← Back to Phoxel

Privacy Policy

Phoxel ("we", "our", or "us") is operated by Maksym Soloviov, an individual entrepreneur (Фізична особа-підприємець / FOP) registered in Ukraine. Registration number and registered business address are available on written request at hello@phoxel.app. This policy explains what data we collect, how we use it, and your rights under GDPR, CCPA, and similar laws.

1. Data We Collect

2. How We Use Your Data

3. Data Retention

4. Third-Party Services

5. Cookies and Tracking

We do not use advertising or tracking cookies. Authentication tokens are stored in your browser's localStorage for keeping you signed in, and until you sign up the app keeps a note there of how you first arrived (see "Sign-up source" in Section 1). Our PostHog analytics does not use cookies or store identifiers in your browser. Cloudflare may set technical cookies necessary for security and basic functioning of the website. The sign-in page loads Google's sign-in widget from accounts.google.com; Google may set its own cookies to recognise that you are signed in to Google. That widget only appears on the sign-in page and is not loaded anywhere else.

6. International Data Transfers

Your data may be processed in the United States, the European Union, or Ukraine (where our team is based). We use providers that comply with GDPR and standard contractual clauses for cross-border transfers.

7. Your Rights

Under GDPR, CCPA, and similar laws, you have the right to:

To exercise any of these rights, email us at privacy@phoxel.app. We respond within 30 days.

8. Biometric and Likeness Data

In subject niches (products, pets, rooms and similar), every reference photo is automatically screened on upload and refused if a person appears in it, so photos of people never enter those pipelines. That screening looks only for human presence in the moment of upload - it does not identify anyone.

In portrait niches, reference photos of people are the input by design. Your likeness in those photos is used only as input to the AI image generation model, at generation time, to produce the photos you requested - the generations are configured to preserve the real likeness of the people in your references, not to invent or substitute a different person. We do not build, store, or sell any facial recognition profile or biometric template, we do not use your photos to identify you or anyone else, and we do not train AI models on your photos. Reference photos follow the retention rules in Section 3: unattached uploads are deleted automatically, and deleting a project deletes its reference photos and results. If an uploaded photo incidentally contains other personal data (for example, a licence plate or a street sign), it is likewise used only as generation input on your behalf and is deleted with the rest of your uploads.

9. Children's Privacy

The Service is not intended for users under 16 years old. We do not knowingly collect data from children. If you believe a child has provided us with data, please contact us immediately at privacy@phoxel.app.

10. Changes

We may update this policy from time to time. The date at the top reflects the latest revision. Material changes will be communicated to registered users via email.

11. Contact

Questions? Email us at privacy@phoxel.app.