Privacy Policy
Phoxel ("we", "our", or "us") is operated by Maksym Soloviov, an individual entrepreneur (Фізична особа-підприємець / FOP) registered in Ukraine. Registration number and registered business address are available on written request at hello@phoxel.app. This policy explains what data we collect, how we use it, and your rights under GDPR, CCPA, and similar laws.
1. Data We Collect
- Account data: email address, your display name, and - if you register with an email and password - a hashed password. If you use Google Sign-In instead, Google sends us your email address, your name, and your Google account identifier; we store those and never receive or store a password for that account.
- Reference photos: the photos you upload to start a project. In subject niches these show a pet, product, vehicle, dish, garment or room, and are automatically screened on upload and refused if a person appears in them. In portrait niches (headshots, dating, wedding, memorial, restoration and similar) the reference photos are photos of you, or of people who have given you their consent. We store them on Cloudflare R2 and pass them to Replicate at generation time as input to the AI model.
- Project data: the niche you picked, the style settings you chose, prompts derived from those settings, and the generated photos delivered to your project.
- Payment data: all payment processing is handled by Whop, our payment provider and Merchant of Record for transaction taxes. We store only the payment ID and the amount of credits added. We never see, store, or process your card details.
- Usage data: IP address (used for rate limiting only, not retained long-term) and request timestamps.
- Analytics data: aggregated, anonymous traffic data (page views, country, device type) collected by Cloudflare Web Analytics. We also use PostHog for product analytics on our website and in the app: page views, clicks on links that lead into the app, script errors, and product events such as signing up, moving through the project wizard, creating a project or opening checkout. PostHog is configured without cookies, without identifiers stored in your browser and without session recording. Once you are signed in, app events are linked to your internal account ID, not to your email address or name. PostHog receives your IP address with each event and uses it to work out an approximate location (such as country and city). PostHog data is processed in the EU.
- Sign-up source: when you create an account we store how you first arrived - the referring website, campaign tags in the link (such as
utm_source) and the page of our website you started from - so we can see which channels bring people to Phoxel. - Error reports: when something fails on our servers, a report is sent to Sentry with the error message, technical details of where it happened and details of the request involved; secrets such as access tokens are removed from URLs before sending. We don't attach your account to these reports, but a report can contain personal data that was part of the failing request, such as an email address.
2. How We Use Your Data
- To operate the photo generation service - passing your reference photos to the AI model and delivering the generated photos back to you.
- To send transactional emails (payment receipts, project-ready notifications, account-related notifications). We use Resend for email delivery.
- To prevent abuse via rate limiting and basic safety checks on uploads.
- To understand aggregate traffic via Cloudflare Web Analytics, and via PostHog how people find and use Phoxel - for example, which pages lead to sign-ups and where the project wizard gets abandoned - so we can improve the product.
- To detect, investigate and fix errors via Sentry.
- To enable retries on failed generations - when a generation fails, we may re-issue the same reference photos to the upstream model to fulfil your order.
3. Data Retention
- Reference photos (uploads): retained while you are still creating a project. Uploaded reference photos that are never attached to a project are automatically deleted after 24 hours. Reference photos that are attached to a project remain available so the project page can show what generations were based on; they are deleted when you delete the project.
- Generated photos: stored on our servers and remain available in your account until you delete the project they belong to. We do not impose an automatic expiry on generated photos. For photos generated before your first purchase we also store a smaller watermarked preview copy; it follows the same rule and is deleted together with the photo or project.
- Account data: retained until you delete your account.
- Payment records: retained for 7 years for tax and accounting compliance.
4. Third-Party Services
- Replicate - runs the AI image generation models (the specific model varies by niche and may change over time; see the Terms of Service). Your reference photos are sent to Replicate as model input. Subject to Replicate's Privacy Policy. Replicate in turn discloses which upstream provider handles inference for each model.
- Google - provides Google Sign-In. If you choose it, Google tells us your email address, name and account identifier so we can create or find your account. We send Google nothing about you: your photos, projects and credit balance are never shared with them. Subject to Google's Privacy Policy.
- Whop - processes payments and acts as Merchant of Record for transaction taxes. Subject to Whop's Privacy Policy.
- Resend - delivers transactional emails (receipts, project-ready notifications, password reset). Subject to Resend's Privacy Policy.
- PostHog - product analytics for our website and app, configured without cookies, browser-stored identifiers or session recording. Data is processed in the EU (PostHog EU Cloud). Subject to PostHog's Privacy Policy.
- Sentry - error monitoring for our backend: receives error reports and performance traces for a sample of requests. Subject to Sentry's Privacy Policy.
- Neon - hosts our PostgreSQL database (used to store accounts, projects, and credit balances). The Phoxel database is fully separate from any other product we operate.
- Railway - hosts our backend application.
- Cloudflare - hosts our landing pages and frontend app, provides DNS and CDN, stores reference and generated photos on R2, and provides Web Analytics.
5. Cookies and Tracking
We do not use advertising or tracking cookies. Authentication tokens are stored in your browser's localStorage for keeping you signed in, and until you sign up the app keeps a note there of how you first arrived (see "Sign-up source" in Section 1). Our PostHog analytics does not use cookies or store identifiers in your browser. Cloudflare may set technical cookies necessary for security and basic functioning of the website. The sign-in page loads Google's sign-in widget from accounts.google.com; Google may set its own cookies to recognise that you are signed in to Google. That widget only appears on the sign-in page and is not loaded anywhere else.
6. International Data Transfers
Your data may be processed in the United States, the European Union, or Ukraine (where our team is based). We use providers that comply with GDPR and standard contractual clauses for cross-border transfers.
7. Your Rights
Under GDPR, CCPA, and similar laws, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Export your data in a portable format
- Object to specific processing activities
To exercise any of these rights, email us at privacy@phoxel.app. We respond within 30 days.
8. Biometric and Likeness Data
In subject niches (products, pets, rooms and similar), every reference photo is automatically screened on upload and refused if a person appears in it, so photos of people never enter those pipelines. That screening looks only for human presence in the moment of upload - it does not identify anyone.
In portrait niches, reference photos of people are the input by design. Your likeness in those photos is used only as input to the AI image generation model, at generation time, to produce the photos you requested - the generations are configured to preserve the real likeness of the people in your references, not to invent or substitute a different person. We do not build, store, or sell any facial recognition profile or biometric template, we do not use your photos to identify you or anyone else, and we do not train AI models on your photos. Reference photos follow the retention rules in Section 3: unattached uploads are deleted automatically, and deleting a project deletes its reference photos and results. If an uploaded photo incidentally contains other personal data (for example, a licence plate or a street sign), it is likewise used only as generation input on your behalf and is deleted with the rest of your uploads.
9. Children's Privacy
The Service is not intended for users under 16 years old. We do not knowingly collect data from children. If you believe a child has provided us with data, please contact us immediately at privacy@phoxel.app.
10. Changes
We may update this policy from time to time. The date at the top reflects the latest revision. Material changes will be communicated to registered users via email.
11. Contact
Questions? Email us at privacy@phoxel.app.