Last updated: 14 August 2026
This policy explains what Pilkix collects when you use the Pilkix app, why we collect it, how long we keep it, and how you can have it deleted. Questions and requests: pilkixapps@gmail.com.
You do not type prompts. Pilkix generates images only from templates we publish and review, so we do not collect free-form prompt text from you.
Pilkix contains no advertising SDK and no third-party analytics SDK. We do not sell your personal data and we do not share it for advertising. The providers above receive only what they need to do the job we use them for.
Where the GDPR applies, we rely on: performance of our contract with you, for everything needed to run your account and produce the images you request; our legitimate interest in keeping the service safe, for abuse detection, content reports and crash diagnostics; and our legal obligations, for retaining accounting records.
This is the one thing that survives deleting your account and can still be connected to you, so it is set out on its own rather than buried in a list.
It is a one-way hash of the identifier your sign-in provider gave us. We cannot read a person, an email or a name out of it, and we do not use it to contact you, to profile you or to restore anything. It answers exactly two questions: has this sign-in already been given free starting credits, and does a refund Google issued after the account was deleted belong here. It is deleted twelve months after the account is.
We keep it under our legitimate interest in preventing abuse of free credits and in settling payments correctly. A hash is not anonymous data — it is still information about you — so it is covered by the rights below, and you can ask us about it at the address at the top of this page.
Pilkix runs on servers in the European Union, and generated images and uploaded photos are stored with Cloudflare R2. Some of the services listed above are operated by companies outside the European Economic Area, so your data is transferred there when they are used:
Both are used under their own data processing terms, which provide the transfer mechanism required for personal data leaving the European Economic Area. If you want to know which mechanism applies to a particular service, ask us at the address at the top of this page and we will tell you what is in place rather than describe it in general terms here.
We do not sell your data, we do not share it with advertisers, and we do not use it to build a profile of you for marketing.
One automated check affects what you get: every generated image is classified for adult content before it is delivered, and an image the classifier rejects is not shown to you and is deleted. This is a filter on the output, not a judgement about you, and it has no other effect on your account. If you think a result was rejected wrongly, write to us at the address above and a person will look at it.
Nothing else about your account is decided automatically. We do not profile you and we do not make automated decisions with legal or similarly significant effects.
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to processing based on legitimate interest, or ask for your data in a portable form. Write to pilkixapps@gmail.com. If you are in the EU or the UK you may also complain to your national data protection authority.
You can delete your account from inside the app, under Profile. You can also request deletion without the app installed — see Delete your Pilkix account, which lists exactly what is erased and what is retained.
Some states give you specific rights over personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. The rights to know, to delete and to correct are the same ones described under Your rights above, and you can use them the same way. We will not treat you differently for exercising them.
Pilkix is not directed at children. You must be at least 13 years old to use it, or at least 16 if you are in the European Economic Area. If we learn that an account belongs to a child below that age, we delete it.
Traffic between the app and our servers is encrypted with TLS. Access to stored images requires an authenticated request from the account that owns them. Access to production systems is limited to the people who operate them.
If you think we have handled your data wrongly, tell us first — the address is at the top of this page, and we would rather fix it than have you find out from a regulator. You also have the right to complain to a data protection authority, normally the one where you live or work. In Ukraine that is the Verkhovna Rada Commissioner for Human Rights; in the European Union it is your national supervisory authority.
If we change this policy we update the date at the top of this page. Material changes will also be announced in the app.