Privacy policy
How PixMender collects, uses, shares, protects and deletes account information, uploaded images, generated results and service records.
Effective · Last updated
Who this policy covers
This policy applies to the PixMender website, web application and API. The PixMender service operator, based in Cyprus, acts as controller for account, billing, support and service-administration data. For images and other personal data submitted by a business customer through the API, that customer may be the controller and PixMender may act as its processor.
Information you provide
We process an email address, name and authentication credentials when you create or access an account. We also process uploaded images, edit instructions, API and webhook settings, support messages, payment order details and any other information you choose to submit. Passwords are stored only as secure hashes, and complete API keys are shown only when created.
Information collected automatically
We record IP address, browser or client type, request time, API-key prefix, job and operation identifiers, status, error, usage, security and audit events. These records help deliver requests, calculate credits, troubleshoot failures, prevent abuse and protect accounts. We do not use submitted images to build advertising profiles.
Images and AI processing
Uploaded images, prompts and operation settings are processed only to perform the edits you request, validate results and address failures or abuse. Depending on the selected operation, the necessary image and instruction may be sent to a configured external inference provider or an authorized processing worker. Do not submit an image unless you have the required rights and authority, especially where it contains another person or sensitive information.
Why we use information
We use account, image and job data to perform our contract with you by providing the service, authentication, credits, downloads and support. We use limited technical and security records for our legitimate interests in reliability, fraud prevention, abuse investigation and product improvement. We process payment and compliance records where required by law. Where consent is the appropriate basis, you may withdraw it without affecting earlier lawful processing.
Service providers and recipients
Information is shared only as needed with infrastructure, content-delivery, authentication, email, payment-network monitoring and AI-processing providers. Current service functions include Cloudflare for public traffic, Google when you choose Google sign-in, Resend for transactional email, TronGrid for confirming USDT transactions and configured inference providers for requested image operations. We may also disclose information where law requires it or where necessary to protect rights and safety.
International transfers
Our providers and processing workers may handle data outside your country or the European Economic Area. Where data-protection law requires a transfer mechanism, we rely on an adequacy decision, approved contractual safeguards or another lawful mechanism and apply technical and organizational protections appropriate to the data.
Retention
Original images, normalized inputs, intermediate files, previews and generated results receive a 24-hour expiry time. Automated cleanup starts after expiry and retries temporary storage failures until deletion succeeds. A locally saved pre-signup image draft remains in your browser for up to 48 hours unless you clear it sooner. Account, job, credit, payment, webhook, security and audit records are retained for as long as needed to operate the account, maintain an accurate ledger, resolve disputes, enforce agreements and meet legal obligations; deletion requests are assessed against those requirements.
Security
We use private object storage, short-lived signed file links, encrypted network transport, hashed passwords and API keys, scoped access, upload validation and operational logging. No service can guarantee absolute security. Revoke an exposed API key immediately and report suspected compromise to [email protected].
Your rights and choices
Depending on your location, you may request access, correction, deletion, restriction, objection or a portable copy of personal data, and may withdraw consent where processing relies on consent. You may revoke API keys in your account. Send a request from your account email to [email protected]; we may ask for information needed to verify identity and will respond within the period required by applicable law.
Complaints, children and automated decisions
You may lodge a complaint with your local data-protection authority, including the competent authority in Cyprus. PixMender is not directed to children under 16, and we do not knowingly offer accounts to them. Image processing is automated, but PixMender does not use account data to make solely automated decisions that produce legal or similarly significant effects about you.
Changes and contact
We may update this policy when the service, providers or law changes. The date above shows the latest revision, and material changes will be communicated through the service or account email when appropriate. Questions and privacy requests can be sent to [email protected].