PixAgain
Language · English

Last updated:

Privacy Notice

This notice explains the PixAgain photo-restoration and animation service. Your selected photo is sent to our server and an AI provider; processing does not happen only on your device. Account identifiers are pseudonymous, not anonymous to our system.

1. Controller and scope

Andrzej Nowakowski, at the address above, is the controller responsible for personal data processed to provide PixAgain. For privacy questions or requests, contact contact@primeart.io with “PixAgain privacy” in the subject.

The app uses a separate recoverable account without requiring a name or email. Apple and Google process store payments and their own account information under their notices. Expo and the device push service process optional completion notifications as described below.

2. Information we process

Selected content: the photograph you choose, its prepared image bytes and format, generated photos/videos and the identifiers needed to retrieve a result. A face is part of the photograph sent for processing. PixAgain does not implement face recognition, identity matching or biometric identification templates.

Account and service records: a random account identifier and installation identifier, hashes of the installation secret and session tokens, terms/age-confirmation timestamp, request identifiers, input fingerprint, quality, timestamps, completion/error status and usage allowances. These records protect access, prevent repeated generation and enforce allowances. The account is linked to its content and purchases; hashing does not make these records anonymous.

Device information: language, settings, result history and local media references, recovery credentials in secure device storage, and optional push registration. Support correspondence contains what you choose to send. Network systems receive connection metadata including IP addresses. Application signup/login rate limits use a keyed hash of the connection address for 24 hours; separate hosting access/error logs and incident backups may last longer where needed for security or recovery.

Purchases: platform, product and transaction identifiers, purchase/expiry/refund information and entitlement status. We verify store receipts or purchase tokens on the server; reusable tokens may be retained to check renewals and refunds. PixAgain does not receive your payment-card number. Purchases are bound to the PixAgain account that verified them. We do not include advertising, an advertising identifier or a dedicated analytics SDK.

3. Purposes and legal bases

We process the photo and necessary service records to carry out the restoration or animation you request and provide the service contract (GDPR Article 6(1)(b), where applicable). For information about another person in a submitted photo, contractual necessity with you is not itself a legal basis for that person: processing must also have an appropriate lawful basis, such as a balanced legitimate interest in the user-requested service, and respect that person’s rights.

We use necessary records for security, abuse prevention, troubleshooting and defending claims where our legitimate interests are not overridden by your rights (Article 6(1)(f)); for legally required records or responses we rely on the relevant legal obligation (Article 6(1)(c)). Optional device permissions are controlled by you. Where a feature requires consent, you may withdraw it without affecting earlier lawful processing.

We do not ask you to provide special-category data, identify people biometrically, infer sensitive traits, or make automated decisions producing legal or similarly significant effects. Do not submit content that would require a special legal basis which the app has not obtained. AI reconstruction can nonetheless change a depicted face or other details.

4. Recipients and AI processing

Your request goes over HTTPS to the PixAgain API hosted on our server, then to fal — Features & Labels, Inc. — for inference. The photo modes currently use GPT Image 2.5 Flare low or medium; animation uses LTX 2.3 Fast. The model name alone does not identify every recipient or processing location. Generated media is downloaded to the PixAgain backend for delivery.

Only providers needed to operate the requested service and authorized personnel should receive the data required for that purpose. Support providers, hosting operators and authorities may receive necessary information for support, security or lawful obligations. We do not publish your uploaded photographs or use them in our advertising.

We do not train our own models on your photos. fal’s published API terms contain content-use protections, with exceptions for designated models, and may route requests to a third-party model provider. Its data-processing agreement also has a defined scope. A model name alone does not establish that scope or a universal no-training guarantee. Provider handling is subject to the applicable model and account terms; the linked documents explain their scope.

5. International processing

fal and other service infrastructure can process data outside the EEA, including in the United States. fal publishes a data-processing agreement with international-transfer terms and standard contractual clauses where that agreement applies; exclusions and model-specific terms may apply. We do not represent that every operation stays in the EU or that an unverified contractual exception is covered. Contact contact@primeart.io for the applicable recipients and safeguards or to request a copy of the relevant transfer protections.

6. Retention and deletion

Restored photos expire 30 days after the request; videos expire seven days after their last completed update. Expired photo links and local video files are removed by background cleanup. Access checks reject expired results. A video source photo is kept only until the provider accepts it or its job ends; stale unfinished jobs are expired. Deleted/expired results cannot be regenerated free by replaying the same request identifier. Keep your own copy of a result you want to retain.

Request identifiers, timestamps, quality, usage source and success/failure records remain until account deletion to prevent repeated free allowances, duplicate spending and replay of old requests. These records do not need to retain the photo or video. Account credentials remain while the account exists; server session tokens expire after one year and old sessions are bounded. You can delete completed media or choose Settings → Delete account. Pending jobs first settle or fail; account access is revoked immediately and late results are discarded.

Deleting the account removes its identifiers, credential hashes, active push registrations and working media/usage records. A restricted purchase ledger retains pseudonymous account and transaction/chain identifiers to prevent the same purchase being claimed again and to meet dispute/legal obligations; reusable store verification tokens are removed. Records subject to a specific legal obligation or active dispute may be retained for that purpose. Deletion does not cancel store renewals or remove copies you saved to your device.

