Privacy Policy
Effective 18 September 2026
This Privacy Policy explains how RED PIXEL (“RED PIXEL”, “we”, “us”, “our”), operated by Daniel Nagaets, collects, uses, stores and shares personal data when you visit redpixel.club or use the RED PIXEL application (together, the “Service”). It forms part of our Terms of Service. By creating an account or using the Service you acknowledge that you have read this Policy. If you do not agree with it, do not use the Service.
1. Who is responsible for your data
The data controller for the Service is Daniel Nagaets, reachable at nagaets.daniel@gmail.com. Where this Policy refers to “you”, it means the person using the Service; if you use it on behalf of a company, you confirm that you are authorised to accept this Policy for it.
2. Data we collect
- Account data — your email address, your password (stored only as a salted bcrypt hash, never in clear text), an optional display name and avatar, the date you registered, and the date and version of the Terms you accepted.
- Content — images you upload, prompts and text you type or dictate, the images and text the Service generates for you, your project graphs and node settings, and the technical metadata needed to render and store them (dimensions, model, timestamps, storage keys).
- Payment data — coin purchases are processed by Stripe. We receive and keep only the Stripe transaction reference, the amount, the currency, the pack bought and the time of purchase. We never see, receive or store card numbers or bank details.
- Coin ledger — every charge, refund, purchase and grant of coins on your account, with its reason, so that your balance is always explainable.
- Technical and usage data — IP address, browser and device type, the pages and endpoints you request, timestamps, error and performance logs, and a random per-tab identifier that prevents two open tabs from overwriting each other’s saves.
- Voice — if you use dictation, the short audio clip is sent to our speech-to-text provider and converted to text; we keep the text you dictated as part of your content, not the audio.
- Communications — messages you send us and our replies.
We do not knowingly collect special categories of data (such as health, political or biometric data). Images of people that you upload may reveal such information; you decide what you upload and you are responsible for it (see section 4).
3. Why we use data and on what legal basis
- To provide the Service (performance of a contract): creating and securing your account, rendering and storing your projects and images, managing your coin balance, answering support requests.
- To take payments and prevent fraud (contract, legal obligation, legitimate interest): processing purchases through Stripe, keeping the ledger, handling disputes and chargebacks.
- To keep the Service secure and working (legitimate interest): access control, abuse and attack prevention, debugging, capacity planning, backups.
- To communicate with you (contract, legitimate interest): password resets, receipts, notices about your account or changes to the Service, and a one-time launch announcement to registered accounts. You can opt out of non-essential emails at any time by writing to us.
- To comply with the law (legal obligation): tax and accounting records, responding to lawful requests from authorities, enforcing our Terms and protecting our rights.
- To improve the Service (legitimate interest): aggregated, de-identified usage statistics. We do not use your content to train AI models and we do not sell personal data.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
4. AI processing and third-party models
The Service generates images and text with models operated by OpenAI, L.L.C. (USA). Content you submit for generation — images, prompts, dictated audio — is transmitted to OpenAI and processed under OpenAI’s API terms and usage policies. According to OpenAI’s API data-usage commitments, content sent through the API is not used to train OpenAI’s models; OpenAI may retain it for a limited period for abuse monitoring. We have no control over how OpenAI operates its models and we are not responsible for its acts or omissions.
The People Enhancement tools detect and segment people locally, inside your browser; nothing leaves your device for that step. Person crops are sent to OpenAI only when you press an enhancement button.
You must have the right, and where required the informed consent of every person depicted, to upload and process any image of a person. Do not upload images of minors, images of people who have not agreed to it, or images you have no right to use. AI outputs are produced automatically; they may be inaccurate, unexpected, inappropriate or similar to outputs produced for other users, and they are provided without any warranty (see the Terms).
5. Who we share data with
We share personal data only with providers that process it on our behalf under contracts that restrict their use of it:
- OpenAI, L.L.C. — AI image and text generation, speech-to-text.
- Vercel, Inc. — hosting of the application, request logs.
- Supabase, Inc. — the database that stores accounts, projects and the coin ledger.
- Cloudflare, Inc. — storage of your images (R2), DNS and network security.
- Resend, Inc. — delivery of service emails (password reset, notices).
- Stripe, Inc. / Stripe Payments Europe, Ltd. — payment processing, receipts, fraud prevention.
We may also disclose data to professional advisers, to authorities when the law requires it or to protect the rights, property or safety of anyone, and to a successor in the event of a merger, acquisition or sale of the Service (who will be bound by this Policy). We never sell personal data and we never share it for third-party advertising.
6. International transfers
Our providers operate in the European Union and in the United States. Where personal data leaves the European Economic Area, the United Kingdom or Switzerland, the transfer is protected by an adequacy decision, by the provider’s certification under the EU-US Data Privacy Framework, or by the European Commission’s Standard Contractual Clauses, together with additional safeguards where necessary.
7. Cookies and local storage
The Service sets one strictly necessary cookie that keeps you signed in. We use no advertising cookies, no third-party analytics cookies and no cross-site tracking. Your browser’s local storage, session storage and IndexedDB hold preferences, the per-tab identifier and a backup of unsaved canvas changes; these stay on your device. Clearing them may lose unsaved work and signs you out.
8. How long we keep data
- Account data: for as long as your account exists, then up to 30 days (backups up to 90 days).
- Content: until you delete it or your account; deleted media is purged from storage within 90 days.
- Coin ledger and payment records: for as long as tax and accounting law requires, typically 7 to 10 years.
- Technical logs: typically 90 days, longer only while needed to investigate an incident.
- Password-reset tokens: one hour.
We may keep de-identified or aggregated data indefinitely.
9. Security
We protect data with TLS in transit, hashed passwords, encryption of secrets at rest, access limited to the operator and reputable infrastructure providers. No system is completely secure; you are responsible for keeping your password confidential and for the security of your own device. If we learn of a breach affecting your data we will notify you and the competent authority as the law requires.
10. Your rights
Depending on where you live (including the EU/EEA, the United Kingdom, Switzerland and California), you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to its processing, to receive it in a portable format, to withdraw consent, not to be discriminated against for exercising your rights, and to lodge a complaint with your data-protection authority. To exercise a right, email nagaets.daniel@gmail.com from the address registered on your account; we may ask for additional verification and will answer within one month (extendable where the law allows). We do not sell or share personal data for cross-context behavioural advertising, so there is nothing to opt out of.
11. Age
The Service is for adults only. You must be at least 18 years old (or the age of majority where you live, if higher) to create an account. We do not knowingly collect data from minors; if we learn that an account belongs to a minor we will close it and delete its data.
12. Changes to this Policy
We may update this Policy. The current version, with its effective date, is always published at this address. For material changes we will notify you by email or inside the Service before they take effect. Continued use of the Service after the effective date means you accept the updated Policy.
13. Contact
Daniel Nagaets — nagaets.daniel@gmail.com