Pixsie Studio Privacy Policy
Effective date: July 28, 2026 Last updated: July 28, 2026
This Policy explains how Heterodox LLC ("Pixsie," "we," "us," or "our") handles information in Pixsie Studio at studio.pixsie.app, including the client galleries photographers deliver through it.
Pixsie Studio is a separate, subscription-based product from the guest-upload service at pixsie.app. Our [Privacy Policy] covers that product. Where the two differ in relation to Pixsie Studio, this Policy controls. Our [Studio Terms] set out the contractual side of the same relationship.
1. Who this Policy covers
Pixsie Studio has two kinds of people in it, and they are in very different positions:
- Photographers. Professional users who create a Studio, subscribe to a Plan, upload their work, and deliver galleries to their own customers. A Photographer is our customer.
- Clients. The people a Photographer invites to view, favorite, comment on, or download a Collection. Clients are the Photographer's customers, not ours. We hold their information in order to provide Pixsie Studio to the Photographer.
That distinction determines who is responsible for what, and it is set out in Section 3.
2. What we collect
From Photographers
Account and Studio information. Email address (sign-in is by emailed link, so the address is the credential), studio name, studio URL, and anything you choose to add: logo, brand colour, cover image, display name and reply-to address for client email, and a custom domain.
Subscription and billing information. Pixsie Studio is billed as a recurring subscription, monthly or annually. Payments are processed by Stripe. We do not receive or store full card numbers. We keep the identifiers and subscription state we need to run your Plan: a payment-processor customer and subscription reference, your tier, subscription status, current period end, storage allowance, and whether the Plan is set to cancel at period end.
Content. The photographs and video you upload, together with the derivative files we generate from them (display copies, thumbnails, and watermarked versions), and any metadata embedded by your camera or editing software, which can include capture time and, in some cases, location.
Usage and technical information. Standard technical data such as IP address, browser and device type, and the events needed to operate and secure the Service.
Notification preferences and interest lists. Whether you want to be told about client favorites and about orders, and whether you asked to be notified when print sales open.
From Clients, on the Photographer's behalf
This is the part the Photographer is responsible for, and it is worth stating plainly.
Email address and name. Collected when a Client opens a gallery, either from the invitation the Photographer sent or from the prompt shown in the gallery.
Engagement record. For each Client on each Collection we record when they last viewed it, how many times they have viewed it, and how many times they have downloaded from it, so the Photographer can see who has engaged with their delivery.
Favorites and comments. Which photographs a Client marked as a favorite, and the text of any comment they leave, each stored against their email address. Comments are free text and a Client should not put anything sensitive in one.
Access state. Whether the Client has entered the Collection's PIN, and whether they have paid for a download, where the Photographer has enabled those gates.
We do not perform facial recognition, faceprinting, or other biometric analysis on uploaded media, and we do not use anyone's Content to train models or to identify individuals.
3. Who is responsible for what
We are the controller of Photographer account, Studio, subscription, and billing information, and of the technical and usage data we collect to operate and secure the Service. We decide how that information is used.
The Photographer is the controller of their Content and of Client information: Client email addresses and names, engagement records, favorites, comments, and access state. In relation to that information we act as the Photographer's processor, handling it on their documented instructions in order to provide Pixsie Studio to them. This matches the commitment in Section 7 of the [Studio Terms].
In practice that means:
- The Photographer decides who is invited to a Collection and what is shared with them.
- The Photographer is responsible for having the rights and permissions needed to upload and deliver Content depicting their Clients and anyone else who appears in it.
- The Photographer is responsible for giving their Clients whatever privacy notice applicable law requires, and for obtaining any consent it requires. We give the Photographer the tools; we do not have the relationship with their Client that would let us do this for them.
- A Client who wants their information or their images removed should contact the Photographer who delivered the gallery. Photographers can delete a Collection, delete individual photographs, and delete a Client's comments themselves. If a Client cannot reach the Photographer, or the Photographer needs help completing a request, contact us at [privacy@pixsie.app] and we will assist.
4. How we use information
- Provide and operate Pixsie Studio: store Content, generate derivatives and watermarks, and deliver galleries to the Clients a Photographer invites.
- Process subscription payments, renewals, and receipts, and enforce storage allowances.
- Authenticate Photographers and keep Studios secure and separate from one another.
- Send email a Photographer has asked for, including gallery invitations sent on their behalf, notifications that a Client has favorited photographs or placed an order, and service messages about their account or Plan.
- Send a Client a reminder if they leave items in a gallery cart without completing checkout, unless they have unsubscribed.
- Verify and serve a custom domain a Photographer connects.
- Detect, prevent, and address fraud, abuse, security problems, and breaches of our terms.
- Comply with legal obligations and enforce our agreements.
For people in regions that require a legal basis (such as the EEA and UK), we rely on performance of our contract with the Photographer, our legitimate interests in operating and securing the Service, consent where we ask for it, and compliance with legal obligations. Where we act as a processor, the Photographer is responsible for establishing the legal basis for processing their Clients' information.
