Privacy Policy
This Privacy Policy explains how Art Block (the “Service”) collects, uses, and shares personal information when you use our mobile application. “We”, “us”, and “our” refer to the operator of Art Block described under Who we are below. By using the Service, you agree to this policy. If you do not agree, please do not use the Service.
Who we are
Art Block is a mobile app for scheduling, logging, and (optionally) sharing creative practice. It is developed and published by an independent operator based in Quebec, Canada, using the Art Block name in the App Store and related materials.
For privacy law (including who is responsible for decisions about your personal information), the data controller is the same person or business identified as the app’s developer / seller on the Apple App Store listing for Art Block. You can reach that party through the contact options Apple provides there, or as described under Contact below.
Backend providers we use
Art Block relies on a small number of third-party processors to run the Service on our behalf:
- Apple — App Store distribution, in-app purchases, local notification delivery, and platform-level protections.
- RevenueCat — RevenueCat validates App Store purchases and manages subscription entitlements. It may process device identifiers and purchase / transaction information.
- Supabase — Supabase hosts the Art Block backend. Cloud backup of your practice content, your social profile, your shared sessions and any cover photos you attach to them, your follows / groups / likes / comments, your in-app notifications, and your moderation actions (blocks, mutes, reports) are stored on Supabase infrastructure. Files (such as session cover photos, profile avatars, and group avatars / banners) are kept in Supabase Storage.
Supabase data is currently hosted on infrastructure located outside Canada (typically in the United States, depending on the project region). If we move to a different region we will update this policy.
Information we collect
Art Block is local-first: your practice journal lives on your device, with cloud backup keeping a copy on our backend so you can move between devices. The optional social features additionally let you share parts of your practice with other people you choose to follow.
1. Account identifier
When you first use a feature that requires the backend (cloud backup or anything social), the app automatically creates an account on Supabase tied to a randomly generated identifier. You don’t have to type a username or password — the credentials are generated and stored securely on your device. We may later introduce optional “Sign in with Apple” or “Sign in with Google” so you can recover your account on a new device. We will update this policy before that ships.
2. Practice content (cloud backup)
With cloud backup enabled, the app uploads a copy of your local practice content — your scheduled practices, session logs, focused minutes, notes, mediums and pursuits — to your private row on Supabase. Only you (the signed-in account) can read this row. We do not analyse the contents of your practice journal.
3. Social profile (only if you turn social on)
Turning social on stores a public-style profile keyed to your account: username, bio, profile avatar, discoverability preference, and whether you require manual approval for follow requests. Other Art Block users may see this profile if you make yourself discoverable, or if they look you up by username.
4. Shared sessions, likes, and comments
When you share a practice session — manually or via the auto-share setting — a copy of that session (title, category, mediums summary, focused minutes, log time, your note, and the cover photo you attached, if any) is published to your Art Block feed at the visibility you chose (private, followers, public, or to a specific group). Cover images are uploaded to Supabase Storage and served through short-lived signed URLs. Other users’ likes, comments, and timestamps are stored against that session row.
5. Followers, following, and groups
We store your follow relationships, follow requests (incoming / outgoing / accepted / declined), group memberships, group session templates you create or adopt, and (for group admins) group avatar / banner images. Group leaderboards and feeds are produced from this data.
6. In-app notifications
When someone follows you, requests to follow you, accepts your follow request, or likes / comments on a session you shared, we create an in-app notification row referencing the actor and the related entity. You can turn most notification categories off in Settings (follow, likes, comments). Follow-request and follow-accepted notifications stay on because they are actionable. All notifications today are in-app only; we do not currently send marketing or push notifications. Practice reminders are scheduled as local notifications on your device.
7. Moderation data (blocks, mutes, reports)
We store the following so the app’s safety features work:
- Blocks — pairs of (blocker, blocked) account identifiers. Blocking another user also hard-deletes any prior follows, follow requests, likes, comments and notifications between the two of you.
- Mutes — pairs of (muter, muted) identifiers. The muted user is not told they were muted.
- Reports — when you report a session or profile, we store the reporter’s account identifier, the reported user’s account identifier, the reported session id (if any), the category you chose, and any short text you added. The Art Block operator can review reports for moderation purposes. Reports are not visible to other users.
8. Anti-abuse rate-limit log
To prevent automation and accidental loops from overloading the Service, the backend keeps a short, append-only log of write attempts (follow, like, comment, publish session, change session cover) keyed to your account. Entries are automatically deleted within roughly an hour. The log is not exposed to clients and is only used to enforce per-user thresholds.
9. Photos and images you choose
If you attach a cover photo to a session, set a profile avatar, or add a group banner, the app accesses your photo library only when you select an item. We re-encode the chosen image to a small JPEG before uploading. Avatar bytes are stored on the corresponding profile / group row; session covers are stored as files in Supabase Storage.
Art Block does not read your contacts, calendar, location, microphone, or device identifiers for advertising. The “Find friends” screen is a username search only.
