Privacy Policy
This policy explains what personal data Piixel (“Piixel”, “we”, “us”) collects when you use our AI app-builder, why we process it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Swedish data protection law. We are the controller for Piixel account and platform data. For generated-app member and store-customer data, the project owner is normally the controller and Piixel is its processor, except where we process limited records for our own security, abuse-prevention or legal obligations.
1. Who we are
Piixel is operated by Piixel Studio, a sole trader (enskild firma) established in Sweden, with registered address Strandliden 29, 165 61 Stockholm, Sweden. If you have any question about this policy or your data, contact us at support@piixel.ai.
2. The data we collect
- Account data — your email address and, when you use social sign-in, the provider name and stable provider account identifier. If you use email sign-in, we store a securely hashed password; we never store it in readable form. During sign-up we also hold a short-lived keyed hash of your verification code.
- Your content — the prompts you type and the projects you build: chat messages, generated source code and files, and snapshots. This may contain personal data if you put it there. Apps you publish are served at a public URL; pages may be public or protected by account features you choose to build.
- Generated-app member data — when a visitor registers in an app hosted by Piixel, we store the name and email they submit, a one-way password hash, and a hashed server-session token in a generated-app database that is separate from Piixel account data. Records are isolated to that app. The app owner decides why member data is collected and should provide visitors with an appropriate privacy notice; Piixel processes it to host and operate the app.
- Generated-store order data — when a customer starts or completes checkout in a generated store, we store the Piixel and Stripe order references, products and quantities, amount and currency, payment/refund/dispute status, fulfilment status and the customer email returned by Stripe. We use verified Stripe events to update this record. We do not receive or store the customer’s card number.
- Billing data — if you subscribe, your plan and a Stripe customer reference, plus the billing name, address and VAT details you enter at checkout. We do not see or store your card number — card details are handled directly by Stripe.
- Usage data — a record of your builds (model used, token counts, cost, whether a build was billed) so we can run quotas, billing and our service.
- Technical data — limited request metadata (such as IP address) used transiently for security, rate-limiting and bot protection.
3. Why we use it, and our legal bases
- To provide the service — create your account, run builds, store and display your projects. Legal basis: performance of our contract with you (Art. 6(1)(b)).
- To take payment and keep records — process subscriptions through Stripe and meet tax/accounting obligations. Legal basis: contract, and legal obligation (Art. 6(1)(b),(c)).
- To operate generated-store checkout — create and reconcile orders, show them to the store owner, record fulfilment, and detect refunds, disputes and abuse. For customer data, the store owner determines the purpose and legal basis and Piixel acts as its processor/service provider; for platform security and abuse prevention, Piixel acts as controller based on legitimate interests and legal obligations (Art. 6(1)(c),(f)).
- To keep the service secure and prevent abuse — bot protection (Cloudflare Turnstile), rate limiting and the usage ledger. Legal basis: our legitimate interests in a secure, sustainable service (Art. 6(1)(f)).
- To operate, maintain and improve the service. Legal basis: legitimate interests (Art. 6(1)(f)).
- To send you service messages (e.g. about your account or a purchase). Any optional marketing is sent only with your consent. Legal basis: legitimate interests / your consent (Art. 6(1)(a),(f)).
4. AI processing of your content
Piixel turns your prompts into working software by sending them — together with the relevant code from your project — to third-party AI model providers that generate the plan, the code and any images. This processing is necessary to deliver the feature you asked for (Art. 6(1)(b)). We do not use your content to train our own models. Your content is processed by the AI subprocessors listed in section 5 under their own terms; we choose providers and settings to limit further use of your data, but we encourage you not to include sensitive personal data in prompts you don’t need to.
5. Who we share data with (subprocessors)
We do not sell your personal data. We share it only with service providers that help us run Piixel, under appropriate data-processing terms:
- Cloudflare — hosting, database, storage, edge delivery and bot protection (the infrastructure Piixel runs on).
- Stripe — Piixel subscription payments and, when a project owner enables commerce, checkout and direct charges on that seller’s connected Stripe account. Stripe receives the customer’s payment and checkout information under its own terms.
- DeepSeek — the AI models that plan and write your code; receives your prompts and relevant project code.
