Privacy Policy
Last updated August 17, 2026
This Privacy Policy explains how Epitaph LLC (“we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with Artifact, our field-inspection platform. The Service includes our website and the Artifact Field mobile application for iOS (together, the “Service”). It also describes the privacy rights you may have and how to exercise them.
1. Who we are, and the scope of this policy
Epitaph LLC operates the Service. This policy applies to personal information we handle as a business/controller, primarily account, billing, support, and usage data, whether you use our website or the Artifact Field mobile app.
Much of the content created in the Service (inspections, notes, and photos) is submitted by our business customers and their personnel. For that content, the customer organization decides what is collected and why; we process it as a service provider / processor on the organization’s behalf and under its instructions, and the organization’s own privacy notice governs. If an organization gave you access to the Service (for example, your employer), please direct privacy requests about inspection content to that organization, and we will assist them as their processor.
2. Information we collect
We collect the following categories of information:
- Account & profile data: name, email address, role (inspector, manager, or admin), the organization you belong to, and your password (stored only in hashed form by our authentication provider).
- Information from your organization: an administrator may create your account, set your role, and assign your manager.
- Inspection content: checklists, pass/fail verdicts, notes, findings, sign-off names, and photos or document attachments uploaded during an inspection.
- Billing data: your plan, seat counts, and billing contact. Card details are collected and stored directly by our payment processor (Stripe); we never receive or store full card numbers.
- Usage, device & log data: IP address, browser and device information (including device type and operating-system version), pages and features used, timestamps, and actions taken in the Service.
- Communications: messages you send us (for example, support or sales inquiries) and your contact details.
3. How we use information
We use personal information to:
- provide, operate, maintain, and secure the Service;
- authenticate users and enforce role-based access within an organization;
- generate inspection reports and, where an organization enables it, deliver them to integrations;
- provide optional AI-assisted features, for example drafting an inspection template from a document or checklist text a manager chooses to submit (see “How we disclose information” below);
- process subscriptions and send transactional email (invitations, password resets, overdue notices, and service messages);
- monitor reliability, diagnose and debug errors, and detect, prevent, and address fraud, abuse, or security issues;
- review diagnostic and server-log data (errors, performance, and security events) to keep the Service working and to improve it. We do not mine the content of your inspections, notes, or photos to improve our product, and we do not use Customer Data to train AI models;
- comply with legal obligations and enforce our agreements; and
- communicate with you, and (only where permitted) send product updates you can opt out of.
4. Where we offer the Service
Artifact is offered and sold only in the United States. We operate the Service from the United States, we host and process data there, and we do not market, sell, or direct the Service to individuals or organizations in the European Economic Area, the United Kingdom, or Switzerland. We do not currently offer the Service to customers who require us to process personal data subject to the EU or UK GDPR.
If your organization is subject to those laws and you want to use Artifact, contact us at privacy@epitaph.llc first. We would need to put the appropriate arrangements in place before you sign up, and we would rather tell you that up front than take your money and leave you non-compliant.
5. Photos, camera, and location
Inspection photos are an important part of the record. When you capture a photo in the Artifact Field app we use your device camera, and you can also attach an existing image from your photo library. To protect privacy, when a photo is uploaded we generate an optimized copy and strip embedded metadata, including EXIF GPS location, before the image is stored. This optimized copy is the version we retain; we do not keep the full-resolution original file from your device, so keep your own copy of any photo you need at full resolution.
If you turn on “Keep my original in Photos” in Settings, the app also saves the original, unmodified photo (which may still contain its embedded location) to your own device photo library. That copy stays on your device and is not uploaded to us. We do not use your device’s precise geolocation, and the Service requests no location permission.
6. The mobile app and device permissions
The Artifact Field mobile app is distributed through the Apple App Store. The app requests only the device permissions it needs, each the first time you use the related feature: camera access to capture inspection photos, photo-library access to attach existing images, and permission to add photos to your library when you enable “Keep my original in Photos.” You can grant or revoke these permissions at any time in your device settings; declining a permission only disables the related feature.
The app does not request location, contacts, microphone, or tracking permissions, and we do not track you across other apps or websites. As the app’s distributor, Apple may collect limited technical information under its own privacy policy, and if you enable Apple’s optional app analytics at the device level, Apple may share aggregated diagnostics with us. Payments and subscriptions are handled on our website, not through in-app purchase, so the app does not collect payment information.
7. How we disclose information
We do not sell your personal information. We disclose it only as described here:
- Service providers (subprocessors): parties who process data on our behalf to run the Service, including hosting, database and file storage, off-site backup, email delivery, payments, and error monitoring. See our Subprocessors list.
