Privacy Policy

Effective date: September 20, 2026

This Privacy Policy explains how Artemis Insights LLC ("Artemis Insights," "we," "us") handles information across three genuinely different things this business involves: this marketing website, the vendor-operated infrastructure that supports licensing, billing, and optional integrations, and the Artemis Insights software itself. That third one matters most, and it's the one most privacy policies for software products get vague about, so we're going to be specific about it up front.

The short version: Artemis Insights is self-hosted software. Your company installs it on infrastructure your company controls — your own server, your own cloud account, your own Docker host. We do not operate a copy of it, we do not have a login to it, and your payroll records, financial data, HR records, customer data, or anything else your company puts into it is never transmitted to us, stored by us, or visible to us at any point. What we do handle is described precisely in Part 3 below, and it's a narrower list than you might expect from a typical software vendor.

On this page
  1. Part 1 — This website
  2. Part 2 — The software itself
  3. Part 3 — What we actually receive
  4. AI features
  5. Prop Trading integrations
  6. Data retention
  7. Security
  8. Your rights
  9. Sub-processors
  10. International transfers
  11. Children's privacy
  12. Changes to this policy
  13. Contact

Part 1 — This website

What we collect

If you submit the "Get started" form at myartemisinsights.com, we collect your name, email address, company name, and whatever you write in the message field, plus your phone number if you choose to provide it. We don't run tracking cookies or analytics scripts on this site, and we don't collect anything from you just by visiting it.

How we use it

Solely to respond to your inquiry — it's emailed directly to our team. We don't sell it, rent it, license it, or use it for advertising, and we don't share it with anyone except the email delivery provider (Resend) used to send that notification.

Part 2 — The software itself

When your company deploys Artemis Insights, it runs entirely on infrastructure your company chooses and controls — your own server, a cloud account you control (AWS, GCP, Azure, or any other provider), or anywhere else you choose to run it. The application, its database, and every record your company creates in it — accounts, business data, uploaded files, everything — live there, not with us. Your company is the sole operator and data controller of that instance. That means:

This is a structural fact about how the product is built, not a promise about how we intend to behave — there is no code path in the software or in our own infrastructure that sends your company's business data to us.

Creating your first admin login

Self-service signup is disabled on every install, so a brand new company's very first admin login is set up by us on your behalf, using an install-specific secret generated when your account was provisioned — not one your own instance chose for itself. Once your company has that first admin login, your own admin can create further ones (or any other kind of login) directly from within the Software, without our involvement; we're only involved again if you ask us to, for example to recover access if every admin login has been lost. The password for a login we create is generated on your own install, not by us; it passes through our infrastructure once, in order to be emailed to the admin contact you gave us, and isn't stored by us afterward. We'd recommend changing it and turning on two-factor authentication once you're signed in, both under Settings — the email we send says the same thing.

Multi-Site (optional, off by default)

A company running more than one install — separate instances for a production line, a department, a site — can optionally connect them into a hierarchy, where one install reports a small status summary (counts, not records) up to another on a schedule, and an authorized user on the receiving install can pull a connected install's compliance documents live, on demand. Both directions are install-to-install: the data travels directly between your company's own instances and never passes through, or becomes visible to, our infrastructure at any point.

This feature is off by default for every install, and turning it on for a specific pair of installs currently requires our involvement to configure — the credentials that authorize one install to read from another are generated using a setup process tied to each install's own administrative secret. In plain terms: we can configure which of your company's installs are allowed to exchange data with each other, but we do not receive, view, or store the status summaries or documents that pass between them once that's set up. If your company uses this feature, you're relying on us for that one-time setup step, not for ongoing access to what flows through it afterward.

Part 3 — What we actually receive

A small set of vendor-operated services support the software without ever touching your company's business data. Here's the complete list:

ServiceWhat it involvesWhat we receive
Licensing & account setup Provisioning your company's install and its login credentials Company name, a billing/admin contact email, and an install identifier — not anything from inside your instance. If we also create your first admin login on your behalf (see "Creating your first admin login" below), that one-time password passes through our infrastructure to be emailed to you, but isn't stored by us afterward
Update checks Your install periodically checks for a newer version Install identifier and current version number
Usage-based billing If your plan includes metered charges, your install reports usage totals to our billing relay, which forwards them to Stripe Install identifier and a numeric usage/charge amount — not the records that usage was calculated from
Remote feature management Your install checks in for any vendor-side feature or package changes Install identifier and the list of feature names your install currently supports — not data from inside those features
Account and billing administration We can view and add billing charges on your account, and, if you engage us to bill you directly, generate a Stripe payment link, produce an invoice document, or upload and send a contract for electronic signature on your behalf Each charge's amount and a free-text description of what it's for; an uploaded contract document; and, for an e-signature request, the signatory's name, email address, typed or drawn signature, and IP address. This is limited to billing- and contracting-related records — it does not extend to your company's own product data
Cross-company benchmarking (opt-in) If an admin turns this on, your install computes its own metric locally (e.g. "our overtime rate is 6.2%") and sends only that number One aggregate number per metric, tagged with a self-declared industry and size bucket — never the underlying records, and this is off unless an admin turns it on
Third-party integration setup (Gusto, QuickBooks, ADP, etc.) Connecting one of these requires an OAuth handshake with credentials that can't safely be embedded in self-hosted software, so we broker that one step A short-lived authorization code, valid for a couple of minutes and usable once. The resulting access tokens are handed directly to your own install and are not retained by us afterward
Support tickets (optional) If your company's admin opens a support request with us, using the same login credentials issued for installing the software The content of whatever you write to us, and the associated company name. We recommend not including business data (customer records, employee data, etc.) in a ticket description - a screenshot or a general description of the problem is almost always enough for us to help
Trader portal redirect (Prop Trading, optional) If a Prop Trading install has no custom domain configured, a generated trader portal link instead points to an isolated redirect page we host, which sends the trader's browser on to the install's own portal URL The install's own portal URL passes through as part of the request — this page does not look anything up, store anything, or log the destination beyond standard web server access logs any page on this site generates. It never renders any trader or account data itself

