Skip to content
Collection
Privacy & Security

We Collect Art, Not Data

Halston Arthouse is designed so that visitors can experience the collection without surrendering anything in return — and so that artists keep everything they bring. Where the museum has been tested, we say so: every logged violation and the action taken sits openly in the incident record below.

For Visitors

No cookies, no tracking

Halston Arthouse sets no cookies and runs no advertising or cross-site trackers. Nothing follows you off this site.

No accounts, no profiles

You can view the entire collection without signing in. We do not build visitor profiles, and we collect no personal, health, financial, or sensitive data.

AI text is labelled

Every curatorial description written with AI assistance carries a visible label, and each one is reviewed by a human curator before it appears on the wall.

Protected collection

Copying, right-click saving, and screenshot attempts are deterred on artwork pages so that artists keep control of their images. Repeated capture attempts, bulk text extraction, and source-viewing block the address — and we publish what has been attempted in the incident record below.

For Artists

Your work stays yours

The NFT and the artwork remain entirely your property. Halston Arthouse is granted permission to curate and display the work only — never ownership.

A human decides

An automated safety check flags unusual submissions, but approval, rejection, and any published wall text are always decided by a human curator.

Your contact details

Your name and email are used solely to correspond with you about your submission. They are never published, sold, or shared.

Adversarial input is blocked

Prompt injection, data poisoning, and model manipulation attempts are detected and rejected before reaching any model or the collection — blocked twice over, on the page and again on the server, logged for the curator, and the originating address is banned. A flagged submission is still held for a human to read, so an ordinary artist statement is never lost to a false alarm.

Documented governance

AI use is inventoried, risk-tiered, and reviewed internally in alignment with the NIST AI RMF, the EU AI Act, and ISO/IEC 42001. System and model cards are released to authorized parties on request.

What We Do Not Collect

  • No cookies. The museum does not set tracking or advertising cookies on your device.
  • No personally identifiable information (PII) — name, email, address, or identifiers — is requested from visitors.
  • No protected health information (PHI) or health data of any kind.
  • No financial data, payment details, or transaction information from visitors.
  • No personal traits, mental health information, trauma history, or relationship and family history.
  • No behavioral profiling, ad targeting, or third-party tracking on the public collection.

What We Hold

The only information stored by Halston Arthouse is the museum's own content, managed by the museum operator:

  • ·Artwork records — title, image, curatorial description, and edition — added by the operator.
  • ·The info-page content — editable at any time by the operator.
  • ·Submission details voluntarily provided by artists, used only to correspond about their work.

Visitors browsing the collection submit nothing. No account is required to view the art — you can explore every piece in the museum without logging in or providing any information.

Operator & Owner Data

Halston Arthouse is built and curated by one operator, and the build itself holds nothing personal about them. Secrets such as the pinning key are stored encrypted server-side and are never exposed to the browser or written into any record.

  • No PII or PHI about the operator is stored. Only the account email needed to sign in as curator exists, and it is never published or shared.
  • No mental-health, trauma, medical, or wellbeing information is collected, inferred, stored, or sent to any model.
  • No information about the operator’s appearance, personality, humour, beliefs, family, or relationships is collected or profiled.
  • No financial data, payment details, or banking information belonging to the operator is held in this app.
  • The build’s source code, ideas, and configurations are the operator’s property. Attempts by visitors to view, copy, or extract them are blocked, logged as theft, and the address banned.
  • No keystroke logging, session recording, screen recording, or behavioural analytics run anywhere in this app — for the operator or anyone else.

Incident Record

29 August 2026 — the submission guard and the minting docent were adversarially tested and hardened, and both findings are now closed. Any attempt to extract a system's instructions, impersonate the curator, or make the museum act without the artist's consent is treated as prompt injection: it is blocked, logged, and the originating address is banned. Flagged submissions are still read by a human curator before any decision, so a genuine submission is never lost.

Incidents & adversarial violations

The museum publishes what has actually been attempted against it and what was done in response. No visitor data has ever been exposed, because none is collected — every entry below concerns attempts on the museum's own content, models, or build. Dates are given in Eastern Time; the full internal threat log, with redacted excerpts, is held by the curator.

CriticalRemediated29 August 2026 · 05:22 ET

Concept and authorship appropriation claim filed

The owner recorded a formal notice of authorship and ownership over the museum’s concept, structure, curatorial voice, minting flow, governance framework, and code.