- At your direction: your organization can turn on integrations that send inspection data to destinations it controls. Every integration below is off by default, is enabled by an administrator, and can be disconnected at any time.
- Procore. When an admin connects a Procore account and selects a project, each completed inspection is pushed into that project. This includes a complete copy of the inspection report as a PDF, which contains every checklist item and its result, inspector notes, the inspection photos, the name of the inspector, and any sign-off name. This happens on every completed inspection, whether or not anything failed. In addition, each failed item is created as a separate Procore observation carrying the item title, the inspector's notes, the inspector's name, and any attached photo.
- Outbound webhooks to an endpoint your organization configures (for example Jira, Zapier, Microsoft Teams, or any HTTP endpoint). When an inspection is completed we send your organization name and identifier, the template name, the name and email address of the inspector, the start and completion times, any sign-off name, a link to the report, result counts, and, for each failed item, flagged item, and ad-hoc finding, its title, the notes, and a time-limited link to its photo.
- API keys your organization issues to pull its own data out of the Service.
- AI-assisted features: when a manager or admin chooses to use AI template generation, the document or text they submit is sent to our AI subprocessor (listed in the Subprocessors page) solely to draft a template for review. The feature is optional, runs only when invoked, and no inspection content is sent to it automatically. Under the commercial API terms we are subject to, our AI subprocessor states that it does not use content submitted through that API to train its models. That is their commitment under their terms rather than a guarantee we can independently make on their behalf.
- Legal, safety, and rights: when required by law or legal process, or to protect the rights, property, or safety of our users, the public, or us.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
- With your consent, or as otherwise disclosed at the time of collection.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
8. On-device and offline storage
Artifact works offline. Inspection data and photos you capture in the field are stored locally on your device (in the browser’s IndexedDB on the web, and in the app’s local storage in the Artifact Field app) until they sync to our servers. When you sign out or switch users on a shared device, the app clears its local inspection data, cached templates, and offline session. Ordinary operating-system and browser caches are outside our control, so signing out is not a forensic wipe of the device. On a shared or company-owned device, rely on device-level controls as well.
9. Cookies and similar technologies
On the web, we use strictly necessary cookies to keep you signed in and to secure requests; the Service does not function without them. In the mobile app, we use equivalent local storage to keep you signed in rather than browser cookies. We also use a privacy-conscious error-monitoring tool (Sentry) to capture diagnostics when something breaks, configured so that it does not attach your identity to error reports.
We do not run third-party product analytics. There is no analytics or tracking SDK in the web app or in the Artifact Field mobile app, and we do not set any cookie or local-storage identifier to profile how you use the Service or to recognize you across visits for measurement purposes. We do not use advertising cookies or cross-site tracking, and we do not track you across other apps or websites.
Because we do not sell or share personal information, do not use cross-context behavioral advertising, and run no analytics or advertising trackers, browser signals such as Global Privacy Control have nothing to opt out of on our site.
10. Data retention
We keep account and inspection records for as long as your organization’s account is active. Inspection photos and attachments are retained for a configurable window (one year by default) measured from when an inspection is completed, after which the underlying files are deleted from the live store to bound storage; the inspection record itself (results, notes, statuses) is preserved. Because deleted photos are not kept in the live product once purged, download anything you need to keep before the retention window ends.
We maintain encrypted off-site backups of the database and stored files for disaster recovery. When you make a verified deletion or erasure request, we act on it in the live Service within the timeframe required by applicable law, so the data stops being visible, searchable, and usable in the product.
We want to be precise about backups, because many privacy policies are vague here. The two kinds of backup behave differently:
- Database backups are snapshots that expire automatically on a fixed schedule (currently about 35 days), so deleted records age out of them without any action by us.
- File and photo backups are written on an append-only basis and do not expire on their own. A photo removed from the live Service therefore remains in the off-site backup until we remove it deliberately.
Because of that, when you make a verified deletion or erasure request, or when an organization deletes its account, we perform a targeted deletion of the affected files from the off-site backup as a required step, within the timeframe required by applicable law (generally within 30 days), and we record that step in our internal request log. We do not use backups to repopulate deleted data, and if we ever restore from a backup we re-apply any outstanding deletion requests after the restore.
When an account is closed, we delete or de-identify personal information within a reasonable period, except where we must retain it to meet legal, accounting, security, or dispute-resolution obligations. We keep security and audit logs for a limited period to protect the Service.
