and everything still inside it, including user-added files and subfolders, are moved to the OneDrive recycle bin. Items moved outside the app folder are outside the app-folder permission and are not deleted.
- Dropbox: On a successful disconnection, ArtistAssistApp deletes every immediate item inside its Dropbox App Folder. Deleting a folder recursively deletes its contents, including user-added files and subfolders. Items moved outside the App Folder are outside ArtistAssistApp's access and are not deleted. Dropbox may retain its empty, provider-managed outer App Folder.
Disconnection deletes the cloud connection record and encrypted access and refresh tokens from ArtistAssistApp's authentication database and clears the access token held in browser memory. The authentication service then has no stored credentials with which to mint new access tokens for that connection. For Google and Dropbox, it also sends the provider a request to revoke the OAuth authorization. Microsoft does not provide an endpoint that revokes only this app's refresh token, so you can additionally revoke access in your Microsoft account settings. You may also revoke ArtistAssistApp from the connected-app settings of Google, Microsoft, or Dropbox at any time.
Deleting your ArtistAssistApp server data requests the provider-specific cloud deletion described above and uses permanent deletion for the Google Drive app folder. Whether or not the Cloud Provider completes file deletion, the authentication service deletes its cloud connection record, encrypted provider tokens, and account records. Any cloud files the provider did not delete remain in your provider account and must be removed there. Provider-side retention, recovery copies, and deletion timing remain governed by the provider's own policies and are outside our direct control.
You may rename reference photo files inside the Google Drive app folder. If you move an item outside that folder or delete a previously synchronized folder or photo, it is missing from folder-based synchronization. ArtistAssistApp does not silently recreate the missing content. It pauses and asks for confirmation before republishing the data from the current device.
6. Google API Limited Use Disclosure
ArtistAssistApp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, information received from Google APIs:
- is used only to provide or improve the prominent, user-facing Google Drive synchronization, download, and deletion features;
- is not transferred to third parties except as necessary to provide those features with your consent, for security, to comply with applicable law, or as otherwise expressly permitted by Google's Limited Use requirements;
- is not sold, used for advertising, used to determine creditworthiness or lending eligibility, or used to create, train, or improve a generalized AI or machine-learning model; and
- is not read by a human except with your affirmative agreement for specific data, when necessary for security, when required by law, or when otherwise expressly permitted by Google's Limited Use requirements. In normal operation, our servers do not receive your Google Drive file content.
Google Drive data is also handled in accordance with the Google Workspace User Data and Developer Policy.
7. Service Providers and Disclosure
We disclose limited information only as needed to operate the service, at your direction, or when required by law. Relevant providers include:
- Cloudflare: hosting, content delivery, authentication-service execution, database storage, rate limiting, network security, and related infrastructure. Cloudflare may process network and operational data, account records, and encrypted provider tokens on our behalf. See the Cloudflare Privacy Policy.
- Resend: delivery of a one-time login email when you request email-code authentication. Resend receives the destination email address and email content needed for delivery. See the Resend Privacy Policy.
- Patreon: membership, payments, Patreon login, and membership verification. Patreon receives information directly from you and returns limited identity and membership information to us. See the Patreon Privacy Policy.
- Google, Microsoft, or Dropbox: if you choose a cloud integration, the selected provider processes authorization details, API requests, synchronized files, and associated metadata under its own policy. Review the Google Privacy Policy, Microsoft Privacy Statement, and Dropbox Privacy Policy.
We may disclose information when reasonably necessary to comply with law, protect users, investigate abuse or security incidents, or establish and defend legal claims. If the business is involved in a merger, acquisition, or sale of assets, information may be transferred subject to applicable law. Google user data will be transferred in such a transaction only with the explicit prior consent required by Google's Limited Use requirements.
We do not sell or rent personal information or cloud-storage data to data brokers, advertisers, or information resellers.
8. Cookies, Local Storage, Analytics, and Advertising
ArtistAssistApp uses an essential, secure cookie for authentication and uses browser storage for app data, settings, offline functionality, and session state. These technologies are necessary to provide features you request; they are not used for cross-site behavioral tracking.
