Privacy Policy

Last Updated: October 17, 2025

1. Introduction

BrixlAI ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our AI-powered image generation service.

2. Information We Collect

2.1 Account Information

  • Email address
  • User ID (generated automatically)
  • Authentication credentials (managed by Firebase)

2.2 Usage Data

  • Image generation prompts
  • Generated images
  • Credit balance and purchase history
  • API usage statistics
  • Device information and browser type
  • IP address and location data

2.3 Payment Information

Payment information is processed securely through Stripe. We do not store your credit card details. Stripe collects and processes your payment information according to their privacy policy.

3. How We Use Your Information

  • To provide and maintain our image generation service
  • To process your payments and manage your credit balance
  • To send you service-related notifications
  • To improve our service and develop new features
  • To detect and prevent fraud and abuse
  • To comply with legal obligations

4. Data Storage and Security

Your data is stored securely in our PostgreSQL database hosted on Hetzner servers in Germany. We implement industry-standard security measures including:

  • Encryption in transit (SSL/TLS)
  • Encrypted database connections
  • Regular security audits
  • Access controls and authentication
  • Rate limiting and DDoS protection

5. Data Sharing

We do not sell your personal data. We share your data only in the following circumstances:

  • Google AI: Image generation prompts are sent to Google's Gemini API for processing
  • Stripe: Payment information for processing transactions
  • Firebase: Authentication and user management
  • Legal Requirements: When required by law or to protect our rights

6. Your Rights (GDPR & CCPA)

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your account and data
  • Data Portability: Download your data in JSON format
  • Object: Object to processing of your data
  • Withdraw Consent: Withdraw consent at any time

To exercise these rights, visit your Account Settings page.

7. Data Retention

We retain your data for as long as your account is active. When you delete your account:

  • Your account and profile are permanently deleted
  • All generated images are removed from our servers
  • Credit history and purchase records are deleted
  • Backup data is purged within 30 days

We may retain certain data longer if required by law or for legitimate business purposes (e.g., fraud prevention).

8. Cookies and Tracking

We use essential cookies for:

  • Authentication and session management
  • Security and fraud prevention
  • Service functionality

We do not use third-party advertising cookies or tracking pixels.

9. Children's Privacy

Our service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

10. International Data Transfers

Your data may be transferred to and processed in countries outside your residence, including the United States (Google AI) and Germany (hosting). We ensure appropriate safeguards are in place for such transfers.

11. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of our service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this privacy policy or wish to exercise your rights, please contact us:

Email: [email protected]
Data Protection Officer: [email protected]