Artora · Your trust matters
Privacy Policy
Last updated October 4, 2026
Clear information about your account, your creative workspace, and your choices.
1. Who we are
Artora operates Artora, a creative workspace for Roblox thumbnails and icons. This policy explains how we handle information when you visit the website, create an account, or contact us. Questions and privacy requests can be sent to artorathumbs@gmail.com.
Artora currently offers a demo generator with sample artwork. AI generation and paid checkout are not active. We will update this policy and provide any required notices or consent before introducing new uses of personal information.
2. Account and Google sign-in information
For email signup, we process your email address, display name, password through our authentication provider, verification status, and account identifier. Passwords are handled by Supabase Auth; Artora does not store plaintext passwords in its profiles table.
If you choose Google sign-in, we receive your Google account identifier, email address, name, and profile picture when provided. We use this information to authenticate you, maintain your account, and show your profile. We request only openid, email, and profile permissions. We do not request access to your Gmail messages, contacts, or Google Drive files.
Google account information is processed through Supabase for authentication and account storage. We do not sell it, use it for advertising, or use it to train AI models. Artora’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
3. Prompts, references, and demo history
In the current demo, prompts, generation settings, sample result history, demo credit balances, and reference filenames are stored in your browser’s local storage, separated by account ID. These workspace records are not synced to a hosted workspace database or sent to an AI service.
When you choose to reuse a prompt from history, the prompt and settings are included in the generator page’s URL. That URL is sent to the website host when the page loads and may appear in request logs, browser history, or links you copy and share. Avoid putting sensitive information in prompts or sharing these links unintentionally.
Reference images you select or drag into the generator are previewed locally in your browser. Their image contents are not uploaded by the current generator. Reference previews are removed when you remove them or leave the page. Do not include confidential or sensitive information in prompts or reference files.
4. Cookies, technical records, and support
We use authentication cookies to keep you signed in and refresh your session. Browser local storage also saves your theme preference and demo workspace. You can remove this storage through your browser settings; doing so may sign you out or erase local history. Account → Reset demo workspace clears the saved demo workspace for the current account without deleting your authentication account.
Our hosting and authentication providers may record IP addresses, browser information, request timestamps, request paths, and errors for operation, security, and troubleshooting. Artora does not currently add advertising trackers or third-party marketing analytics.
If you email support, we receive your email address and the information you choose to include. We use it to respond to your request and resolve problems. Do not send passwords or sign-in tokens.
6. Retention and security
Account information is retained while your account is maintained. You can request account deletion by emailing us. We may need to verify that you control the account before acting. Some information may remain in provider backups or security records according to their retention practices, or where needed to comply with legal obligations or resolve disputes.
Local demo history stays in your browser until you clear it, reset the demo workspace, or your browser removes it. Logging out does not automatically erase that local history. Shared-device users should clear saved workspace data before leaving the device.
We use HTTPS, authenticated access, and database access controls to protect account information. No online service or device storage can be guaranteed completely secure.
7. Your choices and requests
You can update your display name in Account, log out, clear local workspace data, or stop using Google sign-in. You can also remove Artora’s access in your Google account’s third-party connections settings. Revoking Google access does not by itself delete your Artora account or local browser data.
Contact artorathumbs@gmail.com to request access, correction, or deletion of account information, or to ask about other privacy rights that apply where you live. We will assess requests under applicable requirements and may verify your identity before responding.
8. Age requirements
Artora is intended for creators aged 13 and older, subject to any higher age requirement where they live. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information in violation of this requirement, contact us so we can investigate and remove it where appropriate.
9. Changes and contact
We will update the date on this page when the policy changes. For material changes to how we handle personal information, we will provide notice and obtain consent where required before applying a new use.
Privacy contact: artorathumbs@gmail.com.