Privacy Policy
Last updated: August 3, 2026
ModyPixl, operated by MVIRAI (“we”, “our”, “us”), is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, how we use it, how long we keep it, and what rights you have, when you use the ModyPixl app and website (“Services”).
Short version
We collect the minimum needed to run your account, AI generations, and subscription / credit billing. AI inputs (your photos, prompts) are sent only to our own servers, auto-screened for safety, processed, and not retained beyond the request. Uploaded face and voice inputs are deleted once your generation finishes. Generated results are held only for a short download window and then purged (we keep only a one-way image hash for safety-compliance auditing) — so download anything you want to keep. We never use your content or prompts to train AI models. We never sell your data or share it with anyone beyond the infrastructure providers needed to run the service. Free accounts may be shown advertising, with consent where required. You have full GDPR / DPDP / CCPA rights to access, export, and delete your data.
0. Our Three Data Promises
Everything below is detail. These three commitments are the substance, and they apply to every photo, prompt, video, audio clip, and design you put into ModyPixl:
- We do not train on your content. Your uploads, prompts, and generated outputs are never used to train, fine-tune, evaluate, or improve any AI model — ours or anyone else's.
- We do not sell or share your content. We do not sell, rent, licence, or trade your content or personal data. We share it only with the infrastructure processors strictly needed to run the service (authentication, hosting, our own AI infrastructure, payment processing, abuse prevention), each acting on our instructions and only for that purpose. We never hand your content to a third-party AI model provider, a data broker, or an advertiser.
- Face and voice uploads are not retained. Photos and audio you upload for an AI template are used for that one generation and deleted afterwards. We keep no face or voice embeddings, no biometric templates, and no copy of the file.
1. Data We Collect
We collect information you provide directly and information collected automatically:
- Account data: Name, email address, and authentication credentials (Firebase Auth) when you sign up.
- Billing data: Your subscription plan and status, credit balance, top-up history, and per-generation credit ledger entries (stored securely). We do not store payment card details — those are held by our payment processors (Razorpay, Paddle, Apple, Google).
- Generation inputs (transient): Photos, prompts, audio reference, and language preferences you send when using AI templates. These are processed and discarded — see Section 3.
- Generation outputs: The AI image / video / audio result is held on our servers only for a short download window — long enough for you to fetch it from My Generations — and is then purged. The remaining time is shown on the result itself. Download anything you want to keep: once the window closes the result is gone and we cannot recover it.
- Usage and security data: Feature usage, generation success/failure counts, hashed IP, device fingerprint (one-way hash), crash reports, and security-event logs used to detect abuse and run our rate-limit / anomaly guard. Used to keep the Services safe and reliable.
- Device data: Device type, OS version, app version, locale — for compatibility and bug triage.
2. How AI Generations Are Processed
When you tap “Generate” on an AI template, the following happens:
- Your inputs (template selection, your photo if any, prompt, language) are sent securely from your device to our servers, encrypted in transit and at the application layer.
- Your prompt is checked against our content policy. Prompts that violate it are rejected before generation begins.
- Automated safety screening of uploads: every uploaded image and video is automatically analysed by an on-server safety classifier solely to screen for prohibited content (nudity / sexual content and related policy violations) at generation time. Screening is fully automated, happens in memory as part of the request, and is not used for profiling, identification, advertising, or any other purpose. Requests that fail screening are blocked before generation and the credits are refunded.
- Your request is processed on AI infrastructure we operate. Inputs are held in memory only for the duration of the generation.
- The output (image / video / audio) is returned to your device with embedded machine-readable AI-provenance metadata (see Terms §4).
- Your inputs are deleted. Uploaded images, audio, and prompts are not retained on our systems once the generation finishes.
