Artica
Pricing Security
Log in Free 30-Day Audit

Legal

Privacy Policy

Last updated 19 July 2026

This policy explains what data Artica collects, why, who helps us process it, and the choices you have. It covers the marketing site at askartica.com, the Artica application at app.askartica.com, and the Artica Chrome extension.

Two roles to keep straight. For your Artica account data (name, email, workspace, billing), Artica is the data controller. For the support-ticket data inside the Zendesk instance you connect — which contains your own customers' personal data — you are the controller and Artica is a processor acting on your instructions. If you're a support requester of a company that uses Artica, contact that company directly; we'll assist them as their processor.

1. Who we are

Artica is a B2B service that analyzes a company's Zendesk support tickets to find help-center coverage gaps, and helps that company write and export help-center articles. It is operated by Hosam Hassan LLC ("Artica," "we," "us"), a Wyoming limited liability company at 30 N Gould St. # 48472, Sheridan, WY 82801, USA. For any privacy matter: hello@askartica.com.

2. What we collect and store

Your account. Your name and email address, via our sign-in provider Clerk (Google sign-in or email/password — Clerk holds the credentials; we never see passwords), plus a user identifier, your workspace membership and role (Owner / Editor / Viewer), invitations you send (invitee email, role, timestamps — the invite link token itself is stored only as a hash), and your email preferences.

Your Zendesk connection. Your Zendesk subdomain, the OAuth scopes you granted, your help center's locale, the identity of the person who authorized the connection, and the OAuth tokens — encrypted with AES-256-GCM before storage.

The product's output (derived data). Topic categories and topics: AI-generated titles, descriptions, and example questions; numerical embedding vectors; ticket volume counts by month; and Zendesk ticket ID numbers used as links back into your own Zendesk. Also metadata about your already-published help-center articles: title, public URL, section, a content hash, and an embedding.

Content you author. Articles drafted in Artica and images you add, including workflow screenshots captured by the Chrome extension. Screenshots are automatically redacted in your browser — emails, card numbers, credentials, phone numbers, SSNs, IBANs, password fields — before upload; the unredacted image never reaches our servers.

Billing. Handled by Stripe. We store only your Stripe customer and subscription identifiers — never card numbers.

Operational records. Job status and progress, error messages, and AI usage records (token counts and cost — no content).

3. What we deliberately never store

This is the core of the product's design, and it is enforced by an automated check in our build pipeline that fails any code change creating a place for ticket content to live:

  • Ticket text is never stored. During a pull, ticket text is processed in an ephemeral compute environment: converted to numerical embeddings, used to label topics, and discarded as it's processed. It is never written to a database, disk, or file.
  • Ticket requester identities are never stored. No names or emails of your customers, from your tickets, land in Artica.
  • No ticket field is cached for display. Where the product links to a ticket it stores only the ID number; clicking takes you to Zendesk, which authenticates you and shows you your own data.
  • The AI-generated example questions retained for each topic describe the topic across many tickets; generated text too similar to any single ticket is automatically rejected and regenerated during processing.

The full technical story, including how the guarantee is enforced, is on our Security page.

4. How we use data

  • To provide the service — pulling and analyzing tickets under your OAuth grant, computing the taxonomy and coverage report, powering the editor and export.
  • To operate and secure it — authentication, workspace isolation, job orchestration, error diagnosis, and cost accounting.
  • To communicate — operational email (invites, audit-ready notices, connection-failure notices) and, for paid workspaces, a monthly digest you can unsubscribe from. Operational account email isn't subject to marketing-style unsubscribe.

We do not sell personal data, and we do not use your data for third-party advertising. Where laws such as the GDPR require a legal basis: performance of a contract (providing the service), legitimate interests (securing and improving it), consent where we ask for it, and legal obligation.

5. AI processing

Artica uses AI providers to do its core work: OpenAI converts text to embedding vectors, and Anthropic (Claude) labels topics, analyzes redacted screenshots, and helps draft and match articles. Ticket text reaches these providers only transiently, during a processing run, to produce a result. Under our API terms with OpenAI and Anthropic, API content is not used to train their models. AI credentials are held server-side and are never exposed to browsers or the extension.

6. Subprocessors

We share data only with the vendors that run the service, each under data-protection obligations, and where the law requires it. The current list, with what each receives, is maintained at askartica.com/subprocessors. We update that page and notify workspace Owners by email at least 30 days before adding or replacing a subprocessor.

7. Retention

  • Ticket text: not retained. Its effective lifetime is the duration of a processing run, in memory only.
  • Derived taxonomy, embeddings, articles, and account data: retained while your workspace exists.
  • Per-run ticket embeddings (vectors keyed by ticket ID, kept so an interrupted job can resume without re-reading everything): retained with the run records, deleted with the workspace.
  • Capture screenshots: if you cancel a capture, deleted immediately and permanently. Otherwise retained as part of the draft they back.
  • Invite records: retained with acceptance/revocation timestamps as an audit trail of who was granted access.

8. Deletion

  • Disconnect Zendesk anytime in Settings — this ends Artica's access to your Zendesk.
  • Workspace deletion is handled by support on request (hello@askartica.com): deleting a workspace cascades through all its data — taxonomy, embeddings, articles, connection records including encrypted tokens, memberships — and its stored media. Self-serve deletion is planned.
  • Residual copies in our infrastructure providers' backups expire on their platform schedules.

9. Security

Summarized here — the full picture is at askartica.com/security: TLS in transit; encryption at rest; application-level AES-256-GCM for Zendesk OAuth tokens; authenticated sessions on every product route; per-workspace isolation of data and files; and the build-pipeline check that enforces the no-ticket-text guarantee on every code change.

10. Cookies and analytics

The application uses essential cookies set by our authentication provider (Clerk) to keep you signed in — required for the product to function. The marketing site uses no analytics at all — nothing counts, profiles, or identifies your visit. We use no advertising cookies and no cross-site tracking, anywhere.

11. International transfers

Artica operates from the United States and our subprocessors are US-based. If you use Artica from outside the US, your data is processed in the US. For personal data transferred from the EU/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

12. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar), you may have rights to access, correct, delete, export, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. For your Artica account data, email hello@askartica.com — we won't discriminate against you for exercising your rights. For personal data inside support tickets, the company that connected the Zendesk instance is the controller: contact them, and we'll assist as their processor. Notably, Artica cannot search stored data for a ticket requester's information — ticket text and requester identities are never retained.

13. Children

Artica is a business product not directed at children, and we don't knowingly collect personal data from anyone under 16.

14. Changes

We'll post updates here, revise the date above, and notify workspace Owners by email of material changes before they take effect.

15. Contact

hello@askartica.com, or Hosam Hassan LLC, 30 N Gould St. # 48472, Sheridan, WY 82801, USA.

Artica
PricingSecurityPrivacyTermsDPASubprocessors

© 2026 Artica. Built with ♥ for support teams.