PixOnDeck Privacy Policy
Last updated: September 24, 2026
This policy describes how PixOnDeck processes personal information for https://pixondeck.com (the "Site") and the PixOnDeck Chrome extension (together, the "Services").
1. Scope and Service Availability
PixOnDeck is operated by an individual sole proprietor based in Hong Kong and trading as PixOnDeck. Privacy requests can be sent to privacy@pixondeck.com.
PixOnDeck offers a visual-recipe library, browser-based image and video tools, accounts and saved work, hosted image and video generation, credit features, and optional email subscriptions. The Chrome extension provides image-to-prompt analysis using your PixOnDeck account, with a choice of PixOnDeck credits or, when enabled, your own API credentials (BYOK). Feature availability depends on the Services and account settings; a preview or disabled control does not mean that a feature is available.
The sections below describe the additional processing that applies if you use an enabled hosted-generation, credit, or checkout feature. We do not sell personal information, run targeted advertising, or use cross-site advertising trackers.
2. Information We Process
- Files used with Free Image Tools: Images selected for the upscaler, compressor, resizer, converter, or background remover are processed locally in your browser. The image bytes and locally produced result are not sent to PixOnDeck servers. Your browser still requests the page, model, runtime, and codec assets needed to run the tool; ordinary hosting and security data described below may be processed when those resources are delivered.
- Hosted stamp-edge tool: This tool sends your selected image to PixOnDeck for server-side transformation. The input is processed in memory, and the resulting PNG is stored privately under your account. This tool is separate from the browser-only tools above. Its stored outputs are not covered by the generation-history deletion controls described below; contact privacy@pixondeck.com about deletion.
- Account information: If you create an account through Clerk, we receive account identifiers and profile information such as your email address, name, and profile image. Clerk handles authentication credentials.
- Deck information: For signed-in users, we process the identifiers of skill cards saved to a Deck. A browser may also keep a local Deck selection.
- Waitlist and Newsletter information: We collect the email address you submit and optional context such as role, interests, source page, locale, or selected skill.
- Generation content: When hosted generation is enabled and you use it, we process your reference images, video or audio (where supported), prompt, selected recipe, model choice, aspect ratio, resolution, duration and other generation controls, and generated output. Do not upload government identifiers, medical or biometric records, other highly sensitive information, images of children, or third-party material you do not have the right to process.
- Chrome extension content: When you select a webpage image or upload a file for image-to-prompt analysis, the extension prepares an upload locally with a longest edge of at most 480 pixels. In PixOnDeck credit mode, it sends this prepared image and image dimensions to PixOnDeck, which sends the prepared image through OpenRouter to the configured OpenAI model to produce a prompt. Original source images are not included in this reverse-analysis upload. Generated prompts and text you choose to send to the Site are also processed. Account identifiers, authentication/session information and credit balances support login, authorized requests and credit settlement. The extension does not record browsing history or automatically submit images you browse.
- Chrome extension BYOK: When you choose BYOK, the extension sends the prepared image and analysis instructions directly to the HTTPS API endpoint you configure, using your API key and selected model. PixOnDeck does not receive that key or process the BYOK analysis request on its servers. The endpoint operator receives your image, request, API credential and ordinary connection information, and applies its own charges, retention and data-use policies. BYOK analysis requires PixOnDeck sign-in but does not spend PixOnDeck credits. Copying a resulting prompt into another service is a separate action governed by that service.
- Saved prompts: When you save a prompt to your library, PixOnDeck stores the prompt text, title, image dimensions, timestamps and optional compressed thumbnail under your account for cross-device access. This applies to prompts from both credit and BYOK modes. Saving does not upload your original image or BYOK API key. The free library holds up to 100 saved prompts per account.
- Generation and credit metadata: We process the account ID, generation and client-request IDs, selected skill and model, status, stage, error and timing information, reserved or restored credits, storage-object references, provider-reported cost, and a provider generation ID when available. Generation history can store prompt text and settings in D1 alongside generation metadata. Source media bytes are kept separately from those database records; credit-ledger entries record accounting activity.
- Payment and accounting information: If paid packs are enabled, we process the account ID, pack and price identifiers, credit amount, USD amount and currency, Stripe checkout, payment, event, refund, and dispute identifiers, payment state, timestamps, and append-only credit-ledger entries. PixOnDeck is the seller and merchant. Stripe processes checkout contact, billing, and payment-method information as our payment processor. PixOnDeck does not receive or store full card numbers. Signed webhook bodies are read to verify and durably process an event; PixOnDeck does not intentionally retain the raw webhook body after the request.
- Communications: We keep messages you send for support, copyright, billing, legal, or privacy requests.
