SfumatoART ← Back to app
⚠️ Working Draft — 3 items need legal sign-off before publishing
  1. Effective date — confirm with lawyer once reviewed (shown in gold below)
  2. Legal entity / ABN — sole trader name or company name + ABN or ACN
  3. Response time — how many business days to respond to privacy requests (shown in gold below)
Once placeholders are filled, have a qualified Australian technology/privacy lawyer review before removing this notice.

Privacy Policy

Effective date: [PENDING — requires legal review and sign-off]
Operator: [INSERT LEGAL ENTITY / SOLE TRADER / COMPANY NAME], [INSERT ABN / ACN]
Contact: feedback@sfumatoart.com

1. Purpose

This Privacy Policy explains how SfumatoART handles personal information and app data. It is written for users in Australia and other regions where the app may be accessed.

2. Data minimisation

SfumatoART collects the minimum data needed to provide the feature the user chooses. Where possible, app data remains on the user's device unless the user chooses a feature that requires upload — such as an AI-assisted feature, support request, cloud sync, or account feature.

3. Types of information the app may handle

Depending on the features used, the app may handle:

CategoryExamplesHandling
Contact detailsEmail from support or feedbackCollected only when user contacts support or creates account
Artwork / imagesUploaded painting photos, colour samplesProcessed only for the selected feature
Paint dataPaints owned, stock levels, palettesStored locally on device by default
Teacher dataClass names, student count, lesson notes, order recordsAvoid student names; local by default
Device / technical dataBrowser, device, error logs, IP addressMinimal — for security/debugging only
AI prompts / outputsUser prompt, image if submitted, AI responseSent only when user triggers an AI feature
Purchase dataPlan, subscription status, receiptsUsually handled by App Store / payment provider
Sensitive informationHealth, veteran, trauma, student infoAvoid collecting unless strictly necessary and consented

4. Information users should avoid entering

Users should avoid entering:

5. How information is collected

Information may be collected when users:

6. Why information is used

Information may be used to:

7. AI providers and third parties

When a user chooses an AI feature, relevant prompts, images or app context may be sent to an AI service provider to generate the requested output. The app does not send images or prompts to an AI provider unless the user intentionally uses an AI feature.

Current AI features use an Anthropic Claude model via a secure server-side proxy (/.netlify/functions/ai-proxy). The AI provider's own terms and data handling policies apply to data processed by the provider.

8. Storage

Most app data (paints, palettes, stocktake, class records, project notes) is stored locally on the user's device or browser. Local storage is not a permanent backup — it can be lost if the user clears browser data, changes devices, or uses private browsing. Users should export important data.

If cloud storage, accounts or sync are added in future, this Privacy Policy will be updated before launch.

9. Disclosure

Information may be disclosed to:

The app does not sell personal information.

10. Children and students

The app is not intended to collect personal information directly from children without appropriate adult, school or parental authority. Teachers and schools should use anonymous labels wherever possible. If student personal information is accidentally provided, contact feedback@sfumatoart.com to request deletion.

11. Sensitive information

The app does not intentionally collect sensitive information such as health information, mental health information, religious information, biometric information or detailed veteran/trauma information unless a specific feature clearly requires it, the user is informed, and express consent is obtained.

12. Security

Reasonable technical and organisational steps are used to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Security controls include least-privilege access, API key protection via server-side proxy, secure hosting, and prompt incident response.

13. Data retention

Information is kept only as long as reasonably needed for the purpose collected, unless legal obligations require longer retention. Local device data remains under user control and can be deleted by clearing app or browser data.

14. Access, correction and deletion

Users may contact feedback@sfumatoart.com to request access to, correction of, or deletion of personal information held by the app operator. Some data stored only locally on the user's device may not be accessible to the app operator — the user controls that data directly.

15. Overseas users

If the app is used outside Australia, local privacy laws may apply. If the app is intentionally offered to users in the EU, UK, US or other regions, the operator will review local requirements before launch.

16. Complaints

Privacy questions or complaints can be sent to feedback@sfumatoart.com. The operator aims to respond within [INSERT RESPONSE TIME, e.g. 10 business days]. Users may also have the right to complain to the relevant privacy regulator — in Australia, the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

17. Changes

This Privacy Policy may be updated. Material changes will be announced in-app or on the website where practical. Continued use of the app after a policy change constitutes acceptance of the revised policy.