Legal
Privacy Policy
Effective date: June 22, 2026
Last updated: August 5, 2026
At a glance (not the full policy)
- We collect the minimum needed to run Pictoflix and bill you.
- We do not sell or rent personal data, and we do not use your photos to train public AI models.
- You can access, correct, export, or delete your data — see "Your rights".
- Authorized Pictoflix personnel may temporarily act-as your account for support; every session is logged.
- EU/UK users have full GDPR rights; international transfers rely on Standard Contractual Clauses.
1. Controller and contact
The data controller for personal data processed through the Pictoflix service is Pictoflix, headquartered in Montreal, Quebec, Canada, owner and operator of the Pictoflix.com service.
- Privacy contact: hello@pictoflix.com
- Security incident reporting: hello@pictoflix.com
- General contact: hello@pictoflix.com
- Postal: Pictoflix, Montreal, Quebec, Canada (full address available on request)
Where you are a customer of a Pictoflix subscriber and your photos are uploaded by that subscriber, Pictoflix acts as a processor on the subscriber's behalf; please contact the subscriber first for any rights request, with us on copy.
2. Scope
This Policy describes how we collect, use, share, and protect personal data when you visit pictoflix.com, create an account, upload Customer Content, generate Tours, make payments, or otherwise interact with the Pictoflix service (collectively, the "Service"). It applies globally and contains specific disclosures for the European Economic Area, the United Kingdom, and other jurisdictions where required by law.
3. Categories of personal data we collect
- Identity & account data: name, email address, password hash (for email/password sign-in) or third-party identifier (e.g. Google sub), profile picture URL, organization name.
- Authentication metadata: sign-in timestamps, IP address, user agent, sign-in provider, MFA status.
- Customer Content: property photos, floor plans, brand assets, scripts, voice samples, and any embedded metadata (EXIF, including GPS where present).
- Generated Tours: the rendered videos and associated metadata (length, model used, render parameters).
- Billing data: Stripe customer ID, subscription status, invoice history, last 4 digits and brand of payment card, billing country, tax ID where provided. We do not store full card numbers — those are tokenized by Stripe.
- Usage and telemetry: pages visited, features used, request/response metadata, performance and error logs, approximate IP-derived country.
- AI cost telemetry: per-call records of which AI model was used (Fal, ElevenLabs, Lovable AI Gateway), input/output token counts or render units, latency, and computed cost. Used for billing accuracy, abuse prevention, and capacity planning.
- Admin impersonation logs: when an authorized Pictoflix administrator acts-as your account, we record the administrator's identity, the target account, start/end timestamps, IP, and the documented reason.
- Communications: messages you send to support, survey responses, in-product feedback.
- Consent records: the version of these terms and privacy policy you accepted, the timestamp, and the IP from which acceptance occurred.
We do not intentionally collect special-category data (e.g. health, biometric, religious data) and we ask that you do not upload such data. Photos that incidentally show identifiable individuals should only be uploaded where you have the consent or legal basis required by applicable law.
4. How we use personal data and legal bases (GDPR)
For users in the EU/UK, we rely on the following Article 6 GDPR legal bases:
- Performance of a contract (Art. 6(1)(b)) — to create your account, render Tours, deliver Generated Tours, process payments, provide support.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud and abuse, monitor uptime and quality, calculate AI costs and margins, perform administrative impersonation strictly necessary for support or security, conduct limited product analytics, and defend legal claims. We balance these interests against your rights and you may object (see Section 9).
- Consent (Art. 6(1)(a)) — for non-essential cookies/analytics where applicable, for marketing emails to non-customers, and for any optional processing we tell you is consent-based. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation (Art. 6(1)(c)) — to keep tax/accounting records, respond to lawful requests from authorities, and comply with security-incident reporting laws.
We do not use personal data for solely automated decisions producing legal or similarly significant effects within the meaning of GDPR Article 22.
5. AI processing of Customer Content
To generate Tours, we transmit Customer Content to specialized third-party AI providers listed as subprocessors below. We have contractually required these providers to:
- process Customer Content only to perform the requested render;
- not use Customer Content or Generated Tours to train their public foundation models;
- delete inputs and outputs from their systems on a defined schedule;
- implement appropriate technical and organizational security measures.
Generated Tours are statistical outputs of machine-learning models and may contain inaccuracies. You are responsible for reviewing each Tour before publication.
6. Subprocessors and other recipients
We share personal data only with the categories of recipients below, under written agreements that impose confidentiality and data-protection obligations consistent with this Policy and, where applicable, GDPR Article 28.
- Cloud hosting & database — application hosting, primary database, file storage, and backups.
- Stripe — payment processing, tax calculation, invoicing, fraud detection. Stripe acts as an independent controller for payment data.
- Fal — generative video/image rendering models.
- ElevenLabs — voice synthesis for Tour narration.
- Lovable AI Gateway — multi-model LLM gateway used for in-product assistants and admin analytics summaries.
- Email delivery — transactional email (receipts, render-complete, password reset, security alerts).
- Customer support tooling — used by our team to respond to your messages.
- Professional advisors — auditors, lawyers, accountants under duties of confidence.
- Acquirers — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and to this Policy continuing to apply.
