Privacy Policy
1. Who we are
PiPiPix ("we", "us", "our") operates the PiPiPix website and related AI-assisted image generation services. This policy explains how we handle personal data when you visit our site, create an account, generate images, or contact us.
2. Data we collect
- Account data: email address, name (optional), password hash, authentication session identifiers, and security-related metadata (for example token version on password change).
- Usage and technical data: IP address, user agent, approximate timestamps, and diagnostic information needed to operate, secure, and improve the service.
- Content you submit: prompts, uploaded reference images, generation parameters, and outputs produced through the service, as required to fulfill generation requests and maintain history where your plan includes storage.
- Billing data: if you subscribe or purchase credits, our payment processor handles card details; we receive limited billing metadata (for example subscription status and invoice references) as described in our Terms of Service.
3. How we use data
We use personal data to:
- Provide, operate, and improve generation features, queues, and account areas.
- Authenticate users, prevent abuse, enforce rate limits, and protect security.
- Communicate about the service, respond to support requests, and send transactional notices.
- Meet legal obligations and defend legal claims where necessary.
We do not sell your personal information. We may use aggregated or de-identified statistics that cannot reasonably identify you.
4. Legal bases (EEA/UK users)
Where GDPR applies, we rely on one or more of: contract, legitimate interests (security and product improvement), consent where required, and legal obligation.
5. Sharing and subprocessors
We use infrastructure and service providers (for example hosting, database, email, analytics, payment, and AI model providers) who process data on our instructions. They are bound by contractual obligations appropriate to the processing. A current list of categories of subprocessors may be provided on request.
6. International transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers.
7. Retention
We retain account and billing records as needed to provide the service and comply with law. Generation content retention depends on your plan and product settings; we may delete or anonymize data when no longer needed.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. You may also withdraw consent where processing is consent-based. To exercise rights, contact us using the details in the Terms notice section. You may lodge a complaint with your supervisory authority.
9. Children
The service is not directed to children under 16 (or the age required in your jurisdiction). Do not provide children's data without parental authority as applicable.
10. Security
We implement technical and organizational measures appropriate to the risk. No method of transmission or storage is 100% secure; use strong passwords and protect your credentials.
11. Changes
We may update this policy. We will post the revised version with a new "Last updated" date and, where required, provide additional notice.
