Legal
Customer media retention
Effective 2026-06-16.
Storage
Originals and generated derivatives are stored in private object storage. Pictage.ai generates short-lived signed URLs only after server-side authorization confirms the viewer can access the workspace or gallery.
Retention
- Active account media is retained while the account is active and within plan limits.
- Incomplete, failed, duplicate, abandoned, unsafe, or policy-violating uploads may be deleted sooner.
- Generated derivatives may be regenerated or removed to control storage cost.
- Routine backups roll off under the backup schedule described in the Privacy Policy.
AI provider processing
When you enable AI features, Pictage sends the minimum input needed for the task, such as downscaled images, EXIF metadata, and text, to third-party AI vendors. Full-resolution originals are not sent. These vendors are not operated under zero-retention terms: under their standard commercial terms they may retain the inputs we send for up to 30 days for abuse monitoring, safety, and security before deletion, and do not use them to train their models. See the AI provider policy for details.
Biometric identifiers
Face embeddings and person clusters are optional and require a separate workspace owner consent. They are deleted on withdrawal or when the grouping purpose ends, and no later than three years after last use. We do not sell this data. Closed-eyes flags are not biometric identifiers. See the biometric consent and retention policy.
Deletion and removal
Account deletion removes active workspace media from the application path. Operator removals can immediately remove media from delivery while a storage purge or backup expiration completes.
Third-party subjects (client data requests)
A photographer's clients may have personal data in the product, such as names, emails, and phone numbers, without holding a Pictage account. On a verified request from such a subject, Pictage runs a deterministic sweep across every table that holds that data and either exports it or erases it within a 30-day service-level window. Erasure replaces the subject's identifying fields with an anonymized token in place. Records we must keep for financial or legal retention, such as invoices, orders, and signed contracts, are retained with only the identifying fields anonymized, not deleted. Every request is logged with its intake, decision, and completion timestamps.
EXIF and GPS
Generated derivatives are intended for client delivery and should not expose unnecessary metadata. If a derivative path cannot strip metadata, it must be documented as a blocker before broader release.