This Privacy Policy explains how Pix Me (pixme.org) collects, uses, shares and protects personal information when you read our online magazine, subscribe to our newsletter, contact us, or use the AI-assisted visual services of our studio, Pixme AI. We have written it in plain English and tried to be specific about what we actually do, rather than listing everything a website could theoretically do. It covers the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), along with other privacy laws that may apply to you.
Key takeaways
- Pix Me is a static website. We do not run analytics or advertising trackers by default; analytics such as Google Analytics 4 may only be switched on if you give consent.
- We collect only what you give us: contact form details, your newsletter email address, and the files and instructions you send us for a project.
- Photos you upload, including images of faces, are used only to deliver the service you ordered. We do not use them to train AI models unless you explicitly opt in.
- Client photos are normally deleted within 30 days after final delivery unless you ask us to keep them longer or delete them sooner.
- We do not sell or share personal information for cross-context behavioral advertising.
- You can contact [email protected] at any time to access, correct, delete or export your data, or to object to processing.
Effective date: September 21, 2026
Last updated: September 21, 2026
Who we are and scope of this policy
In this policy, "Pix Me", "Pixme", "we", "us" and "our" refer to the operator of the website at www.pixme.org, including the online magazine and the Pixme AI visual content studio. "You" means any person who visits the site, reads our articles, subscribes to our newsletter, contacts us, or becomes a client.
This policy applies to personal information we process through:
- the website www.pixme.org and all of its pages, including the blog and category pages;
- the contact form on our contact page and any email correspondence that follows;
- our newsletter;
- the services described on our services page: AI photo enhancement, AI product photography, AI headshots and portrait retouching, content creation, and SEO and search marketing.
This policy does not apply to third-party websites, platforms or services that we link to, even if you reach them from our pages. Those services have their own privacy notices, and we encourage you to read them.
This policy should be read together with our Cookie Policy, our Terms of Service and our Disclaimer.
Data controller and how to contact us
For the purposes of the GDPR and UK GDPR, Pix Me (pixme.org) is the data controller of personal information collected through the website, the newsletter and general enquiries. That means we decide why and how that information is processed and we are responsible for handling it lawfully.
When we deliver a service for a business client and that client provides us with images or information about other people (for example, photos of their staff for team headshots, or images featuring their customers), we may act as a processor or service provider on the client's behalf for that material. In that situation, the client is responsible for having a lawful basis to share those images with us and for informing the people concerned, and we process the material only on the client's documented instructions. Where we act as a controller of project data (for example, for our own billing records), this policy applies directly.
You can reach us about anything in this policy in the following ways:
- Privacy and data protection requests: [email protected]
- General questions and project enquiries: [email protected]
- Our contact form
We have not appointed a statutory Data Protection Officer because, given the size and nature of our processing, we are not currently required to. Privacy questions are handled directly by the person responsible for data protection at Pix Me via the privacy address above. Where the law requires us to appoint a representative in the EU or UK, we will publish the representative's details in this section.
Categories of personal information we collect
We aim to collect the minimum amount of information needed for each purpose. Depending on how you interact with us, we may process the following categories of personal information.
Information you give us through the contact form
- Name — so we know how to address you.
- Email address — so we can reply.
- Phone number (optional) — only if you choose to provide it and would like a call.
- Service of interest — for example, AI headshots or SEO and search marketing.
- Budget range — so we can suggest a realistic scope.
- Message — whatever you choose to tell us about your project. Please avoid including sensitive information in this field unless it is necessary.
- Consent confirmation — a record that you ticked the consent box agreeing to us processing your enquiry, together with the date and time of submission.
Newsletter information
- Email address and the date you subscribed.
- Subscription status (subscribed, unsubscribed) and, if our email provider supports it, confirmation of your double opt-in.
- Basic delivery data such as whether an email bounced. If we ever enable open or click tracking in newsletters, we will tell you in the sign-up form and in this policy, and in jurisdictions where consent is required we will only do so with consent.
Client and project information
- Identity and contact details of the client or the client's representative.
