Security
Last updated: July 22, 2026
Data Deletion
You can delete any generated asset from your library at any time. Deletions are soft-deleted instantly and permanently purged from our servers within 30 days. Your uploaded source photos can be deleted from your account settings. Request full account deletion via [email protected] — all data is removed within 72 hours.
No Training on Customer Images
We never train AI models on your photos. Your uploaded images are used solely to generate your requested output and are never stored, shared, or repurposed for model training. Your content is your content.
Encrypted Storage
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Images are stored on Cloudflare R2 with bucket-level encryption. Database connections use SSL. API keys and secrets are stored in environment variables, never in code or logs.
GDPR Compliance
Pixfino is GDPR-compliant. You have the right to access, rectify, erase, and export your personal data. To exercise these rights, contact [email protected]. We respond to all GDPR requests within 30 days.
Backups
Database backups run automatically on a daily schedule with 7-day retention. Encrypted backup snapshots are stored in a separate availability zone. In the event of data loss, we can restore to within 24 hours of the incident.
Report a Vulnerability
If you discover a security vulnerability, email [email protected] with details. We respond within 48 hours and credit responsible disclosure.