Privacy Policy
Last updated24 July 2026
This policy explains what data Artifically collects, how it is used, who it is shared with, and how long it is kept. It describes what the product actually does today — not what it may do in future.
1Who we are
Artifically is currently operated by Omar Abubaker, an individual doing business as Artifically, based in the United Arab Emirates. Formal entity registration is in progress; this page will be amended upon completion. Privacy inquiries and rights requests: privacy@artifically.com.
Artifically is a marketplace for prebuilt AI automations. You buy an automation, connect the tools it needs, configure it, and it runs on your behalf. You do not build workflows; we build and operate the automations.
2What this policy covers
This policy covers the Artifically marketing site, the customer dashboard, and the automations we operate for you.
Where you connect a third-party tool, that provider's own privacy policy continues to govern the data held in their systems. This policy covers what we do with data once it reaches us.
3Data we collect
- Account and identity data — your name, email address, and organisation membership. Accounts are managed through our authentication provider, Clerk.
- Billing data — subscription and payment records. Card details are handled by our payment providers and are not stored by us.
- Automation configuration — the settings and field values you enter when configuring an automation, including any credentials you choose to supply for tools that do not use OAuth.
- Connected-tool credentials — OAuth access and refresh tokens for the tools you connect (see 'Tools you connect').
- Operational records — automation run history, usage counts against your rate-limit tier, and audit logs of significant account actions.
- Content processed by your automations — the messages, tickets, documents, records, and other content your automations read or write in the course of doing their job.
- Knowledge content — documents you upload for retrieval-based automations, which are stored together with vector embeddings generated from them.
- Voice and telephony data — where you run our phone-support automation (see 'Phone calls and recording').
4How we use it
We use your data to operate the service you bought: running your automations, authenticating you, metering usage against your rate-limit tier, billing you, providing support, investigating faults, and keeping the platform secure.
- We do not sell your data.
- We do not use your content, your uploaded documents, or your automation traffic to train our own models.
- We do not use your content for advertising.
5Tools you connect
When you connect a third-party tool, we store the OAuth access token and, where the provider issues one, the refresh token. These are what let your automation act on your behalf while you are not present.
Those tokens are encrypted at rest using AES-256-GCM. Encryption keys are managed through our application configuration and support key rotation. Tokens are never stored in plaintext, and the connector features that depend on them fail closed if the encryption key is unavailable.
We request the narrowest scopes an automation needs to function. When you disconnect a tool, the stored credentials for that connection are deleted.
You can disconnect any tool at any time from your dashboard. Disconnecting stops the automation from acting on that tool.
6Google user data and Limited Use
Some automations connect to Google services. Depending on which automation you buy and which features you enable, we may request access to Gmail, Google Calendar, and Google Drive.
We use Google user data only to provide and improve the specific automation features you have enabled — for example reading and sending mail on your instruction, reading and writing calendar events, or reading and writing files your automation is configured to work with.
Artifically's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data for advertising, and we do not allow humans to read it except with your explicit consent, where necessary for security purposes such as investigating abuse, or to comply with applicable law.
We do not use Google user data to train generalised artificial-intelligence or machine-learning models.
7Phone calls and recording
Our AI phone-support automation answers calls on a number you control. Call audio is carried by our telephony provider, Twilio.
Call recording is switched off by default. It only happens if you, as the operator of the number, turn it on.
When recording is enabled, callers are always told. You choose between two consent modes: an announcement at the start of the call, or an explicit request for the caller's agreement before recording begins. In the second mode, a caller who declines is not recorded. There is no silent-recording option, and the disclosure is spoken in the caller's language — English or Arabic.
Where a call is recorded, the audio is held by Twilio under their retention and security controls. Transcripts are processed before storage: personal data and payment-card numbers are redacted, and the remaining text is encrypted with a key specific to your organisation before it is written to our database.
Caller phone numbers are stored only as a salted hash, never in the clear.
