Legal

Privacy Policy

How Pictag processes account, credit-purchase, usage, image-workflow, provider-connection, support and security data.

Effective: 9 August 2026

This Privacy Policy explains how pictag.ai (“Pictag”, “we”, “us” or “our”) processes personal data when you use pictag.ai and its related services.

1. Controller and contact

Data controller: pictag.ai. Address: Greece. Privacy enquiries: support@pictag.ai.

2. Scope

This policy applies to the Pictag website, accounts, credit-pack purchases, AI chat, Manual and Smart image tagging, AI upscaling, multilingual Read Aloud, image generation, connected-provider features, synchronisation, support and related application functions. External providers operate under their own privacy policies.

3. Data we process

  • Account and identity data: email address, display name, Google account identifier, account dates and authentication/session information.
  • Payment and credit data: credit balance, ledger entries, credit-pack purchases, and Stripe customer and payment identifiers. Complete payment-card details are processed by Stripe and are not intended to be stored by Pictag.
  • Usage and security data: feature counters, quota periods, request times, IP address, device/browser details, server logs, errors, failed requests and anti-abuse records.
  • Chats, projects and preferences: supported chat text, project names and instructions, preferences, revision data and short-lived deletion records used for account synchronisation.
  • Images and metadata: images selected for processing, prompts, generation settings, provider-hosted result links, titles, descriptions, keywords and related metadata.
  • Connected-provider data: provider name, connection type, encrypted credential, masked hint, provider identity, expiry information and connection timestamps.
  • Support data: information submitted through contact forms or support correspondence.

4. How we obtain data

Data is received directly from you, from sign-in and billing providers when you use those functions, from connected AI or image providers when processing a request, and automatically from application, browser, server and security logs.

5. Why we use personal data

We use personal data to create and authenticate accounts, provide requested features, synchronise supported content, enforce service limits, maintain credit balances, process credit-pack purchases, protect the service, prevent abuse, provide support, diagnose failures, improve reliability and meet legal, accounting and regulatory duties.

6. Legal bases

Where the GDPR applies, processing may rely on performance of a contract, legitimate interests in security and service operation, consent for optional technologies or communications, and compliance with legal obligations. The applicable basis depends on the feature and circumstances.

7. Images, prompts and AI providers

Manual Tagging is designed to process selected files in the browser and can handle batches of up to 2,000 images. AI Tagging / Smart Metadata sends the image data necessary for each requested analysis to the selected or fallback AI provider. The self-hosted AI Upscaler processes selected image data through Pictag infrastructure. Read Aloud may process assistant-response text through Pictag’s self-hosted speech worker; languages not supported by that worker may use the browser or operating-system speech engine. AI-powered analysis or generation otherwise sends the information necessary to the selected or fallback provider. Providers may process prompts, images, outputs and technical metadata under their own policies. Do not submit confidential or regulated data unless you have assessed the feature and provider as appropriate.

8. Connected-provider credentials

When you connect a supported provider, Pictag stores the usable credential encrypted so that it can submit requests you initiate. The full saved credential is not returned to the browser. Disconnecting removes Pictag’s saved credential but does not close the provider account or necessarily revoke access at the provider; use the provider’s own controls where appropriate.

9. Recipients and service providers

Depending on enabled features, data may be processed by hosting and infrastructure providers, Google, Stripe, Pollinations, configured AI providers, SMTP/email services, security services, analytics providers or advertising providers. Only data needed for the relevant function should be sent. Professional advisers, regulators or authorities may receive data where reasonably necessary or legally required.

10. International transfers

Some providers may process data outside Greece or the European Economic Area. Where required, transfers are handled using applicable safeguards provided by law or the relevant provider agreements.

11. Retention

Account data is retained while the account is active and removed from active systems when deletion completes, except where billing, tax, fraud-prevention, security, dispute or legal obligations require continued retention. Provider credentials are removed when disconnected, expired or deleted with the account. Security and diagnostic records are retained only as long as reasonably necessary. Residual copies may remain temporarily in backups until overwritten through the normal backup cycle.

12. Browser storage and synchronisation

Pictag uses a Secure, HttpOnly session cookie for authentication and may keep a user-specific browser cache for fast loading, large-batch interface state and temporary offline resilience. Signing out ends the active session but does not delete server-side synchronised history. Original uploaded image files, upscaled image binaries and generated image binaries are not included in account synchronisation by default.

13. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also complain to the Hellenic Data Protection Authority or another competent supervisory authority.

14. Security

Pictag uses measures including HTTPS, access controls, encrypted provider credentials, Secure HttpOnly sessions, rate limiting and signed billing webhooks. No online service can guarantee absolute security.

15. Age requirement

Pictag is available only to users aged 18 or older. We do not knowingly create accounts for, sell credits to or collect account data from anyone under 18. If we learn that an account belongs to a person under 18, we may suspend or delete the account and remove the associated personal data, subject to records that must be retained by law. A parent, guardian or other person who believes that someone under 18 has created an account should contact support@pictag.ai.

16. Changes

Material changes will be published on this page with a revised effective date.