Legal & Privacy
Privacy Policy
Last updated: 2026-08-02
1. Introduction
At Pictify ("we", "us", or "our"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our cloud gallery platform and API services.
2. Information We Collect
We collect information necessary to provide, maintain, and secure our services to studios and event attendees:
- Account & Studio Data: When you register an account, we collect your studio name, work email, account credentials, and billing information (processed securely via Stripe).
- Media & Content: High-resolution photographs, videos, logos, and watermark assets uploaded by your studio to fulfill gallery delivery.
- Biometric Data (Ephemeral): Temporary facial features processed via AWS Rekognition solely to power the optional "Find My Face" search feature. These face vectors are processed in memory and are never stored permanently.
- Technical Telemetry: Standard server logs, IP addresses, browser types, and access timestamps utilized for performance monitoring, NVMe S3 resource allocation, and security auditing.
3. How We Use Your Information
We use the collected data strictly for operational and platform delivery purposes:
- To provision your studio workspace, process subscriptions, and manage custom domain routing.
- To transcode, stream, and deliver your photography galleries securely to your clients.
- To operate real-time AI facial indexing and search workflows without retaining facial templates past the immediate matching window.
- To communicate service updates, billing alerts, and support responses.
4. Data Sharing & Third-Party Processors
We do not sell, rent, or trade your personal information or media content. We share data only with trusted infrastructure subprocessors bound by strict data protection agreements necessary to run the service:
- Stripe: Secure payment processing and subscription billing management.
- AWS (Amazon Web Services): Cloud infrastructure, S3 storage, and ephemeral facial recognition processing.
- Brixly: High-speed NVMe S3 object storage and server infrastructure.
5. Data Security & Retention
We implement robust technical and organizational security measures, including tenant isolation, encrypted data transmission, and strict access controls. Unpaid or cancelled accounts enter a 30-day grace period, after which unrenewed media and galleries may be permanently purged from our storage nodes.
6. Your Rights & GDPR Compliance
Depending on your jurisdiction (including the UK and GDPR framework), you retain rights to access, correct, export, or request deletion of your personal studio data. Studios acting as data controllers remain responsible for providing appropriate privacy notices and securing necessary end-user consents for event attendees.
7. Contact Us
If you have any questions, concerns, or data requests regarding this Privacy Policy, you can reach our team directly through your dashboard or via our support channels.