Effective and last updated: September 15, 2026
This policy applies to the Pixel Studio image editor at
pixels.mrhalk.com and its related account,
cloud sync, sharing, and AI features.
1. Information we process
-
Local editing data: When you are signed out, projects, sessions,
autosaves, preferences, and PWA caches are mainly stored in your browser. Pixel Studio
does not automatically upload local images unless you choose an online feature
described below.
-
Account data: When you sign in with Google, Google and Supabase Auth
provide basic identity data such as an identifier, email address, display name, and
avatar. Pixel Studio requests only the openid, email, and profile scopes needed for
sign-in, and does not request Google Drive or Google Photos access.
-
Cloud projects: When you choose to save or sync to the cloud, we
process the project name, complete editable project file, thumbnail, size, revision,
digest, and sync status. Project content is kept in private object storage.
-
AI and shared content: Images, masks, and prompts needed for an
operation are transmitted only when you use an online AI tool. When you create a
public share link, anyone who has that link may be able to access the shared content.
-
Technical and usage data: To operate the service, prevent abuse, and
control costs, we may record request times, action or model names, status, estimated
cost, IP address, error details, and administrative audit events. Personal API tokens
are stored only as irreversible hashes with metadata; the original token cannot be
displayed again.
2. Specific use of Google Account data
Pixel Studio uses Google Sign-In only for identity authentication and does not use your
Google Account to read files in Google Drive or other Google services. The sign-in flow
may provide a stable Google subject ID, email address, display name, and profile image
URL. We use this information to create or find your Pixel Studio account, show account
details, attach cloud projects and personal API tokens to the correct account, and
perform account security and administrative actions.
Supabase Auth retains the identity record, while necessary account snapshots and status
are stored by the Pixel Studio Cloudflare Worker in access-controlled database storage.
Pixel Studio does not sell Google user data, use it for targeted advertising, use it to
train AI models, or send it to an AI provider. Signing in alone does not upload your
images; images are uploaded only when you choose a cloud, sharing, or AI feature.
Identity data is retained while the account is active. If you request account and
related data deletion, we process it subject to reasonable verification, provider
constraints, and legally required retention. You can revoke access in your Google
Account's third-party connections and use the support contact shown on the Google OAuth
screen to request deletion.
3. How we use information
We use this information to authenticate accounts, sync and restore projects, provide AI
and sharing features, enforce quotas and rate limits, protect the service, investigate
errors, and maintain administrative and audit records. We do not sell personal
information or use your images for targeted advertising.
4. Service providers
Pixel Studio uses Google for sign-in, Supabase for authentication, and Cloudflare for
website hosting, Workers, databases, caching, and object storage. When you choose an AI
feature, required content may be processed by Replicate or the model or service provider
identified by that feature. Each provider processes data under its own policies and our
service configuration.
5. Retention and security
Local data remains until you clear browser data or use an in-app clearing control. Cloud
projects are generally retained until you delete them; deleted versions may remain for a
short grace period to support recovery and safe cleanup. Temporary uploads and AI
objects are removed by scheduled cleanup. Security, cost, and audit records may be
retained for longer where necessary. We use encrypted transport, private storage,
short-lived signed URLs, and access controls, but no online service can guarantee
absolute security.
6. Your choices and controls
You may remain signed out and edit locally. You may also delete cloud projects, revoke
personal tokens, sign out, and clear account data stored on your device. You can revoke
Pixel Studio's sign-in access in your Google Account settings. For account or privacy
requests, use the support contact shown on the Google OAuth screen. This policy remains
publicly available even if you cannot sign in.
7. International processing and children
Service providers may process information outside your location. Pixel Studio is not
directed specifically to children below the age of digital consent in their location. A
guardian who believes a child provided information improperly should use the support
contact to request deletion.
8. Changes to this policy
We may update this policy as features or legal requirements change. We will change the
“last updated” date on this page and, where reasonable, provide an in-app notice for
material changes.
9. Contact and deletion requests
For privacy questions, sign-in revocation, or a request to delete your account and
related data, email haley@mrhalk.com. This contact
remains available even if you cannot sign in.