Legal
Privacy Policy
Summary. We collect what we need to run PixelCrew: your sign-in profile, the briefs and comments you submit, the API keys you connect, and basic technical logs. Your briefs are sent to third-party AI model providers (through OpenRouter, or directly to Anthropic or Google if you connect those keys) to generate your deliverables. We do not sell your personal information, we do not use your content to train AI models, we do not run analytics or advertising trackers inside the App, and analytics cookies on our website only run if you accept them. Content you put in a shared workspace is visible to the other members of that workspace. Your projects are never published as demos to other users.
- 1. Who we are
- 2. What this policy covers
- 3. Information we collect
- 4. How we use information
- 5. AI processing of your content
- 6. How we share information
- 7. Cookies and analytics
- 8. Data retention
- 9. Security
- 10. International transfers
- 11. Your rights and choices
- 12. Additional information for the EEA, UK and Switzerland
- 13. Additional information for California residents
- 14. Children
- 15. Changes to this policy
- 16. Contact us
1. Who we are
PixelCrew Inc. ("PixelCrew", "we", "us" or "our") is a corporation registered in the State of Delaware, United States. We operate the website at pixelcrew.ai (the "Site") and the PixelCrew application at app.pixelcrew.ai (the "App", and together with the Site, the "Service").
PixelCrew Inc. is the data controller (or "business", in California terms) of the personal information described in this policy. You can reach us at hello@pixelcrew.ai.
2. What this policy covers
This policy explains how we collect, use, share and protect personal information when you visit the Site, use the App, contact us, or otherwise interact with us. It does not cover third-party websites or services that we link to or that you connect to PixelCrew, such as OpenRouter or your sign-in provider. Those services have their own privacy policies.
By using the Service you also agree to our Terms of Service.
3. Information we collect
3.1 Information you provide to us
- Account and sign-in information. You sign in to the App through a third-party identity provider (Google, Apple, GitLab or Microsoft, depending on what is enabled). When you do, the provider sends us your name, email address, profile picture URL (if any) and a provider account identifier. We never receive or store your password for that provider. We do not record your IP address or sign-in history in your account.
- Briefs and content. The design briefs, clarification answers, team notes, comments, questions, files, design-system uploads, website URLs you ask us to redesign, and other materials you submit to the App, together with the research, creative briefs, wireframes, images, HTML and other deliverables the Service generates for you (together, "Content"). If you ask us to redesign an existing website, we fetch and store a copy of that site's pages and images as part of your project.
- API keys. If you use the bring-your-own-key option, the OpenRouter, Anthropic or Google Gemini API keys you paste into the App, and any OpenRouter key a workspace owner adds for their team. We verify a key with the provider before saving it, store it encrypted at rest, show it only in masked form, and use it only to make model requests on your behalf. You can remove your keys at any time from your profile.
- Communications. The name, email address and message you send when you email us at hello@pixelcrew.ai. The Site has no contact form; the message is sent from your own email client and is stored in our mailbox.
- Payment information. The Service is currently free. If we introduce paid plans, payments will be processed by a third-party payment processor and we will update this policy before collecting billing information.
3.2 Information we collect automatically
- Technical and log data. Our hosting provider's request logs record technical information such as your IP address, browser type, the URL requested, timestamps and a request identifier. If something goes wrong, our error-monitoring service (Sentry) receives the error, a stack trace and technical context; we configure it not to send personal identifiers by default.
- Agent run records. For each brief the App records which agents ran, how long they took, the models used, token counts, estimated cost and the status of the run. For debugging and abuse prevention we also keep the full prompts sent to and responses received from the model providers, which contain your Content. Those prompt and response bodies are automatically blanked after 30 days (Section 8).
- Cookies and similar technologies. Described in Section 7.
3.3 Information from third parties
We receive the profile information described above from your sign-in provider. We do not buy personal information from data brokers.
4. How we use information
We use personal information to:
- Provide, operate and maintain the Service, including running your briefs through the agent crew and returning deliverables to you.
- Create and manage your account, authenticate you, and review new accounts where we require approval before access.
- Make requests to AI model providers on your behalf using your connected API keys, or a workspace or PixelCrew-provided key where applicable.
- Let you share projects and workspaces with the teammates you choose (Section 6).
- Respond to your questions, requests and support needs.
- Send you service-related notices, such as changes to the Service, our terms or this policy. If we send marketing email in the future, you will be able to opt out at any time.
- Monitor, analyze and improve the Service, including understanding which features are used and fixing bugs.
