Policy
Privacy
What we store, what we deliberately do not, and who can see what you publish.
Effective
The short version
Artifact Publisher stores the HTML you publish, the link that points at it, and the minimum needed to know that the link is yours. It does not store your email address, your provider password, or any identity token. Recipients never have accounts, so there is nothing to build a profile from.
What we store
- The artifact itself. The self-contained HTML document you publish, plus every previous version. Versions are immutable, so an update stores a new copy rather than replacing the old one.
- Link metadata. The unlisted slug, the title and optional summary you supply, the expiry you choose, whether comments are enabled, and the times things were created or changed.
- An opaque account identifier. If you sign in, we store the identifier our sign-in provider gives us for you — a string like
user_2ab…. That is the only identity fact we keep. - Publisher keys, as digests. We store a SHA-256 digest of each key and a short non-secret prefix for display. We cannot recover the key itself, which is why it is shown exactly once.
- Comments, if you enable them. The comment text, the version it was left on, and a self-declared name if the reader typed one. Names are unverified.
What we deliberately do not store
- No email address, provider handle, password, or OAuth token. There is no column for any of them. Two accounts that happen to share an email address remain two separate accounts, and we never merge them — automatic merging by matching email is exactly the account-takeover pattern this design refuses to allow.
- No plaintext publisher key, in the database, in logs, or anywhere else.
- No recipient accounts. Opening a shared link creates nothing.
- No analytics, advertising, or third-party tracking on the marketing site, the documentation, or the review surface. There are no third-party scripts, fonts, or images.
- No cookies for the account API. It is authorized by an explicit header and sends none.
Who can see a published artifact
A link is unlisted, not private. There is no index, no search, and no public listing — but anyone holding the link can open it, and can pass it on. Treat the link itself as the access grant, and do not publish anything whose disclosure to an unknown holder would harm you or someone else.
You can set an expiry when you publish, and you can revoke a link at any time. Revocation applies to both the review link and the raw versions behind it.
Isolation
Published HTML is untrusted by design — it came from an agent, and we do not audit it. It is therefore served from a separate origin (artifacts.artifactpublisher.com) from the surface that holds your session (app.artifactpublisher.com) and from this site. Links created before the move keep working on the matching currico.ch hosts, with the same separation. Artifact HTML runs sandboxed, gets no account routes, and has no access to your session. This boundary is not a convenience, and we do not relax it.
Where the data lives
Artifact Publisher runs on Cloudflare. Artifact documents are stored in Cloudflare R2, metadata in Cloudflare D1, and requests are served by Cloudflare Workers, which may route through any of Cloudflare's locations. Sign-in is handled by our identity provider, which holds the provider identity we never see.
Deleting things
Revoking an artifact takes it out of service immediately. If you want an account, its workspace, and its stored artifacts deleted outright, ask and we will do it — during the beta this is a manual operation performed by a person, not a button.
Changes
Artifact Publisher is in an early founder-led beta. This page will change as the product does. Material changes to what we store, or to who can see it, will be reflected here with a new effective date.