Privacy Policy
Last updated: August 16, 2026
1. Introduction
This Privacy Policy explains how Picalyze ("we", "us", "our") collects, uses, and protects your personal data when you use our AI-powered photo intelligence platform. We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection laws.
2. Data Controller
Picalyze
Jonas Rohde
Pending verification: complete the legal service address before relying on this notice.
[Street Address]
[Postal Code] [City]
Germany
Email: privacy@picalyze.com
3. Data We Collect and Process
We collect and process the following categories of personal data:
| Data Category | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Account Data Name, email, WorkOS identity reference, profile data | Account creation and authentication | Contract performance (Art. 6(1)(b)) | Account lifetime; deletion requests have a 30-day grace period |
| Photos Uploaded images | AI-powered photo analysis | Contract performance (Art. 6(1)(b)) | User-controlled deletion |
| EXIF Metadata Camera settings, GPS (if present) | Photo analysis and statistics | Contract performance (Art. 6(1)(b)) | Deleted with photos |
| Service and Audit Data Usage counters, security events, consent and audit records | Operate, secure, and audit the service | Contract performance, legal obligation, or legitimate interest depending on the event | Depends on the record; provider and statutory periods are pending verification |
| Payment Data Billing contact, subscription, invoice, and payment status via Stripe | Subscription billing | Contract performance (Art. 6(1)(b)) | Provider and statutory periods are pending verification |
4. How We Use Your Data
- Service Delivery: To provide AI-powered photo analysis, EXIF extraction, and photography insights
- Account Management: To create and manage your account, authenticate you, and process your requests
- Billing: To process payments and manage subscriptions through Stripe Managed Payments, where Stripe (Link) acts as merchant of record
- Communication: To send authentication, account-security, billing, and important service messages
- Optional imports: To retrieve only the account, catalog, and photo data requested when you connect an external photo source
5. Data Sharing and Recipients
The production service currently uses these core providers:
- Vercel: Application hosting and server execution. Data: Application requests, request metadata, and session traffic. Provider privacy notice
- Convex: Application database, file storage, and backend execution. Data: Account records, uploaded photos and metadata, analysis results, subscription state, consent, and audit records. Provider privacy notice
- WorkOS: Authentication, identity, sessions, and account security. Data: Identity and contact data, authentication and session data, and account-security settings. Provider privacy notice
- Stripe: Merchant of record for paid subscriptions (Stripe Managed Payments via Link), subscription commerce, and payment processing. Data: Billing contact data, payment information, subscription state, invoices, refunds, disputes, and billing-portal activity. Provider privacy notice
- OpenRouter: AI model routing for photo analysis. Data: Photo content, analysis prompts, request metadata, and generated analysis output. Provider privacy notice
- PostHog: Consent-gated product and performance analytics. Data: Opaque account identifier, allowlisted product events, coarse event properties, normalized page categories, and Web Vitals after analytics consent. Provider privacy notice
- Legal Requirements: Authorities when required by law
Optional user-connected services
- Google Photos: When connected, Picalyze receives the Google account profile, encrypted OAuth tokens, Picker selections, and selected photo files.
- Dropbox: When connected, Picalyze receives the Dropbox account profile, encrypted OAuth tokens, selected file metadata, and selected photo files.
- Adobe Lightroom: When connected, Picalyze receives the Adobe account profile, encrypted OAuth tokens, catalog metadata, and requested photo renditions.
- Immich: When connected, Picalyze contacts the server URL supplied by the user and stores the API credential encrypted. The server is selected and controlled by the user.
The public demo uses these additional services:
- Unsplash: Hosts the three static thumbnail URLs loaded by the public demo. A visitor's browser requests the images directly from Unsplash.
- Still: Analyzes those three static Unsplash thumbnails through the Still service hosted on Fly.io. This path does not receive Picalyze user uploads or account data.
6. International Data Transfers
Provider documentation describes available contractual and transfer mechanisms, but the mechanism that applies to Picalyze depends on the accepted agreement and configured processing region. Those account-specific facts cannot be proven from the application source code.
- Pending verification: Confirm that the applicable DPA or equivalent data-processing terms have been accepted for every core provider.
- Pending verification: Confirm the configured processing and storage regions for every core provider.
- Pending verification: Confirm the transfer mechanism that applies to each actual Picalyze account and data flow.
- Pending verification: Confirm provider and application retention settings, including OpenRouter routing, logging, and zero-data-retention controls.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access
Request a copy of your personal data (Art. 15)
Right to Rectification
Correct inaccurate or incomplete data (Art. 16)
Right to Erasure
Request deletion of your data (Art. 17)
Right to Restriction
Limit how we process your data (Art. 18)
Right to Portability
Receive your data in a portable format (Art. 20)
Right to Object
Object to processing based on legitimate interest (Art. 21)
To exercise your rights, please contact us at privacy@picalyze.com or use the data export and deletion features in your account settings.
8. Cookies and Tracking
WorkOS uses essential browser storage and cookies for authentication, security, and session management. If you enable analytics cookies, Picalyze uses PostHog for allowlisted product events, normalized page categories, and performance metrics. It may associate those events with an opaque account identifier; it does not send photo contents, filenames, EXIF data, analysis text, email, payment details, campaign parameters, or raw page URLs. You can withdraw analytics consent at any time through Manage Cookies.
9. Data Security
Application-level measures currently implemented include:
- HTTPS for browser and provider API traffic
- WorkOS-managed authentication and account security
- Encrypted OAuth tokens for connected photo sources
- Workspace-level authorization and access controls
- Signed WorkOS webhook verification
- No payment-card details stored by Picalyze
10. Automated Decision-Making
Our AI-powered photo analysis uses automated processing to generate insights about your photographs (composition, style, technical quality). This processing:
- Does not produce legal or similarly significant effects
- Is part of the service you explicitly request
- Can be reviewed and disputed by contacting our support team
11. Children's Privacy
Picalyze is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
12. Right to Lodge a Complaint
If you believe we have not handled your data properly, you have the right to lodge a complaint with a supervisory authority. In Germany, you can contact your state data protection authority (Landesdatenschutzbeauftragter) or the Federal Commissioner for Data Protection (BfDI).
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. The "Last updated" date at the top indicates when this policy was last revised.
14. Contact Us
For any questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@picalyze.com
Or visit our Impressum for full contact details.