- Your result is held briefly, then purged. The output waits in My Generations for a short download window — a matter of hours, with the remaining time shown on the result — and is purged as soon as that window closes or shortly after you have downloaded it. We do not archive it, and we cannot restore it afterwards, so save what you want to keep. All that remains is a short-lived security and abuse-detection log recording template ID, success/failure, and elapsed time — no prompt or image content — plus a one-way cryptographic hash of each uploaded image, kept as an audit record for safety compliance. The hash cannot be reversed to reconstruct your image and is not used for advertising, profiling, or model training.
We do not use your inputs or outputs to train, fine-tune, or evaluate any AI model, nor do we sell them or share them with third-party model providers, data brokers, or advertisers. All AI processing runs on infrastructure we operate.
3. Face and Voice Data — Consent and Sensitivity
Photos containing faces and audio containing voices receive additional protections under GDPR (Art. 9 special categories) and India's DPDP Act:
- You must affirm consent before uploading a face or voice (the in-app consent checkbox).
- Face and voice inputs are processed strictly for the requested generation and deleted immediately afterward — they are never kept.
- We do not perform identity recognition, face matching, or any biometric profiling against your uploads.
- We do not retain face / voice embeddings or biometric templates beyond the generation.
- We never use a face or voice you upload to train, fine-tune, or evaluate any AI model, and we never share it with anyone outside the infrastructure processing that one request.
You are responsible for ensuring that any face or voice you upload belongs either to you or to a person who has given you clear permission — see Terms §7.
4. On-Device Processing (No Server Calls)
Several editor features run entirely on-device — no inputs leave your phone:
- Body Editor (on-device body and face reshaping)
- Face contour detection inside the photo editor
- Background blur, healing/clone, filters, adjustments, crop, rotation
- Canvas editor — layers, text, shapes, drawing, exports
No biometric, body-measurement, or sensor data from these features is transmitted to our servers.
5. Cookies, Advertising, and Tracking
The ModyPixl website uses essential cookies for authentication and preferences, and minimal analytics cookies (anonymised usage metrics) to improve the product. See our Cookie Policy for details.
Advertising. Ad-supported surfaces across the website and apps may show advertising — served by Google (AdSense on the website, AdMob in the apps), including optional rewarded ads you can choose to watch. To serve and measure ads, Google and its advertising partners may use advertising cookies and device advertising identifiers. This applies to both logged-in and logged-out users on ad-supported surfaces. Google acts as an independent provider for this data; see Google's advertising policies for how it uses ad data.
Consent and opt-out. Where required by law (GDPR in the EU/UK, India's DPDP Act 2023, and similar regimes), advertising cookies and identifiers are used only with your consent, collected via the consent prompt shown in your region. You can withdraw consent or switch to non-personalised ads at any time via the in-app / on-site privacy settings, your device's ad-tracking settings, or adssettings.google.com. Subscribers are not shown third-party advertising on paid surfaces.
6. Third-Party Services (Processors Only)
The providers below are the infrastructure processors we need in order to run ModyPixl. Each handles only the data required for its function, acts on our instructions, and is not permitted to use your content for its own purposes or to train models on it. This list is the full extent of who touches your data — we do not share or sell it to anyone else:
- Firebase (Google) — account authentication, security verification, and storage of account and wallet data.
- ModyPixl AI infrastructure — AI generation runs on systems we operate (no third-party AI provider has access to your inputs).
- Razorpay — payment processing for subscription plans (worldwide, charged in INR) and for credit-pack purchases in supported regions.
- Paddle.com — web payments for one-time credit packs outside Razorpay regions (Merchant of Record — handles tax and chargebacks).
- RevenueCat — mobile in-app purchase receipt validation.
- Apple App Store / Google Play — mobile credit purchases.
- Google AdSense / AdMob — advertising on free-account surfaces (website and apps), including optional rewarded ads (subject to your consent where required — see Section 5).
- Cloudflare — DDoS protection, edge caching, and traffic filtering for our backend.
- On-device processing libraries — run entirely on your device; no data is sent to anyone for these features.
7. Data Retention
We retain data for the minimum necessary period:
- Account data — for as long as your account is active. Deleted within 30 days of account closure (some financial records kept up to 7 years for tax / accounting compliance under Indian law).
