Privacy Policy
Last updated: September 28, 2026
In short. We keep what we need to run PixelVibing for you: your account from the provider you sign in with, your projects and what you generate, and your credits. We keep no password and no card. What you generate helps train PixelVibing's own models, and the datasets we build for that name no one. We do not sell your data and we use no advertising or tracking cookies. You can delete your account at any time, and write to [email protected] for anything else.
1. Who is responsible for your data
PixelVibing, United States ("PixelVibing", "we"), is the controller of the personal data described here. Our contact for data protection, including as the person in charge (encarregado) under Brazil's LGPD, is [email protected].
This policy covers the website at pixelvibing.com, the web app, the desktop app, the command-line interface, the MCP server and the API (the "Service"), and is part of our Terms of Service.
2. What we collect
Your account
- From the provider you sign in with — Google, GitHub or Discord — your name, your e-mail address when the provider shares it, and the provider's identifier for you. We never receive or keep your password there.
- When your account was created, which sign-in methods it has, and when you last accepted the Terms by signing in.
- Account tokens you create for the command line or the MCP server: their names, their last four characters and when they were made. We keep a token only as a one-way hash, never its value.
What you make
- Your projects: their names, the ideas you write about your games, and every version of their style guides.
- Your generations: the instructions you write, the reference images you upload, the images that come back, and the feedback you give on them.
- For each generation, a record of what we sent to the AI models that drew or wrote it, and what they returned.
Credits and payments
- Your credits: every grant, spend and refund, and your plan.
- The identifiers Stripe gives your customer record and subscription. Stripe processes your payment details; we never see or keep your full card number.
The waitlist
- Before PixelVibing opens, the name and e-mail address you leave on the waitlist, the language of the page you left them from, and when you did.
Technical data
- Your IP address, to apply rate limits, which are counters that expire within minutes, and in our servers' logs, which record each request's address and path, and errors, but never your credentials.
- Cookies that keep you signed in, listed in section 7.
What we do not keep
The desktop app keeps its sign-in in your operating system's encrypted store where the system offers one, and otherwise only while it runs; the command line keeps its token in your system's credential store.
3. Why we use it, and on what legal basis
| Purpose | Data | Legal basis (LGPD · GDPR) |
|---|---|---|
| Run the Service: sign you in, keep your projects and style guides, generate, store and show your assets | Account, what you make | Performing our contract with you (LGPD art. 7, V · GDPR art. 6(1)(b)) |
| Credits, subscriptions, payments, invoices and taxes | Credits and payments, account | Contract; legal obligations (art. 7, II and V · art. 6(1)(b) and (c)) |
| Keep the Service secure, prevent abuse and fraud, apply rate limits | Technical data, account | Legitimate interest (art. 7, IX · art. 6(1)(f)) |
| Train, evaluate and improve PixelVibing's own models and services | What you make, including generation records and feedback | Legitimate interest (art. 7, IX and art. 10 · art. 6(1)(f)); you can object, see section 8 |
| Tell you when PixelVibing opens | The waitlist | Consent, which you give by joining and can withdraw at any time (LGPD art. 7, I · GDPR art. 6(1)(a)) |
| Tell you about changes to the Service, the Terms or this policy | E-mail address | Contract; legitimate interest |
| Comply with the law and defend legal claims | What the matter needs | Legal obligation; exercise of rights (art. 7, II and VI · art. 6(1)(c) and (f)) |
About training. The datasets we build to train our models are made from generations of accounts that have accepted the Terms, and leave out the animations, rotations and poses drawn by a provider whose terms do not allow it, and any generation that uses one of them as it came back. They name no account, person or e-mail address: a generation is known in them only by an identifier. Text you write, such as an instruction or an idea, goes into them as you wrote it, so please do not put personal details in it.
We do not use your data to make decisions about you by automated means alone that have legal or similarly significant effects.
4. Who we share it with
We do not sell your personal data. We share it only with:
- Service providers who run the Service for us, under contracts that bind them to protect it: hosting and database providers, and object storage for images.
- AI model providers that generate images and text for us. For each generation they receive only what it needs — the instruction, the style guide's text and the images involved — and not your name or e-mail address.
- Stripe, which processes payments as an independent controller of your payment details.
- Cloudflare, whose Turnstile checks that the waitlist's form is filled in by a person, from your browser's signals and IP address, under its own privacy policy.
- Google, GitHub or Discord, when you choose to sign in with them, under their own privacy policies.
- Authorities, when the law requires it, and a company that takes over the Service, which must honour this policy.
You can ask us for the list of the providers we use at [email protected].
5. International transfers
PixelVibing is based in the United States, and our providers may process data in the United States and other countries. When data about people in Brazil or the European Economic Area leaves their country, we rely on the safeguards the LGPD (art. 33) and the GDPR (chapter V) provide, such as standard contractual clauses.
6. How long we keep it
- Your account, projects, generations, images and credits: for as long as your account exists. When you delete your account, we delete them, including the images in storage and the generation records.
- Payment and tax records: for as long as the law requires, even after your account is deleted.
- The waitlist: until we have told you PixelVibing opened, or until you ask us at [email protected] to remove your name and address, whichever comes first.
- Server logs: for up to 30 days. Rate-limit counters: minutes.
- Backups: overwritten on a rolling schedule, normally within 30 days.
- Training: datasets built before you delete your account keep the generations they hold, without anything that names you, and a model already trained cannot unlearn what it learned from them.
7. Cookies and your browser's storage
We use only cookies that the Service needs to work, and no advertising, analytics or tracking cookies.
| Name | What it does | How long |
|---|---|---|
pv_access | Proves you are signed in | 15 minutes |
pv_session | Keeps you signed in and renews pv_access | 30 days from your last visit |
pv_oauth | Protects a sign-in while it is in progress | Minutes |
pixelvibing.language (browser storage) | Remembers the language you chose on our site | Until you clear it |
eternityme.workbench.side (browser storage) | Remembers how wide you left the editor's side panel | Until you clear it |
The cookies cannot be read by the page's scripts, and are sent only to our API.
8. Your rights
Under the LGPD (art. 18) and, where it applies, the GDPR, you can ask us to:
- confirm whether we process your data, and give you access to it and a copy of it, including in a portable format;
- correct data that is incomplete, inaccurate or out of date;
- anonymise, block or delete data that is unnecessary or processed against the law, and delete your account and its data, which you can also do yourself from your account settings;
- tell you who we share your data with;
- object to processing based on our legitimate interest, including training: we will then stop including your generations in the training datasets we build from then on; and
- withdraw a consent you gave, where a processing relies on consent.
Write to [email protected] from the e-mail address of your account. We may ask you to confirm who you are, and we answer within 15 days, or within the time your law sets. You also have the right to complain to Brazil's data protection authority (ANPD) or to the supervisory authority of your country.
9. Security
We protect your data with measures suited to it: connections over HTTPS, sign-in cookies that scripts cannot read, tokens and sessions kept only as hashes, credentials kept out of logs and error messages, and access to production systems limited to those who need it. No system is perfectly secure; if a breach puts you at risk, we will tell you and the authorities as the law requires.
10. Children
PixelVibing is for people 18 and older. We do not knowingly collect data from anyone younger; if you believe we have, write to us and we will delete it.
11. Changes to this policy
We may update this policy. We will post the new version here with its date and, for significant changes, tell you in advance by e-mail or in the Service.
12. Contact
[email protected] · PixelVibing, United States. This page is also available in Portuguese; if the two differ, the English version prevails, except where the law of your country requires the version in your language to prevail.