Pictobank Privacy
•••
Last updated: July 2026
1. Privacy by Workflow Design
Pictobank separates temporary Free processing, saved Storage+ workflows, and device-first Local Processing so each workflow keeps only the data needed to operate.
2. Temporary Free Processing
Free Image Tools and Pipeline workflows are designed for temporary processing and delivery. Their working files and outputs are not treated as permanent Vault storage unless you choose a saved Storage+ workflow, but short-lived data may remain while processing, delivery, security, and cleanup systems finish.
3. Storage+ Cloud Workflows
Storage+ stores exports, folders, Vault metadata, share page records, and snapshot files that you choose to save or share. These files persist until deleted, revoked, expired, or otherwise removed under product rules.
4. Local Processing
Local Processing runs supported image-processing work on your device. It still uses Pictobank services for license activation, verification, recovery, replacement, account-linking, product updates, and other operational requests. Files enter cloud storage only when you separately choose a Storage+ or delivery workflow that requires it.
5. Sharing and Delivery
Share links are accessible by possession of the link while active. Shared files, metadata, events, and snapshots may be stored so a share page can open, download, expire, and be managed. Direct Email sends selected content and message details to the chosen recipients through Pictobank and its configured email delivery provider.
6. Account and Profile Data
Pictobank may store account email, user ID, plan, Storage+ status, billing state, profile records, settings, support tickets, and product ownership links.
7. Billing Data
Payments, subscriptions, invoices, checkout sessions, billing portal access, and payment method handling are processed by Stripe. Pictobank stores payment references and status needed to operate paid access.
8. Email and Support Communications
Pictobank uses email for license delivery, recovery, support, admin alerts, billing notices, account operations, and product reliability messages. Support tickets store your email and message content so we can respond.
9. License Logs
Local Processing recovery, activation, verification, replacement, revocation, and account-linking events may be logged without storing plaintext license keys in operational event tables.
10. Analytics, Reliability, and Abuse Prevention
Usage, processing, Pipeline, sharing, download, email, purchase, error, and security events may be used to understand product reliability, enforce limits, prevent abuse, and improve operations. Pictobank's first-party product events are stored through Supabase rather than a separate analytics vendor.
11. Advertising and Google AdSense
Advertising is currently off. Any activation requires separate authorization and is limited to qualified, indexable public guide pages at registered editorial placements. If authorized, anonymous visitors may see Google AdSense only at those placements. Pictobank excludes product, result, download, share, account, billing, Vault, email, Local Processing, legal, support, noindex, comparison, and thin pages. Google may use cookies or similar technologies under its policies, subject to the saved privacy choice, Global Privacy Control, and required certified consent-framework signals.
12. Cookies and Browser Storage
Pictobank uses cookies, local storage, and browser storage for authentication, settings, workflow state, local license state, analytics session IDs, advertising measurement, and product preferences.
13. Retention and Deletion
Temporary processing and delivery data may be retained briefly while a request, download, email, security check, or cleanup job completes. Storage+ data persists until it is deleted, revoked, expired, or otherwise removed under product rules. Share snapshots expire according to share settings and cleanup systems. During and after account deletion, Pictobank may retain bounded, pseudonymous, immutable evidence required for financial and billing records; purchase and license records; commercial records; audit and security records; Asset evidence; and provenance and lineage evidence. This does not mean raw customer files are retained by default. Operational logs may be retained for security, billing, support, and reliability.
14. Third-Party Providers
Verified providers are Fly.io for application hosting and compute, Supabase for authentication, database, and managed storage, Stripe for conditional billing workflows, Resend for conditional transactional email delivery, and Google AdSense for conditional eligible advertising. The Service Providers page explains category, purpose, data, when used, and current state.
15. Security Safeguards
Pictobank uses operational safeguards such as account checks, license hashing, safe event logs, throttles, abuse prevention, and admin-only diagnostics to protect users and the platform.
16. User Responsibilities
You are responsible for the files you process, the links you share, the recipients you choose, the accuracy of support information you provide, and securing your account access.
17. Contact
Use the support or contact page for privacy questions, account requests, billing questions, license recovery, abuse reports, advertising questions, or data concerns.