Our requests ask fal not to retain JSON inputs/outputs in request history (X-Fal-Store-IO: 0) and request a 30-day lifetime for restored photo files and a 24-hour lifetime for generated video CDN files. These controls apply to those storage categories; they are not a guarantee that every model provider, security record, legal record or backup is erased at the same moment. fal-hosted output addresses may temporarily be accessible to anyone possessing the URL. Restored photos are hosted by fal; our database stores only their URLs and metadata. Existing photos migrated on 27 September 2026 have the same 30-day expiry measured from generation. Downloading for compatibility with installed apps uses temporary memory, not persistent photo storage. Videos still use account-scoped server storage. PixAgain remote deletion does not itself confirm deletion of every upstream copy.

Contact contact@primeart.io for deletion or access help, using a request identifier or account reference when available. We verify control proportionately and handle applicable rights without charging for an ordinary request. Isolated incident/deployment backups and hosting logs are access restricted and must not be restored to bypass a deletion request; their exact lifecycle and any necessary legal hold are available on request. We do not promise that removing an active record instantly erases every backup.

7. Notifications, permissions and store reviews

The app uses a system picker for the photograph you choose; it does not upload your whole photo library. Saving a result may require permission to add an image or video to your library. Camera, microphone, contacts and precise-location access are not required by the current PixAgain flows.

Completion notifications are optional and require explicit opt-in in a supported native app. Expo Go and the browser do not support this feature. Notifications are not used for marketing. We store a random installation identifier, hashed installation credential, Expo push token, language, enabled state and registration time. A global hash of the token associates it with the account currently using that installation. Job/delivery records contain request and installation identifiers, job type and delivery status. The original installation secret remains in secure device storage.

When active, the token and a generic localized completion message pass through Expo Push Service and Apple Push Notification service or Firebase Cloud Messaging. The payload contains the request ID and job type, not your photo, prompt, name or media URL. Registration expires after 90 days without refresh; job bindings and delivery records expire after 30 days. Turning notifications off in the app removes the active registration token and suppresses pending notifications. A token copy for a message already accepted for delivery can remain until its delivery receipt is finalized, subject to the 30-day delivery-record limit. Invalid tokens are removed; changed system permissions are synchronized when the app refreshes. Optional notification delivery relies on your consent; you may withdraw it without losing restoration features.

Where the native store review prompt is available, local eligibility records may track a verified paid entitlement, completed-generation count and the last request date to avoid repeated prompts. Apple or Google handles a submitted rating. PixAgain does not receive the review text through that prompt and does not condition support or credits on a rating.

8. Security and your choices

HTTPS protects transit to the deployed API and AI service. The server and inference provider must read the image to process it; this is not end-to-end encrypted processing. Scoped video links grant temporary access to anyone who possesses the complete link. Do not post those links publicly if you want to keep a video private.

Account requests require a secure session. Session and recovery secrets are stored as hashes on the server, and account media/quotas are isolated. Protect your device and recovery code. No security measure can guarantee protection against every incident; we do not claim end-to-end encryption or a fully audited confidential archive.

Do not upload an image if you do not want remote processing. Keep your originals. You can change language, remove local history items, control device permissions and contact us about server data. Refusing optional notifications or a review prompt does not remove paid functionality.

9. Privacy rights and complaints

Depending on your location and the legal basis, you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, or withdraw consent. These rights are subject to the conditions in applicable law; withdrawal does not affect processing already lawfully performed.

Email contact@primeart.io and identify the relevant job or approximate date where possible. We may request only reasonable information needed to verify your connection to the data. Do not send a full identity document unless a proportionate secure verification process has first been agreed. Under the GDPR, a response is normally due within one month; any permitted extension must be explained within that period. A deletion request does not cancel a store subscription.

You may complain to the supervisory authority in the country where you live or work or where an alleged infringement occurred. In Poland, this is the President of the Personal Data Protection Office (UODO). You do not need to contact us first to exercise that right. We do not penalize you for exercising privacy rights.

10. Adults and changes

The processing service is intended for adults as required by our current AI provider terms. If you believe a minor has used it or personal data was submitted without the necessary rights, contact us so we can investigate and take appropriate action.

We update this notice when actual practices change and draw attention to material changes when required. The date above identifies this version. A privacy notice does not authorize new processing for an unrelated purpose without a lawful basis.

Website audience measurement — added 27 September 2026

On the public PixAgain website, we measure page views and clicks to Google Play to understand which pages and campaigns are useful. Our own server receives the published page path, its language, the referring hostname, limited source/medium/campaign tags when present, and a broad device category: iOS, Android, desktop or other. We do not collect the full page or referring URL, search terms or advertising click identifiers for these reports.

This measurement uses no cookies, local storage, advertising SDK or persistent browser identifier. A random identifier exists only for the current page view to prevent duplicate counting. The server transiently uses the connection IP address to compute a daily keyed hash for an approximate visitor count; neither the raw IP address nor the full browser user agent is stored in the analytics database. Shared networks may be counted together, and one person using different networks may be counted more than once. Reports are not linked to app accounts, photos or purchases.

Page identifiers and daily hashes are deleted after 48 hours, with cleanup running approximately once a minute while the service is operating. Daily aggregate counts are retained for 90 days and are accessible only in our authenticated administration panel. This is separate from access-restricted hosting security logs. The tracker respects browser Do Not Track and Global Privacy Control signals. You can also disable measurement for an individual page by adding analytics=off to its URL query. Questions or objections can be sent to contact@primeart.io.