Privacy Policy
Questions: studioassistant@foldlaboratories.com
1. Who we are
Fold Laboratories, LLC is a Colorado limited liability company. We operate a curated marketplace where galleries and artists list original artworks, and where buyers discover and purchase them through an AI agent acting on their behalf.
We are the controller of the information described in this policy. Where we handle information on a seller's behalf purely to complete an order, we act as their processor for that limited purpose.
2. What we do not do
We think it is as important to say what we do not collect as what we do.
No analytics or tracking. We run no analytics platform, no advertising pixels, no session recording, and no cross-site tracking. We do not know how long you looked at anything.
No advertising. We do not sell personal information, we do not share it for targeted or cross-context behavioural advertising, and we do not accept advertising on the marketplace.
No card data. Card numbers never reach our systems. Payment is completed with a limited-scope token issued by Stripe, and there is no field in our database capable of storing a card number.
Almost no activity logging. Our systems record only these kinds of event: that access to an artwork image was granted; that a payment could not be automatically reconciled, and how a person then accounted for it; that a payment authorisation an agent had given us was withdrawn; that, after review, we removed a listed work or a single print of one, suspended a seller account, or reversed either; that we refunded a sale, in full or in part, whether we did so ourselves or through our payment processor's tools, and whether a refund failed or did not return our fee; that a buyer's bank disputed a payment, and how that dispute was resolved; that a card network warned us a payment might be fraudulent; that our payment processor judged a payment to carry a higher risk of fraud, and that a person then reviewed the sale; that we paid a seller out, paused or resumed a payout, or that a payout did not reach a seller’s bank, and when a seller’s account was put on, or returned from, the payout schedule we run; how a refund that failed was then put right; that we submitted evidence in answer to a dispute, or could not, and which of our records it drew on; that, once a dispute was lost, we took the disputed payment back from the seller or bore the loss ourselves, and whether we reversed the tax recorded for it; that a seller recorded sending a sold work, or corrected that record, with the carrier, tracking number and date they gave; and that we sent, or tried to send, an email about a sale, to whom, when, and whether our email provider accepted it, including when we sent one again or closed it by hand. Separately, when our own software fails we record that it failed, where in our code, and which path was being requested — never who was requesting it. We do not keep a general log of what you looked at.
No buyer accounts. Buying does not create an account, a profile, or a marketing relationship.
3. What we collect, and from whom
Three kinds of people or systems have information with us, and each is different.
3.1 Sellers and artists
Sellers are the only people with accounts, and in most cases the seller is the artist. We collect:
- Legal name and display name
- Contact email, contact phone, and contact display name
- Website address and country
- A Stripe Connect account identifier
- A record of each version of the Seller Agreement you accept: which version, a fingerprint of its text, which signed-in person accepted it, when, and where in the studio
- For each work you sell, your record of sending it: the carrier, the tracking number, the date, and, if you give us one, a receipt or label
We never store a password. Signing in uses either a one-time link sent to your email address or Google sign-in. Identity verification and banking details for payouts are collected and held by Stripe, not by us.
Your record of sending a work is kept so that we can show it is on its way, and it is the evidence we send if the buyer disputes the payment (section 3.2).
Each listing also carries information about the artist who made the work: name, biography, year of birth, year of death, and nationality. Usually that is the seller describing themselves. Where a listing describes someone else — an artist a gallery represents, or an artist who is no longer living — the seller is responsible under our Seller Agreement for having the right to provide that information. If you are an artist and want to know what a listing says about you, or want it corrected, write to studioassistant@foldlaboratories.com and we will work with the seller to resolve it.
3.2 Buyers
Buyers reach the marketplace only through an AI agent. There is no buyer-facing website to browse and no account to create.
At checkout, and only at checkout, we collect the minimum needed to complete and lawfully tax a sale:
- Optional: email address, name, and phone number. If you give an email address, we send your order confirmation to it.
- Required: a postal address
The postal address is required for two reasons: sales tax cannot be calculated without a destination, and it is where the seller sends the work. It goes to the seller for that purpose, in their notice of the sale and on their record of it.
Two more things happen to it, and to your name where you gave one:
- With the payment. We send your name and delivery address to our payment processor, Stripe, with the payment, so that it can screen the payment for fraud. Where you gave no name, we send no address.
- If you dispute the payment. If you dispute the payment with your card issuer, we answer the dispute with our evidence: your name, email address and delivery address as you gave them at checkout, our record of your approval, our record that we sent your order confirmation, the returns policy that applied, your order page, and the seller's record of sending the work. That goes to Stripe, and through Stripe to your card issuer.
