Privacy Policy, Art of Wipe
Effective date: 1 January 2026
Art of Wipe (“Art of Wipe”, “we”, “us”, “our”) operates artofwipe.com. Contact for privacy: privacy@artofwipe.com
This policy explains what personal data we process when you use artofwipe.com and why. We have tried to keep it plain. Where this policy uses GDPR terms, we act as the data controller for the data described here.
We run our own privacy-first analytics (no cookies, no ad networks), we host in the EU, and we do not sell your personal data.
1. What we collect
Account data (when you sign in). We use Steam, Discord, or Google to sign you in. From that we receive and store, depending on the provider: a provider user ID (for example your Steam ID), a username or display name, an avatar, and, for Discord and Google, your email address. We store a first-party session so you stay signed in.
Consent record. When you first create an account we record which version of these policies you agreed to and the time you agreed, so that acceptance is auditable.
Abuse-prevention data. When you start a session we record a one-way HASHED form of your IP address (not the IP itself) to enforce our per-network account limit and to protect the Service. We cannot read the original IP back from the hash.
Service data. The maps you generate, your generation and edit history, the map settings and recipes, and the maps you save to your account.
Feedback data. If you send a bug report, a rating, or a screenshot, we store what you send so we can reproduce and fix issues. Screenshots are visible only to our administrators.
Analytics (usage) data. We use our own self-hosted analytics (Umami) to understand how the site is used (pages viewed, referrer, approximate country, device and browser type). It is cookieless and does not build a cross-site profile of you. IP addresses are used only transiently to derive coarse location and are not stored in identifiable form.
2. How we use it, and our legal bases (GDPR)
- To operate the Service, create and secure your account, generate and store your maps, and enforce limits. Legal basis: performance of our contract with you, and our legitimate interest in running the Service securely.
- To prevent abuse (the hashed-IP account limit, rate limits). Legal basis: our legitimate interest in protecting the Service and other users.
- To understand and improve the Service through cookieless analytics. Legal basis: our legitimate interest in a working, well-performing site. Because the analytics is cookieless and does not identify you, we rely on legitimate interest rather than consent.
- To respond to your feedback and support requests. Legal basis: legitimate interest and, where relevant, performance of our contract.
- To comply with legal obligations. Legal basis: compliance with law.
3. Cookies
We use only the cookies that are strictly necessary to run the Service: a first-party session cookie that keeps you signed in, and an access cookie used by our infrastructure. Our analytics does not use cookies. Because we set only strictly-necessary cookies, we do not show a cookie consent banner. If we ever add non-essential cookies, we will ask for your consent first and update this policy.
4. Who we share it with (subprocessors)
We do not sell your personal data and we do not share it with advertising networks. We use a small set of service providers to run the Service, each under a data processing agreement:
| Role | Purpose | Location |
|---|---|---|
| Managed database and authentication | Holds your account and your maps | EU |
| CDN and edge security | Delivery and access protection | Global edge, under SCCs |
| Application hosting | Runs the generation service | EU |
| Your chosen identity provider | Sign-in (Steam, Discord, or Google) | Per their own policies |
We can provide the specific named providers on request. Our web analytics is self-hosted on our own infrastructure, so usage data is not sent to a third-party analytics company.
We may also disclose personal data where necessary to comply with the law, to enforce our Terms, or to protect our rights, users, or the public.
5. International transfers
Your account and map data are stored in the EU. Some infrastructure providers (for example a global CDN edge) may process limited data outside the EU; where they do, transfers are covered by appropriate safeguards such as Standard Contractual Clauses.
6. How long we keep it
- Account data: while your account exists. When you delete your account, we delete or irreversibly anonymize your personal data, except where we must keep something to meet a legal obligation.
- Maps: until you delete them. You can hard-delete a map from your account at any time.
- Hashed-IP abuse ledger: kept only as long as needed for abuse prevention.
- Analytics: kept in aggregate; it does not identify you.
7. Your rights
Depending on where you live, you have the right to access your data, correct it, delete it, restrict or object to processing, obtain a portable copy, and withdraw consent where we rely on it. You also have the right to complain to your data protection authority. You can delete your maps and your account in the app, or contact us at privacy@artofwipe.com to exercise any of these rights. We will not discriminate against you for exercising them.
8. We do not sell your personal data
We do not sell your personal data and we do not share it for cross-context behavioral advertising, as those terms are used under laws such as the California CCPA/CPRA. We have no advertising trackers on the site.
9. Children
The Service is not directed to children and you must meet the minimum age of the identity provider you use (Steam, Discord, or Google) and the minimum age of digital consent in your country.
10. Changes
We may update this policy. We will change the effective date above and, for material changes, take reasonable steps to notify you.
11. Contact
Questions about this policy or your data: privacy@artofwipe.com