Legal
Privacy Policy
Last updated: March 28, 2026
Introduction
Pictomancer.ai ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you use our AI-powered image processing API.
Our fiscal headquarters are located in Spain, and we comply with the General Data Protection Regulation (GDPR) and Spanish data protection laws.
Information We Collect
Personal Information
- —Account data: email address, name, billing information
- —Usage data: API usage stats, request logs, IP addresses
- —Technical data: browser type, device info, log files
- —Images: temporarily stored for processing only, never retained
Cookies & Tracking
We use essential cookies for authentication, security, and preference storage. See our Cookie Policy.
Legal Basis for Processing (GDPR)
- —Contract: to provide our API services
- —Legitimate Interest: to improve services and prevent fraud
- —Consent: for marketing communications where required
- —Legal Obligation: to comply with tax and legal requirements
How We Use Your Information
- —Provide and maintain our API services
- —Process payments and billing
- —Respond to customer support requests
- —Improve our services and develop new features
- —Comply with legal obligations
- —Prevent fraud and abuse
Data Sharing
We do not sell your personal data. We may share data with:
- —Service Providers: payment processors, cloud infrastructure
- —Legal Requirements: when required by law or to protect our rights
- —Business Transfers: in case of merger or acquisition
Data Retention
Images
Deleted within 24h of processing
Account Data
While account is active
Usage Logs
2 years for billing & security
Marketing Data
Until consent withdrawn
Your Rights (GDPR)
You have the right to:
- —Access your personal data
- —Rectify incorrect data
- —Erase your data ("right to be forgotten")
- —Restrict processing
- —Data Portability
- —Object to processing
- —Withdraw Consent at any time
To exercise these rights: [email protected]
International Transfers
Your data may be processed outside the EU/EEA. We ensure adequate protection through Standard Contractual Clauses and adequacy decisions.
Security
- —Encryption in transit and at rest
- —Regular security audits
- —Access controls and authentication
- —Incident response procedures
Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal information from children.
Data Breach Notification
In case of a data breach, we will notify supervisory authorities within 72 hours, inform affected individuals when required, and take immediate steps to contain the breach.