Skip to content
Pix4Less
BrowseCreatePricingDeveloper docsSign inCreate account

Privacy

Privacy Policy

What we collect, why, and how to get it deleted.

Read the full text
A slender waterfall descends through a mossy rainforest with mist and soft daylight.
Somewhere, the world is stillAI-generated

The short version

What do you collect?
Your email address, display name and a hashed password; your searches, prompts and creations; payment and credit records (never card numbers); and technical data such as your IP address when you visit. Images you create are public in the catalog, with a title, description and tags derived from your prompt but not your name, so keep personal data out of prompts (§§ 3–9).
Do you use analytics cookies?
Only if you agree. Google Analytics and our measurement identifiers load only after you click Accept in the cookie banner; without that, our own page counting is cookieless and has no identifier. When you are signed in, we also record key account events to operate and improve the service. You can change your choice under “Cookies” in the footer. We do not sell personal data or run advertising trackers (§ 2, § 10).
Who do you share it with?
Only the providers that help us run Pix4Less, each for its stated purpose: Cloudflare, Stripe, Google, the AI model providers and TypeSafe AI. Some prompts may be created through Google Gemini accounts we operate, where Google may review them; you can turn this off in your dashboard (“Always use the paid Gemini API”). Some providers process data outside the EU under the safeguards described in the policy (§ 11).
How long do you keep it?
Account data while your account exists. Search logs 90 days, error records 30 days, measurement events and API usage logs 13 months. Payment, ledger and checkout records 10 years, as tax law requires (§ 13).
How do I get my data deleted?
Email [email protected] to close your account or to use your rights to access, erasure and more. When an account is closed we anonymise its email address and name; tax records and published catalog images remain; you can ask us to remove a published image (§ 8, § 13, § 14).

This summary is here to help you find your way and changes nothing: the full text below is what applies.

Last updated: September 27, 2026

LicenseTermsPrivacyImpressumCancel contracts here

1. Who is responsible

The controller for personal data processed on pix4less.com is Taha Yusuf Kömür (Pix4Less), Am Schäfersee 59, 13407 Berlin, Germany, email [email protected]. Full provider details are in our Impressum / legal notice. We have not appointed a data protection officer because the law does not require one for us.

2. Summary

  • Pix4Less is a catalog of AI-generated images with search, downloads, on-demand image creation and a developer API, paid with prepaid credits or a subscription.
  • The application and its database run on a server we operate in Berlin, Germany. Traffic reaches it through Cloudflare.
  • We do not sell personal data to third parties, nor do we run third-party advertising tracking scripts.
  • Google Analytics loads only after you click Accept in the cookie banner.
  • Images you create are public: they join the Pix4Less catalog, where anyone can find, view and license them.

3. Visiting the website

When you open a page, Cloudflare (content delivery, TLS, firewall, and the tunnel to our server) and our own web server and application process your IP address, the time, the requested address, the referrer, your browser’s user agent and the response status, to deliver the site and keep it secure (Art. 6(1)(f) GDPR; § 25(2) no. 2 TDDDG for anything strictly necessary that is read from or stored on your device). Our server logs are rotated automatically by size and are not archived. When a page or request fails unexpectedly, in our server or in your browser, we keep an error record (the error message, the page address without its query string, the time and a request reference; no IP address, account or form data) for 30 days to fix the problem. Fonts are bundled with the site, so no request goes to Google Fonts.

4. Account, sign-in and security

We collect your email address and display name upon authentication (Google sign-in or email credentials), plus your password as a salted scrypt hash, your email-verification status and account timestamps. With “Sign in with Google”, Google shares your email address, name and basic profile; we never receive your Google password. Your sign-in is kept in the cookie curated_session (30 days); our database stores only a hash of it. Email verification and password-reset links are one-time tokens. Cloudflare Turnstile checks sign-up and sign-in for bots (Cloudflare receives your IP address and browser signals). Rate limits store only keyed hashes of IP addresses and email addresses, deleted after 2 days.

