Privacy Policy
Last updated: 18 September 2026 — applies to Arti 1.8.1
The short version
Arti runs entirely on your Mac. The floor plans you draw, the furniture you place and the settings you change are written to a file on your own disk and are never uploaded anywhere. There is no account, no sign-up and no login — and in this version there is no way to create one even if you wanted to.
The browser version keeps the same promise in a different place. It is the same app compiled to run in a page, and nothing you draw in it is uploaded — but it saves your plans in your browser's own storage rather than in a file you own, which means clearing your browsing data deletes them. Section 7 says what that changes.
The only information that ever reaches us is an anonymous crash report, sent when the app hits an error, so that we can fix it. It contains no plan data and nothing that identifies you.
That is the whole of it. The rest of this page is the detail, because a privacy policy that only says "we respect your privacy" tells you nothing.
1. Who is responsible
The data controller for the processing described here is:
Invent Better — Mickael Romaniello EI
FranceContact: contact@artiplans.com
We are established in France, so this policy is written to the General Data Protection Regulation (EU 2016/679) and the French Loi Informatique et Libertés. Where you live elsewhere, section 12 sets out the additional rights you may have.
We have not appointed a Data Protection Officer; the volume and sensitivity of what we process do not meet the threshold in Article 37. Write to the address above and you reach the person who makes the decisions.
2. What Arti stores on your Mac
Everything you make in Arti is stored locally, in a single SQLite database inside the app's own container:
~/Library/Containers/com.inventbetter.arti/Data/Documents/arti_db.sqlite
That single file holds your plans, floors, rooms, walls, openings, furniture, materials and per-app preferences. It is written automatically as you work — there is nothing to save and nothing to sync.
This is not "data collection". We have no copy of it, no access to it and no way to request it. It is your file, on your disk, in the same sense as a Pages document. If you delete the app and its container, it is gone; if you back your Mac up with Time Machine or iCloud Drive backup, your backup contains it and is governed by Apple's terms, not ours.
When you export a plan as an image, the PNG is written wherever you choose to put it. Nothing is transmitted.
3. What we actually collect: crash reports
Arti includes Firebase Crashlytics (Google). It is the only component in the app that talks to a network, and it only speaks when the app fails.
| What is sent | Why | Kept for |
|---|---|---|
| The technical description of the error and the stack trace | To locate and fix the defect | 90 days |
| An anonymous installation identifier generated by Crashlytics | To count how many installations are affected by the same bug, so we fix the frequent ones first | 90 days |
| Mac model and macOS version | To tell an OS-specific failure from a general one | 90 days |
| App version and build number | To know whether a fix has actually shipped | 90 days |
What is deliberately kept out. Before a report leaves your Mac, file paths are rewritten so that /Users/your-name/… becomes /Users/<user>/…. macOS account names are very often real names, and a crash inside the database layer would otherwise carry yours in the error text. No plan content, no room names, no file names you have chosen and no document contents are included in a report.
The installation identifier is not you. It is a random value tied to that copy of the app on that Mac. It is not your Apple Account, not your device serial number, and not an advertising identifier. We cannot use it to find out who you are, and we do not try.
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — keeping the software we distribute from crashing on the people who use it. We consider this proportionate because the data is anonymous, is not linked to any account, is never used to profile anyone, and is discarded after 90 days. If you would rather send nothing at all, see section 12 — you can object, and there is a practical way to stop it in section 5.
Recipient: Google Ireland Limited, acting as our processor, under Google's Firebase data processing terms. Google's own privacy information for Firebase is at <https://firebase.google.com/support/privacy>.
We do not use Firebase Analytics, Google Analytics for Firebase, or any other usage-tracking SDK inside the app. Crashlytics is the entire Firebase integration and it lives in a single source file.
Crash reports from the browser version
Crashlytics cannot run in a browser — it has no web implementation and never has had one — so the browser version reports to our own server instead, at artiplans.com/api/crash. Nothing goes to Google, and no third party is involved. The data stays on the same European hosting as this site.
| What is sent | Why | Kept for |
|---|---|---|
| The error text and the JavaScript stack trace | To locate and fix the defect | 90 days |
| Whether the app could carry on, and a short label saying where the failure came from | To tell a crash from a recoverable glitch | 90 days |
| A random 8-character value identifying one page load | To tell "one session threw forty errors" — a loop — from "forty people threw one" — an outbreak | 90 days |
| The time the browser thought it was | To order events within a session | 90 days |
That 8-character value is not a device identifier and is not allowed to become one. It is generated fresh every time the page loads, is stored in no cookie and no browser storage, and is never joined to anything else. Two visits from the same person produce two unrelated values, and we have no way to connect them.