5. Email we send on a Photographer's behalf
Email sent to a Photographer's Clients carries the Photographer's display name and reply-to address. The sending address remains ours, because message delivery on a shared, verified sending domain is more reliable than per-studio domains would be. A Client replying to one of these messages reaches the Photographer, not us.
Marketing and reminder email carries a one-click unsubscribe. We keep an opt-out list of addresses that have unsubscribed, so that a later message cannot be sent to them by mistake. That list holds only the email address and the date it was added, and it exists specifically to stop mail rather than to send it.
Transactional email that a Client needs in order to use a gallery they were invited to, such as the invitation itself, is not covered by that opt-out.
6. Cookies and similar technologies
On a client gallery we use:
- A sign-in cookie for Photographers, to keep an authenticated session.
- A client identity cookie, set once a Client identifies themselves, so they are not asked for their email on every visit and their favorites follow them between sessions. It lasts 90 days.
- A gallery access cookie, set once a Client enters the correct PIN, so they are not re-prompted on every page. It lasts 24 hours.
- A download purchase cookie, where a Photographer has put a gallery download behind payment, recording that it was paid for. It lasts 24 hours.
- Local browser storage for the contents of a gallery cart, so it survives a page reload. This stays in the Client's browser.
These are necessary to operate a gallery, so they are set without a consent prompt. Analytics and advertising technologies are described in our [Cookie Policy] and are set only with consent.
7. Who else processes this information
We do not sell personal information. We use the following service providers, each processing information only to provide services to us:
| Provider | What it handles |
|---|---|
| Cloudflare (R2) | Storage of photographs, video, derivatives, watermarks, and generated archives |
| Turso | The database holding accounts, studios, collections, and client records |
| Vercel | Application hosting, and verification of custom domains a Photographer connects |
| Stripe | Subscription payments and, where enabled, client payments |
| Resend | Delivery of transactional and notification email |
We also share information:
- With the Photographer. Client email addresses, names, engagement records, favorites, comments, and orders are shown to the Photographer who owns the Collection. That is the purpose of the product.
- Within a Collection. Content is visible to the Photographer and to the Clients they have given access to.
- For legal and safety reasons, where required by law, to respond to lawful requests, or to protect the rights, safety, and property of Pixsie, our users, or the public.
- In a business transfer, if Pixsie is involved in a merger, acquisition, financing, or sale of assets. We will give notice of any change in control.
Where we act as a processor for a Photographer, we engage these providers as sub-processors to deliver the Service. We will give reasonable notice before adding or replacing one.
8. How long we keep information
Photographer accounts. For as long as the Studio is active, and afterwards as needed for legal, tax, and accounting purposes.
Content. While a Plan is active, Collections stay online and Clients can reach them. If a Plan is cancelled, Collections remain accessible until the end of the period already paid for. After a paid Plan ends or lapses, a Studio reverts to the free plan and its allowance, and Content above that allowance may become unavailable to Clients. We will give at least [30] days' notice before deleting any Content for that reason. Reaching a storage allowance never deletes existing Content. This mirrors Section 6 of the [Studio Terms].
Content is not otherwise deleted on a schedule. Pixsie Studio galleries do not expire.
Client information. Kept for as long as the Collection it belongs to exists. Deleting a Collection deletes the access records, favorites, and comments attached to it.
Opt-out records. Kept indefinitely, because their entire function is to remain a suppression list.
A Photographer can export their Content at any time, including on the free plan.
After deletion, residual copies may persist briefly in backups before being overwritten.
9. Security
Photographs and video are held in private storage and served through short-lived signed links rather than public URLs. Sign-in is by emailed link, so control of a Photographer's mailbox is control of their Studio, and it should be secured accordingly. We use reasonable technical and organisational measures including encryption in transit and access controls. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent.
Photographers can exercise these directly: most account, branding, and notification settings are editable in the app, billing is manageable through the payment portal, and other requests can be sent to [privacy@pixsie.app].
Clients should direct requests to the Photographer who delivered their gallery, because the Photographer is the controller of that information. We will assist a Photographer in completing a request, and a Client who cannot reach their Photographer can contact us at [privacy@pixsie.app].
United States (including California). We do not sell personal information for money. Advertising cookies on our marketing pages may be considered "sharing" for cross-context behavioral advertising under California law; those are set only with consent, and we honor Global Privacy Control (GPC) signals. We will not discriminate against you for exercising these rights.
EEA and UK. You may lodge a complaint with your local data protection authority. Controllership is set out in Section 3.
11. Children
Pixsie Studio is for business use and Photographers must be at least 18. We do not knowingly collect account information from children. Photographs delivered through a Collection may include children; that Content is the Photographer's responsibility as set out in Section 3. If you believe we hold a child's personal information improperly, contact us at [privacy@pixsie.app] and we will delete it.
12. International transfers
We operate from the United States. If you use Pixsie Studio from elsewhere, information will be transferred to and processed in the United States and other countries whose data protection laws may differ from your own. Where required, we use appropriate safeguards for those transfers.
13. Changes to this Policy
We may update this Policy. When we make material changes we will update the date above and give notice to the email on the account. Continued use of Pixsie Studio after an update means you accept the revised Policy.
14. Contact
Heterodox LLC Suffolk County, NY Email: [privacy@pixsie.app]