Legal
Privacy Policy
Last updated: August 1, 2026
1. Overview
This Privacy Policy explains how Pixogen ("we", "us") processes personal data when you use pixogen.ai, app.pixogen.ai and related services (the "Service"). We keep it simple: we collect the minimum required to run the Service, we do not sell your data, and your generated content is private by default.
2. Data we collect
- Account data — email address, display name, hashed password (we never store plaintext passwords) and, when you sign in with Google, your Google account id and avatar.
- Billing data — purchase history and payment references. Card details are processed by Stripe and never touch our servers.
- Usage data — generations you start (tool, parameters, credit cost, status), credit transactions and basic device information (IP address, browser type) in server logs.
- Content — files you upload and outputs you generate. These are stored encrypted and linked to your account.
3. How we use data
- Provide, operate and improve the Service
- Process payments and prevent fraud or abuse
- Send transactional emails (receipts, password resets, important service notices)
- Comply with legal obligations
We do not use your uploads or generated outputs to train AI models, and we do not review your content unless you explicitly reference it in a support request or we receive a valid legal demand.
4. Legal bases (GDPR)
Where the GDPR applies, we process data on the bases of contract performance (Art. 6(1)(b)), legitimate interests such as security and abuse prevention (Art. 6(1)(f)), legal obligation (Art. 6(1)(c)) and consent where required (Art. 6(1)(a)).
5. Sharing
We share data only with processors needed to operate the Service: payment processing (Stripe), infrastructure/hosting providers and, where you use them, third-party AI model providers that execute your generation requests. Each processor is bound by a data processing agreement. We never sell personal data.
6. Retention
Account data is kept while your account exists. Generated content stays until you delete it or your account. Server logs rotate within 90 days. Billing records are retained as long as tax law requires.
7. Your rights
You can access, correct, export or delete your data at any time. Most actions are available directly in your account settings; for everything else email [email protected]. EU/EEA users additionally have the rights to restriction, objection and to lodge a complaint with a supervisory authority.
8. Security
Transport encryption (TLS) everywhere, encrypted storage for content, hashed passwords, role-restricted internal access and audit logging on administrative actions.
9. Children
The Service is not directed at anyone under 18. We delete accounts identified as belonging to minors.
10. Changes
We will announce material changes to this policy by email or in-app notice at least 14 days before they take effect.
Contact
Pixogen — [email protected]