PICTOBANK
HomePrivacy

Privacy Policy

Pictobank Privacy

How Pictobank handles temporary processing, Storage+, Local Processing, share links, account systems, support, billing, analytics, and advertising partners.

Pictobank Privacy

•••

Last updated: July 2026

1. Privacy by Workflow Design

Pictobank separates temporary Free processing, saved Storage+ workflows, and device-first Local Processing so each workflow keeps only the data needed to operate.

2. Temporary Free Processing

Free Image Tools and Pipeline workflows are designed for temporary processing and delivery. Their working files and outputs are not treated as permanent Vault storage unless you choose a saved Storage+ workflow, but short-lived data may remain while processing, delivery, security, and cleanup systems finish.

3. Storage+ Cloud Workflows

Storage+ stores exports, folders, Vault metadata, share page records, and snapshot files that you choose to save or share. These files persist until deleted, revoked, expired, or otherwise removed under product rules.

4. Local Processing

Local Processing runs supported image-processing work on your device. It still uses Pictobank services for license activation, verification, recovery, replacement, account-linking, product updates, and other operational requests. Files enter cloud storage only when you separately choose a Storage+ or delivery workflow that requires it.

5. Sharing and Delivery

Share links are accessible by possession of the link while active. Shared files, metadata, events, and snapshots may be stored so a share page can open, download, expire, and be managed. Direct Email sends selected content and message details to the chosen recipients through Pictobank and its configured email delivery provider.

6. Account and Profile Data

Pictobank may store account email, user ID, plan, Storage+ status, billing state, profile records, settings, support tickets, and product ownership links.

7. Billing Data

Payments, subscriptions, invoices, checkout sessions, billing portal access, and payment method handling are processed by Stripe. Pictobank stores payment references and status needed to operate paid access.

8. Email and Support Communications

Pictobank uses email for license delivery, recovery, support, admin alerts, billing notices, account operations, and product reliability messages. Support tickets store your email and message content so we can respond.

9. License Logs

Local Processing recovery, activation, verification, replacement, revocation, and account-linking events may be logged without storing plaintext license keys in operational event tables.

10. Analytics, Reliability, and Abuse Prevention

Usage, processing, Pipeline, sharing, download, email, purchase, error, and security events may be used to understand product reliability, enforce limits, prevent abuse, and improve operations. Pictobank's first-party product events are stored through Supabase rather than a separate analytics vendor.

11. Advertising and Google AdSense

Advertising is currently off. Any activation requires separate authorization and is limited to qualified, indexable public guide pages at registered editorial placements. If authorized, anonymous visitors may see Google AdSense only at those placements. Pictobank excludes product, result, download, share, account, billing, Vault, email, Local Processing, legal, support, noindex, comparison, and thin pages. Google may use cookies or similar technologies under its policies, subject to the saved privacy choice, Global Privacy Control, and required certified consent-framework signals.

12. Cookies and Browser Storage

Pictobank uses cookies, local storage, and browser storage for authentication, settings, workflow state, local license state, analytics session IDs, advertising measurement, and product preferences.

13. Retention and Deletion

Temporary processing and delivery data may be retained briefly while a request, download, email, security check, or cleanup job completes. Storage+ data persists until it is deleted, revoked, expired, or otherwise removed under product rules. Share snapshots expire according to share settings and cleanup systems. During and after account deletion, Pictobank may retain bounded, pseudonymous, immutable evidence required for financial and billing records; purchase and license records; commercial records; audit and security records; Asset evidence; and provenance and lineage evidence. This does not mean raw customer files are retained by default. Operational logs may be retained for security, billing, support, and reliability.

14. Third-Party Providers

Verified providers are Fly.io for application hosting and compute, Supabase for authentication, database, and managed storage, Stripe for conditional billing workflows, Resend for conditional transactional email delivery, and Google AdSense for conditional eligible advertising. The Service Providers page explains category, purpose, data, when used, and current state.

15. Security Safeguards

Pictobank uses operational safeguards such as account checks, license hashing, safe event logs, throttles, abuse prevention, and admin-only diagnostics to protect users and the platform.

16. User Responsibilities

You are responsible for the files you process, the links you share, the recipients you choose, the accuracy of support information you provide, and securing your account access.

17. Contact

Use the support or contact page for privacy questions, account requests, billing questions, license recovery, abuse reports, advertising questions, or data concerns.

Privacy documentLast updated: July 2026

This page is structured for reading, printing, and section review. Plain-language helpers explain context but do not replace the controlling policy text.

