Privacy Policy
What we store
Your account email and a salted bcrypt hash of your password (never the password itself); your workspace's catalogue — photographs, inspection notes, comparable sales, value conclusions, and reports; and standard server logs (request method, path, status, timing, IP address) kept for operations and security. Workspaces are isolated: photographs and records are served only to signed-in members of the workspace they belong to, and appraisal records routinely concern clients' property — they are treated as confidential client data, not ours to browse.
What leaves the server, and to whom
Only what each feature needs:
- Anthropic (Claude API) — the photographs and notes you submit for cataloging, pasted comp text for structuring, and the catalogue fields + comps of a piece when you generate a value conclusion. Sent only when you click the corresponding action.
- Art Market API — the search terms of a comp search (artist, medium, size, price window). Your photographs and client data are never sent there. Records you attach to a piece become part of that piece's evidence and are included in the drafting prompt above, like any comp you typed in yourself; search results you don't attach go nowhere.
- frankfurter.dev (ECB rates) — currency pairs and dates only, never amounts or any catalogue data.
- Resend (only if the deployment configures email) — recipient address and the content of password-reset or invite emails.
That list is exhaustive. Your data is never sold, never used for advertising, and never shared beyond the processors above.
Cookies
One signed session cookie to keep you logged in (30 days). No analytics or tracking cookies.
Export and deletion
Export your full workspace (JSON/CSV) from the workspace page at any time. To delete an account or workspace, contact the operator of this deployment; deletion removes the workspace's records and photographs from the live database.
Contact
Privacy questions go to the operator of this deployment.