Legal basis: Art. 6(1)(b) GDPR (your account); Art. 6(1)(f) GDPR (security and abuse prevention).

5. Emails

We send service emails (welcome, email verification, password reset, receipts for top-ups and plans) through Cloudflare’s email service from @pix4less.com addresses (Art. 6(1)(b) GDPR). We do not send marketing emails.

6. Payments

Payment processing is handled by Stripe. Pix4Less never receives or stores your credit card numbers or banking credentials. We store your Stripe customer and subscription IDs, plan and renewal dates, and a credit ledger of every credit movement (top-ups, plan grants, trial credits, charges and refunds for searches, downloads and creations, royalties and adjustments). When you start a checkout we also store your confirmation about immediate delivery and the right of withdrawal, with the terms version, time, IP address, a shortened browser user agent and the Stripe checkout reference.

Legal basis: Art. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (tax and accounting duties) and Art. 6(1)(f) GDPR (proof of your confirmation). These records are kept for 10 years (§ 147 AO, § 257 HGB), also after the account is closed.

If you cancel through the cancellation page (“Cancel contracts here”), we store what you enter (name, email address, type of cancellation, reason, requested end date and contract details), the time we received it, your IP address and a shortened browser user agent, and we email you a confirmation. Legal basis: Art. 6(1)(b) and (c) GDPR (§ 312k BGB) and Art. 6(1)(f) GDPR (proof of your cancellation). These records are kept like the payment records above.

7. Searching the catalog

We log search query terms and IP hashes for rate-limiting, search quality improvement, and abuse prevention: the text you search for, the corrected query, the number of results, match confidence, timing, whether the search came from the website or the API, a search-session ID and your account ID if you are signed in. Search runs on our own search engine; some ranking decisions may use TypeSafe AI’s structured-judgement service. Result pages are cached in your browser tab (sessionStorage) until you close it. Legal basis: Art. 6(1)(b) and (f) GDPR. The search log is deleted after 90 days.

8. Creating images — your creations are public

When you create an image we store your prompt, negative prompt, style preset, model, format and resolution, status, timing and cost, linked to your account. Every prompt is screened before creation by keyword rules and by TypeSafe AI; prompts that break our rules are rejected automatically, without charge and without other consequences for you. The prompt and settings then go to the provider of the model that creates the image (section 11). Upscaling runs on our own hardware.

Images you generate join the public Pix4Less catalog, where other people can find, view, and license them. A title, description, and tags derived from your prompt are published with each image; your name and account are not. Please do not put personal data or anything confidential in prompts. Published images stay in the catalog after your account is closed; you can ask us to remove one. When another paying member downloads an image you created, we record both accounts to credit royalties. Saved style presets are stored in your account and in your browser (localStorage).

Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR for safety screening. Creation records are kept while your account exists.

9. Downloads and the developer API

Images are stored in Cloudflare R2 object storage. Downloads use signed links that expire after 15 minutes, and we record which images you licensed so you are never charged twice. API keys are shown once; we store only a hash, a short prefix and the last four characters. For the developer API we keep a usage log (endpoint, method, status, request ID, key, account, time) for billing, rate limits and abuse prevention, deleted after 13 months. Legal basis: Art. 6(1)(b) and (f) GDPR.

10. First-Party Product Measurement and Google Analytics

Before you choose in the cookie banner, and if you decline, our own measurement is cookieless: we count page views and a few main clicks without any identifier, without storing anything on your device, and without linking them to your account. We keep only the page path (never the query string), the referring domain, campaign parameters, a broad device category, and categorical event details (Art. 6(1)(f) GDPR).

If you accept, we also set a random first-party identifier (cookie p4l_gtm, up to 30 days) and a per-tab session identifier so we can see which pages and campaign links lead to sign-up and successful product use; after you sign in, this measurement may be linked to your Pix4Less account (Art. 6(1)(a) GDPR, § 25(1) TDDDG). When you are signed in, we also record key account events (such as account creation, searches, downloads, generations, and purchases) with categorical details to operate and improve the service (Art. 6(1)(f) GDPR). This measurement does not contain raw search terms, generation prompts, email addresses, API keys, signed image URLs, or payment-card details. Measurement events are deleted after 13 months.