What is deliberately kept out. Before a report leaves your browser, query strings and URL fragments are replaced with ?… and #…, and home directory names are rewritten the same way they are on the Mac. No plan content, no room names, no file names and no IP address are stored with a report. There is no account to attach one to.
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — keeping the software from failing on the people using it. The same proportionality argument as above applies, and more easily: there is no third-party processor and no transfer outside the EEA.
4. What we do not collect
To be explicit, because "we only collect what we need" is worth nothing without a list of what that excludes:
- Your plans. Not their content, not their names, not their number, not their dimensions.
- Your identity. No name, no email address, no postal address, no phone number. Arti has no account system to attach them to.
- Your location. The app never requests location permission and would be refused by macOS if it tried.
- Your usage. No screen views, no session lengths, no feature counters, no funnels, no heatmaps.
- Advertising identifiers. There are none in the app. There is no advertising in the app, and we do not sell, rent or share anything with ad networks or data brokers.
- Your contacts, photos, calendar, microphone or camera. Arti asks for none of these permissions.
5. Turning crash reporting off
Open Settings and turn off Send crash reports. Nothing is sent while the switch is off, and the app carries on working normally.
You can also block it at the network level. Crash reports go to Google's Firebase endpoints (crashlyticsreports-pa.googleapis.com and firebaselogging-pa.googleapis.com). A firewall rule such as Little Snitch or LuLu blocking those hosts for Arti stops it too.
6. What Apple knows
Arti is distributed exclusively through the Mac App Store. Downloading it, and any purchase you make, is a transaction between you and Apple — Apple is the seller, and Apple's privacy policy governs it: <https://www.apple.com/legal/privacy/>.
What we receive from Apple is aggregate and anonymous: how many units were downloaded, in which countries, on which OS versions, plus crash counts and the ratings and reviews that are public anyway. We never see who bought the app. If you write a review, we see the review under whatever nickname you publish it with, exactly as any other visitor does.
If you contact Apple for a refund, we are not told your identity, only that a refund occurred.
7. This website
The website at artiplans.com is separate from the app and collects less than most sites you visit today.
No cookies for tracking. We use no advertising cookies, no social plug-ins, no Facebook pixel, no Google Analytics. If your browser stores anything from us, it is a strictly functional preference — for example, remembering that you chose the dark theme — which is exempt from consent under Article 82 of the French Loi Informatique et Libertés and does not require a banner.
Audience measurement. We use a privacy-preserving analytics tool that sets no cookies and builds no cross-site profile. It records, per page view: the page URL, the referring site, the country (derived from the IP address and then discarded), and a coarse browser/OS family. IP addresses are not stored. Nothing there identifies a visitor, and no two visits can be linked into a profile. Legal basis: legitimate interest (Art. 6(1)(f)) — knowing which pages are read at all, in a form that cannot single anyone out.
Server logs. Our host records requests for security and abuse prevention: timestamp, requested URL, HTTP status, user agent and IP address. These are kept for 12 months and are used only to investigate incidents and attacks, never for marketing. Legal basis: legitimate interest (Art. 6(1)(f)) — network and information security, which Recital 49 recognises explicitly.
If you write to us. The support and contact addresses reach a mailbox. We keep the correspondence for 3 years after the last exchange, so that we can follow up on a bug you reported and so we have a record if a dispute arises. Legal basis: legitimate interest (Art. 6(1)(f)) — supporting our own product — and, where your message concerns a purchase, performance of a contract (Art. 6(1)(b)).
The browser version of Arti runs entirely in your browser. Nothing you draw in it is sent to a server, and we never receive, see or hold a plan made in it.
It does, however, save. The browser version is the whole app, not a demo, and it stores your plans in your browser's own storage so that they are still there when you come back. That storage is on your machine and under your control, and three things follow from it: clearing your browsing data, site data or cache deletes your plans and we cannot recover them, because we never had a copy; the plans belong to that one browser on that one machine and do not follow you anywhere; and a private window keeps nothing once it closes. Export a plan as an image if you want it to outlive the browser. Legal basis: none is needed — this is storage on your own device that we neither read nor receive, and it is strictly necessary to provide the editor you asked for, so it is exempt from consent under Article 82 of the French Loi Informatique et Libertés.
Newsletter. If we offer one, you will only be added after you ask to be, with a double opt-in, and every message will carry a one-click unsubscribe. Legal basis: consent (Art. 6(1)(a)), withdrawable at any time.
8. Accounts and plan sharing — not active in this version
Arti 1.8.1 has no account system and no cloud. Some buttons in the app's toolbar are drawn but disabled, waiting on a future release. Nothing in this section describes anything that happens today; it is here so that you can read the commitment before the feature exists, instead of discovering the change afterwards.
