Who we are
Artica is a collection of tools for building help centers, at artica.tools, plus the Artica Chrome extension. It is operated by Hosam Hassan LLC, a Wyoming limited liability company, at 30 N Gould St. #48472, Sheridan, WY 82801, USA (“Artica,” “we,” “us”). Artica is run by one person, its founder, Hosam Hassan. For any privacy matter, email hello@artica.tools.
We have not appointed a representative in the European Union or the United Kingdom. You can reach us directly at the address above, in English.
Controller and processor
Artica plays two different roles, depending on whose data it is.
- Artica is the controller of the data about you as our user and visitor: your account, your workspace, how you use the tools, the emails we exchange, website analytics and our logs. This policy is our notice for that data.
- You (or your organisation) are the controller, and Artica is your processor, for the content you bring to the tools: support tickets, help center articles, documents, captures and screenshots, and anything about your own customers inside them. We process it only to provide the tools to you, under our Data Processing Addendum. If you are one of our customer’s customers and want to know what happened to your data, please contact that company first; we will help them answer you.
The short version
- We keep your account, your workspace, records of what you did (counts, never content), and the things you create on purpose: articles, captures and their screenshots, Topic finder results, theme requests.
- Support tickets are never stored. Ticket exporter, Article exporter and Format fixer pass content through our servers in memory and build the result in your browser.
- Topic finder removes personal data from tickets before any AI step. Article generator screenshots are redacted for patterns such as emails and card numbers, but names and other text on the page are not blurred, and the screenshots are kept with your article until you ask us to delete them.
- AI is provided by Anthropic. Your content is not used to train models. Anthropic keeps API data for a limited period under its standard terms.
- We count page views ourselves, without cookies. The visitor code we use is pseudonymous, not anonymous.
- We don’t sell or share personal data for advertising, and we don’t use it for anything unrelated to the tools.
- To delete your account and everything in it, email hello@artica.tools. We do it within 30 days.
Your account and workspace
Account
You sign up with your email address and a password, through our sign-in provider Clerk. Clerk holds your credentials (we never see your password), your email address, your name if you give one, and the security records it keeps for every sign-in: your IP address, browser and device, and session times. If you turn on two-factor authentication, Clerk holds that too.
Workspace
The first time you use a tool, we create a workspace for your account. Everything you do in Artica belongs to it. It holds:
- Your suite: which tools you have used, and when each was added.
- Usage records: each action you take (for example previewing or installing a theme, starting an export, finishing a capture, running a Format fixer check or fix), with the time, your user id and small facts about it: counts, the tool’s options, an error code. Never the content.
- Allowance counters: how much of each free monthly allowance you have used, and the AI or processing cost to us of that use.
- Where your account came from: in the visit where you sign up, the first page you landed on, the site that referred you (its domain only, never the full address), and any campaign tags in the link (
utm_source,utm_medium,utm_campaign). This is kept with your workspace once. - Extra allowances we grant you by hand, with a short internal note.
What each tool collects
For each tool: what passes through, what is kept, and what (if anything) goes to an AI provider. “In memory” means the data exists only in a running server process for as long as the job takes, and is never written to a database, file or log.
Ticket exporter
- What it reads: the Zendesk tickets you choose (by date range and brand), through your Zendesk connection, one page at a time.
- Remove personal data (the default): each page is scrubbed on our servers before anything reaches your browser. Our pattern rules (emails, phone numbers, card and account numbers, IDs, links, signatures and greetings) run on Vercel; names, companies and addresses will be found by an open-source name-finding model on our own processing service, Modal, which will receive the ticket text and the requester’s and agent’s names for that page only. That name model is not switched on yet: today, scrubbed exports remove the patterns above but not names, and the export says so. Matches become placeholders such as
[NAME_1], and the requester and assignee columns are always left out. - Keep everything as it is: tickets are passed through to you unchanged, including requester name and email and assignee name. Never stored, never logged, never sent to an AI provider. You are responsible for that file.
- Where the file is made: in your browser, on your computer. Artica keeps no copy.
- What we keep: a record that you exported, with counts only: how many tickets, the length of the range, whether personal data was removed and how much was removed, by kind.
- AI providers: none.