- Technical and usage data: Hosting and security systems may process IP address, browser and device details, language, visited pages, timestamps, pseudonymous HMAC-based identifiers, rate-limit buckets, and limited interaction events needed for operation, security, and aggregate product analysis. We do not intentionally store raw IP addresses in the application analytics or rate-limit tables. To prevent repeated welcome-credit claims, we also store HMAC-based identifiers derived from your verified email address, its domain, and a first-party random browser identifier, linked to the successful credit award. These pseudonymous records are kept with the credit ledger while needed to prevent repeat claims.
3. How and Why We Use Information
We use information to authenticate accounts; synchronize Decks; provide requested image-to-prompt analysis, generation and private result delivery; reserve, settle, or restore credits; create and reconcile enabled purchases, refunds, chargebacks, and other required payment adjustments; process requested Waitlist or Newsletter subscriptions; secure and operate the Services; prevent abuse and duplicate billing; diagnose failures; measure limited aggregate use; answer communications; enforce our terms; and comply with law.
For people in the EEA or UK, the applicable legal bases may include performance of a contract for requested account, generation, credit, and purchase features; consent for Newsletter marketing; legitimate interests for security, fraud prevention, service reliability, support, and limited aggregate analysis; and legal obligation for accounting, tax, payment disputes, refunds, chargebacks, and legally required requests.
4. Service Providers and Other Recipients
We disclose only the information reasonably needed for the relevant function:
| Provider or recipient | Purpose |
|---|---|
| Clerk | Account authentication and account profile management |
| Cloudflare | Site and API hosting, D1 application records, private R2 media, Workflow execution, delivery, security, and operational logs |
| OpenRouter and the selected AI model provider, including Google, OpenAI, ByteDance, MiniMax or Alibaba | Receive the compiled generation prompt, reference images, video or audio (where supported), and controls for image or video generation, or the prepared selected image for extension image-to-prompt analysis; return generated media or prompt text and usage metadata. PixOnDeck does not send the Clerk account ID in the model request |
| Your configured BYOK endpoint operator | Receives the prepared image, analysis instructions, selected model and your API credential directly from the extension to provide the analysis you request |
| Stripe | Payment processor for enabled checkout, payments, fraud prevention, refunds, disputes, and chargebacks |
| Resend | Newsletter contact and subscription management, requested newsletter delivery, and transactional email where configured |
| beehiiv | Newsletter subscription management, when configured |
OpenRouter and downstream model endpoints may have different retention and data-use policies. PixOnDeck does not use generation or extension image-to-prompt content to train its own model, but we do not promise that every selected third-party endpoint is zero-data-retention unless the product expressly states and enforces that setting. Stripe processes checkout and payment information under its own privacy notice and legal obligations.
We may also disclose information when required by law, to protect rights or safety, or as part of a business transfer. We do not sell, rent, or disclose personal information for targeted advertising.
5. Media and Record Retention
- Ordinary generation-job working inputs and request envelopes are scheduled for deletion from private R2 after terminal success or failure, with retry cleanup if needed. Recipe-session references and uploads not yet attached to a video job follow the separate periods below.
- Your generation history retains the submitted prompt and settings until you delete the record. Server-side reference images are stored temporarily to execute the generation job and deleted after it ends, with scheduled retries if cleanup fails. Your browser may retain an account-scoped local reference cache for repeat generation, valid for 24 hours and limited to 20 images / 50 MB. Expired entries are removed when the cache is next accessed; clearing browser site data also removes them. Missing or expired references must be uploaded again. We do not keep a server-side reference-image library. Generated outputs remain available for up to seven days. Deleting a history record removes its saved prompt/settings, media and the corresponding local cached reference in that browser; operational accounting records remain.
- A successful generated output is normally available for seven days. Physical deletion may finish on a later cleanup run. Failed, filtered, or unusable partial outputs are deleted during terminal cleanup.
- Generation metadata, payment records, and the append-only credit ledger may be retained after media deletion as needed to operate accounts, prevent duplicate charges or abuse, reconcile provider costs, maintain accounting and tax records, process refunds or chargebacks, resolve disputes, and meet legal obligations. These records contain operational identifiers and amounts rather than the source image or generated image bytes.
- Recipe-session state and reference media have a 24-hour validity period and are removed by subsequent scheduled cleanup. They may remain across individual steps within that session. Video reference uploads that have not yet been attached to a submitted job have a two-hour validity period, followed by cleanup.
- Account and Deck data are retained while needed to provide the account feature and for a reasonable period after closure, subject to security, legal, and backup requirements.
- Unsubscribing stops newsletter marketing; it does not necessarily delete the contact record. We may retain subscription status, consent and minimal suppression records to honor the opt-out and demonstrate it. You can separately request deletion of information no longer needed.
- Communications and operational logs are retained only as reasonably needed for support, security, analysis, dispute handling, or law. Deleted data may remain for a limited backup or disaster-recovery cycle before being overwritten.
