Pixel Studio · Legal

私隱政策
Privacy Policy

我們以本機編輯為核心,只在你選擇登入、雲端同步、分享或使用網上 AI 功能時處理所需資料。

Google Account data summary

Google Sign-In is optional. Pixel Studio requests only the openid, email, and profile scopes. We use the Google subject ID, email address, display name, and profile image URL returned by sign-in to create or find a Pixel Studio account, show account details, and associate optional cloud projects with the correct account.

Pixel Studio does not read Google Drive or Google Photos, sell Google user data, use it for targeted advertising, or use it to train AI models. Supabase Auth stores the identity record and the Pixel Studio Worker stores the minimum account and project metadata in access-controlled Cloudflare storage. Images are uploaded only when you choose a cloud, sharing, or AI feature. You can revoke access in your Google Account settings or request account and data deletion at [email protected].

繁體中文

生效及最後更新日期:2026 年 9 月 15 日

本政策適用於位於 pixels.mrhalk.com 的 Pixel Studio 圖像編輯器及其相關帳號、雲端同步、分享與 AI 功能。

1. 我們處理的資料

  • 本機編輯資料:未登入時,專案、工作階段、自動儲存、偏好及 PWA 快取主要保存在你的瀏覽器。除非你選擇下列網上功能,Pixel Studio 不會自動上傳本機圖片。
  • 帳號資料:使用 Google 登入時,Google 與 Supabase Auth 會提供身份識別碼、電郵地址、顯示名稱及頭像等基本個人資料。Pixel Studio 只要求登入所需的 openid、email 及 profile 權限,不要求 Google Drive 或 Google Photos 存取權。
  • 雲端專案:當你主動儲存或同步到雲端,我們會處理專案名稱、完整可編輯專案檔、縮圖、大小、版本、雜湊值及同步狀態。專案內容存放於私有物件儲存空間。
  • AI 與分享內容:只有當你使用 AI 工具時,該操作所需的圖片、遮色片和提示文字才會傳送到處理服務。你建立公開分享連結時,持有連結的人可能存取相關內容。
  • 技術及使用資料:為提供服務、防止濫用及控制費用,我們可能記錄請求時間、操作或模型名稱、狀態、估算費用、IP 地址、錯誤資料及管理操作紀錄。個人 API token 只保存不可逆雜湊及相關中繼資料,不保存可再次顯示的原始 token。

2. Google 帳戶資料的具體用途

Pixel Studio 使用 Google Sign-In 只作身份驗證,不會使用 Google 帳戶來讀取你的雲端檔案。登入流程可能提供以下資料:Google 帳戶的穩定識別碼(subject ID)、電郵地址、顯示名稱及個人頭像網址。這些資料用於建立或尋找你的 Pixel Studio 帳號、顯示帳號資料、把雲端專案及個人 API token 綁定到正確帳號,以及執行帳號安全和管理操作。

上述身份資料會由 Supabase Auth 保留,必要的帳號資料快照及狀態會由 Pixel Studio 的 Cloudflare Worker 儲存在受存取控制的資料庫。Pixel Studio 不會把 Google user data 出售、用作廣告定向、用作訓練 AI 模型,或交給 AI 服務處理;除非你主動使用雲端、分享或 AI 功能,登入本身不會上載你的圖片。身份資料會在帳號有效期間保留;如你要求刪除帳號及相關資料,我們會按可行的驗證、服務商及法定保存要求處理刪除。你可以在 Google 帳戶的第三方連結設定撤銷授權,並可使用 Google OAuth 畫面所列的支援聯絡資料提出刪除要求。

3. 使用目的

我們使用上述資料來驗證帳號、同步及還原專案、提供 AI 與分享功能、執行配額和速率限制、保障服務安全、調查錯誤,以及維持管理及審計紀錄。我們不出售個人資料,也不使用你的圖片作廣告定向。

4. 服務供應商

Pixel Studio 使用 Google 提供登入、Supabase 提供身份驗證,以及 Cloudflare 提供網站、Worker、資料庫、快取與物件儲存。當你選用 AI 功能時,所需內容可能交由 Replicate 或該功能標示的模型/服務供應商處理。各供應商會按其政策及我們為提供功能而作出的配置處理資料。

5. 保存與安全

本機資料會保留至你清除瀏覽器資料或使用應用程式內的清除功能。雲端專案一般保留至你刪除;系統可能在短暫寬限期內保留已刪除版本,以支援復原及安全清理。臨時上傳和 AI 暫存內容會由排程清理。必要的安全、費用及審計紀錄可能保存較長時間。我們使用傳輸加密、私有儲存、短效簽署網址及存取控制,但任何網上服務均不能保證絕對安全。

