Privacy Policy
Last updated: May 1, 2026
This Privacy Policy describes how Piko Apps LLC, doing business as Piko Club ("Piko Club", "we", "us"), collects, uses, shares, and protects personal information when you use piko.cluband the related services (the "Service"). It is intended to be read alongside our Terms of Service.
1. About this policy
We care about your privacy and we try to do the obvious right things: collect only what we need to run the Service, store it securely, never sell it, and never use your creative work or your prompts to train our own AI models. This document spells out the details so there are no surprises.
2. Scope
This Policy applies to information we collect when you visit our website, create an account, sign in, upload Content, run a generation, collaborate with teammates, contact support, or otherwise interact with the Service. It does not apply to third-party websites, services, or AI providers that you connect to or that we link from the Service — those are governed by their own privacy policies.
3. Information we collect
Information you provide
- Account details — name, email address, profile picture (when you set one), and authentication identifiers (such as a Google account ID if you sign in with Google).
- Subscription & billing — plan tier, billing cycle, billing address and tax identifiers as required, and a payment-method token returned by Stripe. We do not store full card numbers or CVV codes; Stripe handles card data directly.
- Content — projects, canvases, files (images, video, audio), prompts, references, comments, node metadata, exports, and any third-party API keys you choose to store with us. API keys are stored encrypted at rest.
- Collaborator data — emails of people you invite to a project, the role you assigned them, and acceptance status.
- Support messages — anything you send us via the in-app feedback form, support email, or chat (including any attachments and the canvas/project IDs we automatically include for context).
Information collected automatically
- Device & technical data — IP address, approximate location derived from IP, browser type and version, operating system, screen size, time zone, and language.
- Usage data — feature interactions, navigation paths, generation events, error logs, performance metrics, and aggregated counts (for example, how many generations of a given model type you ran).
- Cookies and similar technologies — session cookies for authentication and preference cookies for in-app state. See Section 11.
- Real-time presence — when you are on a shared canvas, transient signals such as cursor position, selection, and node-level edits are processed via Liveblocks so other collaborators see your activity in real time. These signals are ephemeral and are not stored beyond what is needed to power presence and to undo recent changes.
Information from third parties
When you sign in with a third-party provider (such as Google) we receive your email address and basic profile information from that provider per the consent you gave there. When you connect a BYOK provider account, the provider may report usage data back to us in response to our generation requests; that data is operational metadata, not your provider account credentials.
4. How we use information
We use the information described above to:
- operate the Service: create your Account, authenticate you, store your Content, run generations, sync collaboration, deliver downloads, and similar core functions;
- route generation requests to the third-party AI providers needed to fulfill them, on your instruction;
- handle billing: charge subscriptions and top-ups, issue receipts, manage trials, prevent fraud;
- communicate with you: account notifications (email verification, billing receipts, security alerts), product updates we believe you actively need to know about, and responses to your support requests;
- secure the Service: detect and respond to abuse, suspected fraud, ToS violations, and security incidents;
- improve the Service: analyze aggregate, de-identified usage to fix bugs, prioritize features, and optimize performance;
- comply with our legal obligations and enforce our agreements.
We do not use your Content (including prompts and Output) to train our own AI models or third parties' foundation models. Generation requests are routed to the provider you select for that node, only for the purpose of producing the Output you requested.
5. Legal bases (for users in the EEA, UK, and Switzerland)
Where data-protection law in your jurisdiction requires us to identify a legal basis for processing your personal information, we rely on the following:
- Contract — processing necessary to provide the Service to you under our Terms (e.g., creating your Account, running generations, billing).
- Legitimate interests — securing the Service, preventing abuse, improving features, and operating our business, where these interests are not overridden by your rights.
- Consent — where required, for non-essential analytics or for optional communications you can opt in or out of.
- Legal obligation — keeping invoices and complying with tax, accounting, and law-enforcement requests.
7. International transfers
Piko Apps LLC is incorporated in Delaware, USA, and our infrastructure and subprocessors are located in multiple countries including the United States and the European Union. When we transfer personal information across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, equivalent UK and Swiss addenda, and the additional measures required by applicable law.
8. Retention
We keep personal information only for as long as needed for the purposes described above:
- Account data — for as long as your Account is active.
- Content — until you delete it or close your Account. Deleted Content is moved to a soft-deleted state for up to 30 days for recovery, then purged from active storage. Encrypted backups may persist for a bounded additional period for disaster recovery.
- Billing records — for the period required by tax and accounting law (typically 5–10 years depending on jurisdiction).
- Support tickets — for as long as needed to resolve and follow up on your request, and for a reasonable period thereafter for quality and audit purposes.
- Aggregated, de-identified usage data — may be retained indefinitely.
9. Security
We use industry-standard measures to protect your information. These include encryption in transit (TLS), encryption at rest for media files and stored API keys, scoped access controls, audit logging, regular dependency updates, and careful review of subprocessors. No system can be guaranteed 100% secure, however, and we cannot eliminate every risk. If we become aware of a security incident that materially affects your information, we will notify you and the relevant authorities as required by law.
You can help by using a strong, unique password for the email address tied to your Piko Club Account, enabling two-factor authentication on that email and on your SSO provider, and keeping your devices and browsers updated.
10. Your rights & choices
Subject to applicable law, you have the right to:
- access the personal information we hold about you and request a copy;
- correct inaccurate or incomplete information;
- delete your information (we will honor this except where we must retain it to comply with law, resolve disputes, or enforce our agreements);
- restrict or object to certain processing, including direct marketing;
- port your information to another service in a structured, commonly used, machine-readable format;
- withdraw consent at any time, where processing is based on consent;
- lodge a complaint with your local data-protection authority.
You can exercise most of these rights directly from your Account settings — including downloading your data, removing API keys, and deleting your Account. For anything settings does not cover, email [email protected] from the address on your Account and we will respond within the time frame required by applicable law (and usually faster).
12. Children
The Service is not directed to and should not be used by anyone under 18 (or the higher minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, contact [email protected] and we will promptly delete it.
13. Third-party links & sites
The Service may include links to third-party websites, models, or services that we do not operate. We are not responsible for the content, privacy practices, or security of those third parties. Please review their policies before providing them with information.
14. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. If a change is material, we will give you advance notice by email or in-app message at least 15 days before it takes effect. Your continued use of the Service after that date means you accept the updated Policy.
15. Contact
For privacy questions, requests to exercise your rights, or any other concerns, please email us at [email protected]. We will respond within the timeframes required by applicable law.