10. Payment-related information
Paid features are purchased through Apple’s App Store. We do not receive your full payment card details. RevenueCat receives the transaction information needed to validate purchases and report entitlements.
11. Device and technical data
Such as device type, operating system, app version, and crash / diagnostic information allowed by your device settings. If we add third-party crash or analytics tools, we will list them here and update this policy before they go live.
How we use information
We use personal information to:
- Provide, maintain, and improve the Service;
- Sync your practice content across your devices via cloud backup;
- Operate the optional social layer — show your profile to people you’ve made yourself visible to, deliver follow / like / comment / group activity, and route in-app notifications;
- Manage subscriptions and entitlements (through RevenueCat);
- Enforce our Terms of Use and protect users — for example by honouring blocks and mutes, applying server-side rate limits, reviewing reports, and removing or restricting content or accounts where appropriate;
- Detect, prevent, and address technical or security issues, abuse, or fraud;
- Comply with law and protect rights, safety, and security.
How information is shared with other users
Most of what the social features store is intentionally visible to other users. The visibility you choose for each shared session controls who can see it:
- Private — only you see it on your profile.
- Followers — visible to accounts that follow you.
- Public — visible to any signed-in Art Block user who can find you (subject to discoverability and follow-approval settings).
- Group — visible only to active members of the group you tagged.
Your username, bio, avatar, follower / following counts, and any sessions you choose to publish at followers or public may be shown to other Art Block users. Likes and comments you leave on someone else’s session are visible to the audience that can see that session.
Storage, retention, and international transfers
Cloud backup, social, and moderation data are stored on Supabase infrastructure (currently outside Canada, typically in the United States). Subscription processing through RevenueCat may also involve servers outside Canada.
We retain personal information only as long as reasonably needed for the purposes described in this policy:
- Your cloud backup persists until you delete the data through the app, or you delete your account.
- Shared sessions, likes, and comments persist until you delete them or your account.
- Notifications are pruned over time and you can dismiss them individually.
- Reports may be retained even after the related session or account is removed, where reasonably necessary for safety, abuse prevention, or to meet legal obligations.
- Rate-limit log entries are removed within roughly an hour.
Sharing with third parties
We do not sell your personal information. We may share information with:
- Apple — to operate distribution, subscriptions, and platform-level protections.
- RevenueCat — to validate App Store purchases, manage entitlements, and perform related technical operations.
- Supabase — as our hosting and database processor, for cloud backup, the social features, file storage, and authentication.
- Other service providers — if we add new vendors (for example email delivery, push notifications, or analytics), we will list them here when they apply.
- Legal or safety — when required by law, legal process, or a proportionate request by public authorities, or to protect users, the public, or the Service.
Your choices and rights
- You can turn social off at any time in Settings. When social is off you are not discoverable, your profile is not shown to other users, and auto-share is disabled.
- You control your discoverability, whether follows require manual approval, the default audience for shared sessions, and which notification categories generate activity rows for you.
- You can delete your shared sessions, likes, comments, follows, and groups from inside the app. Deleting a shared session also removes its cover photo from Supabase Storage.
- You can block or mute any other user from their profile or any of their cards in the feed.
- You can report a session or profile that violates our Terms.
- You can request full account deletion (cloud backup, social profile, shared sessions, follows, groups, etc.) by contacting us as described under Contact. Some moderation records (such as past reports filed by or against you) may be retained where reasonably necessary for safety or to meet legal obligations.
- If you are in Canada, including Quebec, you may have rights to access your personal information, correct inaccuracies, withdraw consent where processing is consent-based, and obtain information about how we handle personal information, subject to applicable exceptions. You may also have the right to challenge compliance and, where applicable, to request cessation of dissemination or de-indexation in line with local law.
- To exercise these rights, contact us as described under Contact. We may need to verify your identity before responding.
Children
The Service is a productivity and journaling style tool for artists; it is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe a child has provided us with personal information, please contact us using the details under Contact and we will take reasonable steps to delete it. Age thresholds and consent rules can vary by region; additional requirements may apply where local law says so. The social features in particular are not intended for users under 13, and we may suspend accounts we reasonably believe are used in violation of these age requirements.
Changes
We may update this policy from time to time. When we do, we will post the updated version on this page and change the “Last updated” date above. If we materially expand what we collect — for example by adding push notifications, a public web profile, advertising, or new third-party processors — we will surface a notice in the app where practicable.
Contact
Questions about this policy or requests regarding your personal information:
- Use the developer contact or support channel shown on the Apple App Store listing for Art Block.
- If we publish a dedicated email address for privacy or account deletion requests, we will add it here so you can reach us directly.
Apple Inc. has its own privacy policy governing its platforms; for App Store, iOS, and related payment processing, see Apple’s documentation for how Apple handles data. Supabase and RevenueCat also publish their own privacy policies; see the links above.