Legal
Privacy Policy
Effective September 15, 2026
What pixelart.dev collects, why, who it is shared with, and the choices you have. Written to be read, not skimmed past.
1. Who is responsible
PixelNova LLC ("PixelNova", "we", "us") operates pixelart.dev (the "Service") and is the data controller for the personal data described here. Contact us at support@pixelnova.app for anything privacy related.
2. What we collect
Account data
- Your email address and a hashed password, used to sign you in and to send account emails such as confirmation and password reset.
- Your subscription status, plan and credit balance, and a ledger of what each generation cost. Payment details themselves go to Stripe (see section 5); we receive a customer reference and the last four digits and brand of your card, never the full number.
Content you create
- Prompts and the settings you pick for a generation (asset type, scale, sheet layout, palette and pixel options).
- Reference images you upload, and assets you approve as project references.
- Generated images, both the raw model output and the processed sprite, and every version you rebuild or edit.
- Projects: their names, settings, palettes and icons.
- Your actions in the workspace, such as which results you keep, rebuild, revert, approve or delete.
Technical data
- Server logs and error records, which can include your user id, the request that failed, its timestamp and the error message. We keep these to fix problems.
- Anonymous, aggregated usage measurements if we enable web analytics (see section 4).
We do not collect your name, phone number, address, or precise location, and we do not buy data about you from anyone.
3. How we use it, and why we are allowed to
- To run the Service: signing you in, generating and storing your assets, charging credits, and showing you your history. Legal basis: performance of our contract with you.
- To improve the Service. We use the content you create and the actions you take on it, including your prompts, uploads, generated images, and which results you keep, rebuild or discard, to understand what works, tune our prompts and pixel processing pipeline, evaluate and fine-tune models, and set better defaults. Legal basis: our legitimate interest in making the Service better, and the license you grant us in the Terms of Service. You may object to this use (section 8), and we will honor that for future improvement work.
- To keep it secure and honest: detecting abuse, enforcing usage limits and credit accounting, and debugging failures. Legal basis: legitimate interest and legal obligation.
- To bill you and keep the financial records the law requires. Legal basis: contract and legal obligation.
- To answer you when you email support. Legal basis: legitimate interest.
- To tell you about material changes to the Service or these policies. Legal basis: legitimate interest and legal obligation. We do not send marketing email without your consent.
We do not sell your personal data, and we do not use it for advertising.
4. Cookies and analytics
The Service sets only the cookies it needs to keep you signed in. They are first-party, marked HttpOnly, and are not used for tracking or advertising. Because they are strictly necessary, no consent banner is required for them.
Your browser's local storage holds a few conveniences, such as your workspace layout and an unsent draft prompt. That data stays on your device and is not sent to us.
To understand how the site is used we may run privacy-preserving web analytics that meet GDPR and COPPA without consent banners: no cookies, no local storage, no fingerprinting, no cross-site tracking, and no personal identifiers stored. We are currently considering Cloudflare Web Analytics, which works this way and reports only aggregate counts such as page views, referrers, browser type and country. If we adopt a different provider it will meet the same standard, and this section will be updated to name it.
5. Who we share data with
We share data only with the providers that make the Service work, and only what each needs:
- AI model providers (currently fal.ai and Runware, which route to models. They receive your prompt, the generation settings, and any reference images for that generation, so the model can draw it. They do not receive your email or account details. Each provider processes requests under its own terms; we choose providers whose API terms do not permit training on customer inputs without agreement.
- Supabase: hosting for our database, authentication and image storage. Holds account data, content and logs.
- Stripe: payments and subscriptions. Receives your email and payment details, and handles them under Stripe's privacy policy.
- Cloudflare or a comparable provider, if we enable analytics as described in section 4. Receives only anonymous, aggregate measurements.
- Email delivery for account messages such as confirmation and password reset.
We may also disclose data if the law requires it, to protect our rights or the safety of others, or as part of a merger or sale of the business, in which case this policy continues to apply to your data.
6. International transfers
We are based in the United States, and our providers process data there and in other countries. If you are in the European Economic Area, United Kingdom or Switzerland, your data is transferred under appropriate safeguards such as standard contractual clauses or an adequacy decision or framework certification of the provider.
7. How long we keep it
- Account and content: for as long as your account exists. Assets and versions you delete are removed from your workspace immediately and from storage within a reasonable time after that, subject to backups.
- After account deletion: we delete your account, projects, prompts and images within 30 days, except for records we must keep (such as invoices, kept for as long as tax law requires) and for content that has already been used, in de-identified form, to improve the Service.
- Error and server logs: up to 90 days.
- Backups: rotate out within 30 days of the deletion above.
8. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you, and get a copy of your content in a portable form (your assets already export as PNGs from the app).
- Correct data that is wrong.
- Delete your account and data.
- Object to our use of your content to improve the Service, or to any other processing based on legitimate interest, and we will stop unless we have a compelling reason that overrides your interests.
- Restrict processing while a request is being handled.
- Withdraw consent where consent was the basis, without affecting what was done before.
Email support@pixelnova.app from the address on your account. We respond within 30 days and never charge for a reasonable request. If you are in the EEA or UK you may also complain to your local data protection authority. Residents of California and other US states with privacy laws have equivalent rights under those laws, and we do not "sell" or "share" personal data as those laws define it.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from anyone under 13. Our analytics, if enabled, is cookieless and collects no personal identifiers, in keeping with COPPA. If you believe a child under 13 has created an account, email support@pixelnova.app and we will delete it. Users between 13 and 18 need a parent's or guardian's permission, and paid plans may only be bought by adults.
10. Security
Data is encrypted in transit and at rest with our providers. Passwords are hashed and never stored in the clear. Access to production data is limited to the people who run the Service. Writes to your data go through our servers, which check that you own what you are changing. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and any regulator the law requires, without undue delay.
11. Changes to this policy
We may update this policy as the Service changes. The effective date at the top shows the current version. If a change materially affects how we use your data, we will notify you by email or in the app before it takes effect.
12. Contact
PixelNova LLC, https://pixelnova.app/ · support@pixelnova.app