Who I am
ArtDeck is made by me, Alexandre Alves, an independent developer based in France. This policy covers the ArtDeck app for iPhone, iPad, and Mac, and the websites at getartdeck.com and docs.getartdeck.com.
For personal data handled by ArtDeck, I am the data controller. Some user-requested features also involve third-party services, such as Apple iCloud or websites you ask ArtDeck to contact for previews; those services handle data under their own privacy policies.
For privacy questions, email privacy@getartdeck.com. For support or bug reports, email support@getartdeck.com. For board-library suggestions, email boards@getartdeck.com.
ArtDeck app
ArtDeck is designed so your reference boards stay with you. The app has no ArtDeck account system, no ads, no tracking, and no third-party advertising SDKs.
No account, ads, or tracking
You can use ArtDeck without creating an ArtDeck account or signing in to a developer-operated service. ArtDeck does not operate a backend that stores your boards, and it does not use your app activity for advertising or tracking.
Local app data
Your boards and the content you add to them are stored locally on your device unless you choose to sync, export, or share them. Board content can include images, GIFs, videos, PDFs, links, text, drawings, notes, and other files you choose to add.
ArtDeck does not receive a copy of your local boards on an ArtDeck server.
Optional iCloud sync
If you enable iCloud sync, board data and assets sync through your iCloud
using Apple iCloud and CloudKit services, including the container
iCloud.com.getartdeck.ArtDeck. ArtDeck does not operate a
separate sync server.
Apple provides and controls iCloud. You can manage or delete iCloud app data through your Apple device and iCloud settings.
Photos, Files, Camera, and imports
ArtDeck may ask for access to Photos, Files, Camera, scanning/import tools, or Continuity Camera only when you choose a workflow that needs that access. For example, you may choose to import a file, pick an image, scan a document, capture a photo, or save/export content.
If you do not grant a permission, the related workflow may not work, but the rest of the app remains available.
URL previews and remote media imports
When you add or share a URL into ArtDeck, the app may contact the linked website to fetch preview information such as the page title, metadata, preview image, favicon, or similar details. For supported video links, ArtDeck may contact the provider needed to create the preview.
When you share a remote image, video, or link into ArtDeck, the share extension may follow redirects, check the content type, and download the media you selected so it can be added to your board.
These requests are started by you and are needed to create previews or import the content you chose. The contacted website or provider may receive normal network information such as your IP address, user agent, and the requested URL. Their own privacy policies apply.
Optional feedback emails
Feedback and support emails are optional. If you choose to send one, the generated email may include app version and build, operating system, device information, locale, and accessibility display settings such as Dynamic Type or Bold Text where applicable. It also includes whatever you write or attach.
Diagnostics and system APIs
ArtDeck may keep MetricKit or performance diagnostics locally in the app for operational diagnostics. These local diagnostics are not uploaded to an ArtDeck server.
The app uses certain system APIs for app functionality, such as file timestamps, disk space, preferences, and elapsed timing. These APIs are not used for tracking.
Websites
The websites at getartdeck.com and docs.getartdeck.com are separate from the app. Both use a small amount of data for website analytics. The main website also uses data for roadmap voting and optional board-library suggestions.
Website analytics
I use self-hosted Umami, opens in a new tab analytics to understand which pages are visited and to find loading or interaction problems on the main website and documentation website. Umami collects the page path and title, referrer, device type, browser, operating system, screen size, language, and country derived from IP address. Query strings and URL fragments are excluded. IP addresses are not stored.
On the main website, performance measurements include Core Web Vitals and related timing breakdowns, a short technical description of the page element involved, a coarse phone, tablet, or desktop category, and, when the browser provides them, effective connection type and the Save-Data setting. The website also measures when the visible hero images finish loading. These measurements do not include text you enter or the contents of your boards.
Umami also records a small number of named interactions, such as a click on an App Store download button, together with the page and button location. Analytics records are not intended to identify you and are not connected to an ArtDeck account or app activity.
Umami does not use cookies and does not track you across websites. Each website uses a separate analytics identifier, respects your browser's Do Not Track setting, and hosts its analytics data in Germany.
Analytics preference. You can stop analytics from loading on future page views at getartdeck.com. The choice is stored only for this website in this browser. It does not apply to docs.getartdeck.com, which is a separate website. A page view recorded before you change the setting is not linked to an identifier that this button can retrieve or delete.
Embedded videos
The press page embeds a product demo hosted by Vimeo, opens in a new tab. The embedded player uses Vimeo's Do Not Track setting, which prevents Vimeo from collecting player session data and analytics for that embed. Loading or playing the video still connects your browser to Vimeo and may use essential security cookies. Vimeo receives normal network information such as your IP address, browser details, and the requested video.