- Subscription and credit ledger — retained for the financial-records period (typically 7 years) for audit and refund/chargeback dispute resolution.
- Generation inputs (prompts / photos / audio, including faces and voices) — deleted once the generation finishes; not retained beyond the generation request. A one-way hash of each uploaded image is kept as a safety-compliance audit record (see Section 2).
- Generation outputs — retained only for a short download window (hours, not days) so you can fetch the result, then purged. Download promptly; expired results cannot be recovered or regenerated for free.
- Security / abuse logs — retained up to 90 days for anomaly detection.
- Cloud sync of local design files — only stored if you explicitly enable cloud sync (off by default).
8. Your Rights (GDPR / DPDP / CCPA)
Depending on your location, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (“right to be forgotten”) — subject to lawful retention obligations for financial records.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing or withdraw consent.
- Opt out of the sale or sharing of personal information (CCPA / CPRA). We do not sell your personal information.
- Lodge a complaint with your local data-protection authority (GDPR / DPDP supervisory authority).
- Nominate a representative to exercise rights on your behalf in the event of incapacity or death (India DPDP Act 2023).
To exercise any of these rights, email us at contact@modypixl.com. We respond within 30 days (or 45 days for complex requests, with notice). There is no charge for reasonable requests.
9. International Data Transfers
Our servers may be hosted in multiple regions (currently primarily EU and North America). Where personal data is transferred outside your home jurisdiction, we rely on standard contractual clauses or other recognised safeguards where required by GDPR / DPDP / UK GDPR.
10. India DPDP Act — Specific Disclosures
ModyPixl processes personal data within the meaning of India's Digital Personal Data Protection Act, 2023 (“DPDP”). The grounds we rely on for processing:
- Consent — for AI generation using face / voice uploads (see Section 3) and for personalised advertising on free accounts (see Section 5).
- Legitimate use — for account operation, security, fraud prevention, and abuse detection.
- Performance of a contract — for delivering your subscription plan and paid generations using your credits.
You can withdraw consent at any time by emailing us. Withdrawal does not affect processing done before withdrawal but stops the relevant processing going forward.
11. EU AI Act — Synthetic Content Labelling
ModyPixl embeds machine-readable AI-provenance metadata in every AI-generated output — PNG provenance text chunks for images and equivalent container metadata for video and audio, including the IPTC digital source type trainedAlgorithmicMedia — supporting Article 50 of the EU AI Act for generative AI systems. This labelling is always applied and must not be removed when you share the output. When you publish AI Output on third-party platforms, you must also set those platforms' AI-content disclosure flags — see Terms §9.
12. Children's Privacy
The minimum age to use ModyPixl is 13. We do not knowingly collect personal information from children under 13, and accounts we identify as belonging to an under-13 user are closed and their data deleted.
Users aged 13–15 face additional restrictions. Where local law sets a higher digital-consent age (16 in several EU member states, and the parental-consent requirement under India's DPDP Act), a parent or guardian must consent before the account is used, and you must obtain that consent before using AI generation involving face or voice uploads or before enabling personalised advertising. If you believe a child has provided us with personal data, contact us at contact@modypixl.com and we will delete it immediately.
13. Data Security
We implement defence-in-depth security measures including:
- TLS encryption for all data in transit.
- Cryptographic request verification on every API call to prevent tampering and replay.
- Industry-standard encryption in transit and additional application-layer encryption on sensitive requests.
- Verified sign-in and app integrity checks on every request.
- Encrypted credentials for upstream AI infrastructure (the key never appears in client-readable form).
- Edge filtering, anomaly detection, and rate limiting.
- Multi-language content moderation on every prompt and reference image.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security; but we work continuously to improve.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. Continued use of the Services after changes constitutes acceptance.
15. Contact Us
For privacy questions, data-subject requests, or to contact our Grievance Officer (India DPDP Act), email us at contact@modypixl.com. We respond within 30 days for routine requests and within 7 days for the initial acknowledgement.