Privacy modes

How data handling changes by workflow

These cards summarize the operating modes. The full policy sections below remain the source of detail.

Free processing

Designed for temporary processing and immediate download, not permanent cloud storage.

Storage+

Saves exports, folders, Vault metadata, and share page records that users choose to save or share.

Local Processing

Runs supported image work on-device while licensing and other operational requests still use Pictobank services.

Share links

Active links can make selected files available to people who have the link.

Account and support

Account records and support tickets keep context needed to operate access and answer requests.

Billing provider

Stripe handles payment records, invoices, checkout, and billing portal tasks.

Cookies and browser storage

Browser data can support auth, settings, workflow state, local license state, ads, and measurement.

Advertising context

Free workflows may include advertising partners when placements are approved and separated from controls.

Reader navigation

Common privacy questions

Jump to the sections users most often check before choosing a workflow.

Policy sections

Privacy details

The wording below preserves the existing privacy substance with a more readable layout.

Privacy by Workflow Design

Pictobank separates temporary Free processing, saved Storage+ workflows, and device-first Local Processing so each workflow keeps only the data needed to operate.

Temporary Free Processing

Free Image Tools and Pipeline workflows are designed for temporary processing and delivery. Their working files and outputs are not treated as permanent Vault storage unless you choose a saved Storage+ workflow, but short-lived data may remain while processing, delivery, security, and cleanup systems finish.

Storage+ Cloud Workflows

Storage+ stores exports, folders, Vault metadata, share page records, and snapshot files that you choose to save or share. These files persist until deleted, revoked, expired, or otherwise removed under product rules.

Local Processing

Local Processing runs supported image-processing work on your device. It still uses Pictobank services for license activation, verification, recovery, replacement, account-linking, product updates, and other operational requests. Files enter cloud storage only when you separately choose a Storage+ or delivery workflow that requires it.

Sharing and Delivery

Share links are accessible by possession of the link while active. Shared files, metadata, events, and snapshots may be stored so a share page can open, download, expire, and be managed. Direct Email sends selected content and message details to the chosen recipients through Pictobank and its configured email delivery provider.

Account and Profile Data

Pictobank may store account email, user ID, plan, Storage+ status, billing state, profile records, settings, support tickets, and product ownership links.

Billing Data

Payments, subscriptions, invoices, checkout sessions, billing portal access, and payment method handling are processed by Stripe. Pictobank stores payment references and status needed to operate paid access.

Email and Support Communications

Pictobank uses email for license delivery, recovery, support, admin alerts, billing notices, account operations, and product reliability messages. Support tickets store your email and message content so we can respond.

License Logs

Local Processing recovery, activation, verification, replacement, revocation, and account-linking events may be logged without storing plaintext license keys in operational event tables.

Analytics, Reliability, and Abuse Prevention

Usage, processing, Pipeline, sharing, download, email, purchase, error, and security events may be used to understand product reliability, enforce limits, prevent abuse, and improve operations. Pictobank's first-party product events are stored through Supabase rather than a separate analytics vendor.

Advertising and Google AdSense

Advertising is currently off. Any activation requires separate authorization and is limited to qualified, indexable public guide pages at registered editorial placements. If authorized, anonymous visitors may see Google AdSense only at those placements. Pictobank excludes product, result, download, share, account, billing, Vault, email, Local Processing, legal, support, noindex, comparison, and thin pages. Google may use cookies or similar technologies under its policies, subject to the saved privacy choice, Global Privacy Control, and required certified consent-framework signals.

Cookies and Browser Storage

Pictobank uses cookies, local storage, and browser storage for authentication, settings, workflow state, local license state, analytics session IDs, advertising measurement, and product preferences.

Retention and Deletion

Temporary processing and delivery data may be retained briefly while a request, download, email, security check, or cleanup job completes. Storage+ data persists until it is deleted, revoked, expired, or otherwise removed under product rules. Share snapshots expire according to share settings and cleanup systems. During and after account deletion, Pictobank may retain bounded, pseudonymous, immutable evidence required for financial and billing records; purchase and license records; commercial records; audit and security records; Asset evidence; and provenance and lineage evidence. This does not mean raw customer files are retained by default. Operational logs may be retained for security, billing, support, and reliability.

Third-Party Providers

Verified providers are Fly.io for application hosting and compute, Supabase for authentication, database, and managed storage, Stripe for conditional billing workflows, Resend for conditional transactional email delivery, and Google AdSense for conditional eligible advertising. The Service Providers page explains category, purpose, data, when used, and current state.