Article exporter
- What it reads: help center articles, their categories, sections and images, either from a public help center link you paste (public pages only, one at a time, following the site’s robots.txt and only from that help center’s own address) or through a connection: your Zendesk connection, or an Intercom token or Freshdesk or Help Scout key you paste. A connection can read every article that account can see, including internal and restricted ones, and drafts if you choose.
- Keys you paste: used for that export only. The key is encrypted (AES-256-GCM) into the export’s short-lived session (at most 4 hours), which your browser holds; our server opens it in memory for each request and sends it only to that platform. It is never saved or logged.
- Where the zip is made: in your browser. Our servers pass one page of articles or one image at a time to you without keeping or logging it.
- What we keep: a record that you started and finished (or failed) an export, with the source type (link or connection), the platform, and counts (articles, languages, images). Never the help center’s address, titles or content.
- AI providers: none.
Topic finder
- What it reads: a file of tickets you upload (CSV, Excel, JSON, PDF, TXT or HTML), or the tickets created in the last 30 days in your connected Zendesk.
- Uploaded files: stored in private, encrypted storage (Cloudflare R2) until the analysis starts. Our processing service reads the file when you upload it (to count the tickets) and again when the analysis starts, and deletes it as soon as it has read it. A file you upload but never analyse is deleted by a daily clean-up within about two days.
- Scrubbing first: on our processing service (Modal), personal data is removed from every ticket before any other step: names, companies, emails, phone numbers, card and account numbers, addresses and signatures become placeholders. While reading a file, the tool may show Claude the column names and a few scrubbed sample rows, or scrubbed lines of a document, to work out its structure.
- The analysis: each ticket’s scrubbed subject and first message (up to 2,000 characters) is sent to Claude, which rewrites it as a one-sentence customer question. Those questions are grouped by an open-source model running on Modal, and Claude names the topics and categories from the questions. Ticket text exists only in memory during the analysis.
- What we keep: the result: topic and category names, descriptions, example questions written by the AI (checked so they don’t repeat real ticket text), the ticket IDs behind each topic, counts and weekly volumes. Plus the run’s details: the uploaded file’s name and format, or the Zendesk subdomain and brand; the tickets’ date range; status; a short error message (redacted); and the AI usage and cost. Ticket IDs are not anonymous: they identify tickets in your own help desk.
- Zendesk access: the processing service asks our server for a fresh Zendesk access token for each analysis and does not store it.
Article generator and its Chrome extension
- What a capture records: when you start a recording, a screenshot per click, a short description of what was clicked, where on the page the click landed, and the page’s title and address. The address is cut to the site and path; query strings and fragments never leave your browser.
- Redaction, and its limits: before upload, the extension blurs emails, card numbers, tokens, phone numbers, US Social Security numbers and IBANs on the screenshot, including values typed into form fields and content in same-origin frames, and removes the same patterns from the step text. Names, addresses and any other text on the page are not blurred. If you record a screen showing your customers’ names, those names are in the screenshot. Step text is redacted again on our server.
- What we keep: the screenshots (in Cloudflare R2, under your workspace), the recorded steps (descriptions and screenshot references), the article Artica drafts, your edits, images you add, the Zendesk article and section it was exported to, and the AI usage and cost of the draft.
- How long: until you ask us to delete them or delete your account. Archiving an article hides it; it does not delete it or its screenshots.
- AI: the redacted screenshots, step text, page titles and addresses are sent to Claude to draft the article.
- Export to Zendesk: when you export, the article and its images are sent to your own Zendesk help center as a draft.
Format fixer
- What it reads: one article at a time: a public article from a link you paste, a document you open (converted in your browser; the file isn’t uploaded), or an article you pick through your Zendesk connection (including drafts and restricted articles your account can see).
- The Check: runs entirely in your browser, with no AI, and needs no account. A linked or Zendesk article passes through our servers without being kept or logged. Without an account, requests are rate-limited by a hash of your IP address, held in server memory only.
- The AI fix: before anything leaves your browser, personal data our scrubber finds (emails, phone numbers, card and account numbers, keys and similar) is replaced with placeholders, and every link and image address with a short reference. Our server scrubs it again, then sends Claude the article’s cleaned text and structure, its title and the article type you chose. The real values are put back only in your browser.
