Legal
Privacy Policy
Last updated September 19, 2026
This Privacy Policy explains what personal data PIXVIX collects when you use pixvix.app and related services, how we use it, and the choices you have. We wrote it to match how the product actually works today — not a generic template.
Who we are
PIXVIX is a web product for creating and stitching counted cross-stitch charts (and related studio tools) at pixvix.app. Our API runs at api.pixvix.app.
When this policy says “we,” “us,” or “PIXVIX,” it means the operators of the PIXVIX service. We do not list a separate legal entity name in the product beyond the PIXVIX brand.
What data we collect
We collect only what is needed to run the product: your account, the charts and files you create, payments and credits, support messages, and technical data needed to keep the service secure and working.
- Account details (email, name, optional profile photo)
- Authentication and session data
- Pattern, project, and workspace data you create
- Uploaded images and generated PDF assets
- Payment and credit records
- Support and feedback messages
- AI prompts and related usage records when you use AI features
- Server logs and security events
- For PIXVIX administrators only: YouTube channel connection and publishing data used in Social Studio
Account information and authentication
You can create an account with email and password, or sign in with Google.
For email registration we store your email address, the name you provide, and a hashed password (we do not store your password in plain text).
We keep signed-in sessions so you stay logged in. Session records may include device/browser information and IP address for security.
If your account is marked deleted by an administrator, you will not be able to sign in. End users do not currently have a fully automated self-serve account deletion button in the product; contact us if you need help (see Contact).
Google Sign-In (Google OAuth for login)
If you choose “Sign in with Google,” PIXVIX uses Google OAuth with the scopes openid, email, and profile.
From Google we receive an ID token and use it to read your Google user id, email address, name, and profile picture URL. We store those on your PIXVIX account so we can sign you in and show your profile.
Google Sign-In for PIXVIX accounts uses online access. We do not store Google refresh tokens for ordinary member login.
You can disconnect Google access from your Google Account permissions settings. That does not automatically delete your PIXVIX account.
YouTube API and Google user data (administrators)
PIXVIX’s Social Studio can connect an official YouTube channel so PIXVIX staff can publish brand videos. This YouTube connection is separate from Google Sign-In for member accounts. It is available only inside the PIXVIX Admin panel to authorized administrators — not as a feature for every member account.
When an administrator connects YouTube, PIXVIX requests Google OAuth access for YouTube upload and related YouTube Data API access (including youtube.upload and youtube.force-ssl scopes).
Through the YouTube Data API we may access and store: channel id and channel title (and related channel metadata returned by the API), video upload results (such as video id and URL), and metadata the admin provides for publishing (title, description, tags, privacy, thumbnail).
We use this Google / YouTube user data only to operate Social Studio for PIXVIX: authenticate the connected channel, upload and update videos on behalf of that channel, and keep a record of publish jobs and outcomes.
We do not sell Google user data. We do not use YouTube / Google user data for advertising. We do not use it to train AI models. We do not transfer it to third parties except as needed to provide the service through Google’s APIs and our infrastructure processors listed below.
Administrators can disconnect YouTube in Social Studio. Disconnecting stops new publishing with that connection; historical publish records may remain in Admin activity logs.
OAuth tokens and secrets
OAuth access tokens and refresh tokens used for YouTube (and other integration secrets such as API keys or seller tokens where those features are enabled) are stored encrypted at rest using PIXVIX’s server-side encryption (AES-GCM). They are not returned to the browser after storage.
YouTube application credentials (client id / client secret) configured in Admin are also stored with the client secret encrypted. The secret is never shown again in the Admin UI after save.
We do not put OAuth client secrets or refresh tokens into front-end code or public URLs.
Media, charts, and files
When you create charts, PIXVIX stores source images, previews, thumbnails, pattern data, and PDF exports associated with your account or projects. Files are stored in private or public object storage operated for PIXVIX (currently via storage backends such as Supabase Storage, and optionally other configured drivers).
