Last updated 9 September 2026

Privacy Policy

What we collect, who else touches it, and how to get it back or delete it.

1. Who is responsible

[LEGAL ENTITY NAME] is the controller of personal data described here. Contact: [CONTACT EMAIL].

2. What we collect

  • Account data. Your email address, a password hash (we never see the password itself), your account handle, and your tier. Authentication is handled by Supabase.
  • Prompts and images. The text you write and the images generated from it, along with the style, dimensions, and model used.
  • Usage data. Generation counts, per-request cost records, cache hit records, and API key usage timestamps.
  • Technical data. IP addresses, used for rate limiting and abuse prevention. Referring domains, for embeds served on your sites.
  • Analytics and errors. Page views and product events, plus error reports. Sentry session replay may record your interactions inside the dashboard.

We do not collect payment information. There is no payment processor connected during the free beta.

3. Where your prompts go

Your prompt text leaves our systems. It is sent to Runware to generate the image, and often to OpenAI first, which rewrites it to match the style you picked. Both are third parties with their own terms. Do not put confidential or personal information in a prompt.

4. Who else processes your data

ServicePurposeData involved
SupabaseDatabase, authentication, and image storageAccount records, hashed credentials, prompts, generated images
VercelHosting and content deliveryRequest metadata, IP addresses
RunwareImage generationPrompt text and generation parameters
OpenAIPrompt rewriting, image captioning, and search embeddingsPrompt text and image captions
UpstashCaching, rate limiting, and background job statePrompt hashes, IP-derived rate limit counters
PostHogProduct analyticsUsage events, page views, account identifiers
SentryError monitoring and session replayError reports, request context, replay of dashboard sessions

Email delivery for account confirmation is handled by [EMAIL PROVIDER].

5. The shared library

Images you generate may be added to a public shared library, watermarked and not attributed to you, along with the prompt that produced them. This is described in full in section 7 of the Terms of Service.

Flywheel opt-out is an account setting and prevents any of your images entering the library. Turn it on before generating anything you would not want public.

6. Cookies

We set cookies to keep you signed in. These are necessary for the service to work and cannot be turned off while you are logged in. PostHog sets analytics cookies to measure product usage. We do not run advertising cookies and we do not sell personal data.

7. How long we keep things

Account data is kept while your account exists. Generated images are kept until you delete them or delete your account. Rate limit counters expire within hours. Cost and analytics records are kept in aggregate for business accounting. Images already promoted to the shared library are kept indefinitely, because other people’s pages reference them.

8. Your rights

You can access and export your data from the dashboard, correct your account details in settings, and delete your account, which removes your images, keys, and account record. Depending on where you live you may also have rights to object to or restrict processing, or to complain to a data protection authority. To exercise anything not available in the dashboard, email [CONTACT EMAIL].

9. Children

Pixloom is not for children. Do not create an account if you are under [AGE, 13 or 16 depending on jurisdiction]. We do not knowingly collect data from children, and will delete such an account if we learn of it.

10. Security

Data is isolated per account by row-level security in the database. API keys are stored as hashes, never in plain text, and publishable keys are locked to the domains you register. No system is perfectly secure, and during the beta especially you should not store anything critical here.

11. International transfers

Our providers operate in the United States and elsewhere. Using Pixloom means your data may be processed outside your country, including in the United States.

12. Changes

We may update this policy. Material changes will be communicated to account holders where reasonably possible, and the date at the top of this page will change.

Start free
Privacy Policy | Pixloom