Pikalt documents · 18+
Privacy policy
This policy explains what Pikalt receives, why it is needed, who receives it, how long it is retained and how to exercise your rights.
Data we process
We limit collection to what is needed for accounts, generations, safety and financial records.
- Account: email, protected password hash, language, role, age confirmation and versions of accepted documents.
- Content: prompts, settings, source images, results, technical job identifiers and review status.
- Technical: IP address, request time, session and device data, security events, and errors without prompt or media content.
- Requests: subject, messages, attachments, response history and removal-request information.
- Records: credit entries, promo codes, referral attribution, referred purchases, commission and payout requests.
Purposes and legal bases
The applicable basis depends on the feature and your jurisdiction.
- Contract: registration, authentication, generation processing, history, support and credit accounting.
- Legitimate interests: protecting the service and users, preventing abuse, diagnostics and audit while balancing your rights.
- Consent: separate optional features where required; consent may be withdrawn for future processing.
- Legal obligation and claims: responding to competent authorities, tax and accounting duties, and resolving disputes.
Retention and deletion
Retention depends on purpose and is extended only for an investigation, dispute, safety need or legal requirement.
- Source files and generated media are deleted by default 10 days after creation, or sooner on request unless a valid hold applies.
- Technical security logs are retained for up to 12 months and must not contain passwords, tokens, prompts or media.
- Credit, affiliate, payment and administrator audit records remain as long as needed for ledger integrity and legal obligations.
- After deletion, an object may remain briefly in a protected backup without ordinary access until scheduled overwrite.
Security and international transfers
Controls include access restrictions, short-lived file links, encryption in transit, protected secret storage, administrator audit and log minimisation. No system can guarantee absolute security.
AI providers and infrastructure may be located outside your country. Where required, contractual transfer mechanisms and an assessment of recipient safeguards are used.
Your rights
Depending on where you live, you may submit a request through support. We may verify identity and authority before releasing data.
- Know about processing, receive a copy of data and correct inaccuracies.
- Request deletion or receive applicable data in a portable format.
- Restrict or object to processing, or withdraw consent without retroactive effect.
- Appeal a refusal, avoid discrimination for exercising rights and complain to a competent data-protection authority.
Age and policy changes
Pikalt is not intended for anyone under 18. If we learn that a minor's data is present, the account and data will be restricted and deleted through the applicable process.
An updated policy is published with a new effective date. Registered users receive in-product or email notice of material changes where required.