- What we keep: if you’re signed in, a record of each Check and fix with counts only: the source type, the article type, how many issues, words and personal-data findings, whether a fix succeeded, and its AI tokens and cost. When you save to Zendesk, whether it was a new draft or a replacement. Never the article’s address, title or content.
- Save to Zendesk: only when you click Save or Replace.
Pre-built themes and Custom themes
- Pre-built themes: we record when you preview or install a theme, and which one.
- Custom themes: a request stores the name, email and help center address you enter, and we email it to our inbox so we can reply. We keep internal notes and a status on each request. All later conversation happens by email.
Your Zendesk connection
Used by Ticket exporter, Article exporter, Topic finder, Article generator and Format fixer. We store your Zendesk subdomain, the brand and help center locale you chose, the permissions Zendesk granted (read, and hc:write if you allowed it), the OAuth access and refresh tokens encrypted with AES-256-GCM, and the Zendesk user id and email address of the person who authorised the connection, so we can help with support. When you disconnect, the connection and its tokens are deleted. If Zendesk stops accepting the tokens (for example you revoke access in Zendesk), the connection is marked disconnected and kept, with tokens Zendesk no longer honours, until you connect again or your account is deleted.
Website analytics
We count page views ourselves, without cookies, browser storage or any third-party analytics service. For each page view on artica.tools (except our admin pages), and on the demo help centers of our Zendesk themes, we store:
- the page path (never the query string), and for the demo help centers, the theme;
- the referring site’s domain, and any campaign tags (
utm_*) in the link; - your country, from our host’s IP lookup;
- your device type (phone, tablet or computer, worked out from your browser’s user agent) and a screen-width band (five sizes);
- a daily visitor code: a keyed hash of the date, your IP address and your browser’s user agent, cut to 16 characters.
We don’t store your IP address or user agent. The visitor code changes every day, so we only count unique visitors per day. It is pseudonymous, not anonymous: the hashing key stays the same, so someone holding that key and your IP address and user agent could recompute your code. We don’t try to do that, and we don’t link page views to your account. Page views have no automatic expiry today. To opt out, block requests to artica.tools/api/collect (most content blockers can).
Emails we send
| To | Contains | |
|---|---|---|
| Welcome | You, once, when your workspace is created | A short note from the founder. Replies come to our inbox. |
| Analysis ready | You, when a Topic finder analysis finishes | A link to the result and its counts. |
| Custom theme request | Us | The name, email and help center address you entered. |
| New sign-up alert | Us, when a new workspace is created | Your email masked to its first letter and domain (for example m***@example.com), your sign-up source, and the first tool you used. |
| Daily summary | Us, every morning | The day’s sign-ups (masked the same way, with sources), visitor and usage counts, costs and error counts. |
Emails go out through Resend. For each send we record only its kind and whether it was accepted, not the recipient or the content. Mail to and from hello@artica.tools is handled by Google Workspace. We don’t send marketing email.
Logs and security records
- Server logs: our host, Vercel, logs each request (path, status, timing, and your IP address and user agent at Vercel) and our servers’ error messages. We write error logs by error name or code wherever we can; a few may include a provider’s error message, a Zendesk subdomain or a record id. We never log ticket text, article content or keys. Vercel keeps these runtime logs for about an hour.
- Processing logs: our processing service, Modal, logs counts, run ids and error types, kept under Modal’s retention.
- Admin audit log: every action taken from our admin view or our maintenance scripts: who acted, what was done, on which workspace, run or request id, and counts. No content. It is kept indefinitely, including after an account is deleted (the entry for a deletion records the user id and what was deleted, as counts).
- Scheduled jobs: each daily job records when it ran and its counts.
Payments
Artica does not take payments today: every tool is free within its monthly allowance. Paid credits are built but switched off, so no payment data exists. If we turn payments on, card details will be entered on Stripe’s own checkout page and never reach Artica, and we will keep what billing needs (the bundle, amount, credits and expiry, Stripe’s reference numbers and receipt link). We will update this policy before that happens.