- Business details such as company name, website, billing address and tax information where required for invoicing.
- Project content — photos, product images, logos, brand guidelines, written briefs, drafts, keyword lists and website access you choose to give us.
- Images of people, including faces — for example, selfies and portrait photos submitted for AI headshots or retouching. See the section on photo and face data below.
- Communications — emails, feedback, revision requests and approvals.
- Transaction information — amounts, dates, invoice numbers and payment status. We do not receive or store your full card number; payments are handled by a payment processor.
Technical information
- Server and security logs — our hosting provider automatically records standard request data such as IP address, date and time, requested page, browser type (user agent) and referring URL. These logs are used for security, troubleshooting and preventing abuse.
- Cookie-consent preference — your cookie choice is stored in your own browser's localStorage under the key
pixme_cookie_consent. It stays on your device and is not sent to us. - Analytics data (only with consent) — if analytics are enabled and you accept them, information such as pages viewed, approximate location (country or city level), device type, and a pseudonymous identifier. See Analytics.
Information we do not intentionally collect
We do not ask for, and ask you not to send us, special category data such as information about health, religion, political opinions, sexual orientation or ethnic origin, except where it is inherently visible in a photo you have chosen to send us. We do not create biometric templates (mathematical faceprints) for the purpose of identifying people. We do not knowingly collect information from children.
Where we get personal information
- Directly from you, when you fill in a form, subscribe, send us an email, upload files or talk to us.
- From our clients, when a business client sends us material that includes information about other people, such as employees or models in product photos.
- Automatically, through server logs and, only if you consent, analytics tools.
- From service providers, such as our payment processor confirming that a payment has been made, or our email provider confirming that a message bounced.
- From public sources, only in limited cases, for example checking a client's public website when preparing an SEO proposal they asked for.
How we use personal information and our legal bases
Under the GDPR and UK GDPR, we must have a legal basis for each use of personal information. The table below sets out what we do, which data is involved and which legal basis we rely on.
| Purpose | Data involved | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Responding to enquiries sent through the contact form or by email | Name, email, phone (optional), service, budget, message | Consent (Art. 6(1)(a)) given via the form, and steps at your request before entering a contract (Art. 6(1)(b)) |
| Preparing quotes and proposals | Contact details, project brief, budget, public website data | Steps prior to entering a contract (Art. 6(1)(b)) |
| Delivering services: photo enhancement, product photography, headshots, retouching, content creation, SEO | Project content, photos (including faces), briefs, communications | Performance of a contract (Art. 6(1)(b)); for face images, see the photo and face data section |
| Invoicing, bookkeeping and tax compliance | Name, business details, billing address, transaction records | Legal obligation (Art. 6(1)(c)) and contract (Art. 6(1)(b)) |
| Sending the newsletter | Email address, subscription status | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Remembering your cookie choice | pixme_cookie_consent value in localStorage | Legal obligation to record consent choices and legitimate interests (Art. 6(1)(c) and (f)); strictly necessary under ePrivacy rules |
| Website analytics (only if enabled) | Pseudonymous identifiers, pages viewed, device and approximate location data | Consent (Art. 6(1)(a)) |
| Keeping the website secure and preventing abuse or spam | Server logs, IP address, form submission metadata | Legitimate interests (Art. 6(1)(f)) in operating a secure service |
| Using portfolio samples or case studies | Selected deliverables, client name | Consent (Art. 6(1)(a)); we never publish images of identifiable people without their permission |
| Improving AI workflows with client images (opt-in only) | Images you specifically approve for this use | Explicit consent (Art. 6(1)(a) and, where relevant, Art. 9(2)(a)) |
| Establishing, exercising or defending legal claims | Relevant correspondence, contracts, records | Legitimate interests (Art. 6(1)(f)); Art. 9(2)(f) where special category data is involved |
Where we rely on legitimate interests, we have considered whether our interests are overridden by your rights and freedoms, and we have concluded that they are not for the uses listed. You can ask us for more information about this balancing test, and you have the right to object (see Your rights).
