Privacy Policy
Last updated: 28 July 2026
Controller. Oscar Wiren, trading as Larssoni (sole trader), 1 Potters Road, London SW6 2WQ, United Kingdom (contact: support@larssoni.com).
Which role we play depends on the data, and we think it’s worth being precise rather than vague:
- Your account data — we are the controller.
- The contents of the artifacts and connected data sources you publish — you are the controller and we act as your processor, on your instructions (see the DPA).
- The email address a gated viewer enters to unlock an artifact — we are the controller. We decide to ask for it, what to check it against, how briefly to keep it, and that the artifact’s owner is never shown it. We do not act on the owner’s instructions here, so it would be wrong to call ourselves a processor for it.
What we collect.
- Account data: your email, sign-in method, workspace name, plan, and (via Google sign-in, if used) your Google account email and basic profile.
- Content you create: the artifacts you paste or upload, their versions, and metadata (title, tags, source model).
- Connected-source data: when you connect a Google Sheet or upload a CSV/JSON, we read and store the data needed to refresh your artifact. Your real data values are never sent to our AI provider — see below.
- Viewer data: for gated artifacts, we use the viewer’s email address once — to check it satisfies the gate and to send the access code — and then keep only a one-way, per-artifact hash of it plus open timestamps. This lets the owner see how many distinct people opened an artifact and how often. The owner is never shown who. The hash cannot be reversed to an address and cannot be matched against any other artifact.
- Usage/technical: basic analytics (privacy-respecting, no third-party ad trackers), and standard server logs. We do not run third-party advertising beacons inside your artifacts.
What our AI provider sees, and when. Setting up an auto-updating artifact involves exactly one call to our AI provider (Anthropic), whose only job is to locate where each number appears in your page. That call sends the artifact’s own markup — the page you made — together with your data source’s column names and example rows we generate synthetically ourselves. Your real data values are never sent. After setup there is no AI provider in the loop at all: every refresh is a deterministic substitution performed by our own systems, with no model call. We do not use Your Content or your connected data to train AI models.
Google user data (Limited Use — required disclosure). If you sign in with Google we receive your Google account email and basic profile, used only to create and secure your account. If you connect a Google Sheet, we request read-only access to your spreadsheets and use it for exactly one thing: reading the sheet you choose, on the schedule you set, to refresh the numbers in your artifact. We store an encrypted copy of the access token and the sheet data needed for your artifact; we never modify your sheets, never access sheets you did not connect, and never share or sell Google user data. During AI-assisted setup we send only the structure of your data (column names and synthetic example rows) to our AI provider — never your real values. Disconnecting a sheet (Settings → Sources) revokes our access and stops all reads; you can also revoke at myaccount.google.com/permissions. Larssoni’s use of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace user data and developer policy, including the Limited Use requirements. In particular, we do not use Google user data — nor anything aggregated, anonymised or derived from it — to create, train or improve any machine-learning or artificial-intelligence model.
Why / lawful basis.
| What | Why | Lawful basis |
|---|---|---|
| Account data | To create and run your account | Contract (Art. 6(1)(b)) |
| Artifacts and connected-source data | To host, refresh and display what you publish | Contract; and as processor, your instructions |
| A gated viewer’s email | To check they satisfy the gate the owner set, and to send them a one-time code | Contract — it is the only way to deliver the access the viewer is asking for (Art. 6(1)(b)) |
| The anonymous open-count hash | So the owner can see how many people opened their artifact | Legitimate interests (Art. 6(1)(f)) — a hash that cannot be reversed or correlated is the least intrusive way to answer “how many”, and we do not use it for anything else |
| Security, abuse prevention, safety checks | To stop the service being used to defraud or harm people | Legitimate interests, and legal obligation where it applies |
| Billing | To charge you | Contract |
We do not rely on consent for any of the above, so there is no consent for you to withdraw — but you can object to anything we do on legitimate interests by emailing support@larssoni.com.
Automated decision-making. We run automated safety checks on published artifacts (phishing-pattern scoring, credential detection, threat-list checks). These can hold an artifact for review, and a person reviews it. They are not automated decisions producing legal or similarly significant effects on individuals within the meaning of Article 22, and we do not profile you.
We do not sell your data and do not use your content or connected data to train AI models.
Who we share it with (subprocessors): Cloudflare (hosting, storage, edge — EU/global), Stripe (payments, merchant of record), Postmark (transactional email), Anthropic (AI setup pass — receives structure-only data as above).
Google is not on that list, deliberately. If you sign in with Google or connect a Google Sheet, we aren’t sending your data to Google — Google already holds it, and discloses a narrow slice to us at your instruction, on its own consent screen. For that, Google is an independent controller rather than our subprocessor. What we then do with what we receive is covered by everything else on this page.
Where data is held. Your artifacts and account data live on Cloudflare’s network (storage and database on Cloudflare infrastructure); payments data is held by Stripe. We are UK-based. Where data goes outside the UK: Cloudflare, Stripe, Google and Postmark are certified under the UK Extension to the EU-US Data Privacy Framework, which UK adequacy regulations cover, and we check those certifications remain active. Transfers to Anthropic rely on the EU Standard Contractual Clauses as amended by the ICO’s International Data Transfer Addendum, with a transfer risk assessment on file. Detail in the Data Processing Terms.
Retention. Actual periods, not “as long as necessary”:
| What | How long |
|---|---|
| Account data | While your account is active, then erased 30 days after deletion |
| Artifacts and their versions | Until you delete them, or 30 days after account deletion |
| Files you upload as a data source | Same — until you delete the artifact or your account |
| Google Sheet values | Never stored. Read at refresh time and discarded; we keep only a one-way fingerprint (30 days) to tell whether anything changed |
| A gated viewer’s email address | Not retained. Used to check the gate and send the code, then reduced to an irreversible hash |
| The anonymous open-count hash | Erased when the artifact is deleted, or at account teardown |
| Viewer access pass | 7 days, revocable by the owner at any time |
| Security and change audit log | 24 months; entries linked to a payment are kept 6 years to match the limitation period for contract claims |
| Billing records | 6 years (UK tax and limitation requirements) |
Your rights (UK GDPR). Access, rectification, erasure, restriction, portability, and objection. Email support@larssoni.com and we’ll answer within one month.
If you’re a viewer, not a customer. If you unlocked someone else’s artifact and want to exercise a right over what we hold about you, email support@larssoni.com. In practice there is very little to act on — we don’t retain your address — but we’ll tell you exactly what exists and erase what we can. If your question is really about the artifact’s content, that belongs to the person who published it, and we’ll help you identify who to ask.
You can also complain to the ICO (ico.org.uk). We are registered with the ICO under reference ZC202186.
Security. Artifacts are served from an isolated content domain under a strict content-security sandbox: no outbound network calls, no form submission, and scripts limited to a short allowlist of common library CDNs (jsDelivr, cdnjs, unpkg) needed to render pasted pages — never arbitrary third-party code. Data connections’ credentials are encrypted at rest. Sessions and access codes are hashed. See the DPA and the security page for detail.
Children. The service isn’t directed at under-18s.
Changes. We’ll notify material changes by email or in-product.