Legal

Privacy Policy

This policy explains what Pixeloop collects, why, who else processes it, and the control you have over it. We have tried to write it in plain language rather than legalese. If anything here is unclear, email us at hello@pixeloop.app and we will explain it.

Last updated
22 September 2026

01Who this policy applies to

Pixeloop is operated by First Media Network Private Limited, a company incorporated in India with its registered office in Rewari, Haryana (“Pixeloop”, “we”, “us”). It applies to the Pixeloop website and web application.

You can use much of Pixeloop without an account: cropping, collages, compression and exporting all work as a guest. This policy covers both guest and signed-in use, and says which parts apply to which.

02What we collect

2.1 Information you give us

  • Account details (signed-in users only): your email address, and optionally your name and profile picture. If you sign in with Google, we receive these from Google rather than asking you to type them.
  • Your content: images you upload and designs you create. As a guest, your work stays in your browser and is not saved to our servers unless you export through our service. When you are signed in and save a design, it is stored on our servers so you can return to it.
  • Messages you send us: if you email us for support, we keep that correspondence so we can answer and follow up.

2.2 Information we collect automatically

  • Abuse and quota counters: we count AI operations per day to enforce limits and to stop the service being drained. For guests, that counter is keyed to a one-way hash (SHA-256) of your IP address. We do not store your raw IP address for this purpose, and the hash cannot be reversed back into it.
  • Standard server logs: like any web service, our infrastructure processes technical information such as IP address and browser type in order to deliver pages and defend against attacks.

2.3 Payment information

Payments are handled by Razorpay. Card numbers and similar payment credentials are entered with Razorpay and never reach our servers. We store the outcome, meaning which plan or credit pack you bought, the amount, the status, and an identifier linking you to your Razorpay customer record, because we need it for entitlements, refunds and accounting.

2.4 What we do not do

  • We run no analytics, advertising or tracking SDKs. There are no tracking pixels, no advertising cookies and no third-party behavioural profiling on Pixeloop.
  • We do not sell your personal information, and we do not share it for advertising.
  • We do not use your designs or images to train AI models.

03How your images are processed

This differs by tool, and the difference matters:

  • Stays on your device. Crop, collage, compression and the image upscaler all run in your browser. For these, your image is never uploaded to us. The upscaler in particular runs the AI model locally on your own hardware.
  • Sent for processing. AI background removal is performed by OpenAI. On the Background removal page, the image you selected is sent together with the instruction shown in the prompt field, including any wording you change. If you leave the instruction untouched, only the image is transmitted and our standard instruction is applied on our server. This happens only when you press the button; editing the instruction on its own sends nothing. We do not store the image or the instruction on our servers. The result is returned to your browser, and nothing about it is written to our database.
  • What OpenAI then does with it is governed by OpenAI’s API terms, not by us. We have never opted our account into training on API content, so OpenAI’s defaults for API traffic apply: they state that content sent through the API is not used to train their models, and that it may be held for a limited period for abuse monitoring before deletion. Those are their terms, they can change them, and they carry exceptions, for example where retention or review is required by law or to investigate suspected misuse.
  • Sent to the AI models. When you generate an image, a carousel, a thumbnail or a video, your prompt goes to fal.ai, who run the model you picked. Any reference images you attach, and the image you are editing, go with it. Asking us to rewrite a prompt, reading a poster you save as a style, or turning on the web-search facts panel sends that text or image to Google instead. Each provider handles what it receives under its own terms. We never send your work to anyone for the purpose of training a model on it.
  • Stored by us. Designs and assets you save while signed in are stored on our infrastructure (Cloudflare R2) so that your projects persist.

04Why we use it

  • To provide the service: making, saving and exporting your work.
  • To authenticate you and keep your account secure.
  • To process payments and apply the credits or plan you purchased.
  • To enforce fair-use limits and prevent abuse of paid AI features.
  • To respond to support requests.
  • To meet legal, tax and accounting obligations.

Where the GDPR or a similar law applies, we rely on: performance of a contract (providing the service you asked for), legitimate interests (security and abuse prevention), legal obligation (financial records), and consent where we ask for it.

05Who else processes your data

We use a small number of providers to run Pixeloop. Each receives only what it needs for its function:

ProviderPurposeData involved
ClerkAuthentication and session managementEmail address, name, profile image, sign-in metadata
RazorpayPayments and subscriptionsBilling details you enter at checkout, payment and subscription status
fal.aiRunning the AI image and video modelsYour prompt, any reference images you attach, and the image you are editing
OpenAIAI background removalThe single image you run the tool on, plus your instruction text if you edited it on the Background removal page
GoogleRewriting a prompt, reading a saved style, and web search for the facts panelThe prompt text, the poster you save as a style, and the topic you ask it to look up
Cloudflare R2Storage for saved designs and assetsImages and design files you save to your account
Google FontsServing the typefaces and icon fontIP address and browser details, as with any web font request

We may also disclose information where we are legally required to, or to protect our rights, users or infrastructure.

06Cookies and local storage

  • Session cookies set by Clerk keep you signed in. Without them you cannot stay logged in.
  • Preference cookies (pc-theme, pc-nav) remember whether you chose the light or dark theme and whether you collapsed the side menu.
  • Browser storage holds your in-progress editor session on your own device so a refresh does not lose your work. It is not transmitted to us.

We do not use advertising or analytics cookies.

07How long we keep it

  • Your designs and assets: until you delete them, or until you delete your account.
  • Your creations: images, videos and carousels in your history are kept for 30 days, then deleted automatically. You can delete any of them sooner.
  • Account details: when you delete your account we close it immediately and sign you out everywhere, so nobody can sign in to it again. We keep a minimal record of the account itself after that, and we will erase it on request. Email us and we will confirm once it is done.
  • Financial records: purchase, subscription and credit-ledger entries are deliberately retained after account deletion, detached from your identity where possible, because we are required to keep accurate accounting records.
  • Abuse counters: kept only as long as needed to enforce the relevant daily limit.

08Security

Access to production data is restricted, traffic is encrypted in transit, and payment credentials never touch our systems. No service can promise perfect security, but if a breach affects your personal data we will notify you and the relevant authority as required by law.

09Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can edit or delete most of your content directly in the app. For anything else, email hello@pixeloop.app and we will respond within the period the applicable law requires.

If you believe we have handled your data improperly, you may complain to your local data protection authority.

10International transfers

Our providers may process data in countries other than yours. Where required, such transfers are made under appropriate safeguards, such as the European Commission's standard contractual clauses.

11Children

Pixeloop is not for children. Indian law treats anyone under 18 as a child, and you must be 18 to hold an account with us. We do not knowingly collect a child's personal data, and we do not profile children or target advertising at them. If you believe a child has given us data, contact us and we will delete it.

12Changes to this policy

If we make a material change we will update the date at the top and, where the change significantly affects you, tell you in the app or by email. Continuing to use Pixeloop after a change means you accept the updated policy.

13Contact

Questions, requests or complaints about privacy: hello@pixeloop.app.

This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023. Pixeloop is operated by First Media Network Private Limited, registered office Rewari, Haryana.