We will not use personal information for a new purpose that is incompatible with the purpose for which it was collected without telling you and, where required, asking for your consent.
Photos, faces and biometric considerations
Many of our services involve images of people. AI headshots and portrait retouching, in particular, require you to send us photos of your face. We treat these images with extra care, because a photograph of a person is personal data, and in some legal contexts images processed with certain technical means to uniquely identify a person can be treated as biometric data.
Our commitment: images you upload are used only to deliver the service you ordered. We do not use them to train, fine-tune or improve general AI models, and we do not share them with anyone for that purpose, unless you give separate, explicit, opt-in consent in writing. Declining has no effect on the price or quality of your order.
How face images are used
- Service delivery only. Your photos are used to produce the headshots, retouched portraits or enhanced images you requested, and for the revision rounds included in your order.
- No identification. We do not use face images to identify you, to verify your identity, or to build a database of faces. Some AI tools create temporary internal representations of a face in order to generate or edit an image; where this happens it is limited to your project, and any project-specific model or representation is deleted together with your source images.
- No sale or advertising use. We never sell face images or use them for advertising targeting.
- No publication without permission. We will not show your photos or results in our portfolio, on social media or in articles unless you give specific permission, which you can withdraw.
Legal basis for face images
We process face images to perform our contract with you. We do not process them for the purpose of uniquely identifying a natural person, which is what triggers the stricter "biometric data" rules under Article 9 of the GDPR. Where local law (for example, certain U.S. state biometric privacy laws) treats face geometry or similar data as biometric information regardless of purpose, we will obtain any written consent required by that law before the work begins, tell you the purpose and retention period, and destroy such data within the period stated below or earlier where the law requires.
Photos of other people
If you send us photos that show other people, such as colleagues for a team page, models for product images, or family members, you confirm that you have the right to do so and that those people have agreed to their images being edited with AI tools. Our Terms of Service set this out in more detail. We will refuse or stop work where we believe images have been supplied without the depicted person's consent or for a harmful purpose.
Secure transfer and storage
- Files are transferred over encrypted connections (HTTPS/TLS) using a secure upload link or file-transfer service that we provide. Please do not send face photos as ordinary email attachments if you can avoid it.
- Files are stored in access-controlled cloud storage with encryption at rest, accessible only to the people working on your project.
- Where we use a third-party AI processing service, we choose providers whose terms prohibit them from using customer inputs to train their models, and we configure available settings to disable data retention and training where such settings exist.
Retention of photos
Source photos, intermediate files and any project-specific AI representations are deleted within 30 days after final delivery of your order, unless you ask us in writing to keep them for longer (for example, to allow for future edits) or to delete them sooner. Final deliverables may be kept for the same period so that we can resend them if a download fails. You can ask for immediate deletion at any time by emailing [email protected].
AI processing and automated decision-making
Pixme AI uses artificial intelligence tools as part of an AI-assisted workflow. Examples include upscaling and denoising, background removal and replacement, lighting and color correction, generation of product scenes, portrait retouching and headshot generation, and assistance with drafting and optimizing written content and SEO research.
Important points about how we use AI:
- Human review. A person on our team reviews AI output before it is delivered to you. AI is a production tool, not a substitute for our judgment.
- No solely automated decisions with legal or similarly significant effects. We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you, within the meaning of Article 22 GDPR and UK GDPR. Decisions such as whether to accept a project, what to charge or whether to issue a refund are made by people.
- No profiling for marketing. We do not use AI to build profiles of individuals for advertising or marketing purposes.
- Limited third-party processing. Where a third-party AI provider processes your content, it acts as our processor under a written agreement, and we share only what is needed for the task.
- Transparency about outputs. AI-generated or AI-edited images may need to be labeled in some contexts. Our Terms of Service and Disclaimer explain your responsibilities when publishing AI-assisted content.
Analytics
By default, the Pix Me website runs without analytics or advertising trackers. It is a static site: pages are delivered as files, and no analytics script is loaded unless it has been enabled and you have agreed to it.
