Privacy Policy

Last updated: May 1, 2026

This Privacy Policy describes how Piko Apps LLC, doing business as Piko Club ("Piko Club", "we", "us"), collects, uses, shares, and protects personal information when you use piko.cluband the related services (the "Service"). It is intended to be read alongside our Terms of Service.

1. About this policy

We care about your privacy and we try to do the obvious right things: collect only what we need to run the Service, store it securely, never sell it, and never use your creative work or your prompts to train our own AI models. This document spells out the details so there are no surprises.

2. Scope

This Policy applies to information we collect when you visit our website, create an account, sign in, upload Content, run a generation, collaborate with teammates, contact support, or otherwise interact with the Service. It does not apply to third-party websites, services, or AI providers that you connect to or that we link from the Service — those are governed by their own privacy policies.

3. Information we collect

Information you provide

  • Account details — name, email address, profile picture (when you set one), and authentication identifiers (such as a Google account ID if you sign in with Google).
  • Subscription & billing — plan tier, billing cycle, billing address and tax identifiers as required, and a payment-method token returned by Stripe. We do not store full card numbers or CVV codes; Stripe handles card data directly.
  • Content — projects, canvases, files (images, video, audio), prompts, references, comments, node metadata, exports, and any third-party API keys you choose to store with us. API keys are stored encrypted at rest.
  • Collaborator data — emails of people you invite to a project, the role you assigned them, and acceptance status.
  • Support messages — anything you send us via the in-app feedback form, support email, or chat (including any attachments and the canvas/project IDs we automatically include for context).

Information collected automatically

  • Device & technical data — IP address, approximate location derived from IP, browser type and version, operating system, screen size, time zone, and language.
  • Usage data — feature interactions, navigation paths, generation events, error logs, performance metrics, and aggregated counts (for example, how many generations of a given model type you ran).
  • Cookies and similar technologies — session cookies for authentication and preference cookies for in-app state. See Section 11.
  • Real-time presence — when you are on a shared canvas, transient signals such as cursor position, selection, and node-level edits are processed via Liveblocks so other collaborators see your activity in real time. These signals are ephemeral and are not stored beyond what is needed to power presence and to undo recent changes.

Information from third parties

When you sign in with a third-party provider (such as Google) we receive your email address and basic profile information from that provider per the consent you gave there. When you connect a BYOK provider account, the provider may report usage data back to us in response to our generation requests; that data is operational metadata, not your provider account credentials.

4. How we use information

We use the information described above to:

  • operate the Service: create your Account, authenticate you, store your Content, run generations, sync collaboration, deliver downloads, and similar core functions;
  • route generation requests to the third-party AI providers needed to fulfill them, on your instruction;
  • handle billing: charge subscriptions and top-ups, issue receipts, manage trials, prevent fraud;
  • communicate with you: account notifications (email verification, billing receipts, security alerts), product updates we believe you actively need to know about, and responses to your support requests;
  • secure the Service: detect and respond to abuse, suspected fraud, ToS violations, and security incidents;
  • improve the Service: analyze aggregate, de-identified usage to fix bugs, prioritize features, and optimize performance;
  • comply with our legal obligations and enforce our agreements.

We do not use your Content (including prompts and Output) to train our own AI models or third parties' foundation models. Generation requests are routed to the provider you select for that node, only for the purpose of producing the Output you requested.

6. Sharing & subprocessors

We do not sell your personal information. We share it only with the categories of recipients below, in each case under contracts that require them to protect your data and use it only as we instruct.

Subprocessors and infrastructure

  • Cloud hosting & databases — providers such as Vercel/Railway and our managed Postgres provider, used to run the Service and store account and project metadata.
  • Object storage & CDN — Cloudflare R2 and Cloudflare CDN, used to store and deliver your media files.
  • Real-time collaboration — Liveblocks, used for cursors, presence, and live canvas state.
  • Payments — Stripe, used to process subscription and top-up payments.
  • Email — Resend, used for transactional email (verification codes, billing receipts, support replies).
  • Analytics & error monitoring — privacy-respecting analytics and error-tracking tools used to understand aggregate usage and diagnose issues.