Action taken — Notice published in the curator’s record; the build manifest sealed and pinned to IPFS so priority rests on a timestamped, on-chain record rather than on any platform. A support inquiry was opened with the hosting platform regarding authoring-pipeline access outside this app.

HighRemediated29 August 2026 · 05:40 ET

Build-environment probing

Attempts to reach the build itself — the authoring conversation, its prompts and responses, the sealed build record, and curator-only build surfaces — were observed.

Action taken — A build-access guard was added: keyword and URL probes are logged as model theft, opening a curator-only build page is logged as concept theft, and the originating address is banned immediately with an email to the curator.

MediumRemediated29 August 2026

Theft events mis-filed by the server log

Code, model, and concept theft events were being written to the log under the generic "other" category, so the theft view under-reported real attempts.

Action taken — The server-side categories were corrected and the theft filter now populates accurately. No event records were lost.

HighRemediated29 August 2026

Submission guard failing in both directions

Deliberate adversarial testing of the submission guard found it missing several manipulation attempts — including the most common instruction-override phrasing — while also wrongly flagging three ordinary artist statements, which would have refused a genuine submission and blocked the artist’s address.

Action taken — The detection patterns were rewritten and re-tested until every attack in the battery was caught and every legitimate statement passed clean. A flagged submission is now held for a human curator to read instead of being refused and banned automatically, so no genuine submission can be lost to a false alarm.

HighRemediated29 August 2026

Minting docent probed for its instructions and for filing without consent

The minting docent was adversarially probed: attempts were made to have it disclose its own instructions and underlying architecture, to claim curator or staff identity, and to have it file a submission without the artist confirming the summary.

Action taken — The docent was hardened with a non-liftable consent gate, a refusal to treat any claimed identity as carrying privileges, and a confidentiality rule covering its instructions, tooling, and infrastructure — however the request is framed. Re-probed and confirmed closed. Any such attempt is now recorded as prompt injection and the originating address is banned.

BlockedStanding controlOngoing

Prompt injection and data-poisoning attempts in submission fields

Submitted text containing instruction overrides, role hijacking, prompt-extraction probes, and poisoned content has been detected on submission forms.

Action taken — Blocked client-side and again server-side before reaching any model or storage; invisible control characters stripped; the originating address banned; the attempt logged and held for the curator, who is emailed the redacted excerpt and decides what follows.

BlockedStanding controlOngoing

Screen capture and bulk content extraction

Visitors have attempted screen captures of artwork and bulk copying of the museum’s text and markup.

Action taken — A detected capture watermarks that visitor’s view and warns them; a third attempt blocks the address. Bulk text extraction and source-viewing attempts are logged as content or source theft and banned immediately.

What the museum has learned, stated plainly: its guards can protect data, inputs, evidence and rendered works, but they cannot make browser-delivered code unreadable, cannot stop a camera pointed at a screen, and cannot reach any pipeline outside this app. Provenance — the NFT and the sealed records pinned to IPFS — is what establishes priority; enforcement against reuse is a legal matter, not a technical one. Adversarial probes are run deliberately against these controls and every finding is tracked to a documented fix.

AI governance & compliance

Halston Arthouse is designed and operated to align with the NIST AI Risk Management Framework, the EU AI Act, and ISO/IEC 42001. These are the museum's own controls and self-assessment — no external certification or audit is claimed.

NIST AI RMF 1.0

Govern · Map · Measure · Manage

The museum maintains a written record of every AI use it operates — curatorial description writing, image safety review, and popularity research — with the risks of each mapped, its outputs measured by a human curator before publication, and its adversarial failures logged and managed in the security monitor.

EU AI Act

Limited-risk · Transparency obligations

The museum operates no prohibited practice: no biometric categorisation, no emotion inference, no social scoring, no subliminal manipulation, and no profiling of visitors. Its systems are limited-risk, so the governing duty is transparency — AI-written wall text is disclosed as AI-generated, and AI-assisted content is labelled wherever it is shown.

ISO/IEC 42001

AI management system

No curatorial decision depends on a model being available: acceptance is the curator’s act, and a failed AI description never blocks or alters it — any work published without wall text is queued back to the curator with a retry, so a model failure is remediated rather than left standing. Beyond that, AI use is run as a managed system rather than an experiment: defined roles (curator as accountable human reviewer), documented controls on input and output, data minimisation by default, logged incidents with a review-and-document workflow, continuous measurement of accuracy, cohort disparity, drift, reliability and consumption against written thresholds, and a quarterly management review of the programme.