AI processing
Artica’s AI provider is Anthropic (Claude models), called from our servers. Exactly what each tool sends is set out above and in our AI use page. In short: Article generator sends redacted screenshots, step text, page titles and addresses; Topic finder sends scrubbed ticket subjects and first messages, scrubbed samples while reading a file, and AI-written questions; Format fixer sends one article’s cleaned text with personal data and links replaced. Ticket exporter and Article exporter use no AI provider.
- No training: under Anthropic’s commercial terms, your content is not used to train its models.
- Retention at Anthropic: we use Anthropic’s standard API terms. Anthropic keeps API inputs and outputs for a limited period (currently up to 30 days) and longer where its usage policies or the law require. We have not yet arranged zero data retention with Anthropic.
- No other AI company sees your data. Scrubbing and grouping use open-source models that run on our own processing service.
- No automated decisions about people: nothing Artica does makes decisions with legal or similar effects about you or anyone else.
The Chrome extension
- When it collects: only during a recording you start, until you complete or cancel it. It never records keystrokes, browsing history, or anything outside a recording.
- What it collects: the screenshots, click descriptions, click positions, page titles and addresses described under Article generator, redacted in your browser before upload.
- Where it goes: screenshots upload straight to our private storage (Cloudflare R2) through short-lived signed links; the steps go to artica.tools. Screenshots that were uploaded but never became part of a capture are removed automatically after about a day.
- On your computer: while recording, the extension keeps the recording’s state and its redacted screenshots in Chrome’s session storage, which Chrome clears when the browser closes, and removes them when the recording ends. It also caches whether you’re signed in. It sets no cookies; Chrome attaches your artica.tools sign-in to its requests.
- Permissions:
activeTab,scriptingandstorage; access to artica.tools when you sign in; and access to all sites, asked for on your first recording, used only while a recording you started is running.
Limited Use. Artica’s use of information received from the Artica Chrome extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use it only to provide the extension’s single purpose, turning your recording into a help center article for you; we transfer it only to the service providers listed on our subprocessors page to provide that purpose, for security, or as the law requires; we never sell it, use it for advertising, or use it to determine creditworthiness or for lending; and no person reads it except with your permission, for security, or as the law requires.
Why we may use it
For people in the EU, UK and similar places, these are our legal bases as controller:
| Purpose | Data | Legal basis |
|---|---|---|
| Providing your account and the tools | Account, workspace, usage records, allowance counters, Zendesk connection | Performing our contract with you |
| Replying to custom theme requests and support emails | Name, email, help center address, messages | Steps you asked for before a contract, and performing it |
| Telling you an analysis is ready | Email address | Performing our contract |
| Welcome email, sign-up alerts and the daily summary | Email address (masked for us), sign-up source, usage counts | Our legitimate interest in running and improving a small service |
| Website analytics and sign-up source | Page views, visitor code, sign-up source | Our legitimate interest in understanding how people find and use Artica |
| Security, abuse prevention, logs and the audit log | IP addresses, logs, audit entries | Our legitimate interest in keeping Artica secure, and legal obligations |
| Payments, when switched on | Billing records | Performing our contract, and tax and accounting obligations |
| Content you bring to the tools | Tickets, articles, captures | We act on your instructions as your processor; you choose the legal basis |
Where we rely on legitimate interests, you can object (see Your rights).
How long we keep it
| Data | Kept |
|---|---|
| Account (Clerk), workspace, suite, usage records, allowance counters, sign-up source | Until your account is deleted |
| Articles, captures, their screenshots and images | Until you ask us to delete them, or your account is deleted. Archiving doesn’t delete. |
| Topic finder results | Until your account is deleted |
| Uploaded ticket files | Until the analysis starts; at most about two days if it never does |
| Ticket text, exported tickets and articles, Format fixer articles, pasted keys | Not stored: in memory for the length of the job only |
| Zendesk connection and tokens | Until you disconnect (deleted at once), or until your account is deleted |
| Custom theme requests | Until your account is deleted; the emails stay in our mailbox until we delete them |
| Page views | No automatic expiry today |
| Email send records (kind and success only) | No automatic expiry |
| Admin audit log | Indefinitely, including after account deletion |
| Vercel runtime logs | About an hour |
| Database backups (point-in-time restore) | About 6 hours |
| Data at Anthropic | Under Anthropic’s standard terms (see AI processing) |
| Unclaimed screenshot uploads from the extension | About a day |
Who can access it
- You. Your articles, captures, screenshots and results are tied to your workspace and served only to your account.
