What Picozy collects, why, who else touches it, and how long it lasts. The short version: we hold your photographs and your email address for as long as it takes to give you your report and let you download it again, and then we delete them.
1. Who this covers
This policy covers picozy.com and the Picozy service. It applies whether you buy anything or just try the free sample.
Open for legal review
- Insert the controlling legal entity, its address, and a privacy contact.
- Determine whether an EU/UK representative or a Data Protection Officer is required given the volume and nature of processing.
2. What we collect
Photographs you upload, and the report generated from them.
Your email address, when you give one for report delivery, to sign in, or through the contact form.
Payment records. Stripe processes the payment itself; we keep the transaction identifiers and the amount, and never receive your card number.
Contact form submissions: your name, email address, the topic you chose, and your message.
Basic technical information needed to operate and protect the service, including a one-way hash of the IP address a contact form submission came from. We store the hash, not the address itself.
If you consent to analytics cookies, usage information about how you move through the site. If you decline, these are not set and no analytics data is collected.
3. What we do with it
Produce your report, deliver it, and let you download it again while it is retained.
Take payment and keep the records of it that we are required to keep.
Reply to you when you contact us, and identify repeated automated submissions so the contact form stays usable.
Understand, with your consent, which parts of the site work and which do not.
We do not sell your personal information, and we do not share it with advertisers. Analytics events carry no photograph, no email address, and no line from any inventory.
Open for legal review
- Map each purpose to a lawful basis under GDPR Article 6 — contract for report production and delivery, legitimate interests for security and abuse prevention, consent for analytics, legal obligation for financial records.
- Confirm the "we do not sell or share" statement against the CCPA/CPRA definitions, which are broader than the ordinary meaning and can capture some advertising-cookie configurations. The Meta Pixel in particular warrants a specific look.
4. Your photographs
Your photographs are sent to an automated image-analysis service operated by Anthropic, which identifies the items visible in them. No human at Picozy reviews your photographs as a matter of routine.
They are stored so that your report can be regenerated and re-downloaded during the retention period, and then deleted along with it.
A photograph of a room can contain more than furniture — documents, screens, photographs of people, personal effects. Only upload what you are comfortable sending, and be aware that anything visible in the frame is uploaded with it.
Open for legal review
- Confirm and then state accurately whether uploaded images may be used to train models under the API terms in force. This is the single question customers in this category ask most, and the answer must match the contract rather than the intention.
- Assess whether incidental capture of identifiable individuals engages biometric or likeness statutes (BIPA and comparable state laws) even though no facial analysis is performed.
5. Who else processes your data
Anthropic — automated analysis of uploaded photographs.
Stripe — payment processing for one-time report purchases and extended-storage subscriptions.
Amazon Web Services — storage of photographs and generated reports, delivery of email, and hosting.
Google Analytics and Meta, only if you accept analytics cookies. Neither receives photographs, email addresses, or report contents.
Each of these acts on our instructions for the purposes described above.
Open for legal review
- Put data processing agreements in place with each processor and record where each stores and processes data.
- Establish the transfer mechanism for personal data leaving the UK/EEA — Standard Contractual Clauses or an adequacy route — and complete the transfer risk assessments.
- Decide whether a published subprocessor list with advance notice of changes is offered; business customers increasingly require one.
6. How long we keep things
Photographs and reports: 30 days from upload, then deleted. If an active extended-storage subscription is attached to the account that owns them, they are kept while it runs. If that subscription is cancelled, a further 30 days runs from the cancellation date and they are then deleted.
Contact form messages: up to 12 months, so a conversation outlives the report it was about.
Sign-in links: minutes. They expire shortly after being sent, can be used only once, and are stored hashed so the stored value cannot be used to sign in.
Account records: until you ask us to delete the account.
Payment records: as long as financial and tax rules require.
Deletion is enforced by a scheduled job, not by a promise. When the window passes, the photographs, the generated PDF and the underlying record are removed and cannot be restored.
Open for legal review
- Confirm the statutory retention period for financial records in the jurisdiction of the operating entity, and state it as a number rather than "as required".
7. Cookies and analytics
Cookies strictly necessary to operate the site — keeping you signed in, and remembering your cookie choice — are always set.
Analytics and advertising cookies are set only after you accept them. Until then the tags are not loaded at all: measurement is set to denied before any analytics script runs, and the advertising pixel is not loaded.
You can decline, and declining is presented as plainly as accepting. You can change your mind later from the cookie notice.
Open for legal review
- Confirm the banner satisfies the consent standards that apply — ePrivacy and GDPR in the EU/UK, and the opt-out and Global Privacy Control requirements under CPRA and similar US state laws.
- Decide whether Global Privacy Control signals are honoured automatically, and say so here if they are.
8. Your rights
You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it.
You can ask us to stop using analytics at any time by declining cookies.
To make a request, use the contact form at /contact and choose "Privacy or data request". We will ask you to confirm control of the email address involved, so that nobody else can make a request about your data.
Because reports are deleted automatically after 30 days, a deletion request about an old report may find there is nothing left to delete. We will tell you if that is the case.
Open for legal review
- Set the response deadline and state it — one month under UK/EU GDPR, 45 days under CCPA.
- Confirm the identity-verification step is proportionate: too weak enables one person to delete another's data, too strong collects more than the request warrants.
- Add the relevant supervisory authority and the right to complain to it, plus the CCPA non-discrimination statement if serving California.
9. Security
Photographs and reports are stored encrypted, and are not publicly listed or browsable.
A report link contains a long random identifier and is not guessable, but it is not password-protected either: anyone you forward it to can open the report while it exists. Treat it like a document, not a login.
Sign-in links and stored fingerprints of IP addresses are hashed, so the stored values cannot be reversed into a usable credential or an address.
Open for legal review
- Confirm breach notification obligations and the internal timeline for meeting the 72-hour GDPR deadline.
- Consider whether report links should expire independently of the retention window, given that a forwarded link is effectively a bearer token.
10. Children
Picozy is not intended for children, and we do not knowingly collect their personal data. If you believe a child has sent us data, contact us and we will delete it.
Open for legal review
- Set the age threshold and confirm it against COPPA and the UK Age Appropriate Design Code.
11. Changes to this policy
If this policy changes materially we will say so on the site, and by email where we hold your address and the change affects you.
12. Contacting us
Use the contact form at /contact and choose "Privacy or data request". It reaches us directly and we reply to the address you give.
Open for legal review
- Add a named privacy contact and a postal address. A form alone is unlikely to satisfy the contact requirements in GDPR Article 13.