- Detect, investigate and prevent fraud, abuse, security incidents and violations of our Terms of Service.
- Comply with legal obligations and enforce our agreements.
We do not use your Content to train AI models, and we do not sell personal information or share it for cross-context behavioral advertising.
5. AI processing of your content
PixelCrew works by sending your briefs, related context and intermediate agent outputs to large language models operated by third parties. Depending on the keys connected to your project, these requests go through OpenRouter to the model provider it routes to (such as Anthropic, Google, OpenAI or others), or directly to Anthropic or Google (Gemini). This means:
- Your Content leaves our systems and is processed by OpenRouter and by the model provider under their respective terms and privacy policies. When you use your own key, you have a direct relationship with that provider and the data and privacy settings of your account with them apply, including OpenRouter's data-policy settings that control which upstream providers may receive your prompts.
- Some model providers may retain inputs for a limited period for abuse monitoring, and some let you choose whether your prompts may be used for training. Because requests are made with your own key, those choices live in your account with the provider, not with us. Check the privacy settings of your OpenRouter, Anthropic or Google account before running briefs. We do not control third-party providers.
- Do not include personal information about other people, health, financial, government identifiers, passwords, secrets or other sensitive information in a brief unless it is necessary for your deliverable.
- Generated output is produced automatically and may be inaccurate. You are responsible for reviewing it before use, as described in our Terms of Service.
6. How we share information
We share personal information only as described here:
| Recipient | What and why |
|---|---|
| AI model providers | OpenRouter, Anthropic and Google receive your Content and related metadata to generate your deliverables (Section 5). |
| Sign-in providers (Google, Apple, GitLab, Microsoft) | Authentication requests when you sign in. They learn that you are using PixelCrew. |
| Hosting and infrastructure | DigitalOcean (application hosting, managed database and object storage) and Amazon Web Services (object storage) host our systems and your data. Sentry receives error reports. Google Fonts serves the typefaces on some App pages, which reveals your IP address to Google. These providers process data on our behalf under contracts that restrict their use of it. |
| Your teammates | If you join or are added to a workspace, every member of that workspace can see every project in it, including briefs, deliverables, files, and comments and questions with the name of who wrote them. Project owners can also add individual members to a single project. Members are added by email address, which reveals to the person adding them whether an account exists for that address. Briefs you run inside someone else's project or workspace stay in that project after you leave or delete your account, without your account attached; your comments and questions are deleted with your account. |
| Showcase demos | The App shows demo projects to all signed-in users. Demos are made only from projects that PixelCrew staff created themselves. Your projects are never published as demos, and comments or questions you leave on a staff project are never copied into one. |
| Analytics providers | Google Analytics on the Site, only if you accept analytics cookies (Section 7). We do not use analytics or advertising trackers inside the App. |
| Professional advisers | Lawyers, accountants and insurers where needed to run our business. |
| Legal and safety | Courts, regulators, law enforcement or other parties when we believe disclosure is required by law, or necessary to protect the rights, property or safety of PixelCrew, our users or others. |
| Business transfers | A buyer or successor in connection with a merger, acquisition, financing, reorganization or sale of assets, subject to this policy. |
| With your direction | Anyone you ask us to share with, for example team members you invite to a workspace. |
7. Cookies and analytics
Site (pixelcrew.ai). The Site does not set any cookies until you make a choice in the cookie banner. If you click "Accept", we load Google Analytics 4, which sets cookies (such as _ga and _ga_*) to measure page views and usage. IP addresses are anonymized. If you click "Decline", no analytics run. Your choice is stored in your browser's local storage under the key pc-consent so we do not ask again, and you can change it at any time using the "Cookie settings" link in the footer. Learn how Google uses data at policies.google.com/technologies/partner-sites. You can also install the Google Analytics opt-out browser add-on.
App (app.pixelcrew.ai). The App uses only strictly necessary and functional cookies: an encrypted session cookie that keeps you signed in and protects against cross-site request forgery, and a small preference cookie that remembers whether your sidebar is open. Your browser's local storage keeps your theme preference, which discussions you have already read, and your progress through the product tour. None of these are used for advertising or shared with third parties, so no consent banner is shown in the App.
Do Not Track and Global Privacy Control. If your browser sends the Global Privacy Control signal, the Site treats it as "Decline" and does not load analytics. We do not sell or share personal information for advertising, so no further action is needed.