If a caller reads out a payment-card number, the automation detects it, redacts the digits from the transcript, and pauses the recording for that portion of the call. We do not capture keypad tones.
8AI processing
Automations use large language models to interpret and generate text. Depending on the automation and the routing in effect, content may be sent to OpenAI, Anthropic, Google, Mistral, or Cohere for processing.
Before content leaves our systems for a model provider, it passes through an automated redaction step that removes recognisable personal and secret data — including email addresses, phone numbers, national identifiers, payment-card numbers, IP addresses, API keys, and passwords.
We do not keep a separate archive of model prompts and responses. Conversational content persists only where the automation itself stores it — for example a call transcript, an execution record, or an uploaded knowledge document.
Data belonging to different customers is isolated at the automation-runtime level.
9Who else processes your data
We use the following providers to run the service. Each processes only what it needs for its function.
- Authentication — Clerk
- Payments — Stripe; Coinbase Commerce for cryptocurrency payments
- AI model providers — OpenAI, Anthropic, Google, Mistral, Cohere
- Telephony, SMS, and call recording — Twilio
- Speech synthesis and transcription — ElevenLabs, Deepgram
- Email and notifications — SendGrid; Amazon Web Services (SNS)
- Hosting and infrastructure — Vercel, Amazon Web Services
- Caching — Upstash
- Error monitoring — Sentry
- Bot protection — Cloudflare (Turnstile)
- Any third-party tool you choose to connect — the provider of that tool receives and returns data as part of the automation you configured.
10How long we keep it
Our retention policy is as follows.
- Call transcripts — 90 days.
- Call records and metrics (excluding transcript text) — 13 months.
- Deleted accounts — retained for 90 days after deletion, then permanently removed.
- Automation data — removed after an automation is deactivated, following a 90-day grace period.
- Records we are required to keep for legal, tax, or accounting reasons are kept for as long as that obligation lasts.
11Your rights and choices
You may ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a use. To exercise any of these, email privacy@artifically.com. We handle these requests manually — there is no self-service privacy portal, and we will not pretend otherwise. We aim to respond within 30 days.
Deleting your account: when your account is deleted, it is first marked as deleted and removed from service, then permanently erased after 90 days. Active API keys are revoked immediately.
Callers to an Artifically-operated phone line can ask, during the call, for their data to be deleted. That request is honoured at the end of the call: the recording, transcript, and call record for that caller are permanently deleted, and the request itself is logged so it can be audited.
If you are in a jurisdiction that grants you a right to lodge a complaint with a data-protection authority, you may do so.
12How we protect it
We do not hold any security certification, and we make no certification claims on this site.
- Connected-tool credentials are encrypted at rest with AES-256-GCM, with support for key rotation.
- Call transcripts are redacted and then encrypted with a per-organisation key before storage.
- Data in transit is protected with TLS.
- API keys are stored only as hashes; the full key is shown once, at creation.
- Access to production systems is restricted, and account access supports multi-factor authentication through our authentication provider.
- Payment-card numbers spoken during a call are detected, redacted, and excluded from recordings.
13International transfers
We operate from the United Arab Emirates and our providers operate in a number of countries, including the United States and the European Union. Using the service therefore involves transferring your data across borders.
Where we transfer personal data out of a jurisdiction that restricts such transfers, we rely on the transfer mechanisms offered by the provider concerned, such as standard contractual clauses.
14Children
Artifically is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, email privacy@artifically.com and we will delete it.
15Changes to this policy
When this policy changes materially we will update the date at the top of this page and, where the change affects how we handle your data, notify account holders by email. Continuing to use the service after a change takes effect means you accept the updated policy.
16Contact
Privacy questions and rights requests: privacy@artifically.com.
Artifically is operated by Omar Abubaker, an individual doing business as Artifically, based in the United Arab Emirates. Formal entity registration is in progress; a registered address will be published on this page once registration completes.