Privacy Policy
Last updated: 31 August 2026
Who we are
Pictofy is operated by Pictoday (CVR 30059891), Børkop, Denmark. Contact: support@pictofy.app.
Controller or processor?
The role depends on how Pictofy is used:
- Private use: Pictofy (Pictoday) is the data controller for your account, purchases, and the operation of the service. For photos and information about children that you add yourself, you decide the purpose — you must have consent from the holder of parental responsibility, and we process them only to deliver the service to you.
- Institutional use (schools, institutions, municipalities): The institution is the data controller for pupil/citizen data (profiles, photos, schedules), and Pictofy is the data processor, processing only under instruction. We sign a data processing agreement (the Danish DPA's standard template) — contact us at support@pictofy.app.
What we store
- Account information: Email address, password (encrypted), licence/organisation membership
- Purchase history: Credit purchases, subscriptions and physical orders (via Stripe); delivery address on physical orders
- Generated pictograms: Prompt, style, image, metadata
- Photos and characters: Uploaded photos and their generated style variants — both in private, access-protected storage (see below)
- Profiles and schedules: Child profiles (name, optional age, avatar), visual schedules and share links. Profiles can be shared with colleagues you choose
What we do NOT store
- Payment card details (handled by Stripe)
- IP addresses (only temporarily for free generation, deleted after 90 days; country is read at the network edge without third-party lookups)
- Third-party tracking cookies. Product analytics (PostHog, EU-hosted) runs only with your consent
Photos and children's data
- Photos are processed only in the EU/EEA: AI image generation from photos runs on GPUs pinned to the EU/EEA (RunPod: Sweden/Iceland/Norway; standby: Nebius, Finland). Photos and images of recognisable people are never sent to US AI services.
- Uploaded photos and their generated style variants live in private, access-protected storage — never on a public CDN.
- Pictograms made from photos are always private and never used in galleries or marketing.
- You can delete characters, profiles and photos at any time — deleting a profile deletes its schedules, share links, character and photo.
- Only adults (16+) can create an account. If you upload a photo of a child, you must have consent from the holder of parental responsibility. If you discover an account created by a child, contact us.
Community and marketing
Pictograms generated from text alone may appear in our library, gallery, or marketing. Pictograms generated from photos (the character and image features) are never used for those purposes.
Sub-processors
We use the following services to deliver Pictofy. For institutional customers the list is identical to the DPA's annex, and we give 30 days' notice of changes.
| Service | Processing | Location | Safeguard |
|---|---|---|---|
| Supabase | Database, login, file storage, server functions | EU (Frankfurt) | DPA with SCCs |
| Vercel | Web application hosting | US/EU | DPA + SCCs / EU-US DPF |
| RunPod | AI image generation from photos — GPUs pinned to EU/EEA (Sweden, Iceland, Norway) | EU/EEA | DPA + SCCs |
| Nebius | AI text, search and image analysis plus standby GPU (Zero Data Retention) | EU (Finland) | EU company and EU data centre |
| OpenAI (Ireland) | Text processing of prompts and library metadata — never personal photos or images of recognisable people | US (inference) | DPA + SCCs — planned phase-out |
| Replicate | AI image generation without photos (prompt text only) | US | SCCs — planned phase-out |
| Stripe | Payments and subscriptions | Ireland/US | DPA + SCCs |
| Prodigi | Printing and shipping of physical orders | United Kingdom | EU adequacy decision |
| Resend | Transactional and notification emails | US | DPA + SCCs |
| PostHog | Product analytics (only with cookie consent) | EU-hosted | DPA, EU hosting |
| Cloudflare | Bot protection (Turnstile) on public forms | Global | DPA + SCCs / DPF |
None of the AI services use your data to train models.
Data retention
- Account, pictograms, profiles and schedules: as long as the account exists
- Unsaved generations and unused uploaded photos: deleted after 90 days
- IP logging for free generation: deleted after 90 days
- Sent email contents: deleted after 12 months
- On account deletion: account, pictograms, photos, characters, profiles and schedules are removed immediately; bookkeeping-relevant purchase data is retained as required by accounting law
Your rights (GDPR)
- Access your data — contact us for an overview
- Rectification of incorrect data — update it yourself, or contact us
- Erasure — use "Delete account" under Account, or delete individual characters/profiles directly
- Data portability — contact us for an export
- Complaint — you can complain to the Danish Data Protection Agency (Datatilsynet), www.datatilsynet.dk
Security
Data is stored with Supabase in the EU (Frankfurt) with encryption in transit and at rest, row-level access control, and access-protected file storage for photos. Two-factor login (TOTP) can be enabled under Account. In case of a personal data breach we notify affected controllers without undue delay.
Changes
We may update this policy and will announce material changes on this page. Institutional customers are notified directly of changes to the sub-processor list.
Contact
Questions about personal data: support@pictofy.app