Privacy Policy
Last updated: 29 September 2026
1. The short version
- We ask for your name and email so you can sign in and keep your subscription across devices.
- The photo or short video clip you check is sent to be analysed and then discarded. We never store it, publish it, or add it to any library.
- We count how many checks you have made, because the subscription includes a set number and free checks are unlocked by watching an ad.
- The app shows rewarded ads (Google AdMob) to people who are not subscribed. Subscribers see no ads.
- We use Google Analytics for Firebase to see which screens are used and how checks go. It never sees your photos, and you can switch it off in Settings.
- If you say yes to notifications, we can send you occasional tips and offers. You can turn them off in Settings at any time.
- If the app crashes, a crash report (Firebase Crashlytics) tells us where. It never contains your photos, clips or account details.
2. What we collect
Account details. When you sign in with Google or Apple we receive your name, email address and profile picture from that provider, and store them in Firebase Authentication. If you use Apple's "Hide My Email", we only ever see the relay address Apple gives us.
The photo or clip you check. Described in full in section 3.
Usage counters. For each account we store the number of checks and Deep checks made, the timestamps of the current daily and monthly windows, and how many free checks have been used. This is what enforces the allowance included in a subscription and prevents abuse of a paid service. It contains no image data.
Subscription status. Whether your subscription is active, when it expires, which product was purchased and which store it came from, the plan (monthly or yearly), whether it is a free trial, whether it was made in the store's test environment or for real, when it started, when we last verified it with the store, and a hashed (one-way) form of the store's transaction identifier so the same purchase cannot be claimed by two accounts. We never hold the store receipt itself or your payment details — Apple and Google do.
Ad unlocks. If you are not subscribed, a check is unlocked by watching a rewarded ad. We record that an ad was completed (a one-time token and Google's transaction reference) so the check it paid for can be granted exactly once, and we count how many checks you have unlocked this way each day.
Advertising data (non-subscribers only). Ads are served by Google AdMob. To do that, the AdMob SDK on your device may collect your device's advertising identifier, IP address, approximate location derived from it, device and app information, and how you interact with the ads. What is collected depends on the choices you make in the consent prompt (UK/EEA) and, on iPhone, in the tracking permission prompt: decline either and you still get ads, just not personalised ones. Google's own practices are described at https://policies.google.com/technologies/ads. We never send your photos, your verdicts, or your account details to the ad network.
Reminders. If you switch on "Remind me when checks reset" in Settings, the app schedules one notification on your device for the moment your daily checks come back. This reminder is scheduled on the phone itself.
Push notifications (tips & offers). If you allow notifications for the app, we store a push token for your device (issued by Apple or Google through Firebase Cloud Messaging) together with your account's internal ID (not your name or email), the platform, the app version and whether you said yes to tips & offers. Only if you said yes do we use it to send you occasional messages about new features and Pro offers. Turn "Tips & offers" off in Settings, or turn notifications off for the app in your phone's settings, and we stop. The token is deleted when you sign out on that device or delete your account.
Alerts to us. When a new account is created, and when a new subscription starts, our server sends a short notification to the phones of the app's administrators. For a sign-up it names the sign-in provider (Google or Apple); for a subscription, the plan and the store. In both cases the email address is masked (for example j•••@gmail.com), and nothing else about you is included.
In-app offers. The app may show an offer card, for example a Pro free trial. Whether it appears is decided on your phone from how many checks you have made and whether you are subscribed. Whether you opened or dismissed it is counted in usage analytics (below), which you can switch off.
Usage analytics. We use Google Analytics for Firebase to understand how the app is used: which screens are opened, that a check ran and which verdict band it got (AI, real or unclear), that a paywall or an offer was shown and what you tapped, that an ad unlock finished, your answer to the notifications question, that a notification was opened, sign-ins, and that a purchase was made. With these events Google receives an app-instance identifier, your account's internal ID (not your name or email), device and app information, and an approximate location derived from your IP address. It never receives your photos, anything else about their content, or your email address. You can switch analytics off at any time in Settings → Share usage analytics.
Crash reports. The app uses Firebase Crashlytics to collect crash reports so we can find and fix bugs: the device model, OS version, app version, the stack trace of the crash and an anonymous per-install identifier. A crash report never contains your photos or clips, your verdicts, or your account details.
What we do not collect. We do not collect contacts, calendar, health data or precise location. We do not collect face data or any other biometric data. Apart from the ad SDK, analytics and crash reporting, the app makes no network requests other than signing in, checking a photo or clip, verifying a purchase, loading offers and registering for notifications.
3. How your photo or clip is handled
This is the part most people care about, so it is spelled out step by step.
- You choose a photo, or a video clip of up to 15 seconds, from your device. A photo is resized on your device before it is sent; a clip is sent as it is.
- The photo or clip is sent over an encrypted connection (HTTPS) to our own server function.
- That function forwards it to Sightengine, the specialist provider whose models perform the detection, and receives scores back. Every photo check asks two questions: how likely the image is AI-generated, and how good its technical quality is (low quality is the usual reason a verdict is unclear). A clip is checked frame by frame: Sightengine samples a few frames and asks the first question of each, and the verdict is built from those scores. A "Deep check" sends the photo a second time and asks one more question: whether a real person's face was swapped in.
