Arteriya — Privacy Policy
Effective date: 1 August 2026 Version: 3.0 Supersedes: section 10 (Privacy notice), section 11 (Cookies and local storage) and section 12 (Artificial intelligence) of the Arteriya User Agreement v2.0, and all previously published Privacy Policy and Cookie Policy documents.
This Policy explains what personal data we process, why, on what legal basis, who else sees it, and what you can do about it. It is the complete privacy notice for Arteriya.
It sits alongside the Terms of Service, which governs your use of the service, and the Operator details page, which carries the statutory identification of the operator. Together those three documents replace the single User Agreement published on 27 July 2026.
Table of contents
- Who we are, and who is responsible
- What we collect
- Why we process it, and on what basis
- Automated decisions
- Face data — read this section
- Image metadata, and why GPS matters
- Emergency contacts
- Who else sees your data
- Your rights
- Transfers outside Ukraine
- Artificial intelligence and your data
- The provenance ledger
- Cookies and local storage
- How long we keep things
- Security
- Changes to this Policy
- How to contact us
1. Who we are, and who is responsible
Arteriya is a professional network for creative practitioners — photographers, models, make-up artists, stylists, retouchers, creative directors and others who work together on creative projects. The service is operated by a private entrepreneur registered in Ukraine.
The controller of personal data is that operator, contactable at privacy@arteriya.pro and at the registered address given on the Operator details page. The person responsible for personal data protection under Article 24(2) of the Law of Ukraine "On Personal Data Protection" is the operator personally.
In this Policy, "we", "us" and "our" mean that operator. "You" and "your" mean you — whether you hold an Arteriya account or simply appear in a photograph someone else uploaded.
2. What we collect
You give us:
| Data | Notes |
|---|---|
| Email address, authentication credentials | via Firebase Authentication |
| Display name, nickname, username | |
| Legal name, citizenship | optional; used for verification and credits |
| City and country | |
| Profile: biography, avatar, primary role, social links, website | |
| Working areas | geographic coordinates and radius that you place on a map |
| Emergency contact: name, telephone, relationship | a third party's data — see section 7 |
| Photographs and the metadata inside them | see section 6 |
| Projects, participations, credits, applications, messages | |
| Rate cards and availability |
We generate or observe:
| Data | Notes |
|---|---|
| IP address and browser user-agent | on provenance verification requests (section 12), and transiently for rate limiting |
| Image analysis | colour, tonal, sharpness and composition metrics |
| Numerical embeddings of your images | for search, style matching and recommendations |
| Captions and tags | machine-generated descriptions of your images |
| Adult-content scores | per image |
| Face data | see section 5 |
| Creative fingerprint | a machine-written description of your style |
| Server logs | correlation identifiers, request paths, timings — retained 7 days |
We do not collect your date of birth other than as required to confirm you are 18, do not collect your telephone number, and do not operate any behavioural analytics or advertising tracking.
3. Why we process it, and on what basis
| Purpose | Basis (Ukraine) | Basis (GDPR, where applicable) |
|---|---|---|
| Creating and running your account; delivering the service | performance of the contract | Art. 6(1)(b) |
| Storing and displaying your portfolio; generating derivatives | performance of the contract | Art. 6(1)(b) |
| Projects, participations, credits, casting | performance of the contract | Art. 6(1)(b) |
| Search, discovery ranking, style matching, recommendations | legitimate interest in a functioning service | Art. 6(1)(f) |
| Automatic captioning and tagging | legitimate interest | Art. 6(1)(f) |
| Content moderation and adult-content classification | legitimate interest in a lawful, safe service | Art. 6(1)(f) |
| Face detection and recognition data | consent, and legitimate interest | see section 5 |
| Security, abuse prevention, rate limiting | legitimate interest | Art. 6(1)(f) |
| Provenance verification and the theft ledger | legitimate interest in evidencing image theft | Art. 6(1)(f) |
| Safety check-ins and escalation | performance of the contract | Art. 6(1)(b) / (f) |
| Transactional email | performance of the contract | Art. 6(1)(b) |
| Retaining removed content as evidence | legitimate interest; legal claims | Art. 6(1)(f); Art. 9(2)(f) |
Where we rely on legitimate interests, you may object at any time — write to us and we will stop unless we have compelling grounds that override your interests.
4. Automated decisions
Adult-content classification is automated and can cause an image to be blurred or withheld from public surfaces before any person has looked at it. Permanent removal and account termination are decided by a human being, with a recorded justification (section 7.1 of the Terms of Service).
If an automated decision affects you, you may ask for human review under the appeals procedure in section 7.4 of the Terms of Service.
5. Face data — read this section
When you upload a photograph, our systems detect faces in it and compute, for each detected face:
- a bounding box and five facial landmark points, used to crop images intelligently so faces are not cut off in grid layouts;
- a 512-dimensional numerical face template, produced by a face-recognition model (ArcFace). A template of this kind is capable of determining whether two photographs show the same person;
- an estimated age and gender;
- a cropped image of the face, stored in our object storage.