- Artica’s operator. Artica is run by one person. Our admin view shows counts, costs, run and capture metadata, and email addresses masked to their first letter and domain; it never shows ticket text, articles, topics or screenshots. The one exception is a custom theme request, whose full contact details can be revealed to reply, and each reveal is logged. The admin view is protected by the operator’s Artica sign-in; it does not require a second factor today. Account changes (extra allowances, retrying or cancelling an analysis, disconnecting Zendesk, deleting an account, looking up a full email address) are made with scripts on the operator’s computer using production credentials, and each is recorded in the audit log. With those credentials the operator can technically read anything stored, including articles and screenshots. We only look at your content when you ask us to (for example for support), to keep the service secure, or when the law requires it.
- Our providers, only to run their part of the service, under their own terms (see below).
International transfers
Artica is based in the United States, and so are most of our providers: our database runs in AWS us-east-1 (Virginia). Some providers process data elsewhere: Cloudflare’s storage and Vercel’s network are global, Google Workspace is global, and our processing service on Modal is not pinned to a region, so a job may run in any region Modal uses. If you use Artica from outside the US, your data is transferred to the US and these places.
For your account data, the transfer is necessary to provide the service you sign up for, and our providers protect it under their own transfer terms (such as the EU Standard Contractual Clauses). For customer data we process for you, our DPA incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Artica itself is not certified under the EU-US Data Privacy Framework.
Security
Everything travels over TLS 1.2 or 1.3 and is encrypted at rest by our providers. Zendesk tokens are also encrypted by Artica (AES-256-GCM), pasted keys are never stored, and every record and file is scoped to its workspace. More on our security page.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a copy in a portable format;
- correct it;
- delete it;
- restrict or object to how we use it, including anything based on legitimate interests;
- withdraw consent, where we rely on it;
- complain to a data protection authority, such as the one where you live or work (in the UK, the Information Commissioner’s Office).
How: email hello@artica.tools from the address on your account (or tell us how to verify you). We answer within 30 days. There is no self-serve deletion in the app today: when you ask, the operator deletes your account within 30 days. That removes your files in storage, your workspace and everything in it, and your sign-in account. What remains afterwards: database backups for about 6 hours, our providers’ logs and copies under their own schedules (including Anthropic’s retention), the audit-log entry recording the deletion, and emails in our mailbox unless you ask us to delete those too. We won’t treat you differently for using your rights.
If your request is about data a company put into Artica (for example a support ticket you wrote to them), we will pass it to that company, since they decide what happens to it.
California and other US states
In the last 12 months we collected these categories of personal information, for the purposes and from the sources described above: identifiers (name, email, account and workspace ids, IP address); internet activity (page views, usage records, logs); approximate location (country); and, inside content you bring, whatever your tickets, articles and screenshots contain.
We do not sell or share personal information (as California law defines “share”: for cross-context behavioural advertising), and we don’t use sensitive personal information to infer characteristics about anyone. You have the right to know, delete and correct, and not to be discriminated against for using these rights. You may use an authorised agent. Residents of other US states with privacy laws (such as Colorado, Connecticut, Virginia and Texas) have similar rights; contact us the same way, and if we refuse a request you may appeal by replying to our answer.
If something goes wrong
If a security incident affects your personal data, we will tell you without undue delay, with what we know and what we are doing, and notify the authorities where the law requires (under GDPR, within 72 hours of becoming aware). For customer data we process for you, we follow the notice terms in our DPA.
Children
Artica is a business product, not directed at children. You must be 16 or older to use it, and we don’t knowingly collect data from anyone under 16. If you think we have, email hello@artica.tools and we’ll delete it.
Changes
We change this policy in the same release as any change to what Artica collects or who processes it, and update the date above. If a change is material, we will also email account holders before it takes effect.
Contact
Hosam Hassan LLC, a Wyoming limited liability company, 30 N Gould St. #48472, Sheridan, WY 82801, USA. Email hello@artica.tools.