One record survives deletion, by design. Free trials are limited to one per customer. To enforce that after an account is deleted, we keep a one-way cryptographic hash of the email address that used the trial. The hash is not reversible into an email address by reading it, though it can be matched against an address someone already has, which is exactly how the check works: it lets us test whether a new sign-up matches an address that has already trialed. We treat it as personal data for that reason, we keep no other record of a deleted account for this purpose, and we do not use it for marketing, profiling, advertising, or any purpose other than preventing repeat free trials. We retain it for as long as we offer free trials, and our basis for keeping it is our legitimate interest in preventing trial abuse. If you object to this specific retention, contact us and we will consider your objection on its merits; the consequence of removal is simply that the address becomes eligible for another free trial.
11. Security
We maintain an information-security program appropriate to our size and the sensitivity of the data we handle. It includes, among other measures, encryption in transit (HTTPS/HSTS), database row-level security to separate each organization’s data, role-based access controls, removal of EXIF/GPS metadata from uploaded photos, audit logging of sensitive actions, and encrypted off-site backups. We describe these measures so you understand how we work; they are a description of our current program rather than a guarantee of a particular result, and we may change specific measures as the Service and the threat landscape evolve.
Two limits are worth stating plainly. First, no method of transmission or storage is perfectly secure, and we cannot promise that the Service will never be compromised. Second, where your organization directs us to send data out of the Service (see “At your direction” above), the protections described here apply to our systems, not to the destination you chose. Webhook deliveries, for example, include time-limited links that grant access to the linked photo to whoever holds them, so send them only to endpoints your organization trusts.
If we become aware of a security breach affecting personal information, we will notify the affected organization and, where applicable, affected individuals and the appropriate authorities, without undue delay and as required by applicable law.
12. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information; to restrict or object to certain processing; and to withdraw consent where processing is based on consent. To exercise a right, contact us at privacy@epitaph.llc.
Some of these rights can be exercised without contacting us. An administrator of your organization can export a member’s data as a file from the admin area, permanently erase a member’s personal data, and delete the entire company account and its data from the billing settings. If you are unsure who administers your organization, or you want us to handle the request, write to us at the address above.
We will verify your request (typically by confirming control of the email on file) and respond within the time required by applicable law. An authorized agent may submit a request on your behalf with proof of authorization. We will not discriminate against you for exercising your rights. If we decline a request, you may appeal by replying to our response, and you may also lodge a complaint with your state attorney general or applicable state privacy regulator. If your personal information was provided to us by an organization using the Service, please direct your request to that organization.
13. California privacy rights (CCPA/CPRA)
If you are a California resident, you have additional rights. In the past 12 months we have collected these categories of personal information: identifiers (such as name, email, and IP address); commercial information (such as subscription and billing details); internet or network activity (such as usage and log data); general geolocation inferred from IP address (precise photo geolocation is stripped, as described above); professional or employment information (such as your role and organization); and visual information (inspection photos). We collect this information from you, your organization, your devices, and our service providers, and we use and disclose it for the business purposes described in this policy. We disclose these categories only to the service providers listed on our Subprocessors page, to destinations your organization directs us to send data to, and as described under “How we disclose information” above.
How long we keep each category. Account, profile, and professional information is kept while the account is active and deleted or de-identified after closure. Inspection records are kept while the account is active. Visual information (photos) is kept for the organization’s configured retention period, one year by default. Commercial and billing information is kept as long as needed for accounting and tax obligations. Usage, server-log, and diagnostic data is kept on a rolling basis for security and troubleshooting. The one-way trial hash described in “Data retention” is kept for as long as we offer free trials. See section 10 for the full detail.
You have the right to know/access, delete, and correct your personal information, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information. We do not sell or share personal information, and we do not use sensitive personal information for purposes that require a right-to-limit option. We will not discriminate against you for exercising these rights. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct-marketing purposes. To exercise a right, contact us using the details above; an authorized agent may act on your behalf with valid authorization.
14. International users and data transfers
The Service is operated from, and your information is processed and stored in, the United States, and we offer it only in the United States (see section 4). If you happen to access the Service from outside the United States, for example while traveling, your information will still be transferred to and processed in the United States, where data-protection laws may differ from those in your country.
15. Children’s privacy
Artifact is a workplace tool intended for adults. Our Terms of Service require account holders to be at least 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact us and we will delete it. Where a worker under 18 appears in an inspection photo, the organization that captured the photo is responsible for any consent required (see our Terms).
16. Changes to this policy
We may update this Privacy Policy from time to time, and we will revise the “last updated” date above whenever we do. If we make a material change to how we handle personal information, we will give reasonable advance notice by email to account administrators or through the Service before the change takes effect, and material changes apply only going forward, not retroactively to information already collected under a prior version. Where applicable law requires your consent for a change, we will ask for it rather than infer it from your continued use.
17. Contact us
Questions about this policy or our data practices? Contact Epitaph LLC at privacy@epitaph.llc, 203 Pitt St, Leechburg, PA 15656.