Privacy Policy
Effective Date: September 8, 2026
Your privacy is important to BLOVE INC, a Colorado corporation doing business as Pixel Dojo ("Pixel Dojo", "us", "we", or "our"). This Privacy Policy explains how we collect, use, and manage your personal data when you browse our website https://pixeldojo.ai, including any of its subdomains or sections ("Website") or when you use our services through the Website ("Services").
Basic Information about Data Protection
| Controller | BLOVE INC, a Colorado corporation, doing business as Pixel Dojo ("Pixel Dojo", "we", "us"). Address: 1155 Kelly Johnson Blvd, Suite 111, Colorado Springs, CO 80920. Email: [email protected] |
| Website | https://pixeldojo.ai and its subdomains (the "Website"), the apps, the public REST API, and the hosted MCP server (together, the "Services"). |
| Purposes and legal basis |
|
| Recipients | We will share your personal data with service providers who help or support us, with public administrations or those with whom we have a legal obligation. International transfers of user data may be made, always with sufficient guarantees to comply with the provisions of the applicable regulations. |
| Rights of the data subject | You have the right to access, rectify, erase, object, request limitation or portability or not be subject to automated individualized decisions of your personal data. You can direct your request to [email protected]. |
1. What data we process and what are the purposes
1.1. Information obtained during the use of the Services by Users
During the registration process and the provision of the Services, Pixel Dojo may process personal data provided by Users, including:
- Identification and account data (e.g., name, email, account identifiers depending on the selected authentication method).
- Economic and transactional information (e.g., billing identifiers, subscription tier, invoice IDs, tax status, and other transaction metadata). We do not collect or store full payment card details on our systems.
- User-shared text and multimedia data you upload or generate (e.g., prompts, images, videos) and associated metadata necessary to provide the Services.
- Device and online activity data (e.g., IP address, browser type, pages viewed, session and performance metrics) for security, fraud prevention and analytics.
- Advertising measurement data. When you sign up or make a purchase, we send Google a hashed (SHA-256) version of your email address, your account identifier, the analytics session identifier from the Google cookie set on your first visit, and for purchases the amount paid. Google uses this to attribute the sign-up or purchase to an ad campaign. Google's own tag records the ad click identifier when you arrive from an ad. We never send your email address in the clear.
- Support and communications data (e.g., requests, feedback, and correspondence with us).
- Cookies and similar technologies data. You can control cookies from the Cookie settings link in the footer of our public pages, from Settings in the app, or in your browser settings.
- Audio you upload or generate, datasets you upload to train a custom model, and the trained models the Services produce for your account.
- API keys you create and a log of the requests made with them.
- Content you choose to publish to the community gallery or the prompt gallery, including the work, its prompt, and your comments. Published work and comments are visible to anyone, and comments show your display name and avatar.
- Records of your acceptance of our Terms and of any upload agreement, with the date, time, and version accepted.
- Conversations with our in-app agent, Prompt Studio, and help chat.
- If you send us an abuse report, whether or not you have an account: the report, any contact email you give, and a hashed form of your IP address, which we use to limit repeat submissions. We keep abuse reports for as long as needed to investigate and to meet our legal reporting obligations.
These personal data are used by Pixel Dojo for the following purposes:
- To provide the Services and carry out the maintenance and management of the contractual relationship.
- To manage and improve the Services, including responding to suggestions, conducting surveys, and preventing fraud and abuse.
- To send commercial information and news to Users, where applicable, in relation to the contracted Services.
- To comply with applicable regulations and respond to requests from public authorities.
Payments & Merchant of Record
Whop is the merchant of record for every purchase on Pixel Dojo. Whop processes all subscription and credit pack payments, and charges appear on your statement under Whop's descriptor. We do not collect or store full payment card numbers. We receive limited billing metadata from Whop (e.g., invoice ID, last4, expiration month/year, billing country, tax status) to deliver purchases, provide support, and comply with legal obligations.