Security Safeguards

Pictobank uses operational safeguards such as account checks, license hashing, safe event logs, throttles, abuse prevention, and admin-only diagnostics to protect users and the platform.

User Responsibilities

You are responsible for the files you process, the links you share, the recipients you choose, the accuracy of support information you provide, and securing your account access.

Contact

Use the support or contact page for privacy questions, account requests, billing questions, license recovery, abuse reports, advertising questions, or data concerns.

Use it when

Example decisions

Small practical examples to help choose the right workflow.

Temporary vs saved

Temporary processing is different from saved Storage+ workflows.

Advertising

Free workflows may include advertising partners according to their policies.

Support messages

Support tickets store the email and message needed to answer the request.

Plain-language legend

Quick terms

Short definitions for terms used on this page.

CookieSmall browser data used by sites and providers.

Why it matters: Cookies can support auth, preferences, measurement, and ads.

Example: A cookie can keep a session or ad measurement state available.

Browser storageData stored locally by the browser.

Why it matters: It can hold workflow state, local license state, or preferences.

Example: A browser may remember local settings for a repeat workflow.

Local storageA browser storage area that can persist between sessions.

Why it matters: It may keep preferences or local workflow state on the device.

Example: Local license state can remain until cleared by the user or browser.

SessionA temporary period of signed-in or workflow activity.

Why it matters: Session state can affect authentication and continuity.

Example: Signing out or clearing browser data can end a session.

AnalyticsMeasurement used to understand product reliability and usage.

Why it matters: It helps identify failures, limits, and operational issues.

Example: An upload error event can help locate a broken workflow.

Third-party providerA service Pictobank uses to operate part of the product.

Why it matters: Payments, auth, hosting, email, ads, and analytics can involve providers.

Example: Stripe handles payment flows and billing portal access.

StripeThe payment provider used for checkout and subscription management.

Why it matters: Billing records and payment methods are handled through Stripe systems.

Example: Use Stripe's portal to update a payment method.

SupabaseA provider used for account, auth, database, or storage-related systems.

Why it matters: It supports signed-in product workflows.

Example: Account status can depend on Supabase-backed records.

AdSenseA Google advertising system that may support free workflows.

Why it matters: Advertising partners can use cookies or similar technologies under their policies.

Example: Free pages may reserve ad shelves away from primary controls.

Temporary fileA file intended for short-lived processing or download.

Why it matters: It is not the same as user-chosen saved cloud storage.

Example: Download a free processed file soon after processing.

RetentionHow long data may remain for a workflow or operational need.

Why it matters: Saved workflows and operational logs can have different timelines.

Example: A share snapshot may remain until deleted, expired, or cleaned up.

Operational logA reliability, security, billing, or support event record.

Why it matters: Logs help investigate errors, abuse, purchases, and access state.

Example: A license recovery event can be logged without storing plaintext keys.

Share linkA link that can open selected shared files while active.

Why it matters: Anyone with the active link may be able to view or download it.

Example: Send a share link only to intended recipients and delete it when access should end.

Storage+An account-based subscription for saved exports and organization.

Why it matters: It changes whether cloud exports persist until deleted or expired.

Example: Use Storage+ when you want saved folders and reusable exports.

Local ProcessingA device-first paid mode for heavy private repeat work.

Why it matters: It is separate from cloud Storage+ workflows.

Example: Use Local Processing for large recurring batches on your own device.

Support ticketA tracked support request.

Why it matters: It gives support context and a reference trail.

Example: Include a ticket ID when replying about the same issue.

P.A.R.Q.

Practical privacy questions

Concise answers for deciding which workflow fits your file sensitivity and storage needs.

Are free processed files stored forever?

No. Free processed files are designed for temporary processing and download, not permanent cloud storage.

What changes when I save something with Storage+?

Storage+ saves selected exports, folders, share records, and related metadata until deleted, expired, or otherwise removed under product rules.

What can someone access through a share link?

Someone with an active link may access the files and share page data tied to that link while it remains active.

What does Local Processing keep on my device?

Local Processing is designed for device-first work; browser storage may keep license state, settings, or workflow state on that device.

Why are billing records handled separately?

Billing flows are handled by Stripe, while Pictobank stores the references and status needed to operate paid access.

What are cookies and browser storage used for?

They can support authentication, preferences, workflow state, analytics sessions, advertising measurement, and local license state.

Can support messages include account or file context?

Support messages may include email, account context, license or billing references, and details the user chooses to provide.

How should I handle sensitive files?

Use the workflow that matches your risk, avoid unnecessary saved sharing, and do not paste private file contents into support requests.