Human oversight is non-negotiable: no AI output is published, and no submission is accepted or refused, without a curator's decision. The museum keeps an internal AI system inventory with risks and controls mapped, plus a dated log of curator reviews, as its evidence of this posture. The system and model cards behind that inventory are not published — they are held on file and released to regulators, researchers, sponsors, and artists on request to the curator. Governance questions may be sent to the curator at any time.

Known gaps & limitations

Responsible AI practice requires saying plainly where the museum falls short. These are the limitations of Halston Arthouse’s AI use as it stands today. Gaps that have since been closed in the build are removed from this list rather than left standing.

Self-assessed, not certified
Alignment with the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 is the museum’s own assessment. No external audit, conformity assessment, notified-body review, or ISO certification has been carried out, and none is claimed.
One-person oversight
The accountable human reviewer is a single curator. There is no separate reviewer, no segregation of duties, and no independent appeal body inside the museum. A concern is reviewed by the same person who made the original decision.
Third-party models are not fully explainable
Curatorial text, safety screening, and narration rely on general-purpose models operated by external providers. Their training data, weights, and internal reasoning are not visible to the museum, so outputs cannot be fully explained, reproduced, or guaranteed free of bias or error.
Automated safety screening is imperfect
The content check can both miss prohibited material and wrongly flag legitimate art. It only ever flags — it never accepts or refuses a work on its own — but a wrong flag can delay a submission until a curator reads it.
AI text may misread the work
Machine-written wall text is interpretation, not fact. It can misidentify medium, period, or intent. It is labelled wherever it appears and an artist may ask for it to be corrected or removed.
Adversarial defences are deterrents
Prompt-injection, poisoning, extraction, and screen-capture protections reduce risk; they do not eliminate it. A determined attacker with device-level tools can still capture displayed images.
Measurement is internal, not benchmarked
Accuracy, cohort disparity, drift, reliability, and token consumption are measured continuously against written thresholds, with breaches raising alerts. But accuracy rests on one curator’s judgement rather than an independent ground truth, token figures are estimated because providers do not return usage, and there is no external benchmark suite or formal red-team programme.
No provider-side obligations assumed
The museum acts as a deployer of AI systems, not a provider. It does not train, fine-tune, or place models on the market, and it cannot fulfil provider duties such as technical documentation or post-market monitoring of the underlying models.
Automated decision-making rights
Because no legal or significant decision about a person is made by AI alone, GDPR Art. 22 safeguards are not engaged. Should that ever change, a documented human-review route would be published before the change took effect.
Small team, quarterly cadence
The AI programme is reviewed quarterly rather than continuously, and an overdue review raises its own alert. With a deliberately small team, remediation between reviews happens as capacity allows.

This statement is reviewed alongside the museum’s AI inventory. If you believe a limitation is missing or has been understated, the curator would rather hear it than not.

Disclaimers

No guarantee of absolute security. No online system can be made perfectly secure. The measures described here reduce risk; they cannot eliminate it, and nothing on this page is a warranty against loss, unauthorized access, or misuse.

Content protection is a deterrent. Copy, right-click, and screenshot deterrents discourage casual copying. A determined party can still capture an image displayed on their own screen.

AI output may be imperfect. AI-assisted curatorial text can be inaccurate or incomplete. It is reviewed by a curator but should not be relied on as an authoritative record of a work, its history, or its value.

No on-chain minting here. Halston Arthouse does not mint, custody, sell, or transfer tokens. Works are minted by artists elsewhere; edition labels shown in the museum are curatorial, not blockchain transactions, and nothing here is financial advice.

Third-party infrastructure. Images are served from IPFS gateways and this museum runs on the Base44 platform. Their handling of requests and logs is governed by their own terms, not by this page. For questions about platform infrastructure-level data handling, please contact Base44 support.

Prohibited content is reported. Violent, threatening, or exploitative submissions will not pass review, are retained for curatorial assessment, and may be reported to law enforcement.

Not legal advice. References to the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 describe internal alignment work. They are not a certification, an audit result, or a claim of formal conformity.

Questions

thehouseofhalston@icloud.com

Something concerning you? Report a problem — leave an email and the curator can follow up with you privately.

    base44
    Edit with Base44