Last updated: March 1, 2026
PixelFlair ("PixelFlair", "we", "us", or "our") operates the website pixelflair.co and the image upscaling service (collectively, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and store it, with whom we share it, and what rights you have regarding your data.
This Policy applies to all users of the Service worldwide. Where applicable, it reflects the requirements of the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA). If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, PixelFlair acts as the Data Controller for your personal data.
By using the Service, you acknowledge you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
The data controller responsible for your personal data is:
Illia Khomenko (trading as PixelFlair)
ul. Wrocławska 53B/77, 30-011 Kraków, Poland
NIP: 6793311010 · REGON: 529793459
Email: [email protected]
Website: pixelflair.co
For all data protection enquiries, including exercising your rights, please contact us at the email address above.
We collect personal data in the following categories:
Note on image content: Images you upload may contain personal data about third parties, including photographs of people. We process images solely to provide the upscaling Service. We do not perform facial recognition, biometric identification, or any other automated analysis of image content beyond what is necessary for image upscaling. You are responsible for ensuring you have the necessary rights and consents for the images you upload (see Section 8 of the Terms of Service).
For users in the EEA, UK, and Switzerland, we process personal data on the following legal bases under Article 6 of the GDPR:
Performance of a Contract (Art. 6(1)(b))
Processing necessary to create and manage your account, authenticate you, process image upscaling requests, manage subscriptions, and send transactional communications (e.g. email verification, password resets, billing receipts).
Legitimate Interests (Art. 6(1)(f))
Error monitoring, security and fraud prevention, service performance analytics, and improving the Service. Our legitimate interests do not override your fundamental rights.
Legal Obligation (Art. 6(1)(c))
Retaining financial records and invoices to comply with applicable tax and accounting laws (typically 7 years).
Consent (Art. 6(1)(a))
Analytics and non-essential cookies, where you have given consent via our cookie banner. Marketing communications (promotional emails and product updates), where you have explicitly opted in. You may withdraw consent at any time without affecting processing already carried out.
We do not sell your personal data to third parties. We do not use your images for training AI models.
Marketing communications: We may send you promotional emails and product updates only with your explicit prior consent. You can withdraw consent and unsubscribe at any time by clicking the unsubscribe link in any marketing email or by contacting us at [email protected]. Withdrawing consent does not affect transactional emails related to your account or subscription.
Automated decision-making: We do not make any automated decisions about you that produce legal effects or similarly significantly affect you (GDPR Art. 22). Subscription management and usage tracking are automated processes, but they do not involve profiling or decisions with significant legal consequences — they simply apply the plan limits you selected.
We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law.
| Data Category | Retention Period |
|---|---|
| Account data | Until account deletion, then up to 30 days for backup expiry |
| Uploaded and processed images | Until deleted by the user, or upon account deletion |
| Payment records and invoices | 7 years (legal/tax obligation) |
| Subscription history | 7 years (legal/tax obligation) |
| Application logs and error reports | 90 days |
| Analytics data (Google Analytics) | 26 months (per Google Analytics default) |
| Contact form submissions | 3 years |
| Additional retention | |
|---|---|
| Marketing consent records | Until consent is withdrawn + 3 years (to demonstrate compliance) |
Required data: Account data (email address, password or OAuth identifier) is necessary to provide the Service. Without it, we cannot create or maintain your account. Billing data is required to process payments for paid subscriptions.
When you delete your account, we initiate deletion of your personal data from our systems within 30 days, except where we are required by law to retain certain records.
Images you upload are stored in Amazon S3 (region: eu-central-1, Frankfurt, Germany). They are processed by AI models via the Replicate platform and, where available, partially processed on our servers or your device. Processed output images are stored in the same S3 bucket.
Access to your images is controlled via time-limited secure access links (valid for 10 minutes). No unauthorised third party has access to your images stored on our infrastructure.
Your images are retained until you delete them or until your account is deleted. You can delete individual images at any time from your My Images dashboard. To delete your account and all associated data, go to Account Settings → Danger Zone, or contact us at [email protected].
We share personal data with the following sub-processors and service providers, solely to operate and deliver the Service. Each provider is contractually bound to protect your data and process it only as instructed.
Stripe — Payment Processing
We use Stripe, Inc. to handle all payments and subscription billing. Your payment card details are collected and stored directly by Stripe and are never transmitted to or stored on our servers. Stripe is PCI-DSS Level 1 certified.
Amazon Web Services (AWS) — Cloud Infrastructure
Our image storage and processing queues run on Amazon Web Services (AWS) in the eu-central-1 (Frankfurt, Germany) region, meaning your images remain within the EU. AWS is GDPR-compliant and covered by Standard Contractual Clauses.
