Skip to content

Privacy Policy

Last updated: August 16, 2026

1. Introduction

This Privacy Policy explains how Picalyze ("we", "us", "our") collects, uses, and protects your personal data when you use our AI-powered photo intelligence platform. We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection laws.

2. Data Controller

Picalyze

Jonas Rohde

Pending verification: complete the legal service address before relying on this notice.

[Street Address]

[Postal Code] [City]

Germany

Email: privacy@picalyze.com

3. Data We Collect and Process

We collect and process the following categories of personal data:

Data CategoryPurposeLegal BasisRetention
Account Data
Name, email, WorkOS identity reference, profile data
Account creation and authenticationContract performance (Art. 6(1)(b))Account lifetime; deletion requests have a 30-day grace period
Photos
Uploaded images
AI-powered photo analysisContract performance (Art. 6(1)(b))User-controlled deletion
EXIF Metadata
Camera settings, GPS (if present)
Photo analysis and statisticsContract performance (Art. 6(1)(b))Deleted with photos
Service and Audit Data
Usage counters, security events, consent and audit records
Operate, secure, and audit the serviceContract performance, legal obligation, or legitimate interest depending on the eventDepends on the record; provider and statutory periods are pending verification
Payment Data
Billing contact, subscription, invoice, and payment status via Stripe
Subscription billingContract performance (Art. 6(1)(b))Provider and statutory periods are pending verification

4. How We Use Your Data

  • Service Delivery: To provide AI-powered photo analysis, EXIF extraction, and photography insights
  • Account Management: To create and manage your account, authenticate you, and process your requests
  • Billing: To process payments and manage subscriptions through Stripe Managed Payments, where Stripe (Link) acts as merchant of record
  • Communication: To send authentication, account-security, billing, and important service messages
  • Optional imports: To retrieve only the account, catalog, and photo data requested when you connect an external photo source

5. Data Sharing and Recipients

The production service currently uses these core providers:

  • Vercel: Application hosting and server execution. Data: Application requests, request metadata, and session traffic. Provider privacy notice
  • Convex: Application database, file storage, and backend execution. Data: Account records, uploaded photos and metadata, analysis results, subscription state, consent, and audit records. Provider privacy notice
  • WorkOS: Authentication, identity, sessions, and account security. Data: Identity and contact data, authentication and session data, and account-security settings. Provider privacy notice
  • Stripe: Merchant of record for paid subscriptions (Stripe Managed Payments via Link), subscription commerce, and payment processing. Data: Billing contact data, payment information, subscription state, invoices, refunds, disputes, and billing-portal activity. Provider privacy notice
  • OpenRouter: AI model routing for photo analysis. Data: Photo content, analysis prompts, request metadata, and generated analysis output. Provider privacy notice
  • PostHog: Consent-gated product and performance analytics. Data: Opaque account identifier, allowlisted product events, coarse event properties, normalized page categories, and Web Vitals after analytics consent. Provider privacy notice
  • Legal Requirements: Authorities when required by law

Optional user-connected services

  • Google Photos: When connected, Picalyze receives the Google account profile, encrypted OAuth tokens, Picker selections, and selected photo files.
  • Dropbox: When connected, Picalyze receives the Dropbox account profile, encrypted OAuth tokens, selected file metadata, and selected photo files.
  • Adobe Lightroom: When connected, Picalyze receives the Adobe account profile, encrypted OAuth tokens, catalog metadata, and requested photo renditions.
  • Immich: When connected, Picalyze contacts the server URL supplied by the user and stores the API credential encrypted. The server is selected and controlled by the user.

The public demo uses these additional services:

  • Unsplash: Hosts the three static thumbnail URLs loaded by the public demo. A visitor's browser requests the images directly from Unsplash.
  • Still: Analyzes those three static Unsplash thumbnails through the Still service hosted on Fly.io. This path does not receive Picalyze user uploads or account data.

6. International Data Transfers

Provider documentation describes available contractual and transfer mechanisms, but the mechanism that applies to Picalyze depends on the accepted agreement and configured processing region. Those account-specific facts cannot be proven from the application source code.

  • Pending verification: Confirm that the applicable DPA or equivalent data-processing terms have been accepted for every core provider.
  • Pending verification: Confirm the configured processing and storage regions for every core provider.
  • Pending verification: Confirm the transfer mechanism that applies to each actual Picalyze account and data flow.
  • Pending verification: Confirm provider and application retention settings, including OpenRouter routing, logging, and zero-data-retention controls.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right of Access

Request a copy of your personal data (Art. 15)

Right to Rectification

Correct inaccurate or incomplete data (Art. 16)

Right to Erasure

Request deletion of your data (Art. 17)

Right to Restriction

Limit how we process your data (Art. 18)

Right to Portability

Receive your data in a portable format (Art. 20)

Right to Object

Object to processing based on legitimate interest (Art. 21)

To exercise your rights, please contact us at privacy@picalyze.com or use the data export and deletion features in your account settings.

8. Cookies and Tracking

WorkOS uses essential browser storage and cookies for authentication, security, and session management. If you enable analytics cookies, Picalyze uses PostHog for allowlisted product events, normalized page categories, and performance metrics. It may associate those events with an opaque account identifier; it does not send photo contents, filenames, EXIF data, analysis text, email, payment details, campaign parameters, or raw page URLs. You can withdraw analytics consent at any time through Manage Cookies.

9. Data Security

Application-level measures currently implemented include:

  • HTTPS for browser and provider API traffic
  • WorkOS-managed authentication and account security
  • Encrypted OAuth tokens for connected photo sources
  • Workspace-level authorization and access controls
  • Signed WorkOS webhook verification
  • No payment-card details stored by Picalyze

10. Automated Decision-Making

Our AI-powered photo analysis uses automated processing to generate insights about your photographs (composition, style, technical quality). This processing:

  • Does not produce legal or similarly significant effects
  • Is part of the service you explicitly request
  • Can be reviewed and disputed by contacting our support team

11. Children's Privacy

Picalyze is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

12. Right to Lodge a Complaint

If you believe we have not handled your data properly, you have the right to lodge a complaint with a supervisory authority. In Germany, you can contact your state data protection authority (Landesdatenschutzbeauftragter) or the Federal Commissioner for Data Protection (BfDI).

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. The "Last updated" date at the top indicates when this policy was last revised.

14. Contact Us

For any questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@picalyze.com

Or visit our Impressum for full contact details.