Trust & Privacy

How we handle your photos and data

This page is maintained by the PixPunch team to answer common security and privacy questions about PixPunch AI. It describes the controls currently in place in the app. It is editable project content and is not an independent certification or audit.

Accounts & authentication

  • Sign-in supports email & password and Google sign-in.
  • Passwords are never stored by PixPunch — authentication is handled by our backend provider, which stores password hashes only.
  • Role-based access (Owner, Sub Admin, Supervisor, Reviewer, Editor, User) controls what team members can see and do.

Your photos & data

  • Photos you upload are stored in a private storage bucket. Only you and authorized team members involved in a review or edit you requested can access them.
  • Row-level access rules are enforced on every database table so users can only read and modify their own records.
  • Data is transmitted over HTTPS/TLS between your browser and our services.

Subprocessors & integrations

  • Lovable Cloud — hosting, database, authentication, and file storage.
  • Lovable AI Gateway — runs AI photo analysis, coaching, and optimization features.
  • OpenAI — used for selected AI features.
  • Google — optional Google sign-in (only if you choose to use it).

Subprocessors process data only as needed to provide the features above.

Cookies & analytics

We use essential cookies and local storage to keep you signed in and to remember session preferences. We do not sell your personal data.

Retention & deletion

Your account, photos, and analyses are retained while your account is active. To request deletion of your account or specific photos, contact us using the address below.

Privacy requests & contact

For privacy requests (access, correction, deletion) or general security questions, email nitin.akolia@gmail.com. We aim to respond within a reasonable time.

Reporting a vulnerability

If you believe you have found a security issue, please report it to nitin.akolia@gmail.com. Please do not publicly disclose the issue until we have had a chance to review and respond.

Shared responsibility: PixPunch configures and operates the application described above. Hosting, infrastructure, and platform-level controls are provided by our backend provider. You are responsible for keeping your login credentials safe and for the content you upload.

Last updated: June 23, 2026.