PixGT Privacy Policy
Version 1.0 · Last updated August 14, 2026
LIU CHANG (“we”, “us”) respects and protects your privacy. This Privacy Policy (the “Policy”) explains how we collect, use, store, and share your personal information when you use PixGT (the “Service”), and what rights you have under applicable law.
Please read this Policy before using the Service. By using the Service you confirm that you have read and accepted it. We may update this Policy from time to time; material changes will be announced by email to your registered address before they take effect.
1. Data Controller
The data controller for the Service is:
- Controller: LIU CHANG, an individual sole trader operating under the laws of the People's Republic of China
- Brand / product: PixGT (https://pixgt.com)
- Privacy contact: mianshinn@foxmail.com
- Data Protection Officer: not appointed (not required at our scale of processing)
2. Personal Information We Collect
2.1 Information you provide
- Account information: email address, and password (stored hashed, never in plain text). If you sign in with Google or Apple, we receive the basic profile information those providers release — your email address and, where provided, your display name.
- Payment information: transaction amount, currency, and payment status. We never receive or store your full card number — card data is handled by our payment processor (see Section 5).
- Content you upload: product photos and reference images you submit for generation, and the prompts you write.
- Communications: emails, support tickets, and feedback you send us.
2.2 Information collected automatically
- Device and network: IP address, device model, operating system, browser type, and time zone.
- Usage behaviour: pages visited, features used, actions taken, and session duration.
- Log and performance data: request timestamps, error logs, and page load timings (used to diagnose slow or failing sessions).
- Generation records: the tasks you run, their parameters, and their results, so you can find them again in your history.
We do not collect precise location data, contacts, biometric identifiers, or any special category data. We do not scan your uploads for any purpose other than delivering the Service and enforcing the Acceptable Use Policy.
3. How We Use Your Personal Information
| Purpose | Legal basis |
|---|---|
| Providing and maintaining the Service | Performance of a contract |
| Billing and payment processing | Performance of a contract |
| Customer support | Performance of a contract / legitimate interest |
| Service notices (billing, security, policy updates) | Legitimate interest |
| Security and fraud prevention | Legitimate interest |
| Product improvement and analytics | Legitimate interest |
| Legal compliance | Legal obligation |
We may aggregate or de-identify data for statistical analysis. Such data cannot be traced back to an individual. We do not use your uploaded images or prompts to train AI models without your explicit consent.
4. Cookies and Tracking Technologies
| Type | Purpose | Can be disabled |
|---|---|---|
| Strictly necessary | Keeping you signed in, core functionality | No |
| Functional | Language preference, interface settings | Yes |
| Analytics | Anonymous usage statistics, product improvement | Yes |
We use PostHog for product analytics (PostHog privacy policy). We do not run advertising or cross-site tracking cookies. You can adjust preferences through your browser settings.
5. Sharing and Disclosure
We do not sell your personal information, including as “sale” is defined under applicable law such as the CCPA. We share information only in the situations below:
- Payment processing: payment card data is handled exclusively by our PCI-DSS compliant payment processor and merchant of record, Waffo Pancake, and is never stored on our servers. We receive only the transaction result and the last four digits of the card where the processor provides them.
- AI model providers: to generate your requested output, the images and prompts you submit are transmitted to third-party AI model providers, including Alibaba Cloud Model Studio (Qwen / Wan), ByteDance Volcano Engine (Doubao / Seedream), and Meitu. They process this content to return a result and are bound by their own terms.
- Content-safety providers: to keep the Service lawful and safe, your text prompts are transmitted to Waffo Prompt Sift and to Amazon Bedrock Guardrails for screening before generation, and the images you upload — together with the images we generate for you — are transmitted to Amazon Rekognition Content Moderation for screening. These providers process the content only to return a safety verdict. Waffo states that prompt text is not retained after the verdict is returned.
- Infrastructure providers: cloud hosting, object storage, and email delivery vendors, all under confidentiality obligations and processing only what is needed to run the Service. Uploaded and generated images are stored on Amazon S3 in the Asia Pacific (Singapore) region.
- Legal and regulatory: where required by law, court order, or a lawful request from a competent authority.
- Business transfers: in a merger or acquisition, with prior notice and continuity of protection obligations.
- With your consent: for any other purpose, with your explicit prior consent.
6. Security
- Encryption in transit: TLS / HTTPS across the whole Service.
- Storage security: passwords are hashed; sensitive fields are encrypted at rest.
- Access control: least-privilege access, limited to those who need it to operate the Service.
- Regular dependency and vulnerability review.
If a security incident affects your rights, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it, as required by applicable law. Please keep your account credentials safe and do not share them.
7. Data Retention
| Data type | Retention period | On expiry |
|---|---|---|
| Account information | Life of the account; 90 days after deletion | Deleted |
| Uploaded images and generated results | Life of the account; 90 days after deletion | Deleted |
| Transaction records | 5 years (accounting and tax obligations) | Deleted or archived |
| Support correspondence | 2 years | Securely deleted |
| Security and access logs | 6 months | Securely deleted |
8. Your Rights
To exercise any of the rights below, email mianshinn@foxmail.com. We respond within 30 calendar days and do not charge for reasonable requests.
| Right | What it means |
|---|---|
| Right to be informed | Know what data we collect and how we use it |
| Right of access | Obtain a copy of your personal information |
| Right to rectification | Correct inaccurate or incomplete information |
| Right to erasure | Request deletion of your data, subject to legal retention |
| Right to restrict processing | Pause processing in specific circumstances |
| Right to data portability | Receive your data in a machine-readable format |
| Right to object | Object to processing based on legitimate interest |
| Right to withdraw consent | Withdraw consent where processing relies on it |
You can delete your account and its data directly in the product at any time. If you believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority.
9. Marketing Communications
We send service notices (billing confirmations, security alerts, policy updates) as part of providing the Service — these cannot be opted out of while your account is active. We send marketing email only with your consent, and every marketing email carries an unsubscribe link. Unsubscribing from marketing does not affect service notices.
10. International Data Transfers
Our servers are located in Singapore. Some of our AI model providers and infrastructure vendors operate in the People's Republic of China and other regions, so your content may be transferred across borders in order to deliver the Service. Where we transfer personal data out of the EEA or the UK, we rely on data processing agreements incorporating the EU Standard Contractual Clauses, and we transfer only to recipients that provide an equivalent level of protection.
11. Children
The Service is intended for users aged 18 and over. We do not knowingly collect information from anyone under that age. If you believe a minor has provided us with personal information, contact mianshinn@foxmail.com and we will delete it promptly.
12. Third-Party Links and Services
The Service may link to or integrate with third-party services. This Policy applies only to information we collect directly. We are not responsible for the data practices of third parties — please review their policies before using them.
13. Changes to This Policy
For material changes we will notify you at least 15 days in advance by email to your registered address or by an in-product notice, and we will update the “Last updated” date at the top of this page. Continued use after the effective date constitutes acceptance.
14. Contact Us
- Privacy enquiries: mianshinn@foxmail.com
- Customer support: mianshinn@foxmail.com
- Controller: LIU CHANG (individual sole trader), the People's Republic of China
- Service hours: Mon–Fri 09:00–18:00 (UTC+8)
- Terms of Service: https://pixgt.com/terms/
- Acceptable Use Policy: https://pixgt.com/aup/
Last updated: August 14, 2026 · PixGT · https://pixgt.com