Chrome extension records
-
Cloud-saved prompts and their private thumbnails remain until you delete them; they are separate from the seven-day local recent-task history. Removing a local recent task does not remove its cloud-saved copy. Removing a saved prompt removes it from your cloud library and schedules its thumbnail for deletion, with retry cleanup if needed. Database recovery copies may retain deleted records temporarily under the hosting provider’s backup retention. Uninstalling the extension does not delete cloud-saved prompts.
-
BYOK API keys remain in extension session storage for the current browser session; they are not synced to your Google account or stored by PixOnDeck. You can clear the key in BYOK settings. The endpoint, model and mode preference are stored locally. Webpage content scripts cannot read these credentials. BYOK and credit-mode task history share an account-scoped local workspace with a seven-day expiry and 140-task limit. Closing the panel can interrupt a BYOK request; the provider may still process or charge for it, and the extension does not automatically retry it.
-
Account-scoped task history, prompt drafts, thumbnails, originals and prepared image copies are stored locally in extension storage with a seven-day expiry. Expired records are removed during subsequent use and cleanup, rather than by a guaranteed background deletion at the exact expiry time. The extension keeps at most 140 task tabs per account. Deleting a task removes its corresponding local image cache.
-
A selected webpage image URL may remain temporarily in extension session storage so a pending selection can resume. Pending selections older than one hour are rejected and cleared when processed. This is not a browsing-history feed.
-
In PixOnDeck credit mode, the prepared image is temporarily stored on PixOnDeck infrastructure to run the analysis and is scheduled for deletion after success or failure, with retry cleanup when needed. Server-side reverse prompt content and edited handoff content expire after 24 hours. Expiration prevents access; physical cleanup may complete on a subsequent maintenance run.
-
Operational task metadata, provider usage/cost receipts and credit-ledger records may remain for reliability, abuse prevention and accounting. Deleting a local task does not delete required server accounting records. Third-party provider retention remains subject to the policies described above.
6. Cookies and Local Storage
The Site also uses a first-party pixondeck_visitor cookie, with a lifetime of up to one year, for visitor identification in usage statistics and abuse prevention. Usage events may be associated with your account identifier when signed in, or with a pseudonymous identifier derived from the visitor cookie. These records are not necessarily anonymous merely because the identifier is hashed.
We use essential session cookies for account authentication and limited browser storage for preferences and local Deck state. A first-party security cookie remembers a random browser identifier for up to one year to limit repeated welcome-credit claims across accounts. It does not collect hardware fingerprints or track you across other sites. Clearing it removes the browser identifier from your browser, but does not delete existing account or credit records. Security providers may use short-lived tokens. When Stripe checkout is enabled, Stripe may process necessary cookies and technical data in its checkout under its own privacy notice. OpenRouter requests are made server-to-server and do not add an OpenRouter browser tracker to the Site. We do not use advertising cookies.
The Chrome extension uses the shared PixOnDeck/Clerk sign-in session and essential authentication storage. Its webpage content scripts do not receive session tokens. Website permissions enable the image-selection control and retrieval of an image you explicitly choose, including images on separate hosting domains. You can restrict website access in Chrome and use file upload instead. Extension task records and local image copies are separate from the Site’s local storage; clearing extension data or removing the extension removes those local records.
7. International Transfers
Providers may process information in the United States, Europe, or other countries where they operate. Where required, a provider or other responsible party may rely on an adequacy decision, Standard Contractual Clauses, the EU-US Data Privacy Framework, or another lawful transfer mechanism. A storage location hint or network location is not a promise that all processing stays in one country.
8. Security
We use reasonable technical and organizational safeguards, including encrypted transport, authenticated account routes, private object storage, scoped secret storage, bounded request sizes, rate limits, and append-only accounting controls. No online service can guarantee absolute security.
9. Children
The Services are not directed to children under 16, or a higher minimum age required where they live. Do not upload images of children to hosted generation or image-to-prompt analysis. Contact privacy@pixondeck.com if you believe a child submitted personal information.
10. Your Rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, or portability, withdraw consent, or complain to a supervisory authority. Email privacy@pixondeck.com. We may verify your identity before acting and will respond within applicable legal timeframes.
Deletion and restriction rights may be limited where records must be retained for accounting, tax, payment, fraud-prevention, security, chargeback, dispute, or other legal purposes. Stripe independently controls some checkout and payment records; you may also exercise applicable rights directly with Stripe.
California and other applicable US state residents may exercise rights provided by local privacy law. We do not sell personal information or share it for targeted advertising. You can contact us to exercise any rights that apply to you.
11. Changes and Contact
We may update this policy as the Services change. Material changes will be announced when reasonably required.
- Privacy requests: privacy@pixondeck.com
- General contact: hello@pixondeck.com
- Site: https://pixondeck.com