Skip to content

Legal

Privacy Policy

Version 2026-08-26 · Effective 26 August 2026

This describes what Pictalens collects, what it does with it, and who else touches it. It is written to match the service as it is actually built. The Terms of Service cover what you are buying; this covers your data.

01

Who we are

Pictalens is the controller of the personal data described here. We are contactable at hello@pictalens.com, and that address reaches a person, not a queue. If you want to exercise any right in section 09, that is where to write.

02

Your photographs

When you submit a batch we receive the image files you choose, their filenames, and whatever the files carry inside them — camera model, exposure settings, orientation, and, if your phone recorded it, the location the photograph was taken. We read orientation and use it. We do not use location for anything, and we do not attach it to the images we return.

From each photograph we derive a preview, a thumbnail, a before-image and the edited output, and we record what the pipeline did to it — the geometry it measured, the corrections it applied, the model it used and what that cost. Alongside the batch we store the options you picked, any instruction you typed, and the version of the terms in force when you submitted.

Section 2 of the terms asks you not to upload photographs whose main subject is an identifiable person. That request exists because of this section: a photograph of a room is property data, and a photograph of a person is not.

03

Everything else we collect

Your account. Your email address, a name if you give one, and the sign-in records that keep you signed in. We sign you in with a link sent to your address, so there is no password to store.

Payment. Stripe collects your card details on its own pages and is the merchant of record. We receive a payment reference, the amount, the currency, the time, and the email address you gave Stripe. We never receive, and cannot retrieve, a card number.

Where you came from. If you arrive through a link we published, we set one cookie recording which link it was, so we can tell which channels work. It holds a campaign label, not a profile.

Use of the site. Page views, with batch identifiers stripped from the path before they are recorded. Session recording is off, page text is masked, and we do not capture form fields.

Errors. When something breaks we record what broke and which batch it happened to, so it can be fixed and, where it cost you a photograph, refunded.

04

We use generative AI, and this is what that means

Editing is done by generative models, not by a person and not by a filter. Your photographs are sent to a third-party model provider — currently OpenAI — along with the instructions that describe the edit. The provider processes them and returns an image.

We do not permit providers to train their models on your photographs. Where the provider offers that election, we make it, and we would not use a provider that did not offer it. Nothing you upload is used to train anything of ours either.

No human at Pictalens looks through your batch as a matter of course. We do look at individual photographs when a batch fails and needs diagnosing, or when you ask us to.

Because the output is generated, it is an edited photograph and not a record of the property. What the pipeline is instructed never to alter is set out in section 3 of the terms.

05

Who else processes it

These are the third parties involved, and what each one receives. They act on our instructions, they are not permitted to use your data for their own purposes, and we do not sell your data to anyone.

WhoForWhat they get
OpenAIGenerative editingYour photographs, and the instructions we send with them.
Cloudflare R2 · Amazon S3 and CloudFrontFile storage and deliveryYour photographs and the edited versions, while a batch is live.
VercelHostingRequests to this site, including IP address and user agent.
NeonDatabaseYour account, your batches, and the records described above.
InngestBackground processingBatch and photograph identifiers as work is queued and retried.
StripePaymentYour payment details, which Stripe collects directly. We never see a card number.
ResendEmail deliveryYour email address and the contents of the emails we send you.
MetaAdvertising measurementPage views, and a SHA-256 hash of your email address on purchase — never the address itself.
PostHogProduct analyticsWhich pages are visited, with text and identifiers masked.
Apollo.io · NeverBounceBusiness contact sourcingWork contact details of people we have not met yet. See section 08.
upload-post.comSocial postingExample images we publish, under the licence in section 7 of the terms.

Several of these are outside the UK and the EEA, principally in the United States. Where that is so, the transfer is made under the provider’s standard contractual clauses or its Data Privacy Framework certification.

06

How long we keep it

We keep what you upload and what we make from it — your originals, the edited images, the thumbnails and the comparisons — for as long as you have an account with us. Nothing is deleted on a schedule.

We keep them because they are not reproducible: the photograph was taken in a room we will never stand in, and once it is gone neither of us can get it back. It means your work is still here if you come looking for it a year later, and it means we can re-run an edit rather than ask you to re-shoot.

You can end that at any time. Deleting your account removes every file we hold for you, permanently, within minutes — see section 9. You can also ask us to delete a single batch. Neither request is subject to any of the above: a retention policy is a statement about what we do on our own, never a reason to refuse you your own data back.

Your account and batch records — what was ordered, when, and what it cost — are kept until you delete your account. Payment records are retained by Stripe for as long as tax law requires, independently of us.

07

Cookies

We set a session cookie when you sign in, and a first-touch cookie recording which campaign brought you here. Meta and PostHog set their own cookies for measurement. None of them are used to build an advertising profile of you across other websites beyond what Meta does with its own pixel.

You can block or clear all of them in your browser. Blocking the measurement cookies does not change anything about the service; only the sign-in cookie is required for a signed-in session to work.

08

If we emailed you first

We run outbound email to people in the property business who have not used the service. Their work contact details — name, work email address, employer, job title — come from Apollo.io, a business contact database, and are checked for deliverability by NeverBounce. We do not buy or use personal email addresses for this.

We do it on the basis of legitimate interest in reaching a business audience for a business product. Every one of those emails carries an unsubscribe link, and an unsubscribe is permanent. A later import cannot resurrect an address that has opted out, by design. You can also write to hello@pictalens.com and ask to be removed, and to be told where your details came from.

09

Your rights, and deleting your account

You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to stop using it for marketing, or object to processing. Write to hello@pictalens.com and we will answer within 30 days. There is no charge.

You do not have to ask us to delete your account. Signed-in customers can do it themselves from your dashboard, at the bottom of the page. It takes effect immediately and it is not reversible: your account, your batches, and every image file still held for them are deleted, and any example images taken from your batches are withdrawn from publication.

One thing survives it, deliberately. We keep your email address on a do-not-contact list so that a future contact import cannot start mailing you again. If you would rather we did not, say so at hello@pictalens.com and we will remove that too.

If you think we have handled your data badly, tell us first — but you are entitled to complain to your data protection authority without doing so.

10

Children

The service is for people running property listings and is not directed at children. We do not knowingly collect data about anyone under 16.

11

Changes

We may change this policy — most often because a processor in section 05 is added or removed. The version number and date at the top change with it, and material changes will be announced by email to account holders.

Questions about any of this: hello@pictalens.com.