Security & data handling

Where your data lives and who can touch it.

Written in plain language for owners and office managers, not auditors. If you need something more formal for a customer's vendor review, email us and we'll fill in your questionnaire.

Last reviewed September 16, 2026

Hosting

Artificl apps run on Google Cloud in the United States (us-central1). Databases, file storage and backups are Google Cloud services and inherit Google's physical and network security. Data is encrypted in transit (TLS) and at rest (Google-managed encryption).

Who can see your records

  • Your people. Users you add to your company. Sign-in is with Google, or with an email and password we issue during onboarding.
  • Your AI assistant, if you connect one, within the limits below.
  • The founder, only when needed to run the service for you — an import you asked for, a support question, a bug — or when required by law.

Each company's data is stored under its own organization identifier and every read is checked against it. Two customers on the same app cannot see each other's records.

What an AI connection can and cannot do

CapabilityDefaultNotes
Look up records, deadlines and historyAllowedLimited to the named tools for that one app
Generate reports and CSV exportsAllowedExports are logged like any other action
Create, edit or delete recordsOffA company owner can enable writes in Settings; the change is logged
Send emails on your behalfOffRenewal requests are sent by the app on the schedule you choose, not by the assistant
Reach anything outside the appNeverThe connection exposes one app's tools and nothing else on your account

Connections use OAuth 2.1, so you never paste a password into an assistant. Where a tool can't do OAuth we issue an API key, and we store only a one-way hash of it. Every call — from a person or an assistant — is written to your company's activity log with a timestamp and, for assistants, the question that was asked.

What we don't do with your data

  • We don't sell or rent it.
  • We don't run advertising or share data with advertisers.
  • We don't use your records to train AI models, ours or anyone else's.
  • If you connect an outside AI assistant, that provider's terms govern what they do with the questions you ask it. Business and API tiers of the major assistants don't train on your data by default; check your own plan.

Sub-processors

ProviderPurposeLocation
Google CloudHosting, databases, file storage, sign-inUnited States
Microsoft 365Outbound email (reminders, support)United States
StripePayments and invoices — we never see your full card numberUnited States

Backups, export and deletion

Records are stored on Google Cloud managed database services with built-in redundancy. You can export all of your records as CSV at any time from the app, before or after cancelling. If you ask us to delete your data, we do so within 30 days, keeping only what tax or other law requires us to retain.

If something goes wrong

If we learn of a security incident that affects your data, we will tell you without undue delay, explain what we know, and say what we're doing about it. Security concerns go to support@artificl.us and are read by the founder.

What we don't claim

Artificl is not HIPAA compliant and does not sign business associate agreements. CredCycle and DEAWatch track provider credentials and registrations, not patient information; please don't upload protected health information to any Artificl app. We are a small company and do not currently hold a SOC 2 report; this page and the privacy policy are the honest substitute.