Privacy Policy#
Last updated: 30 September 2026
The short version: we collect what we need to run your account and serve your files, and we do not sell it. On this site we use Google Analytics and the Meta Pixel to see which pages and ads work. In the EEA, the UK and Switzerland they run only if you allow them. Nothing of ours runs on the pages you publish.
Who we are#
Yarrtifacts is a small independent project. These policies are published under the name Yarrtifacts, and "we" below means the people who run it. You can reach us at support@yarrtifacts.com.
We have not registered a company yet. Before paid plans open we will name the operating entity here, along with the law that governs it.
What we collect#
Your account. Your email address, the name you gave, whether the email has been verified, when the account was created, and a hash of your password. We never store the password itself. Sign in with Google instead and we receive your email address, your name and your profile picture from Google; your Google password never comes near us.
Your sessions. Signing in creates a session record that holds the IP address and browser user-agent of that sign-in. It is what keeps you signed in, and what lets a session expire.
What you publish. The files themselves, their names and sizes, the title and link you chose, which version is current, and any custom domain you attached.
Share passwords. Only a hash. A password-protected artifact is unlocked on our own domain, never on the domain the files are served from, so the page you published cannot read the password even in principle.
View counts. One number per artifact. We keep no log of individual visits, no visitor profiles and no referrer history. So that one person refreshing does not count ten times, we store a short record pairing the artifact with the visitor's IP address; it deletes itself after ten minutes and nothing about that visit reaches the database beyond adding one to the counter.
Feedback. If you use the feedback form we keep your message, your email address and which screen you sent it from.
API tokens. The name you gave the token, its last four characters, when it was created and when it was last used, and a hash of the token. The token itself is shown once and never stored.
Analytics on this site. The pages of yarrtifacts.com (the home page, sign-in and the dashboard, but never a published artifact and never these policy pages) can load Google Analytics and the Meta Pixel. They record which pages you open, which ad or link brought you here, and a few steps in the product: signing up, confirming your email, your first publish and adding a custom domain. They recognise your browser by their own cookies and see your IP address. We do not send them your email address or your name. If you are in the EEA, the UK or Switzerland, or we cannot tell where you are, they load only after you click Accept. Everywhere else they load by default and you can turn them off. If your browser sends a Global Privacy Control signal, we take it as a no and load neither. You can change your answer at any time with Cookie settings, in the site footer or on the Account page. Saying no deletes the cookies they set.
What we do not do#
We do not sell or rent personal data.
Published artifacts carry no analytics scripts and no third-party tags: we add nothing to what you upload. The artifact is your own HTML, though, so a tracker you put in it will run.
Cookies#
These are always set, because they run the thing you asked for:
- a session cookie on the dashboard domain after you sign in;
- a short-lived cookie on the artifact domain once you unlock a password-protected or private artifact, so you are not asked again for every file on the page;
yarr_consenton yarrtifacts.com, which remembers your answer to the cookie question for six months.
The rest are set only while analytics is allowed (see Analytics on this site above). Google Analytics sets _ga cookies, kept for up to two years, and the Meta Pixel sets _fbp, kept for 90 days, plus _fbc when you arrive from a Meta ad. They sit on yarrtifacts.com, never on the artifact domain.
Who else touches your data#
- Cloudflare runs everything: the code, the file storage, the database, the DNS and the certificates. Serving a request means Cloudflare processes it, including the IP address it came from.
- Resend sends our email: address verification, password resets and our own internal alerts.
- Google, if you choose to sign in with Google, and for Google Analytics while it is allowed.
- Meta, for the Meta Pixel while it is allowed. Meta uses what it receives to measure the ads we run with them, and under its own terms for its own advertising.
- Stripe handles payments when you buy a plan. They take the card details; we learn that a payment happened and get a customer reference.
Each one gets only what it needs to do its part.
Where your data is#
Files sit in Cloudflare R2 and the metadata in Cloudflare D1, both with a location hint of Eastern Europe. Cloudflare serves requests from whichever of their locations is nearest to the visitor, so request data is processed on their global network.
How long we keep it#
- Your account: until you delete it.
- Your artifacts: until you delete them. Deleting removes the files from storage; the link name is held for a short cooldown afterwards so it cannot immediately be taken by someone else.
- Sessions expire on their own.
- Never-finished uploads are cleared out within a day.
- The view-count records last ten minutes.
- Feedback we keep, because it is how we decide what to build. It goes when you delete your account.
- Cloudflare keeps automatic point-in-time copies of the database for up to 30 days, so deleted data can survive that long in their backups before it ages out.
Your rights#
You can ask for a copy of your data, ask us to correct it, or object to how we use it. Write to support@yarrtifacts.com and we will answer within 30 days.
Deleting the account is yours to do, not ours: Delete account sits in the account menu in the dashboard. We send a confirmation link to your address, and following it removes the account, every artifact in it and every link those artifacts served. Anyone holding one of those links gets a 404 from that moment. The stored files become unreachable immediately and are cleared from storage within a day.
If you think we have mishandled your data, you can complain to the data protection authority where you live.
Children#
The service is not intended for children, and we do not knowingly collect anything from them.
Changes to this policy#
When it changes, the new version appears here with a new date. If the change materially affects you, we will email you first.