These records are stored in our database and indexed for similarity search. They are deleted when the underlying image is deleted.
We want to be direct about three things.
First, this data is generated for everyone depicted in an uploaded photograph — not only account holders. If you are a model photographed by an Arteriya user, face data about you may exist on our systems even though you have never used the service and never agreed to anything. You can require its deletion under section 9 of this Policy and section 5.3 of the Terms of Service, and we will comply.
Second, a face template is biometric data. Under Ukrainian law it is sensitive personal data. Under the GDPR, biometric data processed to identify a person uniquely is special-category data under Article 9, for which the ordinary legal bases are not sufficient.
Third, we do not use this data to identify anyone, to build a searchable index of people, or to match faces across accounts, and we do not disclose it to anyone. Its operational use today is limited to layout cropping, which requires only the bounding box.
If you do not want face data generated from images you appear in, contact us and we will delete it and exclude you.
6. Image metadata, and why GPS matters
Digital photographs carry embedded metadata (EXIF): camera and lens, exposure settings, timestamps and — often — the GPS coordinates of where the photograph was taken.
What we do with it:
- The original file you upload is stored unchanged, with all its metadata intact, in our private storage. It is never served publicly.
- We extract camera settings and, where present, GPS coordinates into our database, and show them to you on your own image's analytics page. Only you can see them. They are not returned by any public endpoint and not shown to other users.
- The display versions we generate and serve — every size shown anywhere on the service — contain no EXIF metadata and no GPS coordinates. Anyone downloading an image from Arteriya gets no location data from it.
⚠️ You should still be careful. Ukraine is at war, and metadata you never look at can reveal where you were standing. Before uploading, consider stripping GPS from photographs taken near military, infrastructure or defence-industry locations — and read section 6.3 of the Terms of Service on Article 114-2 of the Criminal Code. We provide a means to remove this metadata; you are responsible for what your files contain.
7. Emergency contacts
If you use the safety features you may give us the name and telephone number of an emergency contact. That person's data is personal data about them, not about you.
You warrant that you have their permission and have told them why you provided their details.
In accordance with Article 12(2) of the Law of Ukraine "On Personal Data Protection", we will notify that person that we hold their details, why, and how to have them removed. They can require deletion at any time by writing to us, and we will comply without affecting your account.
We use these details only to try to reach that person if you miss a safety check-in. We never use them for marketing.
8. Who else sees your data
We do not sell, rent or trade your personal data. We do not share it with anyone for their own purposes, for marketing or for advertising. We run no advertising on Arteriya and no third-party tracking.
We do use service providers who process data strictly on our instructions, under contract:
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase | authentication | United States |
| Neon | primary database | United States |
| Oracle Cloud Infrastructure | image and file storage | European Union (Frankfurt) |
| Redis Cloud | caching, rate limiting | European Union |
| Neo4j Aura | collaboration graph | [region to be confirmed] |
| Resend | transactional email delivery | United States |
| Self-hosted infrastructure | messaging, image processing, monitoring | operated by us |
Our machine-learning models — image analysis, embeddings, captioning, tagging, adult-content classification, face processing and creative fingerprints — run on infrastructure we control, on model weights we hold. Your photographs are not sent to any third-party artificial-intelligence provider.
We will also disclose data where we are legally required to, or where it is necessary to protect someone's life or safety, or to establish or defend legal claims.
9. Your rights
Under Article 8 of the Law of Ukraine "On Personal Data Protection" you have the right to:
- know who holds your data, where it is, and for what purpose;
- know to whom it has been disclosed;
- access your data — we respond within 30 calendar days;
- have inaccurate data corrected;
- have your data deleted;
- object to processing, and to restrict it;
- protection against decisions taken solely by automated means;
- complain to the Verkhovna Rada of Ukraine Commissioner for Human Rights, or to a court.
If the GDPR applies to processing about you, you additionally have the rights of access, rectification, erasure, restriction, portability and objection under Articles 15–22, and the right to complain to a supervisory authority.
These rights belong to anyone whose data we hold — including people depicted in photographs who have never used Arteriya.
Two related routes are set out in the Terms of Service and are available to you whether or not you hold an account:
- Removal of an image you appear in — section 5.3 of the Terms of Service. We remove it without requiring you to prove the absence of consent.
- Account deletion and data export — section 12 of the Terms of Service, which also lists what necessarily survives deletion and why.
To exercise any of them, write to privacy@arteriya.pro.
10. Transfers outside Ukraine
Our service providers are located outside Ukraine, principally in the European Union and the United States. Transfers are made under Article 29 of the Law of Ukraine "On Personal Data Protection" — to states providing adequate protection of personal data — and, where required, on the basis of your consent to the transfer, which you give when you accept the Terms of Service.
Where the GDPR applies, transfers to the United States rely on the EU–US Data Privacy Framework where the recipient is certified, and otherwise on Standard Contractual Clauses. You may request a copy of the safeguards in place.
