Draft. Effective on publication.
Sittings Privacy Policy (DRAFT v2 — round-1 gate revision 2026-08-06; NOT yet signed off)
The short version
We collect the minimum we need, we never sell any data, we treat health information with strict controls we describe precisely below, and you can exercise your rights by emailing us directly. Sittings is a solo-operated business: the person who built the system answers the privacy mail.
Two hats, said plainly
- Sittings as a business decides how and why to process: marketing-site visits and pilot applications, artist accounts, security logs, analytics, billing, and our own outreach. This policy governs those directly.
- Sittings as the artist's processor handles client inquiries on the artist's behalf and instruction, under our data processing agreement with the artist. For client-inquiry rights we act on the artist's instruction — AND, where the law gives you direct rights against us (see the Washington section), you can come to us directly and we will honor them.
Who and what this covers
- Visitors and applicants (getsittings.com): pilot applications — name, studio/Instagram handle, city, weekly inquiry volume, your description of your inbox, email address; plus campaign parameters (utm fields) and PostHog analytics (below).
- Artists (sittings.ink app): account email, studio settings, pricing criteria, reference images, drafts, roles, and audit events tied to your account actions.
- Clients of artists: inquiry contents — contact details, the tattoo request, budget, placement, reference images; the raw email (full body, headers, and attachments) when an artist forwards inquiries; appointment and deposit records; where health questions are enabled (see below), your consent evidence including IP address and browser user-agent.
- Prospective artists we contact (when our outreach program is active): name, studio, city, and the business email you have published publicly, with a record of where and when we found it (consent provenance), verification-check results, and a permanent record if you opt out (suppression list). Sources: public business listings and your own public pages.
- Operational records: abuse-protection logs (IP, artist-page slug, timestamp), email delivery status and provider message IDs, sanitized payment-webhook records, and security audit events.
Health information — the exact truth
Tattoo inquiries can brush against health topics. Here is precisely what our system does and does not do:
- We never create structured health data from free text or forwarded email. Our AI extraction does not extract, classify, or store health attributes as data fields — this is enforced in the system's design, not just promised.
- But the original message itself is kept and shown. If a client volunteers health information inside an inquiry ("I'm on blood thinners"), that text remains part of the stored message and the raw forwarded email, is visible to the artist handling the inquiry (that is the product working as intended), and — see the AI section — transits our AI provider inside the message body. We do not scrub free text, and we won't pretend otherwise.
- Structured health questions are different and stricter. They are asked only where BOTH the artist's region and the client's region permit them (they are disabled entirely for Québec-resident clients), only with your specific, affirmative, purpose-stated consent collected at the moment of asking (with its own withdrawal path), and the answers live in a single dedicated table with no direct access for anyone — including artists — except through an audited, purpose-limited channel. These controls are intentionally stronger than the controls on ordinary messages.
- We never sell health data. We never sell any data. We never use health information for advertising.
Washington Consumer Health Data — standalone notice
Washington's My Health My Data Act asks for its notice to stand alone, so it lives on its own page: Consumer Health Data Privacy Policy — linked prominently from our homepage and from every surface where health questions can be asked. The summary below repeats its substance; the standalone page governs.
- Categories collected: health conditions/treatments you volunteer in message free text; structured intake answers (where enabled, with consent); and the consent record itself — your consent choice, region, IP address, and browser user-agent, kept as proof of your consent.
- Sources: you directly (forms); your artist, when they forward your email to us; and the email systems that carry that forwarded mail.
- Purposes, exactly: storing your inquiry; showing it to the artist you contacted; AI parsing of the message to size the request and draft the artist's reply; proving your consent; and administering deletion.
- Recipients, exactly: the artist you contacted; Supabase (storage); Vercel (transport); Anthropic (AI parsing of message text); Postmark, when live (email carriage). Health data is NOT shared with PostHog, Stripe, or any outreach tooling. Sold: never.