6. 你的選擇與控制

你可以不登入並只使用本機編輯;亦可刪除雲端專案、撤銷個人 token、登出及清除此裝置的帳號快取。你可在 Google 帳戶設定撤銷 Pixel Studio 的登入授權。帳號或私隱查詢可使用 Google OAuth 畫面所列的支援聯絡資料;即使無法登入,仍可從本網站公開查看本政策。

7. 跨境處理與兒童

服務供應商可能在你所在地以外的地區處理資料。Pixel Studio 並非特別為未達所在地數碼同意年齡的兒童而設;如監護人認為兒童不當提供了資料,請使用支援聯絡資料提出刪除要求。

8. 政策變更

功能或法律要求改變時,我們可能更新本政策,並在本頁修改「最後更新日期」。重大改變會在合理情況下於應用程式內提供提示。

9. 聯絡及刪除要求

如要查詢私隱、撤銷登入或要求刪除帳號及相關資料,請電郵至 [email protected]。即使無法登入,你仍可直接使用這個公開聯絡方式。

English

Effective and last updated: September 15, 2026

This policy applies to the Pixel Studio image editor at pixels.mrhalk.com and its related account, cloud sync, sharing, and AI features.

1. Information we process

  • Local editing data: When you are signed out, projects, sessions, autosaves, preferences, and PWA caches are mainly stored in your browser. Pixel Studio does not automatically upload local images unless you choose an online feature described below.
  • Account data: When you sign in with Google, Google and Supabase Auth provide basic identity data such as an identifier, email address, display name, and avatar. Pixel Studio requests only the openid, email, and profile scopes needed for sign-in, and does not request Google Drive or Google Photos access.
  • Cloud projects: When you choose to save or sync to the cloud, we process the project name, complete editable project file, thumbnail, size, revision, digest, and sync status. Project content is kept in private object storage.
  • AI and shared content: Images, masks, and prompts needed for an operation are transmitted only when you use an online AI tool. When you create a public share link, anyone who has that link may be able to access the shared content.
  • Technical and usage data: To operate the service, prevent abuse, and control costs, we may record request times, action or model names, status, estimated cost, IP address, error details, and administrative audit events. Personal API tokens are stored only as irreversible hashes with metadata; the original token cannot be displayed again.

2. Specific use of Google Account data

Pixel Studio uses Google Sign-In only for identity authentication and does not use your Google Account to read files in Google Drive or other Google services. The sign-in flow may provide a stable Google subject ID, email address, display name, and profile image URL. We use this information to create or find your Pixel Studio account, show account details, attach cloud projects and personal API tokens to the correct account, and perform account security and administrative actions.

Supabase Auth retains the identity record, while necessary account snapshots and status are stored by the Pixel Studio Cloudflare Worker in access-controlled database storage. Pixel Studio does not sell Google user data, use it for targeted advertising, use it to train AI models, or send it to an AI provider. Signing in alone does not upload your images; images are uploaded only when you choose a cloud, sharing, or AI feature. Identity data is retained while the account is active. If you request account and related data deletion, we process it subject to reasonable verification, provider constraints, and legally required retention. You can revoke access in your Google Account's third-party connections and use the support contact shown on the Google OAuth screen to request deletion.

3. How we use information

We use this information to authenticate accounts, sync and restore projects, provide AI and sharing features, enforce quotas and rate limits, protect the service, investigate errors, and maintain administrative and audit records. We do not sell personal information or use your images for targeted advertising.

4. Service providers

Pixel Studio uses Google for sign-in, Supabase for authentication, and Cloudflare for website hosting, Workers, databases, caching, and object storage. When you choose an AI feature, required content may be processed by Replicate or the model or service provider identified by that feature. Each provider processes data under its own policies and our service configuration.

5. Retention and security

Local data remains until you clear browser data or use an in-app clearing control. Cloud projects are generally retained until you delete them; deleted versions may remain for a short grace period to support recovery and safe cleanup. Temporary uploads and AI objects are removed by scheduled cleanup. Security, cost, and audit records may be retained for longer where necessary. We use encrypted transport, private storage, short-lived signed URLs, and access controls, but no online service can guarantee absolute security.

6. Your choices and controls

You may remain signed out and edit locally. You may also delete cloud projects, revoke personal tokens, sign out, and clear account data stored on your device. You can revoke Pixel Studio's sign-in access in your Google Account settings. For account or privacy requests, use the support contact shown on the Google OAuth screen. This policy remains publicly available even if you cannot sign in.

7. International processing and children

Service providers may process information outside your location. Pixel Studio is not directed specifically to children below the age of digital consent in their location. A guardian who believes a child provided information improperly should use the support contact to request deletion.

8. Changes to this policy

We may update this policy as features or legal requirements change. We will change the “last updated” date on this page and, where reasonable, provide an in-app notice for material changes.

9. Contact and deletion requests

For privacy questions, sign-in revocation, or a request to delete your account and related data, email [email protected]. This contact remains available even if you cannot sign in.