Legal
Privacy Policy
What Picsmob collects, which AI providers process your images, how long we keep your work, and how to get it back or delete it.
Effective September 20, 2026
1. Overview
This policy explains what personal data Picsmob collects, why, who else touches it, and what control you have. It covers the marketing site at picsmob.com and the studio application.
The short version: we collect what an account and a credit ledger require, we send your images to AI providers so tools can run, we do not train models on your work, we do not sell your data, and we run no advertising trackers.
2. Who is responsible for your data
[LEGAL ENTITY NAME], of [REGISTERED ADDRESS], is the data controller for the personal data described here. For privacy questions, data access, or deletion requests, write to [email protected].
3. What we collect
Account data:
- Your email address and display name.
- Your profile photo, either uploaded by you or taken from your Google account if you sign in with Google.
- Authentication records held by Firebase Authentication, including sign-in method and timestamps. We never see your password — Firebase stores it hashed.
- Preferences you set, such as default tool, library view, low-credit threshold, and which integrations you would like us to build.
Content data:
- Images and videos you upload, plus thumbnails and display copies we derive from them.
- Results generated by tools, and the editable canvas documents behind saved graphics.
- Prompts, scene descriptions, and tool settings you enter.
- Folder names and file names you choose.
Commercial data:
- Your credit balance and a ledger of every credit movement — signup bonus, reservation, charge, refund, purchase, referral bonus — with the tool and job it relates to.
- Purchase records: pack bought, amount, currency, status, and the Stripe invoice reference.
- Referral records showing who invited whom and whether a bonus was paid.
Technical data:
- Server logs from our backend functions, including job identifiers, tool names, error messages, and timestamps. These are operational records, used for debugging and abuse prevention.
- Theme and interface preferences stored locally in your browser, which never reach our servers.
We do not run analytics, advertising pixels, or third-party trackers on the studio application.
4. How we use it
- To provide the service: authenticate you, store your library, run tools, and return results.
- To operate the credit system: reserve, charge, and automatically refund credits, and show you the history.
- To take payment and issue receipts, through Stripe.
- To support you when you write in, which may mean looking at a specific job or asset you reference.
- To keep the service safe: detect abuse, fraud, duplicate signup-bonus claims, and content that breaches our terms.
- To meet legal and tax obligations, which is why purchase records outlive an account deletion.
We do not use your uploads or generated results to train machine-learning models, ours or anyone else's.
5. How your images reach AI providers
This is the part most worth reading. Picsmob does not run its own models. When you run a tool, our backend sends the relevant image — and, where the tool needs it, your prompt or reference images — to a third-party AI provider, receives the result, and stores it in your library.
Images are transmitted over encrypted connections and are sent only when you run a tool. Browsing your library sends nothing to a provider.
| Provider | What it receives | Used for |
|---|---|---|
| fal.ai | The image you are editing, any reference or mask images, and the tool's prompt | Background removal and generation, object replacement, shadows, try-on, product reveal, reels, and video generation |
| OpenAI | Product descriptions and prompts you type; for some tools, a low-resolution copy of the image | Writing video scripts, choosing palettes for motion ads, and labelling a masked object so a replacement matches it |
Each provider processes the data under its own terms and applies its own content filters. We ask providers not to use submitted content for model training; we cannot audit that on your behalf, and we recommend reading their published policies if you handle unreleased product imagery. If you are under NDA for a product, consider whether third-party processing is acceptable before uploading.
6. Other service providers
Beyond the AI providers above, these companies process data on our behalf:
| Provider | Role | Data involved |
|---|---|---|
| Google Firebase and Google Cloud | Authentication, database, file storage, and the servers our backend runs on | Account records, your library files, credit ledger, job records, logs |
| Stripe | Payment processing, invoices, and the billing portal | Your email, billing name and address, card details, and purchase history |
| Vercel | Hosting and delivery of the website and application | Request metadata such as IP address and user agent |
We do not sell personal data, and we do not share it with advertisers or data brokers. We disclose data to authorities only where we are legally required to, and we will tell you unless the law forbids it.
7. Payment data
Card details are entered on Stripe's hosted checkout and go directly to Stripe. Picsmob's servers never receive or store a full card number. What we store is a reference to the Stripe session, the pack purchased, the amount, and the invoice number, so we can show you your history and grant the right credits.
The billing details page reads your saved name, address, tax ID, and card brand and last four digits from Stripe when you open it. That information lives with Stripe, not with us.
8. Legal bases for processing
If you are in the UK, EU, or EEA, we rely on the following legal bases under the GDPR:
- Performance of a contract — running your account, storing your library, executing tools, and taking payment.
- Legitimate interests — securing the service, preventing fraud and abuse, and improving reliability, balanced against your rights.
- Legal obligation — keeping tax and transaction records.
- Consent — optional things you opt into, such as registering interest in an upcoming integration. You can withdraw consent at any time.
9. How long we keep things
- Library content stays until you delete it. Deleting an asset marks it deleted immediately and removes it from your library; the underlying files are purged from storage shortly after.
- Account data is kept while your account is open.
- Deleting your account removes your profile, library content, and stored files. Allow up to 30 days for removal to propagate through backups.
- Credit ledger and purchase records are retained for up to seven years after a transaction, because tax and accounting law requires it. These are kept in a minimised form tied to the transaction, not to your library.
- Operational logs are retained for a limited period for debugging and abuse investigation, then rotated out.
10. Your rights
You can exercise most of these yourself in Settings, immediately and without contacting us:
- Access and portability — Settings has a data export that produces your profile, credit transactions, purchases, and referral records in a machine-readable file.
- Correction — update your display name, avatar, and preferences at any time.
- Deletion — delete individual assets, or your whole account, from Settings.
- Objection and restriction — write to us if you want us to stop a particular processing activity.
- Withdraw consent — for anything you opted into.
For anything not covered by the in-app controls, email [email protected]. We respond within 30 days. If you are in the UK, EU, or EEA and are unhappy with our response, you may complain to your local data protection authority.
11. Cookies and local storage
Picsmob uses the minimum a logged-in application needs. There are no advertising cookies and no cross-site tracking.
- Authentication tokens, set by Firebase Authentication, keep you signed in. Without them the application cannot work.
- Local storage holds interface preferences such as light or dark theme and which notices you have dismissed. This stays in your browser.
12. Security
Data is encrypted in transit and at rest by our infrastructure providers. Access to your library is enforced at the database and storage layer: rules tie every file and record to your user identity, so one account cannot read another's content. Payment credentials never reach our systems.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.
13. International transfers
Our providers operate globally, so your data may be processed in countries other than your own, including the United States. Where data leaves the UK, EU, or EEA, transfers rely on the safeguards those providers maintain, such as standard contractual clauses and adequacy decisions.
14. Children
Picsmob is a commercial tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact [email protected] and we will remove it.
15. Changes to this policy
We will update this policy as the service changes — particularly if we add or change an AI provider. The effective date at the top always reflects the current version, and we will notify you of material changes by email or in the app before they take effect.
16. Contact
Privacy questions, access requests, and deletion requests go to [email protected], or to [LEGAL ENTITY NAME], [REGISTERED ADDRESS].