11. Artificial intelligence and your data
We use machine learning extensively. Here is exactly what runs and what it does.
11.1 What the systems do
| System | What it does |
|---|---|
| Image analysis | measures colour, tone, sharpness, composition; extracts EXIF |
| Style embeddings | a numerical representation of visual style, for similarity matching |
| Search embeddings | a numerical representation of content, for semantic search |
| Captioning | writes short descriptions of images |
| Tagging | assigns taxonomy tags |
| Adult-content classification | scores images for adult content and flags them for review |
| Face processing | detection, landmarks, recognition templates, age and gender estimates (section 5) |
| Creative fingerprint | writes a short description of your creative style from your portfolio |
11.2 AI-generated text
Descriptions, captions, tags and creative fingerprints are generated by machines and may be inaccurate. Where such text is shown, it is labelled. You can edit or override tags on your own images.
11.3 We do not train generative AI on your work
Your content is never used to train generative image or text models — ours or anyone else's. We do not license your work to third parties for AI training. Your photographs are not transmitted to any third-party AI provider; every model we run operates on infrastructure we control.
We do use your content, and signals derived from it, to operate and improve the systems in section 11.1 — search, matching, tagging and moderation. These are classification and retrieval systems; they do not generate images and cannot reproduce your work.
You may object to this use under section 3.
The invisible watermark embedded in display versions of your images is described in section 13 of the Terms of Service; the data recorded when someone uses the resulting verification tool is described in section 12 below.
12. The provenance ledger
Arteriya embeds an invisible watermark into the display versions of uploaded images (see section 13 of the Terms of Service), and offers a public tool at /verify that checks whether a given image originated on Arteriya.
When someone submits an image to that tool, the image itself is never stored — it is decoded in memory and discarded.
If the check produces a positive match, we record the match together with the submitter's IP address and browser user-agent, so that patterns of image theft can be evidenced and the endpoint protected from abuse. Where no match is found, nothing is recorded. This is explained on the page before submission. These records are retained for 12 months.
13. Cookies and local storage
We use the minimum necessary. We run no analytics cookies, no advertising cookies, and no third-party tracking of any kind.
| Name | Type | Purpose | Duration |
|---|---|---|---|
artplatform_session | cookie | tells the app you are signed in, so pages route correctly | session |
artplatform_admin | cookie | routes administrators to the admin interface | session |
locale | cookie | remembers whether you chose English or Ukrainian | 1 year |
firebase:authUser:… | local storage | your sign-in token, so you stay signed in | until sign-out |
| Firebase internal keys | local storage / IndexedDB | authentication library internals | managed by the library |
All of these are strictly necessary to provide a service you have asked for, so we do not ask for consent to them. You can clear them in your browser, but you will be signed out and some preferences will reset.
If we ever introduce analytics or advertising, we will ask for your consent first, through a banner that lets you refuse as easily as accept, and we will update this section before doing so.
14. How long we keep things
| Data | Retention |
|---|---|
| Account and profile data | while your account is open |
| Your content | until you delete it, then up to 90 days in caches and backups |
| Face data | deleted with the image it came from |
| Server logs | 7 days |
| Provenance ledger records | 12 months |
| Removed content and moderation records | 12 months, as evidence and to allow appeals |
| Derived signals from removed content (scores, embeddings, labels — no images) | up to 3 years, to improve moderation accuracy |
| Suspected child sexual abuse material | handled solely under the process in section 6.3 of the Terms of Service; never retained for any other purpose and never used to develop our systems |
| Acceptance records for the Terms of Service and this Policy | for the limitation period |
| Records required by tax law | as required by Ukrainian law |
15. Security
We use encrypted connections, private storage buckets, access controls and structured audit logging. No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will tell you.
16. Changes to this Policy
We may update this Policy. When we do, we change the version number and the effective date at the top.
- For minor changes — clarifications, corrections, new provider names — we publish the new version and note the change.
- For material changes — anything affecting how we use your data — we notify you and ask you to accept the new version.
Every published version is archived. Ask us for any past version.
Language. This Policy is published in Ukrainian and in English. The Ukrainian version is the authoritative text; the English version is a translation provided for convenience. Where the two differ in meaning, the Ukrainian version prevails. Both versions are published at the same address and carry the same version number and effective date.
17. How to contact us
| For | Contact |
|---|---|
| Data protection, access, deletion, objection | privacy@arteriya.pro |
| Removal of an image you appear in | privacy@arteriya.pro |
| Anything else, and general enquiries | support@arteriya.pro |
| Legal notices and disputes | legal@arteriya.pro |
Operator name, postal address and telephone: see the Operator details page.
You may also complain to the Verkhovna Rada of Ukraine Commissioner for Human Rights, 01008, Kyiv, vul. Instytutska 21/8, about how we handle personal data.
Thank you for reading this. We have tried to write it in plain language rather than legal boilerplate, because a policy nobody can read protects nobody.