Effective: 1 August 2026
This policy explains how pictag.ai (“Pictag”, “we”, “us”) processes personal data in connection with pictag.ai.
1. Controller and contact
Controller: pictag.ai, Greece. Privacy enquiries: privacy@pictag.ai.
2. Data we process
- Account identifiers supplied through Google or phone verification, including Google subject ID, email, display name or phone number.
- Subscription metadata from Stripe, such as customer, subscription, plan and status identifiers. Pictag does not store full payment-card numbers.
- Usage counters required to enforce Free and Pro allowances.
- Text chats, project instructions and preferences when account sync is used.
- Encrypted third-party provider credentials when a user chooses to connect them.
- Images and prompts transmitted for a user-requested analysis or generation operation. Original uploaded image files are not part of account sync by default.
- Security, diagnostic, IP and rate-limit data, plus information sent through the contact form.
3. Purposes and legal bases
We process data to provide the service and subscriptions, secure the application, prevent abuse, respond to support requests, meet legal obligations and—where applicable—operate advertising based on consent or another lawful basis.
4. Providers
Depending on the feature used, data may be processed by Google, Twilio, Stripe, Pollinations, the configured SMTP email provider and configured AI-model or advertising providers. Only the information needed for the requested function is sent.
5. International transfers
Some providers may process data outside Greece or the European Economic Area. Their transfer mechanisms and contractual safeguards apply alongside Pictag’s own obligations.
6. Retention
Account data is retained while the account is active and deleted when account deletion completes, except where legal, fraud-prevention or billing obligations require longer retention. Short-lived security records expire automatically. Provider credentials are removed when disconnected or when the account is deleted. Backup retention depends on the production backup schedule and should be kept to the minimum operational period.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also complain to the Hellenic Data Protection Authority or another competent authority.
8. Security
Pictag uses encrypted credentials, HttpOnly sessions, access controls, rate limiting, signed webhooks and HTTPS-oriented deployment controls. No online service can guarantee absolute security.
9. Children
Pictag is not intended for children under 16. Users under 18 may use the service only with legally valid permission and supervision from a parent or legal guardian where required. Paid subscriptions should be entered into by an adult or with legally valid guardian involvement.
10. Changes
Material updates will be posted on this page with a revised effective date.