Privacy

Privacy policy for Art Says Hi

This English Privacy Policy covers the Art Says Hi website, browser scanner, and English iOS and Android app. Art Says Hi is operated by Qomza, LLC. It explains what we collect, why we use it, where it is kept, and the choices available to you.

The app is local first. You do not need an account, and the current release does not provide a cloud archive or account based sync. The mobile SDK sections describe planned production integrations and apply only when those services are enabled in an app build. The separate Cookie Policy covers browser storage and browser analytics choices.

Images and visual readings

When you choose an image and tap Analyze in the app, the app prepares a bounded working copy and sends the selected photo view, scan target, scan goal, and technical request metadata to the Qomza gateway so it can return a visual reading. Photos are not sent to analytics or advertising services.

The app keeps captured image copies in its private Documents area so saved discoveries can be reopened. Reading text, notes, collections, settings, request identifiers, and related archive data are kept locally. Images are not stored as base64 in the local database.

The browser scanner prepares a working copy in your browser and sends it to the gateway only when you start a reading. Browser history keeps written result fields locally. Raw images and base64 data are not stored in that history.

The gateway and its service providers may temporarily process a request and technical logs to provide the reading, prevent abuse, troubleshoot failures, and keep the service reliable. Local erase cannot recall data already sent to a provider. Contact support for current retention details if you need them.

Permissions and sharing

The app requests camera or photo library access only after you choose an action that needs it. Notification access is optional and is used for Daily Spark reminders when you enable them. The app opens the native share sheet only after you choose to share a result or share card.

The website may use browser storage for consent and local reading history. Optional browser analytics are not loaded until you allow them. Global Privacy Control and Do Not Track are treated as a decline for the website.

  • Camera and photo access lets you select or capture an image for a reading.
  • Notification access lets the app schedule optional Daily Spark reminders.
  • You can change permission choices in your device settings.

Browser analytics and session replay

On the website, accepting optional analytics can load Microsoft Clarity and its session replay. A replay may include rendered page content, the visible scanner preview, URLs, interaction context, filenames or UI text exposed in the page, and browser or device details. Clarity is not loaded before consent. Decline optional analytics if you do not want this optional replay.

The original selected file is not sent as an analytics event. It is sent to the Qomza gateway only when you start a reading. Optional browser Sentry, when configured, receives error diagnostics under the exclusions described below.

Planned mobile advertising with Google AdMob

In a production app build that enables mobile advertising, Google Mobile Ads or AdMob may process app and device information, IP address, advertising or app identifiers, ad delivery and interaction information, and coarse location or similar signals where permitted by device settings and Google configuration. Google may use this information for ad delivery, measurement, fraud prevention, and personalization where allowed.

Ad placements are not used during onboarding, image capture, or the first completed result. Planned in app consent choices, device controls, and applicable regional requirements will govern whether personalized or non personalized ads can be shown. Google may present its own consent choices where required.

Planned Firebase Analytics and Google Analytics 4

In a production app build that enables the planned analytics integration and its required permissions, Firebase Analytics and Google Analytics 4 may receive fixed event names about app use, such as onboarding, scan lifecycle, saves, shares, Daily Spark, and review prompts. They may also receive app instance, device, operating system, app version, runtime, language, and similar technical metadata.

Analytics is designed not to receive selected photos, image bytes or base64, full readings, free form notes, credentials, payment information, or authentication headers. Google controls its own processing and retention under its published terms and privacy documentation.

Sentry diagnostics for app and website

When the planned mobile integration is enabled, Sentry may receive crash and error diagnostics, app version and build, platform and operating system, device or runtime details, bounded operation stage and status, and request identifiers needed to investigate reliability. The browser site can also send optional error diagnostics when browser consent is accepted and a public Sentry configuration is present.

The app diagnostics contract excludes authentication headers, credentials, API keys, session cookies, payment data, raw image bytes or base64, and full image content. Sentry processing is governed by Sentry's own privacy documentation and our configuration of its data scrubbing controls.

Storage, deletion, and retention

Erase all data in the app's Settings removes local discoveries, collections, notes, captured image copies, settings, scheduled Daily Spark reminders, local diagnostics, and local review state from that device. It does not delete information already held by the gateway, Google, Sentry, an app store, or another provider. Contact us if you need a provider deletion request routed to the appropriate service.

On the website, you can decline optional analytics, clear browser storage, and delete locally stored reading history through your browser. Essential operation and the consent choice may still require local storage.

  • Local app archive: private device storage, with no cloud archive in the current release.
  • Gateway processing: selected image views and request metadata sent only when you start a reading.
  • Provider data: retention and deletion are subject to the relevant provider's terms, configuration, and legal obligations.

Children and privacy requests

Art Says Hi is not directed to children under 13, or the higher minimum age required in a user's location. We do not knowingly ask children to create an account or submit personal information. If you believe a child has provided personal information, contact us so we can review it.

You may contact hello@artsayshi.app to ask about access, correction, deletion, or other privacy rights. We may need enough information to verify and safely handle a request. We respond subject to applicable law and reasonable legal or security exceptions.

Changes to this policy

We may update this policy when the app, website, providers, or legal requirements change. The date below identifies the latest version published on this page.

Last updated: August 17, 2026.