- Your rights: confirm processing; access it — including the list of recipients above and how to contact them; withdraw consent; deletion (from live systems promptly, and from backups no later than six months after we authenticate the request); and appeal a refusal.
- Withdrawal vs deletion, plainly: withdrawing consent stops the structured health questions and any further use of your structured answers. Health details you volunteered inside a message are processed as part of the inquiry service you requested, not under that consent — to remove those, ask for deletion of the message.
- How: email chapman@getsittings.com with "health data request." We verify you against the email of record (plus confirmation questions if needed), respond within 45 days, notify processors of deletions, and complete backup deletion within six months. Refusals state reasons; reply "appeal" for a fresh review, answered with reasons and your right to contact the Washington Attorney General.
- A link to this section appears on every surface where health questions can be asked.
AI processing, disclosed exactly
Two distinct uses of Anthropic's Claude models: parsing sends up to the first 20,000 characters of a message's raw text plus sender/subject envelope data, to extract the inquiry's facts — so incidental health content in a message DOES transit Anthropic at this step; drafting sends selected structured inquiry facts (not the raw body) to compose the artist's reply.
[NO-TRAINING CLAIM WITHHELD pending the vendor-terms verification pass — CHAPMAN GATE: once Anthropic's executed terms are verified, this section states the verified commitment and terms version; until then the policy makes no training claim.]
Processors — current vs planned
| Provider | Status | Data it receives | Purpose |
|---|---|---|---|
| Supabase | live | all application/app data | database + storage |
| Vercel | live | request traffic | hosting |
| Anthropic | live | inquiry text | AI parsing + drafting |
| PostHog | live | usage events + network/device metadata | product analytics |
| Google Workspace | live | email to/from our mailbox | our mailbox |
| Postmark | planned (activation pending) | transactional email content + delivery metadata | sending/receiving product email |
| Stripe | planned (deposits) | card details are entered with and held by Stripe — we never see full card numbers; we DO store payment metadata: amounts, currency, status, Stripe session/payment-intent identifiers, timestamps, policy snapshots, and webhook payloads (sanitized when the related inquiry is deleted) | client deposits |
| Outreach tooling (e.g. a sequencer + list-verification vendor) | planned | prospective-artist business contact data only | our own outreach; never client or health data |
Access is limited by purpose and by contract; our vendor-terms review (retention, training, access location for each provider) is in progress, and this table states only what we have verified. Updated when a planned provider goes live.
Analytics, honestly
PostHog receives page/event data plus ordinary network and device metadata (IP-derived location, browser). An application generates a pseudonymous identifier (an internal application ID) — while your application exists, we could link those events to it; deleting your application removes the primary link, though residual correlation may persist in backups and operational logs until their disclosed retention periods expire. We do not put your name, email, or answers in analytics events.
Deletion and your other rights — separate procedures, stated separately
- Pilot applications: email us from the application's address. We first block any pending email about your application from sending, then delete the application and its email queue records. Copies of emails already sent or received sit in our mailbox (deleted by hand on request) and in the email provider's delivery logs until its retention window expires. A message already handed to our email provider for delivery may no longer be recallable.
- Client inquiries: we accept every request. For data Sittings controls we answer directly; for artist-controlled inquiry data we coordinate with your artist and confirm the outcome to you (and for Washington health data you always have the direct channel above). Inquiry deletion uses transactional deletion with a deletion record so the deletion is provable; if a backup is ever restored, we re-run every recorded deletion request against the restored system before it serves traffic (a manual, checklist-driven procedure; an automatic control exists but is not yet proven end-to-end, so we promise only the manual one).
- Artist accounts: closure per your agreement's wind-down terms; then account data deletion on the schedule below.
- What survives a deletion, by design: the deletion record itself (proof — and for health-related deletions it keeps only the minimum needed to prove the deletion happened, not the health content or its category), security/audit logs (abuse defense), anonymized deposit/financial records (legal/accounting), and the suppression-list entry if you opted out of outreach (keeping it is what honors the opt-out). Each is retained for the reason stated and nothing else.