8. Data retention
- Account information, projects, briefs, deliverables, files and comments are kept for as long as your account exists so you can access your work. You can delete individual projects and briefs at any time. When you delete your account from your profile page, your account, your projects and everything in them, your saved keys, and your comments and questions are deleted immediately, except where we must keep specific records longer for legal, tax or security reasons. Briefs you ran inside another person's project or workspace remain there without your account attached.
- API keys are deleted immediately when you remove them or delete your account.
- Model prompts and responses recorded for debugging are automatically blanked 30 days after they are created. The remaining run metadata (model, token counts, cost, timing, errors) is kept for accounting.
- Backups of our database are taken daily by our hosting provider and kept for 7 days, so deleted data leaves backups within 7 days.
- Hosting and error logs are kept by our providers for a limited period, typically no more than 90 days, for security and debugging.
- Emails and support correspondence are kept for as long as needed to handle your request and for a reasonable period afterwards.
9. Security
We use reasonable technical and organizational measures to protect personal information, including encryption in transit (TLS), encryption of API keys at rest, filtering of keys and email addresses from application logs, access controls and logging. A small number of PixelCrew staff can access user accounts and Content, including recorded prompts and responses, to provide support, investigate abuse, review new accounts and debug the Service. That access is limited to what is needed for those purposes. No system is completely secure, and we cannot guarantee absolute security. If we learn of a breach that affects your personal information we will notify you and the relevant authorities as required by law. Please report security issues to hello@pixelcrew.ai.
10. International transfers
We are based in the United States. Our hosting providers may store data in the United States and the European Union, and our AI model providers and other service providers are located in the United States and other countries. If you are located in the European Economic Area, the United Kingdom, Switzerland or another region with data transfer laws, your personal information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. Where required, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You can request a copy of the relevant safeguards by contacting us.
11. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a copy of it.
- Correct inaccurate or incomplete information.
- Delete your personal information.
- Port your information to another service in a machine-readable format.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Opt out of marketing communications.
- Not be discriminated against for exercising your rights.
To exercise any of these rights, email hello@pixelcrew.ai from the address associated with your account, or use the account settings in the App where available. We may need to verify your identity before responding. We will respond within the time required by applicable law (generally 30 days in the EEA and UK, and 45 days in California). If you have an authorized agent, they may submit a request on your behalf with proof of authorization.
You can do several of these yourself in the App: remove your API keys and delete your entire account from your profile page, delete individual projects and briefs, and download a ZIP of any brief's deliverables. For a full copy of your personal information, email us and we will provide it.
12. Additional information for the EEA, UK and Switzerland
If you are in the European Economic Area, the United Kingdom or Switzerland, we process your personal information on the following legal bases:
- Performance of a contract (Article 6(1)(b) GDPR): providing the Service you signed up for, including processing your Content and API key.
- Legitimate interests (Article 6(1)(f) GDPR): securing and improving the Service, preventing abuse, responding to your messages and running our business, where these interests are not overridden by your rights.
- Consent (Article 6(1)(a) GDPR): analytics cookies on the Site and any marketing email. You may withdraw consent at any time.
- Legal obligation (Article 6(1)(c) GDPR): complying with laws that apply to us.
You have the right to lodge a complaint with your local data protection authority. A list of EEA authorities is available at edpb.europa.eu. In the UK, the authority is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first, so please contact us before filing a complaint.
13. Additional information for California residents
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), requires the following disclosures. In the preceding 12 months we have collected the categories of personal information listed in Section 3: identifiers (name, email, provider ID, IP address), internet or network activity (usage and log data), commercial information (your use of the Service), and the contents of your Content and communications. We collect it from you, your devices and your sign-in provider, for the purposes in Section 4, and disclose it to the categories of recipients in Section 6 for business purposes.
We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA. We have no actual knowledge that we sell or share personal information of consumers under 16.
California residents have the rights to know, delete, correct, and to opt out of sale or sharing, as well as the right not to be discriminated against for exercising these rights. To exercise them, see Section 11. Under California's "Shine the Light" law you may also request information about disclosures to third parties for their direct marketing purposes. We make no such disclosures.
14. Children
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. If we make material changes we will notify you by email or by a notice in the App or on the Site before the changes take effect. The "Effective date" at the top shows when the policy was last revised. Your continued use of the Service after the effective date means you accept the updated policy.
16. Contact us
Questions, requests or complaints about this policy or our data practices can be sent to:
PixelCrew Inc.
A Delaware corporation
Email: hello@pixelcrew.ai