- The scores are turned into the verdict you see. The photo or clip itself is then gone.
We do not write your photo or clip to any database, bucket or file store at any point. It exists only in the memory of the server function for the few seconds the check takes — which is also why a Deep check uploads the photo again rather than reusing a stored copy: there is none. There is no copy for us to lose, disclose or be compelled to hand over.
Faces. A Deep check looks for the visual signs of a face swap in the picture you chose. It does not identify anyone, does not compare the face with any other image or database, and does not create a face template, facial geometry or any other biometric data. The only thing produced is a score for the whole image, and the picture is discarded like any other check. No face data is collected, stored, shared or retained — by us or by Sightengine.
Sightengine processes the photo or clip to return a score and does not share it with any third party. We do not submit your photos or clips to Sightengine's feedback or training mechanisms, so they are not used to train anyone's models — ours or theirs.
We never publish a photo or clip, never make it visible to another user, and no person at Pixo looks at it.
4. Why we are allowed to process it (legal basis)
Under UK and EU data protection law:
- Performance of a contract — signing you in, checking your photos, and running your subscription. Without this processing the app cannot do the thing you installed it for.
- Legitimate interests — the usage counters and ad-unlock records, which protect a paid service from abuse and protect us from unbounded costs; the serving of non-personalised ads to non-subscribers; crash reporting; and usage analytics, which you can switch off in Settings.
- Consent — push notifications with tips and offers, personalised advertising, and on iPhone any use of the advertising identifier. You can withdraw it at any time: in the app through the privacy options in the ad consent form, or in your device's settings (iPhone: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads).
- Legal obligation — keeping records of purchases where tax or consumer law requires it.
5. Who else processes your data
| Processor | What they handle | Why |
|---|---|---|
| Google (Firebase) | Account details, usage counters, subscription status, the server function that receives your photo | Authentication, database and hosting |
| Google (Firebase Cloud Messaging) | Push token, platform and app version (only if you allow notifications) | Delivering notifications |
| Google Analytics for Firebase | App-instance ID, account ID, device and app information, usage events, approximate location from IP | Usage analytics |
| Google (Firebase Crashlytics) | Crash reports: device model, OS version, app version, the crash stack trace, an anonymous per-install identifier | Finding and fixing crashes |
| Sightengine | The photo or clip, at the moment of checking | The detection itself |
| Apple | Purchase and subscription records | Sign in with Apple, App Store billing |
| Google Play | Purchase and subscription records | Play billing |
| Google AdMob and its advertising partners | Advertising identifier, IP, device and interaction data (non-subscribers only) | Serving and measuring rewarded ads |
We do not sell your data. Advertising data is shared with Google AdMob and, for personalised ads, with the advertising partners listed in the consent prompt — that sharing is what the prompt is asking you about, and you can decline it. Nobody else receives anything.
6. International transfers
Our processors operate outside the United Kingdom, including in the United States and the European Economic Area. Where data leaves the UK we rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or an adequacy decision, as applicable to the processor concerned.
7. How long we keep things
- Your photo or clip — not kept. Discarded as soon as the check returns.
- Account details — until you delete your account, after which they are removed from our systems.
- Usage counters and ad-unlock records — they roll forward continuously; nothing older than the current 30-day window is meaningful, and they are deleted with your account. Ad tokens expire fifteen minutes after they are issued whether or not they are used.
- Push tokens — until you sign out on that device, turn notifications off (the token then stops working and is removed the next time we try it), or delete your account.
- Analytics events — kept by Google Analytics for at most 14 months, then deleted.
- Crash reports — kept by Firebase Crashlytics for 90 days, then deleted.
- Subscription records — the subscription and subscription-link records in our database are deleted with your account. Apple and Google keep their own records of your purchases, and we keep purchase records only for as long as tax and accounting law requires.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or transfer it elsewhere. You can also withdraw consent where we relied on it.
You can delete your account yourself at any time from Settings → Delete account in the app. That removes your sign-in, your usage counters, your ad-unlock records, the notification tokens of your devices, and your subscription and subscription-link records from our systems immediately. (A subscription is billed by Apple or Google, not by us, so cancel it in your store account as well.)
For anything else, or if you no longer have the app installed, email support@pixovault.com. We reply within 30 days.
If you are unhappy with our response you can complain to the UK Information Commissioner's Office at https://ico.org.uk, or to your local supervisory authority in the EEA.
9. Children
Pixo AI Detector is not directed at children and we do not knowingly collect data from anyone under 13. If you believe a child has given us data, email us and we will delete it.
10. Security
Everything the app sends travels over HTTPS. Account and subscription data sit behind rules that make them unreadable and unwritable by any other user, and the usage counters can only be written by our server, never by an app. An ad only unlocks a check once Google has confirmed to our server, with a signed message, that it was completed — the app itself cannot grant one. Credentials for the detection provider exist only on the server; they are not present in the app you download.
11. Changes to this policy
If we change how any of this works we will update this page and the date at the top. Where a change is significant we will tell you in the app.
12. Contact
Pixo Tech Ltd 566 London Road, Grays, London RM20 3BJ, United Kingdom support@pixovault.com