AI, Safety & Automated Decisions
We run automated safety systems to keep the Services within the law and our policies. Prompts are screened before generation, and that check fails closed: if it cannot run, the generation does not. Every uploaded or referenced image, sampled frames of every video, and every training dataset are screened on every tool. Stored media is hash-matched against known child sexual abuse material on our storage layer. Our own check at delivery time blocks and deletes flagged output, and work submitted to the public gallery is reviewed at publish time. The image, video-frame, and output checks can fail open if a classifier errors, and media processed during such a failure is re-checked shortly afterwards. These controls can block a generation, remove media, limit features, or suspend an account. Blocked attempts are recorded and reviewed. Confirmed child sexual abuse material closes the account, deletes stored media except what the law requires us to preserve, and is reported to the National Center for Missing and Exploited Children as the law requires. You can ask for human review of any removal, suspension, or account closure, including automatic ones, by emailing [email protected] with Appeal in the subject line. A person reviews the decision and replies. How these systems work is described on our Trust & Safety page, and this Policy is part of our Terms of Service.
Output you do not save is held on short-lived storage for about 24 hours (one hour for API outputs) and then deleted automatically. We keep a record of each generation, including the output URLs, for up to 90 days (30 days for API requests) so we can audit abuse and investigate reports. Media you save is kept until you delete it.
2. How long we keep your personal data
We retain personal data only as long as needed for the purposes above, then delete or anonymize it unless a longer period is required by law. Examples: account data (while active and up to 24 months after closure); transactional records (7 years for tax and accounting); output you do not save, about 24 hours (one hour for API outputs); generation records (prompts, settings, and output links), up to 90 days (30 days for API requests); prompt enhancement records (your original prompt, the enhanced prompt, and whether you kept the result) and prompts you save, kept to improve the enhancement feature until your account is deleted; moderation block records, 90 days; records of confirmed safety violations, abuse reports, and media preserved as evidence, for the life of the account and afterwards as the law requires; backups on rolling cycles up to 90 days. Abuse reports, including the email address given, a hashed form of the reporter's IP address, and the account id if the reporter was signed in, are kept to investigate the report and to meet our legal duties. On a valid erasure request we remove a confirmed-violation record after review unless a legal hold or a preservation duty applies. When content is removed, we delete the public copy and the stored file, except where a legal hold, an open investigation, or a legal duty requires us to preserve it. We may retain limited usage signals (e.g., number of images/videos generated) for fraud prevention, accounting, and billing verification.
3. To whom we provide your personal data
We share personal data with service providers that process it on our behalf. They fall into these groups: AI model providers that run our generation, editing, and training tools, which receive your prompts, uploaded media, and outputs in order to produce a result; AI services that screen prompts and flagged media for safety; cloud hosting, storage, and content delivery; database hosting; authentication; email delivery; support chat; analytics and advertising measurement (Google receives usage events and, when you sign up or make a purchase, a hashed version of your email address so it can match the conversion to an ad click); and Whop, our payment processor and merchant of record for billing and tax purposes. The current list of these providers is on our Sub-Processors page. We require each provider to protect personal data with appropriate technical and organizational measures. We may also share information where required by law or to protect our rights, our users, or the public.
4. What are your rights as a data subject
You have the right to access, rectify, erase, object, request limitation or portability of your personal data, and the right to withdraw consent for the processing of personal data. You can direct your request to [email protected].
To make a request, email [email protected] from the email address on your account. We verify requests through that address and may ask for more information before we act. Someone you authorize in writing may make a request for you. We respond within 45 days, or sooner where your local law sets a shorter period. We may extend once by a further 45 days and will tell you if we do. We will not treat you differently for exercising your rights. If we refuse a request in whole or in part, you may appeal by replying to our decision, and we answer within 45 days. If we still refuse, you may contact the data protection authority where you live. Colorado residents may contact the Colorado Attorney General, and EU and UK residents may lodge a complaint with their supervisory authority. We may keep some data after an erasure request where the law allows or requires it, for example tax and billing records, records of confirmed safety violations, or data preserved under a legal hold, as described in Section 2.
We do not sell personal data for money. When you sign up or make a purchase, we send Google a hashed version of your email address and related identifiers to measure ad conversions. Some US state privacy laws, including the Colorado Privacy Act and the California Consumer Privacy Act, treat this as sharing or targeted advertising. You can opt out by emailing [email protected] with "Opt out of ad measurement" in the subject line. We do not treat you differently for opting out.