If your company runs the software in fully air-gapped mode (a license file verified entirely offline, no outbound network calls at all), none of the above happens — that mode exists specifically for companies whose policies require it.

AI features

Certain in-app features — generated insights, the assistant, receipt scanning, and report summaries — call an AI model to produce their output. Your company chooses which model: Anthropic's cloud API, using an API key your company configures and controls directly, or a locally-run model on your own infrastructure with no external call at all. Either way, that call is made directly from your company's own install using your company's own credentials — it does not pass through us, and we have no visibility into what's sent or returned. Anthropic is your company's own AI provider for this purpose, not ours; whatever agreement governs that use is between your company and Anthropic.

Prop Trading integrations (optional)

The Prop Trading module's own optional connections — market data providers, identity verification, broker connectivity (the MT4/5 bridge and any direct broker API), and payout providers including Stripe Connect, Dwolla, and Coinbase — work the same way: your company's own install communicates directly with each provider, using credentials your company configures and controls. We do not receive, route, or have visibility into trade data, identity-verification results, bank or wallet details, or the movement of funds through any of these connections. A trader's own bank routing and account number, entered through their own portal, is sent directly to the banking provider and is never stored by the install itself.

Before any text reaches an AI provider at all, the software runs it through a local filter that redacts common sensitive patterns (Social Security numbers, bank account and routing numbers, card numbers) — this happens entirely within your own instance, before anything leaves it.

Data retention

For your company's own business data, retention is entirely your company's own setting, controlled per record type by your company's admin. Nothing is deleted automatically unless an admin turns on a retention window for that record type. For the limited vendor-side data described in Part 3, we keep install/billing/license records for as long as your company's account is active plus a reasonable period after for legal, tax, and support purposes, and delete or anonymize them thereafter unless we're required to keep them longer.

Security

Within the software: sensitive credentials and connected-integration tokens are encrypted at rest, optional two-factor authentication is available for every account, and an audit log (itself tamper-evident, using a hash chain that makes an after-the-fact edit detectable) records authenticated actions for your company's own admins to review. Live compliance-document access between connected installs (Multi-Site, described above) requires two independently-generated credentials together, not one — a design specifically meant to mean a single leaked credential isn't sufficient on its own. Within our own vendor-operated infrastructure: access to license, billing, contract, and account records is restricted to authorized personnel, and OAuth client secrets used for integration brokering are never embedded in the software itself.

Encryption in transit depends on how your company deploys the software, since that's infrastructure your company controls, not us. Traffic over Tailscale (our recommended setup for remote access — see the software's own setup documentation) is encrypted at the network level regardless of anything else. Beyond that, the software ships listening on plain HTTP by default; encrypting traffic to it — via a TLS-terminating reverse proxy, a Tailscale Let's Encrypt certificate, or an equivalent — is a setup step your company needs to take, and we recommend against exposing an instance directly to the public internet without doing so first.

No system is perfectly secure, and self-hosting shifts real security responsibility to your company — keeping the underlying server patched, access controls tight, and backups handled is your company's job, not ours, since we don't operate the infrastructure it runs on.

Your rights

For data inside your company's own instance — including data about your own employees or customers — your company's admins have direct, full control: export, correction, and deletion tools live in the product itself (Database tab), and any data subject request from your employees or customers about that data should go to your company, since your company is the one who determines what's collected and why.

For data we hold directly (Part 3's license/billing/account records, or a contact form submission), you can ask us to access, correct, or delete it by writing to us through our contact page. We'll respond within a reasonable time and may need to verify your identity or authority to act for your company first. Depending on where you're located, you may have additional statutory rights (for example under the GDPR or a US state privacy law) with respect to data we hold directly — the same contact applies.

Sub-processors

We rely on the following third parties to operate the website and the vendor-side services described in Part 3. Each receives only what its function requires:

Anthropic is not listed here because, as described above, your company's use of Anthropic's API happens directly between your company's own install and Anthropic — we're not a party to that data flow and it isn't processed through anything we operate.

International data transfers

Because Artemis Insights is self-hosted, your company's own business data stays on whatever infrastructure your company chooses, in whatever location your company chooses — international transfer of that data, if any, is entirely your company's own decision and responsibility. The limited data described in Part 3 that we do handle may be processed in the United States, where our infrastructure and sub-processors are located.

Children's privacy

The Service is intended for business use by adults and is not directed at anyone under 18. We don't knowingly collect information from anyone under 18.

Changes to this policy

If we make a material change to this policy, we'll update the effective date above and, for significant changes, notify account admins directly (by email, or via a notice in release-admin.html's Customers section).

Contact

Questions about this policy: reach us through our contact page. Artemis Insights LLC, 4128 Fort Henry Dr Ste D #116, Kingsport, TN 37663.