1. What we collect
Account data
Your name, email address, and a password hash. We store a bcrypt hash, never the password itself, so we cannot read or recover it - only reset it.
Prompts and generated images
Every prompt you submit and every image it produces is stored against your account so your gallery works. Prompts are stored as you typed them. Images are stored with our image hosting provider and referenced by URL.
We also record which style preset you used, how long the generation took, and which of our provider API keys served it. That last field is for quota debugging and contains no information about you.
Payment data
We store the plan you bought, the amount, the credits granted, the payment status, and the Razorpay order and payment identifiers. We never receive, process, or store your card number, CVV, UPI PIN, or bank credentials. Those go directly to Razorpay and never touch our servers.
Technical data
We use your IP address transiently for rate limiting on signup, login, and generation. These counters are short-lived and expire automatically.
We use Vercel Web Analytics to count page views and see which pages people actually use. It is cookieless and does not follow you across other websites. It records the page visited plus coarse technical details such as country, browser, and device type, all of it aggregated. It does not record your name, email, prompts, or images, does not build a profile of you, and does not replay your session.
We run no advertising trackers and no session recording.
2. Cookies
We set exactly one cookie: pixscribe_session. It holds a signed token that identifies you to the service. It is httpOnly, so scripts on the page cannot read it, and it is marked secure in production. It lasts 30 days or until you sign out.
Our analytics is cookieless, so it adds nothing here. There are no advertising or cross-site tracking cookies, and therefore no consent banner to dismiss.
3. Why we process your data
- To provide the service - generating images, keeping your gallery, tracking your credit balance. This is contractual necessity.
- To take payment - creating and verifying orders, and keeping transaction records for accounting and support. This is contractual and legal obligation.
- To keep the service working - rate limiting, abuse prevention, and debugging. This is our legitimate interest in a functioning, non-abused service.
- To enforce our acceptable use policy - reviewing prompts and images that trigger our filters or are reported to us.
We do not sell your data, rent it, or use your prompts or images to train any model of our own.
4. Who else sees your data
We share the minimum necessary with four categories of processor:
- ClipDrop receives your prompt text in order to generate the image. It does not receive your name, email, or account identifier. Their handling of that prompt is governed by their own privacy policy.
- Cloudinary stores your generated images and serves them back to your browser.
- Razorpay handles payment. They receive your name and email to prefill checkout, plus whatever payment details you give them directly.
- Vercel hosts the application and provides the cookieless analytics described above. As the host, their infrastructure necessarily processes requests you make to the site.
We may also disclose data if we are legally required to, or where it is necessary to investigate a serious breach of our acceptable use policy.
5. Public images
Images are private by default. If you choose to publish one to the community showcase, that image and its prompt become visible to anyone visiting the site, including people without an account. Your name and email are never attached to a published image.
Making an image private again removes it from the showcase immediately. Copies other people already downloaded are, of course, beyond our reach.
6. How long we keep things
- Account and gallery data - until you delete it or close your account.
- Deleted images - removed from our database and from image storage when you delete them.
- Transaction records - retained after account closure where tax and accounting law requires it, typically several years. These are stripped of everything but the financial facts.
- Rate limit counters - minutes, then automatically purged.
7. Your rights
You can access your data, correct it, export it, or have it deleted. Some of this is self-serve: your gallery shows everything you have generated and lets you delete any of it, and your account page shows your full purchase history.
For anything else - a full export, or deletion of your entire account - email support@pixscribe.app. We will respond within 30 days. If you have unspent credits when you ask us to delete your account, tell us and we will handle any refund under the Refund Policy before deleting.
8. Security
Passwords are hashed with bcrypt. Session tokens are signed and stored in httpOnly cookies. All API keys and payment secrets are held server-side and are never sent to the browser. Payment confirmations are verified by cryptographic signature rather than trusted from the client.
No system is perfectly secure. If you believe your account has been accessed by someone else, change your password and contact us.
9. Children
PixScribe is not for under-18s. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
10. Changes
If we change this policy in a way that materially affects you, we will email account holders before it takes effect. The date at the top always reflects the current version.