Privacy
Updated October 7, 2026. This notice describes Widget Canvas by ArkheOS, operated by Noah Lewis Kramer.
Creation and private saving
Widget Canvas receives the title and HTML, CSS, and JavaScript that ChatGPT sends to render a widget, together with revision identifiers when supplied. When creator features are enabled for your account, ArkheOS keeps each rendered revision in an account-bound source history. The private account binding prevents other accounts from changing your widget. Source histories are bounded; published revisions retain their exact source.
When account saving is enabled, private interaction state is stored separately in the account database so it can be restored on return. Account saving and creator features are currently being verified with restricted access; their availability depends on your account. Private saved state is not automatically published or shared with ChatGPT.
Your ChatGPT conversation may retain widget source, tool results, and state under OpenAI’s own settings and policies. When you explicitly share widget state with ChatGPT, that state becomes part of the conversation. Avoid entering sensitive personal information into generated widgets.
Public names, uploads and remixes
You choose a public creator name. ArkheOS stores it with a random public creator ID and a private account binding. Your login name, email and private account identifier are not automatically used as your public name or included in public browsing responses.
Publishing requires an explicit review and confirmation. The published title, description, public creator name, code, artwork and default content are public and available for viewing and remixing. Stored private interaction state is excluded. Personal information embedded in source or default content would become public, so review that copy before publishing.
Remixes retain their exact published parent and the credit chain. Hiding a public copy removes its listing and public source access; existing descendants retain its name and credit, marked as unavailable. Hiding a copy does not erase private source history or saved work. A name change does not rewrite the name on older published copies.
Changes made while exploring a public preview stay in that visitor’s browser storage. Public previews do not receive the creator’s private saved state or account credentials. Reset the preview or clear browser storage to remove those local changes. More detail is available in the creator feature privacy notice.
Accounts and billing
Auth0 handles sign-in, email verification, passwords, and password recovery. ArkheOS stores your Auth0 account identifier, verification status in short-lived account sessions, and your Stripe customer and subscription identifiers. Stripe handles payment details; card numbers do not pass through Widget Canvas.
Our account database stores subscription status and the paid-through date needed to decide access. It also stores temporary login flows, sessions, checkout attempt identifiers, and webhook event identifiers and processing status. We do not store the full Stripe webhook payload in that database.
Providers and technical data
Cloudflare hosts the site, renderer, and account database, including source records and private saved state. Auth0, Stripe, Cloudflare, and OpenAI process data needed to operate their services under their own privacy policies. Network services receive technical request data such as IP addresses. Widget Canvas does not sell personal information or run advertising trackers on this website.
Retention and choices
Login flows expire after ten minutes and account sessions after at most one hour; expired entries are removed during later login activity. Private source histories, saved work, creator records, account and billing records remain until removed through an account request or an applicable retention process. Public copies remain available until hidden; descendants retain their attribution chain. Publication previews expire after ten minutes. Financial and operational records may need to be retained for accounting, dispute resolution, or security.
You can sign out, cancel a subscription through the billing portal, hide your public copies, or contact us to request access to, correction of, or deletion of your account information. Removing an ArkheOS account does not remove a ChatGPT conversation; manage those separately in ChatGPT.
Contact
For privacy requests, email support@arkheos.ai. We may need to verify account ownership before acting.