Some files are temporary (for example temporary PDFs or Social Studio publishing caches). Temporary social publishing media is kept only as long as needed to finish a publish job or until it expires, then cleaned up. Publishing does not automatically turn a local file into a permanent media library item.
Retention settings can automatically remove older originals, trash items, and temporary PDFs after configured periods. Some seller/export assets may be retained longer when the product marks them as permanent.
AI features
PIXVIX offers optional AI features (for example assistants, naming help, or vision-related pattern intelligence) that send the text or images you submit for that feature to an AI provider configured by PIXVIX (commonly OpenAI or an OpenAI-compatible endpoint configured in Admin).
We may store conversation messages and usage/cost records so the feature works and so we can operate limits and billing for AI usage.
AI suggestions in tools such as Social Studio are shown for an administrator to review; they are not published automatically.
Do not submit sensitive personal data in AI prompts that you do not want processed by the AI provider.
Payments and credits
If you buy credits or plans, payment is processed by our payment provider (Creem by default; Suby may be configured as an alternative). PIXVIX stores purchase records such as product, amount, currency, status, and provider order identifiers, and updates your credit balances.
Card details are handled by the payment provider — PIXVIX does not store full card numbers.
Email and support
We send transactional email (for example verification, password reset, billing notices) through Resend. Marketing email, when enabled, also uses Resend and respects unsubscribe where applicable.
Human support conversations may use our operational mailbox (Maileroo) with addresses such as support@pixvix.app. Feedback you send in the product is stored so we can respond.
Product contact defaults include hello@pixvix.app and support@pixvix.app.
Logs, security, and operational data
Our servers and Admin tools keep operational logs and audit records (for example admin actions, failed sign-ins, or system health). These help us secure the service, debug issues, and meet operational needs.
We aim not to write OAuth secrets, passwords, or raw payment card data into logs.
Analytics
PIXVIX does not currently embed third-party consumer analytics scripts (such as Google Analytics, Meta Pixel, or similar) in the public web app.
We do use first-party product events and Admin analytics that live in our own database to understand product usage and operate the business.
Third-party services we actually use
Depending on configuration, PIXVIX relies on processors to run the product:
- Google — Sign-In (members) and YouTube Data API (Admin Social Studio)
- Supabase — database and/or file storage (when configured)
- Resend — transactional and marketing email
- Maileroo — human support mailbox
- Creem and/or Suby — payments
- OpenAI or other Admin-configured AI providers — AI features
- Etsy API — when a seller connects an Etsy shop for listing features
- Infrastructure hosting for the PIXVIX web and API services
How long we keep data
Account and project data are kept while your account is active and as needed to provide the service.
File retention policies can remove older originals, trash, and temporary PDFs after set periods. Temporary Social Studio publish media is cleaned after successful publishing, final failure, cancel, or expiry.
Purchase and credit ledger records are kept for accounting and support.
When an administrator soft-deletes an account, sign-in is blocked; residual records may remain until manually cleaned under our operational processes.
Your rights and choices
Depending on where you live, you may have rights to access, correct, or delete personal data, or to object to certain processing. PIXVIX does not currently offer a complete self-serve data-export or delete button for every data type.
You can update profile details in the product where those screens exist, manage marketing email unsubscribe links when present, disconnect Google or YouTube access from the relevant Google / Admin controls, and contact us to request help with access or deletion.
We will respond to reasonable requests sent to the contact addresses below.
Children
PIXVIX is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will take appropriate steps.
International processing
PIXVIX is operated using cloud infrastructure that may process data in more than one country (for example database or storage regions configured for the project). By using the service you understand your data may be processed outside your home country with appropriate safeguards used by our providers.
Changes to this policy
We may update this Privacy Policy when the product or our practices change. We will update the “Last updated” date on this page. For significant changes we may also provide an in-product or email notice when appropriate.
Contact
Questions about privacy or Google / YouTube user data: hello@pixvix.app or support@pixvix.app.
Website: https://pixvix.app