GenPix AI Open the studio

Privacy policy

This page says what we hold about you, why, and how to make us delete it. It is deliberately specific: a service where people upload photographs of faces should not describe itself in generalities.

Version 1.0 · in force since 16 August 2026 · GDPR (EU) 2016/679

1Who is responsible

The controller of your data is the operator of GenPix AI: an individual trader established in France, whose name, registration number and statutory address are not printed on this site and are sent in full to anyone who asks for them at the address below. Write to [email protected] for anything on this page — including that request. We are not large enough to require a Data Protection Officer, so that address reaches the person who actually runs the service.

2What we collect, and why

DataWhy we have itLegal basis
Email addressTo identify your account, send receipts, and reach you about your moneyContract
Password (hashed)To let you back in. We store a one-way hash — we cannot read your password.Contract
Google account id, name, pictureOnly if you sign in with Google, and only to identify youContract
Your promptsTo generate the image, to show you your own history, and to detect abuseContract · legitimate interest
Images you upload as referencesTo generate from them. These may contain faces.Contract · your consent (§4)
Images we generate for youTo deliver them and keep them in your libraryContract
Wallet, payments, refundsTo run your balance and meet accounting lawContract · legal obligation
Drafts — a prompt and its reference photos, saved as you type, before and whether or not you press GenerateSo your work survives leaving the page or signing in, and so unlawful requests can be seen before they become images (§2.2)Contract · legitimate interest
Your IP address, in readable formRate limiting, fraud and abuse detection, the free-trial rule, and being able to attach a picture or a prompt to the connection it came fromLegitimate interest
A daily, irreversible token for page countingTo count visitors without a cookie and without a consent banner. It changes every night, so it cannot follow you from one day to the next.Legitimate interest
Browser and session recordsTo keep you signed in and to show you where your account is logged inContract · security

We keep your IP address in readable form, and we would rather say it plainly than describe it prettily. It is written next to a sign-in, a session, a picture you upload, a prompt you type and a generation you run. It is what lets the operator answer “where did this image come from” for an image that has no account behind it, and it is what makes the free trial one per address rather than one per cleared cookie.

Page counting is the exception, and it works the other way round. Reading a page writes one line with a token that is rebuilt from a secret that changes every night: the same person tomorrow is a different string, and nothing anywhere turns that string back into an address. We keep the readable address on that line for 30 days and then erase it; the line itself is kept six months as a number in a total. That is why this site has no cookie banner — there is no cookie and no cross-day identity to consent to.

We do not run advertising trackers, we do not use analytics that profile you across sites, and we do not sell or rent your data to anyone. The only cookie we set is the one that keeps you signed in.

2.1The free trial, without an account

You can generate your first images without creating an account. That does not mean anonymously, and we would rather say so plainly here than let you assume otherwise.

If you do not want us to hold a prompt, do not type it. A free trial is still a use of the service, and it is recorded like any other.

2.2We look at prompts and reference images

The operator of this service can read the prompts sent to it and view the reference images uploaded to it, whether or not they came from an account, and whether or not a generation was ever run. There is no way to run an image service without this: it is how unlawful use is found, and it is what lets us answer a complaint or a court about a specific image.

Every administrative view of somebody else's image is itself written to an audit log, with who looked and when. That log is the check on the paragraph you just read.

3What we do not do with your images

4Photographs of people — the part that matters

A photograph of an identifiable face is personal data about that person, whether or not they are you. So:

5Who else sees your data

The companies below process data on our behalf. Each is bound by a data-processing agreement and may use the data only to do its job for us. The image-generation row covers more than one company — see the note under the table.

WhoWhat they getWhere
StripeYour email and the amount; your card details, which they collect directly and we never seeEU/US, standard contractual clauses
Our image-generation providersYour prompt and any reference images, in order to generate the result. A generation runs at one of them — whichever is available at that moment.Outside the EU, standard contractual clauses
GoogleOnly if you choose Google sign-in: the fact that you signed inEU/US, standard contractual clauses
HostingerHosts the servers your account and files live onEU (Lithuania)

We do not publish the identity of the image-generation providers, because which systems we run is commercially sensitive. That is a business choice, not a way of hiding where your data goes: write to [email protected] and we will name every one of them to you, along with the transfer safeguards in place. Nobody has to take “a provider” on trust.

Beyond those, we disclose data only where the law requires it — a court order, or the reporting obligation described in section 6.

6Administrative records, including after you delete

This is the clause most services bury, so we will be blunt about it.

When you delete an image from your library, it disappears from your account immediately but is retained in a restricted administrative archive. The same applies to the prompt and the reference images behind it. Only the operator of the service can see that archive.

Why: a generation service can be used to produce illegal material — chiefly sexual content involving minors and non-consensual intimate images. If deleting the evidence also deleted the record, the service could not detect that, could not act on a complaint, and could not answer a lawful request. That is our legitimate interest, and in the case of child sexual abuse material it is also a legal obligation.

The trade this makes, stated plainly: deletion removes your content from your account and from anywhere it was visible, but not from our records. If that is not acceptable to you, do not upload the material. You can still demand full erasure under section 8, and we will grant it unless the law obliges us to keep a specific item.

7How long we keep things

WhatHow long
Your account, wallet and libraryWhile the account is open
Generated images and promptsWhile the account is open, then in the archive of section 6
Uploaded reference imagesSame — and deleted from the generation provider's side, whichever one ran it, under their own retention rules
Payment and invoice records10 years — French accounting law, and we cannot shorten it
Withdrawal-waiver records10 years, with the payment they belong to
Drafts (§2.1) — the last prompt and reference list per barOverwritten each time you edit it; kept while the session or account exists. Clearing the box deletes the record.
Free-trial sessions with no accountThe cookie lasts 30 days. The session record, and anything generated in it, is kept as an administrative record (§6) — an image we made has to stay traceable even when nobody ever signed up for it.
Security and abuse logs (hashed IPs)12 months
Failed sign-in attempts24 hours
Sign-in cookie30 days, or until you sign out

8Your rights

Under the GDPR you may ask us to:

Write to [email protected] from the address on your account. We answer within 30 days and it costs nothing. If we refuse, we tell you why and on which article.

You may also complain to a supervisory authority — in France, the CNIL, or the equivalent authority in your own country.

9Security

Passwords are hashed, not stored. Traffic runs over HTTPS. Session cookies are HttpOnly, SameSite and Secure. The database and every uploaded file sit outside the web root, so no URL reaches them directly; files are served only through a check that you are their owner or an administrator. IP addresses are stored in readable form where §2 says so, inside the same protected database, and are erased from page-counting records after 30 days. The administration console is not reachable without an administrator session.

None of that is a promise of invulnerability, and anyone who makes one is lying. If a breach ever puts your rights at risk, we will tell you and the CNIL within 72 hours, and we will say what actually happened.

10Children

GenPix AI is not for under-16s and we do not knowingly hold data about one. If you believe a child has an account here, write to us and we will delete it.

11Changes

If we change how we use your data in a way that affects you, we will email you and update the date at the top of this page before it takes effect.