- Authorities — where legally required, after validating the request and, where lawful, notifying you.
An up-to-date subprocessor list is available on request to hello@pictoflix.com. We will give reasonable prior notice of new subprocessors to customers with a Data Processing Addendum in place.
We do not sell or rent personal data, and we do not "share" personal data for cross-context behavioral advertising.
7. International data transfers
We are based in Canada and our subprocessors may be located in Canada, the United States, the European Union, and the United Kingdom. Where we transfer personal data of EU/UK residents outside the EEA/UK to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organizational measures. You may request a copy of the relevant transfer mechanism by contacting hello@pictoflix.com.
8. Retention
We retain personal data only as long as necessary for the purposes set out in Section 4 and to meet legal obligations.
- Account data: for the life of the account, then deleted within 30 days of account closure.
- Customer Content uploads: for the life of the account, then deleted within 30 days of account closure or earlier deletion request.
- Generated Tours: for the life of the account (so you can re-download), then deleted within 30 days of account closure.
- Invoices and tax records: retained for the period required by applicable tax law (typically 6–7 years).
- Authentication, security, and impersonation logs: retained for up to 24 months for security and audit.
- AI usage and cost telemetry: retained for up to 36 months in aggregated or pseudonymized form for capacity planning and financial reporting.
- Backups: rolled-off on the standard backup schedule, typically within 35 days of deletion from primary stores.
Specific retention periods may be longer where required to establish, exercise, or defend legal claims.
9. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete personal data.
- Erase personal data ("right to be forgotten"), subject to legal retention obligations.
- Restrict or object to processing based on legitimate interests, including profiling.
- Portability — receive a copy of data you provided in a structured, commonly-used, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to solely automated decisions with legal or similarly significant effects.
- Lodge a complaint with a supervisory authority — for EU residents, your local Data Protection Authority; for UK residents, the ICO; for Quebec residents, the Commission d'accès à l'information du Québec.
To exercise any right, email hello@pictoflix.com. We will respond within 30 days (extendable by up to 60 days for complex requests, with notice). We may need to verify your identity before acting. You will not be discriminated against for exercising your rights.
10. Cookies and similar technologies
Pictoflix uses only strictly necessary cookies and equivalent browser local-storage entries. We do not run advertising cookies, cross-site tracking pixels, or third-party analytics or marketing trackers, so there is no cookie consent banner to accept or decline.
- Authentication and session integrity — keeps you signed in to the Studio and protects your account and requests. Stored by our authentication provider.
- Interface preferences — remembers small choices you make in the product, such as your billing currency selection and pending referral code.
These entries are essential to deliver the service you requested and therefore do not require consent under GDPR/UK GDPR, PIPEDA, or Quebec's Law 25. You can clear cookies and site data in your browser at any time; doing so will sign you out and reset your preferences.
If we ever introduce analytics or marketing cookies, we will update this policy and, where the law requires it, ask for your consent before setting them.
11. Security
We implement administrative, technical, and physical safeguards designed to protect personal data, including:
- TLS 1.2+ in transit and encryption at rest for primary stores;
- least-privilege access controls and role-based authorization;
- row-level security in our database for tenant isolation;
- secure software-development practices, dependency scanning, and code review;
- centralized logging, anomaly detection, and audit trails (including for admin impersonation);
- annual review of access, vendors, and policies;
- incident response procedures with regulator and customer notification timelines aligned to GDPR Article 33–34 (without undue delay and, where feasible, within 72 hours of awareness).
No system is perfectly secure. Please use a strong, unique password (or a passkey/SSO), enable any available second factor, and notify us immediately at hello@pictoflix.com if you suspect account compromise.
12. Children
The Service is not directed to children. We do not knowingly collect personal data from anyone under 16 (or under the higher minimum age set by local law). If you believe a child has provided personal data, contact hello@pictoflix.com and we will delete it.
13. Marketing communications
We send transactional emails that are necessary to provide the Service (e.g. receipts, render-complete notifications, security alerts) regardless of marketing preferences. We send product-update and promotional emails only on the legal basis permitted in your jurisdiction (legitimate interest with an unsubscribe link, or consent where required by law, e.g. Canada's Anti-Spam Legislation). You may opt out at any time using the link in the email or by emailing hello@pictoflix.com.
14. Automated decision-making and AI
We do not make solely automated decisions producing legal or similarly significant effects within the meaning of GDPR Article 22. AI is used to render media you have requested; the decision to publish or use any Generated Tour remains yours.
15. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted on this page with a new "Last updated" date and, where appropriate, communicated by email or in-product banner before they take effect. The version of the Policy you accepted at sign-up, together with the timestamp, is stored as part of your consent record.
16. Contact and complaints
If you have any privacy question, complaint, or rights request, please contact us first at hello@pictoflix.com. You also have the right to complain to a supervisory authority — including, depending on your location, the Commission d'accès à l'information du Québec, your EU national Data Protection Authority, or the UK Information Commissioner's Office (ICO).
This Privacy Policy is maintained by Pictoflix for the Pictoflix service. It is provided as a good-faith description of our practices and is not legal advice. The current list of subprocessors and a Data Processing Addendum are available on request from hello@pictoflix.com.