Skip to main content

Privacy policy

Last updated: 2026-06-10

This privacy policy explains how Pixto (the “Service”) collects, uses, stores and shares personal data. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and applies to everyone who uses the Service, regardless of the country they connect from.

1. Who we are

The Service is operated by the entity being incorporated to run Pixto (referred to here as “we”, “us”, “Pixto”). The formal legal name, registered address, company number and VAT identification number will be published on this page as soon as incorporation is complete.

If you have any questions about this policy or how we handle your data, please use the contact page.

2. What personal data we collect

We collect the following categories of personal data:

  • Account data. Your email address and a hashed password (we never store passwords in plain text).
  • Project content. The briefs, prompts, files, uploaded images, text and other inputs you provide so the Service can generate a website for you, plus the generated output (HTML, CSS, assets) that belongs to your project.
  • Inference logs. The prompts and responses exchanged with our upstream LLM provider (OpenRouter) for debugging and abuse-prevention. These are linked to your account.
  • Security telemetry. IP address, user-agent string, timestamps and minimal request metadata, captured so we can detect abuse, rate-limit, and investigate incidents.
  • Billing data. If you subscribe to a paid plan, our payment processor (see “Sub-processors” below) collects card data on our behalf. We only retain the last four digits of the card and a tokenised reference; we never store the full card number on our servers.

3. Lawful bases for processing

Under Article 6 GDPR, we process your personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b)). Account data, project content and billing data are processed because we need them to deliver the Service you signed up for.
  • Consent (Art. 6(1)(a)). Any marketing emails, non-essential cookies and optional product analytics are sent or set only after you have given us explicit, opt-in consent. You can withdraw consent at any time.
  • Legitimate interest (Art. 6(1)(f)). Security telemetry (IP, user-agent, request metadata) is processed because we have a legitimate interest in keeping the Service available, preventing fraud, and investigating abuse.
  • Legal obligation (Art. 6(1)(c)). We retain certain invoice and tax records for the period required by applicable bookkeeping and tax law.

4. Sub-processors

We share personal data with the following sub-processors, each of whom acts on our written instructions and under a GDPR Article 28 data-processing agreement:

  • Cloudflare, Inc. — CDN, DDoS protection and reverse proxy. Receives IP and request metadata at the edge.
  • Managed database hosting provider — primary application database storing account, project and billing data. The provider's identity will be named here once the production hosting contract is finalised.
  • OpenRouter, Inc. — LLM inference provider. Receives the prompts and project context required to generate your site.
  • Unsplash — royalty-free image search fetched on-demand when you ask for stock imagery. Search queries are sent to Unsplash; no account data is shared.
  • Amazon Web Services (S3) — object storage for uploaded files and generated assets (where configured).
  • Payment processor — an EU/EEA-compliant card payment provider collects card data and processes recurring subscription billing on our behalf. We will name the provider here as soon as the production payment integration is live; payments are not yet enabled.

We maintain an up-to-date list of sub-processors. If we add or remove one, this section will be updated and the “Last updated” date at the top of the page will reflect the change.

5. International transfers

Some of our sub-processors (notably Cloudflare and OpenRouter) operate infrastructure outside the European Economic Area, including the United States. Where personal data is transferred out of the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) and, where relevant, supplementary technical measures (TLS in transit, at-rest encryption on the destination side) to ensure a level of protection equivalent to the GDPR.

6. Retention periods

We retain personal data only as long as we need it for the purposes set out above:

  • Account data: until you delete your account. On deletion we remove your account record within 30 days, subject to legal retention requirements.
  • Intake briefs and uploaded files: 90 days after the project they belong to is closed or abandoned, whichever is sooner.
  • Published sites: retained for as long as you keep the site published. When you unpublish or delete a site, the public assets are removed within 7 days.
  • Security logs: 13 months, then deleted.
  • Inference logs: 90 days, then deleted.
  • Invoices and tax records: retained for the period required by applicable bookkeeping law (typically 7 to 10 years).

7. Your rights

Under the GDPR you have the following rights:

  • Access (Art. 15). You can request a copy of the personal data we hold about you.
  • Rectification (Art. 16). You can ask us to correct inaccurate or incomplete data.
  • Erasure (Art. 17). You can ask us to delete your data — the “right to be forgotten”.
  • Portability (Art. 20). You can request a machine-readable export of the data you have provided to us.
  • Restriction (Art. 18). You can ask us to pause processing while you contest accuracy or our legal basis.
  • Objection (Art. 21). You can object to any processing we carry out under legitimate interest.
  • Lodge a complaint (Art. 77). You can lodge a complaint with your national data-protection authority. A list of EU/EEA authorities is at edpb.europa.eu/about-edpb/about-edpb/members_en.

To exercise any of these rights, send your request via the contact page. We will respond within one month, as required by Article 12(3) GDPR.

8. Children

The Service is not intended for users under 16. We do not knowingly collect personal data from children. If you believe a child has signed up, reach us via the contact page and we will delete the account.

9. Changes to this policy

When we make material changes to this policy we will update the “Last updated” date at the top of the page and, for significant changes, notify registered users by email at least 30 days before the change takes effect.

10. Contact

For privacy questions or to exercise your rights, see our contact page.

Privacy policy · Pixto