Privacy Policy
How Aipicgo collects, uses, stores, shares, and protects information related to your account, creations, and use of the Services. Continued use means you understand the practices described here.
Introduction
Aipicgo (“we”, “us”) takes the security of your personal information and creative work seriously. This Privacy Policy applies to aipicgo.com and related Services. The operating entity for the current deployment is shown in the site footer.
Questions, complaints, or privacy requests can be sent to [email protected].
Information we collect
We process information only as needed to provide the Services, keep them secure, and meet legal duties. This typically includes:
- Account data: email, display name, hashed password, verification status, language preference, and, if you use Google or WeChat sign-in, the identifiers, name, and avatar you authorize;
- Transaction data: orders, plans, credit packs, coupons, payment channel, status, and billing records. Full card numbers are handled by the payment processor; we do not store them;
- Creative content: prompts, references, masks, brand assets, template materials, generation parameters, outputs, task status, and failure reasons;
- Usage and device data: features you use, task timestamps, approximate region, IP address, browser and device type, language, and session data used to keep you signed in;
- Communications: support mail, appeals, copyright reports, and attachments you send us;
- Security and audit logs: sign-in events, permission changes, unusual access, and necessary risk controls.
How we use information
We use this information to create and manage accounts; run generation, editing, storage, and download; process payments and settle credits; send verification, billing, and service notices; review public content; prevent fraud and abuse; understand product usage and improve features; and comply with law.
We do not use your prompts, uploads, or outputs to train our own foundation models unless you later opt in. Content may still be sent to third-party model providers to complete a task you start. See “Sharing”.
Marketing messages are sent only if you opt in or if law allows. You can unsubscribe from those emails. Necessary service messages such as security, billing, and task results are not marketing.
Cookies and local storage
We use essential cookies and local storage to keep you signed in, remember language and theme, and protect the account. These are required for the Services to work.
We use first-party usage data to see whether features work, whether tasks succeed, and basic traffic. The product does not use advertising cookies to follow you across third-party sites.
You can clear cookies in your browser. You may need to sign in again, and some preferences will reset.
Sharing
We do not sell your personal information. We share what is necessary only in these cases:
- Payments: Creem, Waffo, Yipay, and their underlying methods such as Alipay or WeChat Pay, to collect, subscribe, and refund;
- Sign-in: Google or WeChat, only if you choose that method;
- Infrastructure: Cloudflare R2 or S3-compatible object storage, content delivery, and email (Resend or an SMTP provider);
- AI providers: OpenAI, Google Gemini, and other configured image, video, prompt, or safety vendors, to complete your request;
- Legal duty: disclosure required by law, regulation, legal process, or to protect users, the public, or the Platform;
- Business transfer: if we merge, are acquired, or sell assets, information may move to the successor, with notice as required by law.
Regional isolation
Mainland China and global instances use separate databases, cache, object storage, and provider configuration. They do not share a cross-border business database. Your account data stays in the region you actually use.
Prompts and references may still be sent to the region where the model provider processes the task. When a cross-border transfer is required, we use contractual limits, access control, and data minimization.
If you are in the EEA, UK, or Switzerland, we use Standard Contractual Clauses or another lawful transfer mechanism where required.
Asset access
Private assets and unpublished work are stored in private object storage and accessed through short-lived signed URLs. Publishing a work does not automatically expose private references, internal brand-kit files, or unpublished parameters.
Workspace members can access only what their role allows. Staff access content only when needed for support, security review, complaint handling, or legal duty, and only to the minimum extent required.
Security
We use reasonable technical and organizational measures, including HTTPS/TLS, access control, hashed credentials, least privilege, and security logs.
No system is perfectly secure. To the extent permitted by law, we are not responsible for force majeure, attacks beyond reasonable control, credentials you disclose, or risks from third-party sites you choose to use. If a breach requires notice, we will notify you as the law requires.
Retention
We keep information only as long as needed for the purpose, then delete or anonymize it, unless a longer period is required by law:
- Account data: for the life of the account; deleted or anonymized after closure, except records we must keep;
- Creative content: for the life of the account; deleted as soon as practical after closure, usually within 30 days, with short residual copies in backups;
- Billing and invoice records: usually up to 7 years after closure for tax and audit;
- Security and activity logs: usually 13 months, then deleted or anonymized;
- Support and complaint records: usually 3 years from the last communication.
Your rights
Depending on where you live, including under China’s Personal Information Protection Law and, where they apply, the GDPR or CCPA, you may have the right to access, correct, delete, or obtain a copy of your personal information, to restrict or object to some processing, to withdraw optional consent, and to ask how your data is processed.
You can update your name and password, manage your plan, or request closure in account settings. For other requests, email [email protected] from your registered address so we can verify you. We will handle verified requests as soon as we can, usually within 15 business days.
We do not sell your personal information. If we later use advertising that some laws treat as “sharing”, we will offer a way to opt out. Exercising your rights will not cause discriminatory treatment, but some features may stop working if we must delete or limit data.
Children
The Services are not directed to children under 14, and we do not knowingly collect their personal information. The corresponding age is 16 in the EEA and 13 in the United States, or a higher age if your jurisdiction requires it.
If a guardian believes a child provided information without consent, email [email protected]. We will delete the information and restrict the account as soon as we can.
Model training
We do not use your content to train our own foundation models unless you explicitly opt in. Third-party model providers have their own data policies. We send them only what is needed to complete your request and require them to use it for that purpose.
Aggregated or de-identified statistics, such as feature usage and task success rates, are no longer personal information and may be used to improve the Services.
Freezes and appeals
If an account is limited for security, fraud, or policy reasons, you may appeal within 14 days by emailing your registered address, an explanation, and supporting materials to [email protected]. We will reply after verification, usually within 7 business days.
If you disagree with the outcome, you may request a second review within 14 days. That review is final inside the Platform and does not limit other remedies available to you by law.
Changes
We may update this Policy to reflect product, legal, or industry changes. The new version will be posted here with a new date.
If a change materially affects your rights, we will try to notify you in the product or at your account email. Continued use means you understand the updated Policy.
Contact
For questions, requests, or complaints about this Policy or our handling of personal information, email:
The operating entity is the name shown in the site footer. EEA residents may also lodge a complaint with their local data protection authority.
We reply within 15 business days after we receive the request and verify your identity. If we shut down the Services, we will give reasonable advance notice and delete or anonymize personal information as required by law.