THE SMALL PRINT / 01
A small break.
A clear data trail.
What Art Break receives, what it keeps, and what happens when you share.
Last updated September 20, 2026.
What you send.
Art Break receives the API parameters needed to create a gallery or find an artwork: mood, duration, optional seed, artwork ID, or a short search term. An optional personalized request adds up to four art-interest IDs, three art-form IDs, three artist IDs, and 24 excluded artwork IDs. A friend challenge sends exactly three public artwork IDs and the sender's chosen artwork ID. The daily selection needs no query parameters. These requests can carry URL query parameters and network information such as an IP address.
Personalization is optional. Use only minimal art tastes you explicitly share or authorize an agent to use from memory. Art Break does not need a full conversation, biography, personal identifier, or remembered profile. Do not derive preferences from medical information, religion, politics, or other sensitive information. Keep seeds nonpersonal and search terms art-related.
What the application keeps.
There are no user accounts, stored taste profiles, payments, application analytics or tracking scripts, uploaded files, or saved user answers. The application does not log request content, persist a viewing-history database, or cache personalized galleries. Preference and exclusion parameters are used to assemble the requested result; they are not saved as a user profile. Daily picks and friend challenges do not create stored votes, recipient results, or popularity counts. A choice encoded in a link can still appear in browser history or provider logs.
The application keeps public museum responses in a bounded, in-memory cache for up to ten minutes. This includes fixed artwork-record requests and art-search request URLs, query terms, and results. Personalized choices are used locally to rank the curated collection; they are not sent to the museum or used as museum-cache keys. The application does not cache personalized galleries or profiles. Process memory is temporary rather than a permanent archive. This application behavior does not prevent hosting logs or browser history from containing request URLs.
To limit abuse, each server process also keeps temporary rate counters keyed by a process-specific salted hash (HMAC) of the client IP. These have 60-second windows and a maximum of 1,000 entries. The museum cache has a maximum of 100 entries. Cleanup runs on requests and on a best-effort 60-second interval; expired entries are not used, but serverless suspension can delay their physical removal from memory. Neither cache nor counters are written to a permanent database.
Where requests travel.
Search terms and artwork-record requests are sent from the service to the Cleveland Museum of Art API at openaccess-api.clevelandart.org. Art preferences rank the curated collection within Art Break; the museum receives requests for selected record IDs, not your conversation or a preference profile. Normal gallery images load directly from openaccess-cdn.clevelandart.org; the museum receives your browser's IP address and normal request metadata. Following a museum link takes you to its site and its own policies.
For a share card, your browser requests /api/artworks/{id}/image from Art Break. The service fetches a verified curated artwork image from the museum CDN and passes the JPEG back transiently, with a 3 MiB limit and five-second upstream timeout. The museum sees this service request rather than a direct browser request for that image. The endpoint accepts no arbitrary URL. Art Break does not save the proxied image as a user upload or keep a share-card archive.
Vercel hosting logs.
Art Break is hosted on Vercel. On its current Hobby plan, Vercel documents a one-hour window for customer-visible runtime logs. Those logs may include request paths, query parameters, user-agent information, timestamps, and other network metadata, even though Art Break does not log request content itself. Preference selections, search terms, excluded artwork IDs, and challenge choices in query strings may therefore appear in hosting records. See Vercel Runtime Logs.
The one-hour window is not a promise that every provider record is deleted after one hour. Vercel's Privacy Notice describes its processing of network information and logs and purpose-based retention. The maximum lifetime of all internal operational or security records for this deployment has not been confirmed. Application memory limits and hosting-provider retention are separate.
What a shared link contains.
Ordinary gallery links contain mood, minutes, and a seed. Personalized links also contain the bounded interests, forms, artists, and exclude parameters used to recreate the selection. Anyone receiving a link can read these art preferences and excluded IDs. They can also appear in browser history, copied URLs, and hosting query logs. Review the link before sharing; keep the seed nonpersonal.
Friend-challenge links use /play?ids=…&pick=… and contain only three public artwork IDs and the sender's chosen ID. They do not include explicit art preferences, exclusions, a profile, or a seed from the original gallery. The website waits for the recipient's choice before revealing the sender's pick on screen, but the answer is visible in the URL and API response. It is not secret or tamper-proof, and can appear in browser history, copied links, recipient systems, and hosting logs.
Links must not contain a conversation, biography, sensitive detail, or free-text exercise answers. Clipboard copying, printing, and saving a page are handled by your browser; the service does not receive a saved copy.
Cards and native sharing.
The finished PNG share card is generated in your browser. Art Break does not upload or store it. Downloading saves it through your browser; native sharing passes the selected card or link to a destination you choose using your device's sharing controls. That destination handles what you send under its own policies. Art Break does not access your contacts, automatically message anyone, publish posts, or track whether a recipient opens or answers an invitation.
Connected agents.
If you use Art Break through Muse or another agent, that provider handles the conversation and any authorized memory under its own policies. Art Break needs only the minimal art-related parameters. An agent must not send its full remembered profile, your email, contacts, precise location, payment details, or credentials. It should not invent preferences when none are known; the ordinary gallery works without personalization.
Support email.
If you email us, we receive your email address, message, and any attachments so we can respond. Email correspondence is held in the support mailbox separately from gallery requests and their temporary caches. Please avoid sending sensitive information. You can use the contact below to ask about your information or request its deletion.
Contact.
Art Break is operated by Vu Bui. For support or privacy requests, email buidinhvu@gmail.com.