We may decide in future to enable a web analytics service, such as Google Analytics 4, to understand which articles are useful and how to improve the site. If we do:
- The analytics script will not load, and no analytics cookies will be set, until you actively choose "Accept" (or an equivalent option) in our cookie banner.
- If you decline or ignore the banner, analytics stays off.
- We will configure the service in a privacy-conscious way where the tool allows it, for example by disabling advertising features and Google signals, not sending personal information such as names or emails in page data, and using the shortest practical data-retention setting.
- Where supported, we will use consent mode so that the tool respects your choice.
- We will update this policy and our Cookie Policy to name the provider and list the cookies used.
- You can change your mind at any time using the "Change cookie settings" button on the Cookie Policy page.
If Google Analytics is used, Google acts as our processor, and data may be processed in the United States. More information is available in Google's privacy policy.
Cookies and local storage
We use the smallest possible footprint. The only item stored by default is your cookie-consent choice, saved in your browser's localStorage under pixme_cookie_consent for up to 12 months, so that we do not ask you again on every page. Analytics cookies such as _ga and _ga_<ID> are only set if analytics are enabled and you consent. Full details, including how to withdraw consent, are in our Cookie Policy.
Some pages may load resources such as fonts, icons or scripts from content delivery networks. When your browser requests these files, the provider necessarily receives your IP address and browser information. We choose reputable providers and, where practical, host resources ourselves.
Who we share personal information with
We do not sell personal information. We share it only with the categories of recipients listed below, and only as much as is needed.
| Recipient category | What they do | Data they may receive |
|---|---|---|
| Website hosting and content delivery providers | Host and deliver the website, provide security | Server log data, IP addresses |
| Form handling provider | Receive contact form submissions and forward them to us | Contact form fields |
| Email service provider | Business email and newsletter delivery | Names, email addresses, message content, subscription status |
| Cloud storage and secure file transfer providers | Receive and store project files | Photos, briefs and deliverables |
| AI processing providers | Run AI enhancement, generation or editing tasks under our instructions | Only the images or text needed for the task |
| Payment processor | Process payments securely | Name, email, billing details, payment amounts (card data goes directly to the processor) |
| Accounting and bookkeeping tools or advisers | Keep financial records and meet tax obligations | Invoices and transaction records |
| Analytics provider (only if enabled and consented) | Measure site usage | Pseudonymous usage data |
| Professional advisers | Legal, accounting or insurance advice | Information relevant to the matter |
| Authorities and courts | Where required by law or to protect rights | Information we are legally required to disclose |
Service providers that process personal information on our behalf do so under written contracts that require them to use it only on our instructions, keep it confidential and protect it appropriately. If Pix Me is ever involved in a reorganization, merger or sale of its assets, personal information may be transferred to the successor, which will be bound by this policy or tell you about any changes.
International data transfers
Our service providers may store or process data in countries other than your own, including the United States and other countries outside the European Economic Area (EEA) and the United Kingdom. Those countries may not have data protection laws equivalent to yours.
When we transfer personal information from the EEA, the UK or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as:
- the European Commission's Standard Contractual Clauses (SCCs);
- the UK International Data Transfer Addendum to the SCCs or the UK International Data Transfer Agreement;
- adequacy decisions, including the EU-U.S. Data Privacy Framework and its UK extension, where the recipient is certified;
- supplementary measures such as encryption in transit and at rest, where appropriate.
You can ask for more information about the safeguards used, or a copy of the relevant clauses, by emailing [email protected]. Commercially sensitive terms may be redacted.