Accounts. There are none, and Arti is designed to stay usable without one. If a future release ever introduces an account, it will never be a condition of drawing, opening or exporting a plan, this policy will be updated before it ships to say exactly what is stored and for how long, and you will be able to delete it from inside the app — which deletes what we hold. The plans on your Mac are yours and would be untouched by it.
Plan sharing. A future version is planned to let you publish a read-only link to a single plan, so that you can send it to a builder, an architect or a client — and, for professional users, to a prospective buyer or tenant. That feature necessarily uploads the plan you choose to share, and we would then hold a copy of it. When it ships:
- it will be opt-in, per plan, and never automatic — no plan is uploaded because you happened to have an account;
- this policy will be updated before the feature is enabled, with a section stating what is stored, where, and for how long;
- the app's App Store privacy label will be updated in the same release;
- you will be able to revoke a link and delete the uploaded copy, and doing so will actually delete it rather than hide it.
If you are a professional — an estate agency, a decorator, a builder — sharing a plan of a property may involve information about a third party, such as your client or a tenant. In that arrangement you decide what to share and you are the controller of it; we process it on your instructions. When the feature ships we will publish the corresponding data processing terms, as Article 28 requires.
9. Where your data goes
The only transfer outside the European Economic Area is the macOS crash reporting in section 3. The browser version's crash reports never leave our European hosting, and the plans themselves never leave your machine at all. Firebase Crashlytics processing takes place on Google infrastructure, which includes servers in the United States.
That transfer relies on the European Commission's adequacy decision for the EU–US Data Privacy Framework of 10 July 2023, under which Google LLC is certified, and additionally on the Standard Contractual Clauses included in Google's data processing terms. Given that the data transferred is anonymous technical crash information containing no identifiers and no content, the risk to you from this transfer is minimal.
Our website is hosted in the European Union.
10. How long we keep things
| Data | Retention |
|---|---|
| Crash reports | 90 days, then deleted by Crashlytics |
| Web server logs | 12 months |
| Analytics page views (aggregate, non-identifying) | Indefinite as aggregate counts; no personal data is held |
| Support correspondence | 3 years after the last message |
| Newsletter subscription | Until you unsubscribe |
| Crash reports from the browser version | 90 days, then deleted from our own server by a scheduled job |
| Your plans | For as long as you keep them — in a file on your Mac, or in your browser's storage. We hold none of them, in either case. |
11. Security
The app holds your data on your own machine, inside a sandboxed macOS container, protected by your Mac's own file permissions and FileVault if you have it enabled. The app is signed and notarised by Apple.
Arti runs under the macOS App Sandbox and requests exactly three capabilities: outgoing network access (used by nothing except crash reporting), and read and write access to files you pick in a save or open dialog. It cannot read your Documents folder, your Desktop or any other app's data.
The website is served over HTTPS only. Access to the Crashlytics console is protected by a Google account with two-factor authentication enabled, and only one person has it.
We will notify you and the CNIL as required by Articles 33 and 34 if a breach ever occurs that is likely to affect your rights.
12. Your rights
Under GDPR you have the right to access the data we hold about you, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and — where processing rests on consent — to withdraw that consent at any time without affecting what was lawful before.
You can exercise any of them by writing to contact@artiplans.com. We answer within one month, as Article 12 requires.
One honest limitation. For crash reports, we have no way to find "your" data. There is no account, and the installation identifier is not linked to any identity — so if you ask us to produce or delete your crash reports, we cannot locate them, because the anonymity that protects you also prevents the lookup. If you send us the identifier yourself (we can tell you how to find it), we can act on it. This is a consequence of collecting less, not of collecting carelessly, and Article 11 recognises the situation.
If you believe we have handled your data wrongly, you can complain to the French supervisory authority:
CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
<https://www.cnil.fr/en/plaintes>
or to the supervisory authority of the EU country where you live.
13. If you are in the United States
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act. We have never done so and the app contains no mechanism that would allow it.
California residents have the right to know what is collected, to delete it, to correct it, and not to be discriminated against for exercising those rights. The limitation in section 12 applies equally here: anonymous crash data cannot be traced back to an individual requester. Requests go to contact@artiplans.com.
Residents of other US states with comparable laws — Colorado, Connecticut, Virginia, Utah, Texas and others — have equivalent rights and the same contact.
14. Children
Arti is a tool for planning homes and is not directed at children. We do not knowingly collect anything from anyone under 16. Since we collect no identifying information at all, we have no means of determining a user's age, and no reason to.
15. Changes
If this policy changes materially — a new category of data, a new recipient, a new purpose — we will update the date at the top and describe the change here, and where the change concerns the app, in the release notes of the version that introduces it. We will not make a material change retroactive to data already collected under the previous version.
Previous versions are available on request.
16. Contact
contact@artiplans.com — for anything on this page, and for the app itself.
We are a one-person company. You will get a person, and usually within a couple of days.