privacy policy
What we collect, and what we don't.
No dark patterns, no data brokers, no training our models on your work. This page says plainly what happens to everything you type, upload and generate on Piffect.
effective 20 August 2026
01
Who we are
Piffect is an AI marketing studio at piffect.com. You describe a campaign in a sentence; we research it, draft a posting calendar, and generate the images and videos to run it.
For the purposes of data protection law, Piffect is the controller of the personal information described here. Reach us at info@pxlplay.app for any question, request or complaint about your data.
02
What we collect
Four kinds of information, and nothing else:
Account information
Your email address, a display name if you set one, an avatar if you upload one, and a password. The password is stored only as a salted hash that we cannot reverse. If you sign in with Google we receive your email address, name and profile picture from Google. We never receive your Google password.
What you create
The briefs you type, brand kits, products, uploaded logos and images, campaign plans, generated flyers and videos, edits made in the remix editor, and any files you attach to a campaign. This is your working material and it is the substance of the service.
How your files are served. Images and videos you upload or generate are stored on a content network and delivered over a long, randomly generated web address. Nobody can browse or list your files, and they are not indexed by search engines, but the address itself is the key: anyone you send it to can open it without signing in. That is what makes sharing a campaign with a client work. Treat a file link the way you would treat an unlisted document link, and delete anything you would rather not have a durable address.
Billing information
Your subscription status, plan, billing period and credit balance. We never see or store your card number. Card details go directly to Stripe, which is PCI-DSS certified. We hold only the customer and subscription identifiers Stripe gives us.
Technical and usage information
Pages visited, referring page, browser and device type, approximate location inferred from IP, and a session identifier. We record which generation jobs ran, what they cost in credits, and whether they failed. This is how we spot outages and stop double-charging.
We do not collect government identifiers, precise GPS location, biometric data, or the special categories of data protected under data protection law. We do not buy personal data from brokers.
03
Why we use it, and on what legal basis
- To run the service. Generate your campaigns, store your assets, keep you signed in, meter credits. Necessary to perform our contract with you.
- To take payment. Process subscriptions, issue receipts, handle failed payments. Necessary to perform our contract, and to comply with tax and accounting law.
- To send service email. Confirmation, password reset, verification codes, campaign-ready notices. Necessary to perform our contract.
- To keep the service working and safe. Debug failures, monitor abuse, enforce rate limits, prevent fraud. Our legitimate interest in a service that stays up and is not abused.
- To improve the product. Understand which features get used so we know what to build. Our legitimate interest, using aggregated data wherever it will do the job.
- Marketing email. Only if you opt in, and every message carries a one-click unsubscribe link. Consent, withdrawable at any time.
04
How your prompts and uploads are used by AI
This matters more than the rest, so it gets its own section.
- When you run a campaign, your brief and any images you attach are sent to Google (Gemini and Veo) to produce the plan, copy, images and video. Some video work may be routed to fal.ai instead.
- We do not train any model on your content. We have no in-house model, and we do not sell or license your prompts, uploads or generated assets to anyone to train theirs.
- Our providers are bound by their own API terms not to use business API content to train their general models. We rely on those terms. We cannot audit them ourselves, and you should read them if this is critical to you.
- Generated output is yours. See the Terms for the specifics of who owns what.
- When Piffect staff can see your work. We can access your prompts and generated assets for four reasons only: to answer a support request, to diagnose a render that failed, to investigate a report of abuse or a breach of our Terms, and to resolve a billing dispute. Every one of those views is recorded with the reason, the staff member and the time. We do not browse customer campaigns, and we never feature your work in our marketing, on our website or anywhere else unless you have made it public yourself or told us we may. Ask us at any time what has been accessed on your account and we will tell you.
- Please do not paste anything into a brief that you would not want leaving your organisation: payment details, passwords, health records, or anyone else's personal data you have no right to share.
05
Who else touches your data
We keep the list short on purpose. Each of these is a processor acting on our instructions, not a party we sell data to:
- Supabase. Database, authentication and file storage. Hosted in the EU (Stockholm).
- Cloudflare. Hosting, DNS and network protection. Serves the app from the edge location nearest you.
- Google. The Gemini and Veo models that generate your plans, images and video, and Google Sign-In if you use it.
- fal.ai. Additional video generation and background removal, used for some jobs.
- Stripe. Payments, subscriptions and card handling.
- Resend. Delivery of transactional email.
We may also disclose information if the law genuinely requires it, to establish or defend legal claims, or to a buyer if the business is ever sold. In that last case this policy travels with the data and you will be told before anything changes.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
06
Where your data goes
Piffect operates from the United States, and our database is in the European Union. Our providers are global, so your information will be processed in both the US and the EU, and potentially elsewhere our providers operate.
Where data leaves the UK or European Economic Area, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) in our contracts with each provider.
07
How long we keep it
- Account and content. For as long as your account is open.
- After you delete your account. Your content is removed from the live service straight away and purged from backups within 30 days.
- Billing records. Kept up to 7 years after the transaction, because tax law requires it.
- Technical and usage logs. Up to 12 months, then deleted or aggregated so they no longer identify anyone.
- Email suppression list. If you unsubscribe or bounce, we keep your address on a do-not-send list indefinitely. That record exists solely so we do not email you again.
08
Your rights
Wherever you live, you can ask us to do all of the following, and we will:
- See it. Get a copy of the personal information we hold about you.
- Fix it. Correct anything inaccurate.
- Delete it. Close your account and have your content erased.
- Take it. Receive your data in a portable, machine-readable format.
- Object or restrict. Tell us to stop a particular use, including any processing based on our legitimate interests.
- Withdraw consent. Unsubscribe from marketing at any time, without affecting anything you received before.
- Be free of retaliation. Exercising any of these rights will never degrade your service or change your price.
Email info@pxlplay.app and we will respond within 30 days. We may need to confirm your identity first, usually just by checking the request comes from your account email.
If you are in the UK or EEA and think we have got something wrong, you may complain to your national data protection authority. We would rather you came to us first.
09
Security
Traffic is encrypted in transit with TLS and data is encrypted at rest. Passwords are stored as salted hashes. Database access is governed by row-level security, so one account's queries cannot reach another's rows. Administrative access is limited to those who need it and every administrative action is logged.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal information we will tell you and the relevant regulator without undue delay, and within 72 hours where the law sets that deadline.
11
Children
Piffect is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, email info@pxlplay.app and we will delete it.
12
Changes to this policy
When we change this policy we update the effective date at the top. If a change materially affects your rights or how we use your information, we will email you before it takes effect. Continuing to use Piffect after that means you accept the updated policy.
piffect