How long we keep personal information
We keep personal information only for as long as we need it for the purpose it was collected, including any legal, accounting or reporting requirements. When it is no longer needed, we delete it or anonymize it.
| Data | Retention period |
|---|---|
| Contact form enquiries that do not lead to a project | Up to 12 months from our last contact, then deleted |
| Client correspondence and project records (excluding photos) | For the duration of the relationship plus up to 3 years, to handle follow-up questions and potential claims |
| Client source photos, including face images, and project-specific AI representations | Deleted within 30 days after final delivery, unless you ask us to keep them longer or delete them sooner |
| Final deliverables held on our side | Up to 30 days after delivery, or longer if you request it in writing |
| Invoices and accounting records | As long as tax and accounting law requires, typically between 6 and 10 years depending on jurisdiction |
| Newsletter subscription data | Until you unsubscribe; a minimal suppression record (your email address) is kept so we do not email you again |
| Consent records (form consent, newsletter opt-in, image opt-ins) | For as long as the related processing continues plus up to 3 years, to demonstrate compliance |
Cookie-consent preference (pixme_cookie_consent) | Up to 12 months in your browser, or until you clear it |
| Analytics data (only if enabled) | No longer than 14 months, using the shortest practical setting available |
| Server and security logs | Typically up to 30 to 90 days, depending on the hosting provider |
Backups may keep copies of data for a short additional period before they are overwritten on a rolling basis. Data in backups is not used for any other purpose.
How we protect personal information
We use technical and organizational measures appropriate to the risk, including:
- HTTPS encryption across the website and for file transfers;
- encryption at rest for stored project files, where offered by our storage providers;
- access limited to the people who need it for a specific project;
- strong, unique passwords and multi-factor authentication on accounts that hold personal information;
- choosing service providers with recognized security practices and written data processing agreements;
- data minimization, so that we hold less to lose in the first place;
- routine deletion of client photos after the retention period.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you, without undue delay and in accordance with applicable law.
Your rights under GDPR and UK GDPR
If you are in the EEA, the UK or another jurisdiction with similar laws, you have the following rights, subject to certain conditions and exceptions:
- Right of access — to obtain confirmation of whether we process your personal information and a copy of it, together with information about how it is processed.
- Right to rectification — to have inaccurate information corrected and incomplete information completed.
- Right to erasure ("right to be forgotten") — to have your information deleted where, for example, it is no longer needed or you withdraw consent.
- Right to restriction — to ask us to limit processing while, for example, you contest the accuracy of the data or we consider an objection.
- Right to data portability — to receive information you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object — to object to processing based on legitimate interests, and an absolute right to object to direct marketing.
- Right to withdraw consent — at any time, where we rely on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Rights relating to automated decision-making — not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. As explained above, we do not make such decisions.
- Right to lodge a complaint — with a supervisory authority, in particular in the country where you live, work or where an alleged infringement took place. In the UK, this is the Information Commissioner's Office (ICO). In the EU, you can find your national authority through the European Data Protection Board.
We would appreciate the chance to deal with your concern before you approach a regulator, so please consider contacting us first at [email protected].
California privacy rights (CCPA/CPRA)
This section applies to residents of California and supplements the rest of this policy. It uses terms as defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Depending on our size and activities, not every CCPA obligation may apply to us, but we choose to extend these rights to California residents as a matter of good practice.
Categories of personal information collected in the past 12 months
- Identifiers — name, email address, phone number (optional), IP address.
- Customer records (Cal. Civ. Code § 1798.80(e)) — name, contact details, billing information.
- Commercial information — services requested, quotes, purchases.
- Internet or network activity — server log data and, only with consent, analytics data.
- Audio, electronic, visual or similar information — photos you upload, including images of faces.
- Professional or employment-related information — for example, job titles or company names included in headshot projects.
- Sensitive personal information — we do not collect sensitive personal information for the purpose of inferring characteristics about you. Face images are processed only to deliver the service you requested, which is a permitted purpose under the CPRA regulations.
The sources, business purposes, recipients and retention periods for these categories are described in the sections above.
No sale or sharing
We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined in the CCPA. We have not done so in the past 12 months. We do not knowingly sell or share the personal information of consumers under 16.
Your California rights
- Right to know what personal information we have collected, used and disclosed about you, and to obtain specific pieces of it.