Google — Authentication (OAuth) and Analytics
If you sign in using Google, Google authenticates you and shares your name, email, and profile picture with us. We also use Google Analytics 4 to understand how users interact with the Service (page views, sessions, feature usage). Google Analytics pseudonymizes data by truncating IP addresses before storage; no raw IP addresses are retained by Google.
Mailgun — Transactional Email
We use Mailgun to send transactional emails (account verification, password reset, billing notifications). Mailgun processes your email address to deliver these messages.
Replicate — AI Model Inference
Upscaling jobs are processed by AI models hosted on Replicate's infrastructure (Replicate, Inc., United States). Your images are transmitted to Replicate solely for the purpose of AI inference. Replicate may retain prediction inputs and outputs for a limited period in accordance with their own data retention and security practices. This transfer is covered by Standard Contractual Clauses. We recommend reviewing Replicate's privacy policy for full details.
OVHcloud — Backend Server Infrastructure
Our backend application servers (API, worker services, database) run on dedicated or virtual servers provided by OVHcloud SAS, a French company headquartered in Roubaix, France. OVHcloud data centers used for this Service are located within the European Union. Personal data processed by the backend — including account data, subscription data, and image metadata — resides on OVHcloud infrastructure. OVHcloud is GDPR-compliant and acts as a data processor under a Data Processing Agreement.
Calendly — Meeting Scheduling
We use Calendly to allow you to book meetings with us. When you book a meeting, Calendly collects your name, email address, and any additional information you provide. Calendly is a US-based service; transfers are covered by Standard Contractual Clauses incorporated into their Terms of Use.
PostHog — Product Analytics
We use PostHog to understand how users interact with the Service (page views, feature usage, conversion funnels). PostHog is hosted on EU Cloud servers (Frankfurt, Germany), meaning your analytics data stays within the EU. PostHog collects pseudonymous identifiers (device ID, session ID) and event data. No analytics data is collected without your consent. You may opt out via our cookie consent banner.
Cloudflare — DNS and Network Security
We use Cloudflare for DNS resolution and network routing. Cloudflare may process IP addresses and request metadata as part of DNS resolution. Cloudflare does not have access to the content of your requests or personal data stored on our servers.
Our primary infrastructure is located in the European Union (AWS eu-central-1, Frankfurt, Germany). Analytics data processed by PostHog also remains within the EU (PostHog EU Cloud, Frankfurt). Some of our third-party service providers are based in the United States (Stripe, Google, Mailgun, Replicate). Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:
You may request a copy of the safeguards we have in place for international transfers by contacting us at [email protected].
We use cookies and similar technologies. Cookies are small text files stored on your device.
Essential Cookies
Required for the Service to function. These include session authentication tokens, security cookies, and user preference cookies (e.g. dark mode, language). Cannot be disabled without breaking the Service.
Analytics Cookies
Set by Google Analytics 4 (_ga, _gid) and PostHog (ph_*) to collect aggregated information about how visitors use the Service (pages viewed, session duration, feature usage). These cookies use pseudonymous identifiers and do not identify you personally. Enabled only with your explicit consent. Both services can be opted out via our cookie consent banner; existing cookies are deleted upon opt-out.
Third-Party Cookies
Stripe may set cookies during the payment flow to prevent fraud. Google may set cookies if you use Sign in with Google. These are governed by the respective providers' privacy policies.
You can manage cookies through our cookie consent banner, your browser settings, or opt-out tools provided by third parties (e.g. Google Analytics Opt-out). Disabling analytics cookies does not affect your ability to use the Service.
Browser local storage: We use your browser's local storage to save interface preferences such as your chosen theme (light/dark mode) and language. This data is stored only on your device and is not transmitted to our servers.
Do Not Track (DNT): We do not currently respond to browser Do Not Track signals, as no industry-wide standard for DNT has been adopted. Analytics cookies are enabled only with your explicit consent via our cookie banner.
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights under the GDPR (or equivalent UK/Swiss law):
If you are a California resident, you have the following rights under the CCPA/CPRA:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA), with a possible extension of up to 30 additional days where necessary. We may need to verify your identity before fulfilling your request.
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
Despite our efforts, no security measure is 100% infallible. In the unlikely event of a data breach that affects your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.
The Service is not directed to children under the age of 13 (or 16 in certain EU member states). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected] and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on this page with a new "Last updated" date, and where required by law, by sending an email notification to the address associated with your account. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Illia Khomenko (trading as PixelFlair)
ul. Wrocławska 53B/77, 30-011 Kraków, Poland
NIP: 6793311010 · REGON: 529793459
Email: [email protected]
Website: pixelflair.co