PixelBake.Back to PixelBake

Privacy

Privacy Policy

This policy describes the information PixelBake handles when you visit the site, create an account, upload media, convert files, or use storage and backup features.

Effective
August 5, 2026
Operator
PixelBake

1. Scope and operator

PixelBake operates pixelbake.io and is the controller or business responsible for the personal information described in this policy. This policy applies to the PixelBake website, accounts, media workspace, conversions, storage, Trash, and backup features. Contact PixelBake at privacy@pixelbake.io.

2. Information PixelBake collects

  • Account data: name, email address, email-verification status, password hash, theme and backup preferences, account identifiers, and session records.
  • Media and output data: uploaded image, video, and audio files; filenames; MIME type; size; dimensions; duration; frame rate; conversion settings; generated device files; previews; backup state; and deletion or retention timestamps.
  • Plan and usage data: plan entitlement, quotas, reserved and used storage, active jobs, conversion history, Trash status, and backup requests.
  • Technical data: IP address and request information ordinarily contained in server and security logs, browser or device information sent in HTTP requests, rate-limit events, timestamps, and diagnostic errors.
  • Communications: email-delivery information for verification and password reset messages, plus information you include in support or privacy requests.

PixelBake receives most information directly from you and automatically from your browser when you use the service. Media may itself contain personal information about you or other people; only upload it when you have authority to do so.

3. How information is used

PixelBake uses personal information to:

  • create, verify, secure, and support accounts and sessions;
  • receive, inspect, convert, preview, store, back up, restore, and delete media;
  • enforce quotas, retention periods, rate limits, and acceptable-use rules;
  • send transactional account and security email;
  • operate, troubleshoot, protect, and improve reliability of the service;
  • prevent fraud, abuse, security incidents, and unlawful activity; and
  • comply with law and establish, exercise, or defend legal claims.

Where the GDPR or similar law applies, PixelBake relies on performance of its contract with you, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is required.

4. Cookies and similar storage

PixelBake uses essential, secure cookies for authentication, session continuity, and security. These cookies are necessary for signed-in features. PixelBake does not currently use advertising cookies, cross-site behavioral advertising, or a third-party analytics service. Browser controls can block cookies, but signed-in features may stop working.

5. Service providers and disclosures

PixelBake uses service providers to operate specific parts of the service:

  • IONOS provides virtual-server infrastructure.
  • Resend delivers verification and password-reset email.
  • Backblaze B2 stores off-server copies when an eligible user requests backup or enables automatic backup.

Providers receive only the information reasonably needed for their function and process it under their own security and contractual commitments. PixelBake may also disclose information when required by law, to protect rights or safety, in connection with a business transfer, or with your direction or consent.

PixelBake does not sell personal information and does not share personal information for cross-context behavioral advertising. PixelBake does not use uploaded media to train advertising or generative-AI models.

6. Retention and deletion

  • Authentication sessions normally expire after seven days.
  • Email-verification links expire after one hour; password-reset links expire after 30 minutes.
  • Free-plan source files normally expire after 24 hours and conversion outputs after seven days.
  • Paid-plan working files may remain until you delete them or the plan changes.
  • Paid-plan Trash is retained for the period displayed in the account, currently 30 or 90 days.
  • Off-server copies remain until backup is removed, the related file is purged, or the service's retention process removes them. Storage-provider hidden versions may take approximately one additional day to purge.

Account records, security logs, and limited operational records are retained while reasonably needed to provide and secure the service, resolve disputes, meet legal obligations, and enforce agreements. Deletion may be delayed where a lawful exception or backup rotation applies. PixelBake de-identifies or deletes information when it is no longer needed for those purposes.

7. Security

PixelBake uses TLS in transit, secure authentication cookies, hashed passwords, private account-scoped media access, service isolation, least-privilege storage credentials, and encrypted off-server backup storage. No system is perfectly secure, and PixelBake cannot guarantee that unauthorized access, loss, or disclosure will never occur.

8. International processing

PixelBake and its providers may process information in the United States and other countries where providers operate. Those locations may have different privacy laws from your home country. Where required, PixelBake will use an appropriate legal mechanism for international transfers.

9. Your choices and privacy rights

You can review account information and delete working media in the service. You may also request access, correction, deletion, portability, restriction, or an objection to processing when applicable law provides those rights. Send requests to privacy@pixelbake.io. PixelBake may verify your identity before completing a request and may retain information when a legal exception applies.

California residents may have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service. PixelBake does not sell or share personal information for behavioral advertising, so there is no sale or advertising-sharing opt-out to process at this time. Where legally required, PixelBake treats recognized opt-out preference signals consistently with these practices.

Residents of the EEA, United Kingdom, or Switzerland may complain to their local data-protection authority. You may withdraw consent where processing is based on consent without affecting earlier lawful processing.

10. Children

PixelBake is not directed to children under 13 and does not knowingly collect personal information from them. If you believe a child under 13 has provided information, contact PixelBake so it can be investigated and deleted as required.

11. Changes to this policy

PixelBake may update this policy when data practices, providers, features, or law change. The effective date will be revised, and material changes may receive additional notice through the service or by email.

12. Contact

Privacy questions and rights requests may be sent to privacy@pixelbake.io. The related service rules are in the Terms of Use.