Last updated 9 September 2026
Privacy Policy
What we collect, who else touches it, and how to get it back or delete it.
1. Who is responsible
[LEGAL ENTITY NAME] is the controller of personal data described here. Contact: [CONTACT EMAIL].
2. What we collect
- Account data. Your email address, a password hash (we never see the password itself), your account handle, and your tier. Authentication is handled by Supabase.
- Prompts and images. The text you write and the images generated from it, along with the style, dimensions, and model used.
- Usage data. Generation counts, per-request cost records, cache hit records, and API key usage timestamps.
- Technical data. IP addresses, used for rate limiting and abuse prevention. Referring domains, for embeds served on your sites.
- Analytics and errors. Page views and product events, plus error reports. Sentry session replay may record your interactions inside the dashboard.
We do not collect payment information. There is no payment processor connected during the free beta.
3. Where your prompts go
Your prompt text leaves our systems. It is sent to Runware to generate the image, and often to OpenAI first, which rewrites it to match the style you picked. Both are third parties with their own terms. Do not put confidential or personal information in a prompt.
4. Who else processes your data
| Service | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and image storage | Account records, hashed credentials, prompts, generated images |
| Vercel | Hosting and content delivery | Request metadata, IP addresses |
| Runware | Image generation | Prompt text and generation parameters |
| OpenAI | Prompt rewriting, image captioning, and search embeddings | Prompt text and image captions |
| Upstash | Caching, rate limiting, and background job state | Prompt hashes, IP-derived rate limit counters |
| PostHog | Product analytics | Usage events, page views, account identifiers |
| Sentry | Error monitoring and session replay | Error reports, request context, replay of dashboard sessions |
Email delivery for account confirmation is handled by [EMAIL PROVIDER].
5. The shared library
Images you generate may be added to a public shared library, watermarked and not attributed to you, along with the prompt that produced them. This is described in full in section 7 of the Terms of Service.
Flywheel opt-out is an account setting and prevents any of your images entering the library. Turn it on before generating anything you would not want public.
6. Cookies
We set cookies to keep you signed in. These are necessary for the service to work and cannot be turned off while you are logged in. PostHog sets analytics cookies to measure product usage. We do not run advertising cookies and we do not sell personal data.
7. How long we keep things
Account data is kept while your account exists. Generated images are kept until you delete them or delete your account. Rate limit counters expire within hours. Cost and analytics records are kept in aggregate for business accounting. Images already promoted to the shared library are kept indefinitely, because other people’s pages reference them.
8. Your rights
You can access and export your data from the dashboard, correct your account details in settings, and delete your account, which removes your images, keys, and account record. Depending on where you live you may also have rights to object to or restrict processing, or to complain to a data protection authority. To exercise anything not available in the dashboard, email [CONTACT EMAIL].
9. Children
Pixloom is not for children. Do not create an account if you are under [AGE, 13 or 16 depending on jurisdiction]. We do not knowingly collect data from children, and will delete such an account if we learn of it.
10. Security
Data is isolated per account by row-level security in the database. API keys are stored as hashes, never in plain text, and publishable keys are locked to the domains you register. No system is perfectly secure, and during the beta especially you should not store anything critical here.
11. International transfers
Our providers operate in the United States and elsewhere. Using Pixloom means your data may be processed outside your country, including in the United States.
12. Changes
We may update this policy. Material changes will be communicated to account holders where reasonably possible, and the date at the top of this page will change.