- Right to delete personal information we collected from you, subject to exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing — not currently applicable because we do not sell or share, but we will honor Global Privacy Control signals as an opt-out if that ever changes.
- Right to limit use of sensitive personal information — we already limit such use to permitted purposes.
- Right to non-discrimination — we will not deny services, charge different prices or provide a different quality of service because you exercised your rights.
You may use an authorized agent to submit a request on your behalf. We may ask the agent for signed written permission and may ask you to verify your identity directly.
Other U.S. state privacy laws
Residents of other U.S. states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Oregon, Texas and others) may have similar rights to access, correct, delete and obtain a copy of their data, and to appeal a decision we make about their request. If we decline your request, you may appeal by replying to our decision email with the word "Appeal" in the subject line, and we will respond within the time required by your state's law.
How to exercise your rights
Send us your request
Email [email protected] or use our contact form, telling us which right you want to exercise and giving enough detail for us to find your information (for example, the email address you used or your project name).
Verification
To protect your data, we may need to verify your identity, usually by confirming control of the email address associated with your data. We only ask for the minimum information needed, and we use it only for verification.
Our response
We respond within one month under GDPR and UK GDPR (extendable by two further months for complex requests) and within 45 days under the CCPA (extendable by a further 45 days where reasonably necessary). We will tell you if we need an extension and why.
Free of charge
Requests are normally free. We may charge a reasonable fee or decline a request only where it is manifestly unfounded or excessive, as the law allows, and we will explain our reasons.
Newsletter subscribers can unsubscribe instantly using the link at the bottom of every email. To withdraw cookie consent, use the button on our Cookie Policy page.
Children's privacy
Pix Me is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. Our services are intended for adults and businesses. If you are under 16, please do not use the contact form, subscribe to the newsletter or send us any personal information.
Parents or guardians who wish to commission images that include children, such as family portraits, must place the order themselves and are responsible for the child's images. We apply our strictest care to such images, never use them for any purpose other than delivering the order, and delete them in line with our retention rules or sooner on request.
If you believe we have collected information from a child under 16 without appropriate consent, please contact [email protected] and we will delete it promptly.
Do Not Track and Global Privacy Control
Do Not Track (DNT). Some browsers send a "Do Not Track" signal. There is no common industry standard for how websites should respond to DNT. Because the Pix Me website does not track visitors across other websites and runs no analytics without consent, a DNT signal does not change how the site behaves.
Global Privacy Control (GPC). GPC is a browser signal that communicates a request to opt out of the sale or sharing of personal information. We treat a GPC signal as a valid opt-out request for your browser. If analytics are enabled on the site, we will also treat a GPC signal as a refusal of analytics consent unless you actively choose otherwise in our cookie banner.
Marketing communications
We only send newsletters and marketing emails to people who have subscribed or who have otherwise agreed to receive them in a way the law allows. Every marketing email contains an unsubscribe link. We do not buy email lists and we do not pass your email address to other businesses for their own marketing. Service messages about an active project, such as delivery notifications or invoices, are not marketing and will still be sent while the project is ongoing.
Third-party links and embedded content
Our articles may link to other websites or reference external tools. We are not responsible for the privacy practices of those websites. If we ever embed content from another site (such as a video), that site may collect data about you, set cookies and monitor your interaction with the embedded content. Where practical, we use privacy-enhanced embed modes or load embeds only after you click on them.
Changes to this policy
We may update this Privacy Policy from time to time, for example when we add a new service, switch on analytics, change a service provider or when the law changes. We will update the "Last updated" date at the top of the page. If a change is significant, such as a new purpose for processing face images, we will give more prominent notice, for example on the website or by email to clients and subscribers, and we will ask for your consent where the law requires it. Earlier versions are available on request.
Contact us
If you have any questions about this Privacy Policy, want to exercise your rights, or have a concern about how Pix Me or Pixme AI handles personal information, please get in touch:
- Privacy requests: [email protected]
- General enquiries: [email protected]
- Online: our contact page
We aim to acknowledge privacy requests within a few business days and to resolve them well within the legal deadlines.