We do not use third-party behavioral analytics, tracking pixels, device fingerprinting, or personalized advertising. The free experience may display contextual or first-party promotional messages selected without building a personal profile. Following an external link subjects your visit to that destination's own privacy practices.
9. Retention and Deletion
- Local app data: remains in your browser until you delete it, clear site data, uninstall in a way that clears browser storage, or replace it by importing or restoring other data.
- Login codes and OAuth state: are short-lived and are deleted or become unusable after completion or expiration. Expired database records are periodically removed.
- Membership lookup data: Patreon member identifiers and email HMACs are retained to authenticate eligible members by email. The in-app server-data deletion control deletes the records associated with your account. Because Patreon is the source of membership status, a later Patreon login, renewal, or webhook event may create these records again while your Patreon membership continues.
- Cloud connection data: is retained while your cloud account is connected. Disconnecting or deleting server data deletes our stored provider tokens and connection records. Invalid or expired pending connections are also deleted.
- Cloud-synchronized content: remains in your provider account until you delete it, the provider deletes it under its policy, or ArtistAssistApp deletes it under the provider-specific rules in Section 5.4. Those rules cover the app folder and items still inside it, not files moved outside it. Provider recovery systems may retain copies under the provider's own retention rules.
- Operational and security records: may be retained only for as long as reasonably necessary for security, abuse prevention, troubleshooting, legal compliance, and the infrastructure provider's configured retention.
10. Security
We use reasonable technical and organizational safeguards appropriate to the information we process. These include HTTPS/TLS in transit, encryption at rest for stored cloud OAuth tokens, secure and restricted authentication cookies, one-way keyed representations of email addresses and one-time codes in the database, short-lived authorization state, least-privilege cloud scopes, rate limiting, and direct browser-to-provider file transfers. Provider tokens and synchronized content are not intentionally written to application logs.
No system is completely secure. You are responsible for protecting access to your device, email, Patreon account, and connected cloud-storage account. Please contact us if you believe your ArtistAssistApp data or connection has been compromised.
11. International Data Transfers
ArtistAssistApp is operated from Ukraine and is available globally. Cloudflare, Resend, Patreon, Google, Microsoft, and Dropbox may process information in countries other than the country where you live. Those countries may have different data-protection laws. Each provider handles international transfers under its own privacy policy and applicable legal mechanisms.
12. Your Choices and Privacy Rights
Depending on your location, you may have rights to:
- request access to or a copy of personal information we hold about you;
- request correction, deletion, restriction, or portability;
- object to certain processing or withdraw consent where consent is the basis;
- disconnect or revoke a cloud-storage authorization; and
- complain to an applicable data-protection authority.
You can delete local app data through the app's storage controls or your browser settings. While signed in, you can disconnect cloud storage or use the in-app "Delete data on servers" control. The latter requests the provider-specific cloud deletion described above, using permanent deletion for the Google Drive app folder, deletes cloud connection and account records held by our authentication service, and logs you out even if provider file deletion cannot be completed. It does not cancel or delete your Patreon membership, delete your cloud provider account, delete files moved outside the app folder, or delete local data on your device.
You may also manage or revoke ArtistAssistApp in your Google, Microsoft, or Dropbox connected-app settings. Revoking access stops future API access but may not by itself delete synchronized content already stored in the provider account. Contact us to exercise a privacy right that is not available through these self-service controls. We may need to verify your request before acting on it.
13. Children's Privacy
ArtistAssistApp is not directed to children under 13, and children under 13 may not use account, membership, or cloud-storage features. If the law where you live requires a higher age for you to consent to online services or data processing, you may use those features only with the authorization of a parent or legal guardian. If you believe a child has provided personal information contrary to this section, contact us so that we can take appropriate action.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to ArtistAssistApp, provider APIs, legal requirements, or our data practices. The "Last updated" date shows when this Policy was most recently revised. If a change materially expands how we access or use cloud-provider data, we will provide appropriate notice and obtain additional authorization or consent where required before using that data for the new purpose.
15. Contact Information
ArtistAssistApp's operator and data controller is Yevhen (Eugene) Khyst, a sole trader based in Ukraine. For privacy questions, requests, or complaints, contact:
Email: View email address