AI providers

When you trigger a generation, the relevant Input is routed to the AI provider you selected for that node (for example Google AI Studio, Kling AI, OpenAI, Reve AI, Topaz Labs, Seedance, or Sync.so). Those providers process your Input under their own terms and privacy policies, which apply in addition to this Policy. When you use Director's Chat (the in-editor assistant), your chat messages and the canvas context needed to answer them are processed by the chat model provider configured for the Service (currently Anthropic or DeepSeek), under that provider's terms.

Connected AI assistants (MCP connectors)

You can authorize external AI assistants (such as Claude or ChatGPT) to access your Piko Club account through our MCP connector using OAuth. An authorized assistant acts on your behalf with your permissions: it can read your projects and canvases and perform the actions you instruct, and any content it reads is processed by that assistant's provider under their own terms. You control this access entirely — each authorization is scoped to your account, can carry a spending cap you set, and can be revoked at any time in Settings → Agent Access, which immediately invalidates the assistant's credentials.

Other recipients

  • Collaborators you invite — people you add to a project can see the Content and activity in that project per their assigned role.
  • Authorities — when we are legally required to, or to investigate, prevent, or take action against fraud, security, or abuse.
  • Successors — in connection with a merger, acquisition, financing, reorganization, or sale of assets. Where law allows, we will let you know in advance.

7. International transfers

Piko Apps LLC is incorporated in Delaware, USA, and our infrastructure and subprocessors are located in multiple countries including the United States and the European Union. When we transfer personal information across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, equivalent UK and Swiss addenda, and the additional measures required by applicable law.

8. Retention

We keep personal information only for as long as needed for the purposes described above:

  • Account data — for as long as your Account is active.
  • Content — until you delete it or close your Account. Deleted Content is moved to a soft-deleted state for up to 30 days for recovery, then purged from active storage. Encrypted backups may persist for a bounded additional period for disaster recovery.
  • Billing records — for the period required by tax and accounting law (typically 5–10 years depending on jurisdiction).
  • Support tickets — for as long as needed to resolve and follow up on your request, and for a reasonable period thereafter for quality and audit purposes.
  • Aggregated, de-identified usage data — may be retained indefinitely.

9. Security

We use industry-standard measures to protect your information. These include encryption in transit (TLS), encryption at rest for media files and stored API keys, scoped access controls, audit logging, regular dependency updates, and careful review of subprocessors. No system can be guaranteed 100% secure, however, and we cannot eliminate every risk. If we become aware of a security incident that materially affects your information, we will notify you and the relevant authorities as required by law.

You can help by using a strong, unique password for the email address tied to your Piko Club Account, enabling two-factor authentication on that email and on your SSO provider, and keeping your devices and browsers updated.

10. Your rights & choices

Subject to applicable law, you have the right to:

  • access the personal information we hold about you and request a copy;
  • correct inaccurate or incomplete information;
  • delete your information (we will honor this except where we must retain it to comply with law, resolve disputes, or enforce our agreements);
  • restrict or object to certain processing, including direct marketing;
  • port your information to another service in a structured, commonly used, machine-readable format;
  • withdraw consent at any time, where processing is based on consent;
  • lodge a complaint with your local data-protection authority.

You can exercise most of these rights directly from your Account settings — including downloading your data, removing API keys, and deleting your Account. For anything settings does not cover, email [email protected] from the address on your Account and we will respond within the time frame required by applicable law (and usually faster).

11. Cookies & tracking

We use a small number of cookies and similar technologies:

  • Strictly necessary — to keep you signed in, remember your session, and protect against CSRF. The Service does not function without these.
  • Preference — to remember your in-app choices (such as panel layouts and theme settings).
  • Analytics — anonymized, aggregated metrics on feature usage and performance, which we use to improve the Service.

We do not use advertising cookies or sell your information to advertisers. You can block or delete cookies through your browser settings; doing so may break parts of the Service that depend on session cookies.

12. Children

The Service is not directed to and should not be used by anyone under 18 (or the higher minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, contact [email protected] and we will promptly delete it.

13. Third-party links & sites

The Service may include links to third-party websites, models, or services that we do not operate. We are not responsible for the content, privacy practices, or security of those third parties. Please review their policies before providing them with information.

14. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. If a change is material, we will give you advance notice by email or in-app message at least 15 days before it takes effect. Your continued use of the Service after that date means you accept the updated Policy.

15. Contact

For privacy questions, requests to exercise your rights, or any other concerns, please email us at [email protected]. We will respond within the timeframes required by applicable law.