Some articles reference a video hosted by YouTube, opens in a new tab. Those articles load only the video's thumbnail image from YouTube until you press play. Pressing play loads the player from YouTube's no-cookie host, which does not set advertising or viewing-history cookies for that embed. Either request connects your browser to YouTube, which receives normal network information such as your IP address, browser details, and the requested video.
Roadmap voting
The roadmap lets visitors vote on possible future features. When you use voting, the website creates a random pseudonymous identifier and keeps the features you selected in your browser local storage. Your browser sends the identifier and selected feature to the vote API. Before database storage, the server combines both values with a secret key to create a one-way, feature-specific code. The database stores that code and the feature, not the browser identifier itself. This local storage and server-side code are used only to provide voting, prevent duplicate votes, and let you remove a vote later; they are not used to track you across sites.
Neither the browser identifier nor its feature-specific code is tied to an ArtDeck account, name, or email address. The vote API processes your IP address and the feature-specific code in short-lived server memory for rate limiting, but neither is written to application logs. The IP address is not written to the vote database.
Board-library suggestions
The board suggestion form lets you propose a resource or collection, or report a broken link, credit, or rights issue. If you use it, the website processes the contribution type, board or idea, the links and explanation you provide, your email address if you choose to include it, and optional relationship or rights notes.
The website uses your IP address only in short-lived server memory to rate-limit submissions. It does not write the IP address or the submission to the website database. The submitted information is sent as an email through Mailjet to the ArtDeck board inbox and is used only to review the suggestion and, when you provide an email address, follow up when needed. It is not used to add you to a newsletter or marketing list.
Legal bases
When GDPR applies, ArtDeck relies on a small set of legal bases for the processing described in this policy:
- Your consent: optional app permissions where your device asks you to grant access.
- Providing the feature you request: imports, exports, URL previews, remote media imports, optional iCloud sync, support replies, and board-suggestion review.
- Legitimate interests: privacy-friendly website analytics, delivery of embedded videos, roadmap voting and duplicate-vote prevention, rate limiting, security, local diagnostics, and support or board-suggestion history. These uses are kept limited and do not override your privacy rights.
Data sharing and third parties
ArtDeck does not sell personal data. Service providers that process personal data for ArtDeck are used only for the purposes described in this policy, and I rely on their applicable privacy, security, and data processing commitments for the service they provide.
Outside websites and video providers are different: they are contacted only when you ask ArtDeck to create a URL preview or import remote media, and their own privacy policies apply to those network requests.
- Apple/iCloud: used for optional iCloud sync when you enable it, and for Apple platform services such as App Store purchases.
- Websites and video providers: contacted only when you ask ArtDeck to create a URL preview or import remote media.
- Umami and website infrastructure providers: used for privacy-friendly analytics, hosting, databases, and roadmap voting as described above.
- Vimeo: hosts the product demo embedded on the press page, using Vimeo's Do Not Track player setting as described above.
- YouTube: hosts a video referenced in an article, loaded only when you press play and served from YouTube's no-cookie host as described above.
- Email providers: used when you choose to send support, bug report, feedback, privacy, or board-suggestion emails. Website board suggestions are delivered through Mailjet, opens in a new tab.
Retention and deletion
- Local board data: controlled by you. You can delete boards, remove content, delete the app, or manage device storage through your device settings.
- iCloud data: controlled through the app, your device, and iCloud settings. Deleting local data may not delete every synced or backed-up copy unless you also manage the corresponding iCloud data.
- Website analytics: kept for no longer than 24 months. Analytics records older than 24 months are deleted on a recurring schedule.
- Support, feedback, and board-suggestion emails: kept only as long as needed to answer your request, evaluate the suggestion, and keep a reasonable correspondence history, or longer if required for legal, safety, or security reasons.
- Roadmap votes: kept for no longer than 24 months. When a roadmap candidate is shipped, rejected, or removed, its votes are deleted within 90 days. You can remove a vote directly from the roadmap while the browser still has its pseudonymous voting identifier; this deletes the matching vote from the website database and updates the local selection. Clearing browser local storage removes the local identifier and selections, but by itself does not delete votes already submitted to the database. You can also request deletion by email, but I can only locate a specific vote if you provide both its feature and the browser voting identifier before it is cleared; the stored feature-specific code cannot be reversed to recover that identifier.
Your rights
If you are in the European Union or another region with similar privacy rights, you may have the right to access, correct, delete, restrict, or receive a copy of your personal data, object to certain processing, and withdraw consent where processing is based on consent.
To exercise your rights, email privacy@getartdeck.com. I will respond within 30 days where required by law.
You also have the right to lodge a complaint with your local data protection authority. In France, this is the CNIL, opens in a new tab.
Changes to this policy
I may update this policy as ArtDeck changes. When I do, I will update the date at the top of this page. If a change materially affects how I handle personal data, I will provide additional notice where appropriate.