We do not use your information for anything else, and we never send your network address or anything about your device.
Buyers do not receive marketing from us and are not profiled.
3.3 AI agents
When an AI agent uses the marketplace, we record its identifier, its trust tier, the surface it is operating from, and the text of what it searched for.
That last item deserves its own section — see Section 6.
4. How we use each kind of information
This section explains what we actually do with the information described above, and what we do not do with it.
Seller and artist information is used to operate your account, to publish and present your listings, to verify you so that you can be paid, to pay you your share of each sale, to communicate with you about sales and the service, to answer a buyer's dispute about a sale you made, and to meet our tax and record-keeping obligations. Artwork images and the text you write are also sent to the AI services in Section 5 so that listings can be given structured attributes and made findable by agents.
Buyer information is used for one transaction and nothing more: to calculate the correct sales tax, to take the payment and screen it for fraud, to arrange delivery, to send the order confirmation, and to answer a dispute about the payment. We do not use it to market to you, to build a profile, or to inform what we show anyone else.
Agent information is used to authenticate the agent, apply rate limits and trust tiers, keep the marketplace safe from abuse, and understand in aggregate what kinds of work are being sought — subject to the erasure periods in Sections 6 and 7.
We do not use any of this information for advertising, and we do not sell it.
5. Who receives information
We use eight external services. This is the complete list.
| Service | What we send | Why |
|---|---|---|
| Stripe | Payment details; seller verification information; transaction and destination data; with each payment, the buyer's name and delivery address where a name was given; and, when a payment is disputed, the evidence in section 3.2 | To take payments and screen them for fraud, verify sellers, pay sellers out, calculate tax, and answer disputes with the card issuer |
| Supabase | Our database, authentication, and file storage: artwork images, and the receipts or labels sellers give us with a dispatch record | To store the marketplace's records and files |
| Anthropic | Artwork images and seller-supplied text | To extract structured attributes from listings |
| Voyage AI | Artwork text | To generate search embeddings so agents can find works |
| Resend | Email addresses, and the email we send to them: sign-in links for sellers; for each sale, a notice to the seller naming the work, the amounts, and the buyer's name and delivery address; where the buyer gave an email address, the buyer's order confirmation; and, if a buyer's bank disputes a payment, notices to the seller naming the work, what the bank said, what we need from them and by when, and how the dispute ended; and notices to us about a dispute, naming the seller and the work, never the buyer's details | To deliver sign-in links, sale notices, order confirmations, and dispute notices |
| Better Stack | When our software fails: the type of the error, the file and line in our own code where it happened, the identifier we generated for that request, and which of our endpoints was being asked for — its shape, such as /orders/:reference, never the actual address. No personal information of any kind | To tell us our software is broken, and to check from outside that the service is answering |
| Fly.io | Every request to our API, which it runs. Our request log records the method, the path without its query, the status, the time taken and a request identifier — never who was asking | To host the API |
| Vercel | Every request to the seller studio and to this website, which it runs | To host the studio and the website |
Neither AI service trains on what we send it.
- Anthropic. Under Anthropic's commercial terms, content sent through its API is not used to train its models, and inputs and outputs are deleted from its systems within 30 days.
- Voyage AI. We have opted our account out of data storage and model training. Artwork text we send for search indexing is not retained at all.
Artwork images are sent to Anthropic within the request itself, because our image storage is private and not publicly reachable.
Better Stack is told that something broke, not what anyone was doing. It is the only service here that receives nothing about you. When our software hits an error it cannot handle, we send the error's type, the place in our own code it came from, and the SHAPE of the endpoint that was being asked for — /orders/:reference, never /orders/ followed by your actual reference. That distinction is deliberate: a buyer's order link is itself the key to that order, so sending a real one would be handing out a key. We also do not send, and our software has no way to send, the address you were visiting in full, anything you typed, the contents of the request, your sign-in details, your network address, or the text of the error itself, because an error's text can quote the data it was working on. Better Stack also checks from the outside that our service is answering, by requesting pages that contain no personal information. Better Stack stores this in the United States.
Resend sends only transactional email for us, never marketing. We have turned off its open and click tracking, so our messages carry no tracking pixel and no rewritten links. Resend keeps a copy of each message it sends for 30 days. If an address bounces, or its owner marks our mail as spam, Resend keeps that address on a list of addresses not to send to, until we remove it.