5. International Data Transfers
We may transfer personal data outside of your country, including to the United States and other jurisdictions where we and our service providers operate. Where applicable, we use appropriate safeguards such as Standard Contractual Clauses and other lawful transfer mechanisms, or rely on adequacy decisions in accordance with applicable data protection laws.
6. Security
We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
6A. Fraud Prevention, Risk Scoring & Compliance
We use automated and manual processes to detect and prevent fraud, abuse, and violations of our Terms of Service. This includes rate limits, checks for duplicate or automated submissions, review of usage patterns (for example, volume of generated content, abnormal access activity, or unusual billing patterns), our safety strike records, and the fraud tools operated by Whop. We may share limited information where necessary for fraud prevention, chargeback mitigation, or to comply with lawful requests by law enforcement or regulatory authorities.
6B. Content Safety & Moderation Scanning
We use automated and manual moderation to detect content involving minors, non-consensual intimate imagery, sexualized depictions of real people without their consent, hate speech, harassment, extremist violence, and other policy violations. We may block or filter prompts and outputs, limit features, and suspend accounts to enforce our policies. For this purpose, we may process prompts, outputs, thumbnails, and usage metadata (such as frequency and type of requests) solely to operate content safety systems and comply with applicable laws.
7. Children
Our Services are not directed to anyone under 18. You must be 18 or older to create an account. If we learn that an account holder is under 18, we close the account and delete the personal data we hold about that person, except what the law requires us to keep. If you believe someone under 18 has provided personal data to us, contact us at [email protected].
8. Cookies & Tracking Technologies
We use cookies and similar technologies to operate the Services, remember your preferences, keep your session secure, and measure how the Services are used. When you visit the Website, Google Tag Manager and Google Analytics 4 load and may set analytics cookies, and Google Ads conversion measurement runs on the same tags. On our marketing pages only, a Whop conversion pixel also loads so we can measure which pages lead to sign-ups and purchases. Our support chat (Crisp), our sign-in provider (Clerk), and Cloudflare security protections also set cookies. We use our own referral and click identifiers and store app preferences in your browser. If you visit from the European Economic Area, the United Kingdom, or Switzerland, we show a cookie banner before any analytics, ad measurement, conversion pixel, or support chat script loads, and we remember your choice for 12 months. Everyone can change their choice from the Cookie settings link in the footer of our public pages or from Settings in the app. We honor the Global Privacy Control signal as an opt-out of ad measurement, including the conversion events we send to Google from our servers when you are signed in. You can also opt out of ad measurement by emailing [email protected], or block or delete cookies in your browser settings. See our Cookie Notice for the categories we use.
Transparency & AI Use Disclosures
We do not use your prompts, uploads, or outputs to train image, video, or audio models without your explicit consent. The exception is the custom models you ask us to train from your own uploads. We do use prompts to improve our prompt enhancement feature. When you keep a result, we store the prompt you started with, the enhanced prompt, and the outcome, and we use that record to improve enhancement for all users. Prompts you save, including private ones, may be shown to the enhancement system as examples when another user asks for help with a similar prompt. We do not publish your private prompts. We also build a style profile from the work you keep and like so enhancements match your style. It is rebuilt when you use enhancement, at most once a day, and is deleted after 90 days of inactivity or when your account is erased. Third-party providers process your prompts and media to run the tools you use and to screen for safety. The current list, with each provider's purpose, is on our Sub-Processors page, which we update when a provider changes. We may apply watermarks/metadata or safety labels to some outputs consistent with legal requirements. You are responsible for disclosures or labels required by platforms where you publish synthetic media.
9. Changes to this Policy
We may update this Privacy Policy. For a material change we give at least 30 days' notice by email and in the app before the change takes effect. For a non-material change we post the updated Policy here with a new Effective Date. The Effective Date at the top of this page tells you which version applies. This Policy is part of our Terms of Service, and section 12 of the Terms governs how changes are accepted.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
- By email: [email protected]
- By visiting this page on our website: https://pixeldojo.ai/privacy-policy
To report suspected abuse, non-consensual imagery, copyright infringement, or any illegal activity generated or uploaded using Pixel Dojo, email [email protected]. For non-consensual intimate imagery, put "NCII" in the subject line; we remove verified NCII within 48 hours of a complete report. Reports are reviewed promptly, and we may take action including content removal, account suspension, and notifying law enforcement where legally required.