Privacy Policy
Last updated: May 12, 2026
This Privacy Policy describes how PicDash ("we," "us," "our") collects, uses, and protects your information when you use our service.
If you have questions, contact us at hello@picdash.co.
1. What information we collect
Account information. When you sign up, we collect your email address and name.
Payment information. Subscription payments are processed by a third-party payment provider. We never see or store your full credit card number; only billing metadata necessary to manage your subscription.
Content you upload. Images you upload to generate creative are stored in secure cloud storage. We retain them as long as your account is active so you can re-use them in future generations.
Generated images. Images you generate using PicDash are stored in secure cloud storage and remain available in your account.
Usage data. We track aggregate usage of features (how many photos you generate, which scenes you use) to improve the product and enforce subscription limits. We do not sell this data.
Analytics. We use privacy-respecting analytics on our public website to understand visitor behavior. You can opt out using a tracker blocker.
2. How we use your information
We use your information to:
- Provide the service (process generations, store your photos, manage your subscription)
- Process payments and billing
- Communicate about your account (transactional emails)
- Improve the product (aggregate analytics, not individual tracking)
- Comply with legal obligations
We do not:
- Sell your data to third parties
- Use your uploaded photos to train AI models (see below)
- Share your generated images with anyone other than you
3. AI model training
Photos you upload and images you generate are not used to train any AI models. We pass your photos to our AI inference provider only to generate your requested output, and they are deleted from the inference provider's infrastructure after processing. We do not retain training rights to your images.
4. Third-party services
To provide PicDash, we use a small number of trusted third-party service providers, including:
- An authentication and database provider
- A payment processor
- A cloud storage provider
- An AI inference provider
- A hosting provider
- An analytics provider
Each of these providers has been selected for their commitment to data protection and is bound by their own privacy policies, which are GDPR-compliant or operate under equivalent safeguards. You may request the current list of providers at any time by emailing hello@picdash.co.
5. Your rights (GDPR and similar laws)
If you are in the EU, UK, California, or other regions with similar laws, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Export your data in a portable format
- Object to certain processing
- Withdraw consent for optional processing (like analytics)
To exercise any of these rights, email hello@picdash.co. We will respond within 30 days.
6. Data retention
- Active accounts: We retain your data as long as your account is active.
- Cancelled subscriptions: Your account remains accessible for 30 days after cancellation. You can export your generated images during this period.
- Deleted accounts: Within 30 days of deletion, your account data is permanently removed from our active systems. Backup copies may persist for up to 90 days before being purged.
- Billing records: Retained for as long as required by applicable tax and accounting laws.
7. Cookies
We use cookies to:
- Keep you logged in (essential — cannot be disabled)
- Remember your preferences (essential)
- Measure aggregate analytics (optional — can be disabled)
We do not use advertising or tracking cookies.
8. Children
PicDash is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has signed up, contact us at hello@picdash.co and we will delete the account.
9. International data transfers
Your data may be processed in jurisdictions outside of your country of residence depending on the third-party providers we use. We rely on standard contractual clauses and similar safeguards where required by applicable law.
10. Security
We follow industry-standard practices to protect your data:
- All connections use HTTPS
- Passwords are hashed (we never see your password)
- Database access is restricted and logged
- Sensitive payment data is handled exclusively by our payment processor
No system is 100% secure. In the event of a data breach affecting your personal information, we will notify affected users within the timeframes required by applicable law.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or via the app. Continued use of the service constitutes acceptance of the updated policy.
12. Contact
Questions about this policy or your data?
We're in public beta. 