- Other rights: access and correction (we send you what we hold about you and fix what's wrong), export (artists: a structured export exists in-app; applicants and clients: by email), complaint (email us; Canadians may also contact the OPC; Washingtonians the AG). We verify requests against the email of record and explain any refusal with an appeal path. Timelines: Canadian access requests within 30 days (if we need longer we say so within those 30 days, per PIPEDA's extension rules); Washington requests within 45 days (one 45-day extension with notice where the law allows); everyone else within 45 days.
Retention — concrete
- Applications: deleted or anonymized within 90 days after the founding pilot closes.
- Abuse-protection logs, two kinds: intake-form throttle records are deleted opportunistically within about an hour of the next request; application-security throttle records are kept 30 days, deleted on a schedule. Consent-evidence records tied to a health intake are kept with that inquiry — they are proof of your consent, not a log.
- Client inquiries and messages: per the artist's settings, with an outside maximum of 24 months after the inquiry closes unless the artist's agreement states a shorter period.
- Email delivery records: message IDs kept with the message record; provider content/activity logs expire on the configured provider schedule (45 days as configured at Postmark); the provider retains aggregate statistics and bounce/suppression entries beyond that, without message content.
- Deletion records: 6 years (proof). Security/audit events: 24 months. Financial records: 7 years (accounting/tax).
- Backups: expire within 35 days on our database provider's schedule; deletions are re-applied per the deletion section before any restore serves traffic.
Email rules we hold ourselves to
- These rules apply to every message class our sender actually compiles them into — application emails and our own outreach get the full set at send time (identification, postal address, and for commercial messages a clear advertisement identification and unsubscribe); artist-reply emails are the artist's correspondence with their client, carried for the artist, and are not marketing.
- Every commercial email identifies Sittings (and the artist, when we send on an artist's behalf), includes our postal address, uses truthful headers and subjects, identifies itself as an advertisement where the law classifies it as one, and offers a working unsubscribe that stays valid for at least 60 days and is honored within 10 business days — permanently, as our operating practice.
- Recall boundary, stated honestly: once we hand a message to our email provider and delivery begins, it may no longer be recallable.
- Canada (CASL): we send commercial email only with your express consent or valid implied consent (for business addresses you have conspicuously published without a no-solicitation notice, where our message relates to your business role) — and we keep a record of exactly where and when we found the address, so our consent basis is provable. Express consent doesn't expire until you withdraw it; our identification and contact details in each message stay valid for at least 60 days.
- Applying to the pilot is a request for a reply, not a marketing subscription.
Canada — cross-border and accountability
We operate from the United States: Canadian artists' and clients' data is processed and stored in the US and may be subject to lawful access under US law. Chapman is the accountable privacy contact; you may request access or correction, complain to us first, and escalate to the Office of the Privacy Commissioner of Canada (or your provincial regulator) if unsatisfied.
Minors
Sittings is intended for adults. The application form requires an 18+ attestation; inquiry intake is the artist's client relationship and we do not verify client ages. If we learn an inquiry or application came from a minor, we delete it and tell the artist to do the same. Parents/guardians: email us and we will delete a minor's data on verification.
Purposes, mapped
Screening pilot applications (application data) · authenticating artists (account data) · parsing and drafting inquiry replies (inquiry text, via Anthropic) · scheduling and deposits (appointment + payment records, via Stripe when live) · sending and receiving product email (delivery records) · keeping the service safe (abuse logs, audit events) · understanding product usage (pseudonymous analytics) · our own outreach (published business contacts, with provenance and suppression) · meeting legal obligations (consent evidence, financial records, deletion records).
Changes
Material changes get a dated note here and, for artists, advance email. Where the law requires it — including any expansion of health-data collection, use, or sharing — we ask for fresh, specific, affirmative consent BEFORE the change applies to you; an updated page is never treated as consent for that.