Google Analytics (Google tag, provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) loads only after you click Accept; before that, and if you decline, no request is sent to Google. It is never loaded on admin, password-reset, or email-verification pages, page addresses are reported without query strings, and Google signals, ad personalisation and ad storage stay disabled. Google sets the cookies _ga and _ga_<ID> (up to 2 years). Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG. You can review or change your choice at any time using the “Cookies” link in the website footer; we then remove the measurement identifiers.

11. Service providers

We share data only with providers that help us run Pix4Less, each for its stated purpose, under data processing terms where the law requires them:

  • Cloudflare, Inc.: content delivery and security for all website traffic (including your IP address), bot protection on sign-up and sign-in (Turnstile), sending our emails, and image file storage (R2).
  • Stripe Payments Europe, Ltd.: payments, subscriptions, and invoices.
  • Google: “Sign in with Google” when you choose it, and Google Analytics only after you accept analytics.
  • AI image-generation providers: your prompt and settings go to the provider of the model that creates the image (Google Gemini by default; OpenAI or xAI only if you choose one of their models). No account details, email address or other identifiers are sent with a prompt.
  • How Google Gemini is used: Pix4Less images are created through the paid Gemini API. A prompt that our automated screening finds free of personal, sensitive, confidential or sexual content may instead be created through Google Gemini accounts that Pix4Less operates; for that route Google may have reviewers read prompts and may use them to improve its services. API-key requests never take that route, and you can turn it off for your account in your dashboard (“Always use the paid Gemini API”). We record which route each creation took. Legal basis: Art. 6(1)(f) GDPR; you can object at any time with that setting.
  • TypeSafe AI: automated safety screening of generation prompts, the screening that decides the Gemini route above, and parts of search ranking.

Some of these providers process data outside the EU, including in the United States. Such transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).

12. Cookies and browser storage

  • curated_session (cookie, 30 days) and the short-lived Google sign-in cookies (10 minutes): keep you signed in and protect the sign-in flow. Strictly necessary.
  • pix4less_cookie_consent (localStorage): remembers your banner choice. Strictly necessary.
  • theme, pix4less_user_presets (localStorage) and search result caches (sessionStorage): features you use.
  • p4l_gtm (cookie, 30 days), p4l_gtm_session and p4l_gtm_view:* (sessionStorage): first-party measurement, only after you accept.
  • _ga, _ga_<ID> (Google, up to 2 years): Google Analytics, only after you accept.
  • Cloudflare Turnstile and Stripe Checkout may set their own strictly necessary cookies for bot and fraud protection.

13. How long we keep data

Account data is kept while your account exists. Our search query log is deleted after 90 days, error records after 30 days, first-party measurement events and API usage logs after 13 months, and expired sign-in sessions and email or password-reset links 7 days after they expire. When an account is closed we anonymise its email address and name and revoke its sessions and keys; payment, ledger and checkout-confirmation records are kept for 10 years for tax purposes, and published catalog images remain.

14. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where we rely on consent, you can withdraw it at any time with effect for the future (Art. 7(3)), for cookies via “Cookies” in the footer. For any of these, or to close your account, email [email protected]; we may ask you to confirm the request from your account email address.

You also have the right to complain to a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany (datenschutz-berlin.de).

15. Do you have to provide data?

You can browse and search without an account. An account is needed to buy credits, download licensed images, create images and use the API, and payment data is needed to purchase. Analytics consent is optional and does not change what you can use. Pix4Less is for adults (18+) and is not directed at children.

16. Changes

We update this policy when the Service changes. The date at the top shows the current version.

Pix4Less

AI-generated imagery for your next idea.
Check each image and its license before use.

BrowseCreateCollectionsJournalPricingCompareDeveloper APIMCP serverDeveloper docsLicenseTermsPrivacyImpressumCancel contracts hereContact