← Back to Phoxel Privacy Policy
Last updated: June 2026
Phoxel ("we", "our", or "us") is operated by Maksym Soloviov, an individual entrepreneur (Фізична особа-підприємець / FOP) registered in Ukraine. Registration number and registered business address are available on written request at hello@phoxel.app. This policy explains what data we collect, how we use it, and your rights under GDPR, CCPA, and similar laws.
1. Data We Collect
- Account data: email address, a hashed password, and your display name when you register.
- Reference photos: the photos of your subject (pet, product, vehicle, dish, garment or room) you upload to start a project. We store them on Cloudflare R2 and pass them to Replicate at generation time as input to the AI model. Reference photos must not contain identifiable people.
- Project data: the niche you picked, the style settings you chose, prompts derived from those settings, and the generated photos delivered to your project.
- Payment data: all payment processing is handled by Paddle as our Merchant of Record. We store only the order ID and the amount of credits added. We never see, store, or process your card details.
- Usage data: IP address (used for rate limiting only, not retained long-term) and request timestamps.
- Analytics data: aggregated, anonymous traffic data (page views, country, device type) collected by Cloudflare Web Analytics. No cookies are set; no personal identification.
2. How We Use Your Data
- To operate the photo generation service — passing your reference photos to the AI model and delivering the generated photos back to you.
- To send transactional emails (payment receipts, project-ready notifications, account-related notifications). We use Resend for email delivery.
- To prevent abuse via rate limiting and basic safety checks on uploads.
- To understand aggregate traffic patterns via Cloudflare Web Analytics.
- To enable retries on failed generations — when a generation fails, we may re-issue the same reference photos to the upstream model to fulfil your order.
3. Data Retention
- Reference photos (uploads): retained while you are still creating a project. Uploaded reference photos that are never attached to a project are automatically deleted after 24 hours. Reference photos that are attached to a project remain available so the project page can show what generations were based on; they are deleted when you delete the project.
- Generated photos: stored on our servers and remain available in your account until you delete the project they belong to. We do not impose an automatic expiry on generated photos.
- Account data: retained until you delete your account.
- Payment records: retained for 7 years for tax and accounting compliance.
4. Third-Party Services
- Replicate — runs the AI image generation models (currently Google Nano Banana Pro and Black Forest Labs FLUX 2 max). Your reference photos are sent to Replicate as model input. Subject to Replicate's Privacy Policy. Replicate in turn discloses which upstream providers (e.g. Google, Black Forest Labs) handle inference for each specific model.
- Paddle — handles payments as Merchant of Record, including tax compliance. Subject to Paddle's Privacy Policy.
- Resend — delivers transactional emails (receipts, project-ready notifications, password reset). Subject to Resend's Privacy Policy.
- Neon — hosts our PostgreSQL database (used to store accounts, projects, and credit balances). The Phoxel database is fully separate from any other product we operate.
- Railway — hosts our backend application.
- Cloudflare — hosts our landing pages and frontend app, provides DNS and CDN, stores reference and generated photos on R2, and provides Web Analytics.
5. Cookies and Tracking
We do not use advertising or tracking cookies. Authentication tokens are stored in your browser's localStorage for keeping you signed in. Cloudflare may set technical cookies necessary for security and basic functioning of the website.
6. International Data Transfers
Your data may be processed in the United States, the European Union, or Ukraine (where our team is based). We use providers that comply with GDPR and standard contractual clauses for cross-border transfers.
7. Your Rights
Under GDPR, CCPA, and similar laws, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Export your data in a portable format
- Object to specific processing activities
To exercise any of these rights, email us at privacy@phoxel.app. We respond within 30 days.
8. Biometric and Likeness Data
Phoxel does not offer AI generation of photos of people, and reference photos must not contain identifiable people. We do not build, store, or sell any facial recognition profile, and we do not train AI models on your photos. If an uploaded photo incidentally contains personal data (for example, a reflection or a licence plate), it is used only as input to the AI image generation model on your behalf and is deleted with the rest of your uploads.
9. Children's Privacy
The Service is not intended for users under 16 years old. We do not knowingly collect data from children. If you believe a child has provided us with data, please contact us immediately at privacy@phoxel.app.
10. Changes
We may update this policy from time to time. The date at the top reflects the latest revision. Material changes will be communicated to registered users via email.
11. Contact
Questions? Email us at privacy@phoxel.app.