Privacy Policy
Last updated: May 2026
StickPix ("we", "us", "our") operates the website stickpix.art ("Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information.
1. Information We Collect
Information You Provide
- Account Information: Email address (via Google sign-in)
- Photos You Upload: Selfie/portrait photos for AI sticker generation
Information Collected Automatically
- Usage Data: Pages visited, features used, generation history
- Device Information: Browser type, operating system, screen resolution
- Cookies: See our Cookie Policy
Payment Information
Payments are processed by PayPal. We do not store your full payment card details. PayPal retains transaction records per its own privacy policy.
2. How We Use Your Information
| Purpose | Legal Basis | Description |
|---|---|---|
| Provide Service | Contract | Process your photo to generate stickers |
| Account Management | Contract | Maintain your account via Google sign-in |
| Process Payments | Contract | Manage Pro subscription via PayPal |
| Safety & Security | Legitimate Interests | Prevent abuse, fraud, harmful content |
| Service Improvement | Legitimate Interests | Analyze usage patterns |
| Error Monitoring | Legitimate Interests | Detect and fix technical issues |
| Analytics | Consent | Understand user interactions (Plausible Analytics, Google Analytics, usage analytics) |
3. Special Category Data — Facial Images
When you upload a photo containing facial images for sticker generation, this constitutes special category personal data under GDPR Article 9.
We process this data based on your explicit consent. By checking the confirmation box before upload, you consent to:
- Sending your photo to our AI service providers (FAL.ai / OpenAI) solely for sticker generation
- Temporary storage on Cloudflare R2 for processing
Your photo is automatically deleted within 1 hour after generation is complete. Generated sticker images are automatically deleted after 7 days.
Your photos and generated stickers are not accessible to our team. They are processed automatically with access controls preventing human access.
You may withdraw consent at any time by contacting support@stickpix.art.
4. AI Service Providers
FAL.ai (Free tier)
- Purpose: AI image generation for free users (FLUX.1-schnell)
- Data sent: Your uploaded photo and pre-set generation prompt
- Data retention: We configure FAL.ai to not store your input/output (via
X-Fal-Store-IO: 0header) - Training: FAL.ai does not use Customer Data to train models
OpenAI (Pro tier)
- Purpose: AI image generation for Pro users (gpt-image-2)
- Data sent: Your uploaded photo and pre-set generation prompt
- Data retention: OpenAI retains API data up to 30 days for abuse monitoring, then deletes it
- Training: OpenAI does not use API data to train or improve models
5. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google (OAuth) | Login authentication | policies.google.com/privacy |
| Cloudflare R2 | Photo and result storage (US) | cloudflare.com/privacypolicy |
| Cloudflare D1 | User account database | cloudflare.com/privacypolicy |
| PayPal | Payment processing | paypal.com/privacy |
| Google Analytics | Website analytics (usage analytics) | policies.google.com/privacy |
| Plausible Analytics | Privacy-friendly website analytics | plausible.io/data-policy |
| FAL.ai / OpenAI | AI image generation | fal.ai/privacy / openai.com/privacy |
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Uploaded photos | Automatically deleted within 1 hour after generation |
| Generated sticker images | Automatically deleted after 7 days |
| Account information (email) | Until you delete your account |
| Payment records | As required by law (typically 5-7 years) |
| Analytics data | Per analytics provider configuration (Google Analytics and Plausible Analytics) |
| Server logs | 30 days |
7. Your Rights
Depending on your location, you may have:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Deletion: Request deletion ("right to be forgotten")
- Data Portability: Receive data in a structured format
- Withdraw Consent: Withdraw consent for facial image processing and analytics
- Object: Object to processing based on legitimate interests
To exercise these rights, contact support@stickpix.art. You can also delete your account via Account Settings or by emailing us.
California Users (CCPA/CPRA): We do not sell or share your personal information for advertising purposes.
EU/UK Users (GDPR): You have the right to lodge a complaint with your local supervisory authority.
8. International Data Transfers
Your data may be transferred to and processed in the United States. Appropriate safeguards are in place:
- Cloudflare operates under Standard Contractual Clauses (SCCs) and EU-US Data Privacy Framework
- OpenAI is certified under EU-US Data Privacy Framework
- Google is certified under EU-US Data Privacy Framework
- PayPal is certified under EU-US Data Privacy Framework
9. Children's Privacy
StickPix is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If we learn we have collected data from a child under the applicable age, we will delete it promptly.
10. Security
- Encrypted data transmission (HTTPS/TLS)
- Frontend direct upload to R2 via pre-signed URLs (photos do not pass through our backend)
- Automatic deletion of uploaded photos within 1 hour
- Automatic deletion of generated stickers after 7 days
- Our team cannot access your photos or generated content
- Payment processing through PayPal (PCI DSS compliant)
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by posting the new policy with an updated "Last Updated" date. Continued use constitutes acceptance.
12. Contact Us
Questions about this Privacy Policy? Contact support@stickpix.art