Beyond these eight, we disclose information only where the law requires it, to enforce our agreements, to protect people from harm, or in connection with a merger or sale of the business — in which case this policy continues to apply or you will be told otherwise.
6. Buyers, agents, and search text
We want to be unusually direct about this, because it is the part of our system that touches people who never chose to deal with us.
When an AI agent searches on your behalf, the words it sends us are recorded. A search phrase can carry more detail than a buyer would expect us to keep — about taste, a home, a gift, a budget.
So we do three things:
We erase it. Search text is deleted after seven days. The record that a search happened survives so we can understand demand; the words do not.
We never show it to sellers. Galleries and artists see that interest exists in a kind of work. They never see the phrasing a buyer used. Showing them would be a disclosure to a third party, and a buyer who never visited our site has no way to have agreed to it.
We publish this policy openly so that any agent acting for you can retrieve and present it before it acts, and we require agents that use our marketplace to make our terms available to the people they act for. If you bought something through an agent and want to know what we hold, write to studioassistant@foldlaboratories.com — you do not need an account to ask.
Related records follow the same principle: demand events are deleted after thirty days, and agent task history after twenty-four hours.
7. How long we keep things
| Information | Retention |
|---|---|
| Agent task history | 24 hours |
| Search text | 7 days, then erased while the anonymous record of the search remains |
| Demand events | 30 days |
| Seller account information | While the account is open, then 12 months |
| Buyer contact and delivery details | With the order record, for the period below |
| Transaction and order records | 7 years, for tax and accounting obligations |
| A seller's record of sending a work, and the receipt or label they gave | With the order record, for the period above |
| Evidence we send in answer to a payment dispute | Our record of what we sent is kept with the order record, for the period above. What Stripe and the card issuer keep is under their own terms |
| Emails we send about a sale | The record that one was sent, to whom and when, is kept with the order record, for the period above. The text of the message is deleted 30 days after it is written, whether or not it could be delivered |
| Records that our software failed | Held by Better Stack under our account. They contain no personal information, so there is nothing in them to delete. |
| Seller attestations about a Work | Retained for as long as we operate, as the record of what a seller affirmed about an artwork. Questions of authenticity and title can arise long after a sale, and this record protects both buyer and seller |
| A seller's acceptance of the Seller Agreement | Retained for as long as we operate, as the record of what was agreed and when. A question about it can arise long after the account closes |
| Correspondence with us | 3 years |
Where the law requires us to keep something longer, we do, and we delete or anonymise it once that reason ends.
8. Sign-in and session information
Signing in requires a session credential so that we can keep you signed in between pages. It is used for that and nothing else. We do not use cookies or similar technologies for analytics, advertising, or tracking.
9. Your rights
Wherever you live, you may ask us to:
- Tell you what information we hold about you and how we use it
- Correct anything inaccurate
- Delete it, subject to records we must keep by law
- Give you a copy in a portable format
- Opt out of any sale, targeted advertising, or profiling — we do none of these, but the right stands
- Appeal if we say no
We do not treat anyone differently for exercising a right.
How to ask. Email studioassistant@foldlaboratories.com. You do not need an account. We reply within 45 days, and if we need longer we will tell you why before that period ends.
Verifying you. We confirm who you are before acting, usually through the email address connected to the information. An authorised agent may ask on your behalf with your written permission.
If we decline. You may appeal by replying with "Privacy Appeal" in the subject line. We answer appeals within 45 days and explain our reasoning. If we still decline, we will tell you how to contact your state Attorney General.
Universal opt-out signals. We do not sell personal information or share it for targeted advertising, so every visitor already has what a Global Privacy Control signal asks for, whether or not they send one.
10. Security
We protect information with encryption in transit and at rest, access controls limited to what each person or system needs, and authentication on the endpoints that agents use. Artwork images are held in private storage that is not publicly reachable. Card data never enters our systems, and passwords do not exist to be stolen.
No system is perfectly secure. If a breach affects your information, we will tell you and the relevant authorities as the law requires.
11. Children
The marketplace is for adults. We do not knowingly collect information from anyone under 18, and we delete it if we learn we have.
12. Where information is held
We are based in the United States and process information here and with the service providers listed in Section 5. If you contact us or buy from outside the United States, your information will be transferred to and processed in the United States, where data protection law may differ from your own.
13. Changes
We may update this policy. If a change is material, we will post notice at least 30 days before it takes effect and update the date above. Earlier versions are available on request.
14. Contact
studioassistant@foldlaboratories.com Fold Laboratories, LLC · Denver, Colorado, United States