- xAI (Grok) and fal.ai (FLUX) — on-demand image generation for your apps; receive the prompt/topic used to make an image.
- Anthropic and OpenAI — alternative AI model providers we may use as fallbacks; if enabled they would receive the same prompt and project code as our primary model.
- Google — if you choose Google sign-in, it verifies your identity and supplies your verified email address and stable account identifier. Piixel does not retain the provider access token used for sign-in.
- GitHub — if you choose GitHub sign-in, it verifies your identity and supplies your verified primary email address and stable account identifier; the sign-in token is not retained. Separately, if you connect project export, we create/update a private repository in your account and retain that export authorisation encrypted until you disconnect or delete your account.
Your browser also loads fonts and interface libraries (e.g. Google Fonts/Material Icons, the code editor and animation libraries) from third-party content-delivery networks. This exposes your IP address to those providers as a normal part of loading the page. We do not use advertising or analytics trackers.
6. International transfers
Some of these providers are located outside the European Economic Area (EEA) — in the United States (Cloudflare, Stripe, Google, GitHub, xAI, fal.ai, any Anthropic/OpenAI fallback, and the fonts/CDNs above) and, for our primary AI models, in China (DeepSeek). For US providers we rely on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise on the Commission’s Standard Contractual Clauses (SCCs).
Transfers to China are not covered by an EU adequacy decision and carry higher risk. We rely on SCCs together with supplementary measures: model requests are pseudonymised — they contain only your prompt and the project code being built, never your name, email address, account identity or billing details; they are encrypted in transit; and they are processed under data-processing terms that limit use to providing the service. Because your prompts and code are sent as you wrote them, avoid pasting sensitive personal data into them. You can request a copy of the safeguards we rely on at support@piixel.ai.
7. How long we keep it
We keep your account and project data for as long as your account is active. When you delete a project or your account, we delete the associated files, history, snapshots, generated-app member accounts and sessions, and generated-store order records tied to that project; we retain a minimal billing/usage record where we need it to meet legal, accounting and fraud-prevention obligations. A seller remains responsible for exporting any transaction records it must keep before deleting a project. We may retain a connected-account review record after project deletion when reasonably necessary to prevent a suspended or abusive seller from immediately reconnecting through another project. An unfinished email sign-up expires after 15 minutes and its pending email, password hash and code hash are automatically purged. Security and rate-limit data is also short-lived and expires automatically.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format;
- withdraw any consent you have given, at any time.
To exercise any of these, email support@piixel.ai. You can also delete your account — and with it your projects, files, chat history, snapshots and published apps — yourself at any time from the dashboard (account menu → Delete account). You also have the right to lodge a complaint with your local supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, imy.se).
9. Cookies and local storage
Piixel does not use advertising or third-party analytics cookies. The Piixel builder uses local storage for strictly necessary purposes such as keeping you signed in, remembering your theme, and recent/starred projects. Published apps with member accounts use a host-only, secure, HttpOnly session cookie; passwords, account records and session tokens are not stored in local storage. These technologies are not used to track you across unrelated sites.
10. Security
We protect your data with measures including hashed passwords where password sign-in is used, encrypted connections, rotating session tokens, access controls scoped to your account, and bot protection. No system is perfectly secure, but we work to keep your data safe and to respond promptly to any incident.
11. Store owners and their customers
A project owner that sells through a generated app is the controller/business for its customers’ personal data and must provide an accurate store privacy notice, a lawful basis, contact details and a way for customers to exercise their rights. Piixel processes order data on that owner’s instructions to provide checkout infrastructure and the order ledger, while Stripe processes payment data. Customer requests about a purchase should normally be sent first to the store owner; privacy questions about Piixel’s processing can also be sent to support@piixel.ai.
12. Children
Piixel is not directed at children. You must be at least 16, or the age of digital consent in your country, to use the service.
13. Automated decisions
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Piixel’s AI generates software at your direction; it does not profile you.
14. Changes to this policy
We may update this policy from time to time. If we make a material change we’ll give reasonable notice, and the “last updated” date above will change.
15. Contact
Questions or requests about your privacy? Email support@piixel.ai. See also our Terms of Service.