Back to pixforge

pixforge Privacy Policy

Effective date: October 1, 2026

This policy explains what information pixforge (pic.jinlab.com, "we", "us" or "the Service") collects when you use the Service, why, who processes it for us, how long we keep it, and how you can control it. The Service is operated by Jinlab.

At a glance:

  • The free tools (resize, crop, rotate, format conversion, grid split, collage except generating a collage with the 3×3 template, and color handling for wide-gamut and CMYK images) run entirely in your browser. Those images are never uploaded to our servers.
  • Images leave your device only when you use a paid AI tool: background removal is processed by Photoroom, and upscaling and style transfer by fal.ai. Our own servers do not keep your images.
  • Paid results are stored in your own browser (they expire after 7 days and are cleared when you log out). When an upscale or a style transfer finishes, our server keeps the results' download links (not the images themselves) for up to 23 hours so you can fetch them from "My results" even after closing the page; the result files themselves are kept on fal.ai for 24 hours and then deleted.
  • Payments are handled by Stripe. We never see or store your card number. To calculate refunds, we keep each payment's fee, billing country and card-issuing country.
  • We do not sell your personal information, we use no third-party analytics, and there are currently no ads on the site.

1. What we collect and why

Account information

  • Email sign-up: your email address and a bcrypt hash of your password. We cannot see or recover your actual password. We also record whether your email is verified and when the account was created.
  • Google or GitHub sign-in: the email address, name, profile picture URL and account ID that the provider shares with us. We use them to identify you and link that account to your pixforge account. We do not store the access tokens the provider issues for the sign-in, and we never act on your behalf on Google or GitHub.
  • Purpose: creating and running your account, keeping you signed in, sending verification and password-reset emails, and preventing abuse. Every feature requires sign-in, so this information is necessary to provide the Service.

Credits and purchases

We record your credit balance and every change to it (top-ups, points charged for paid tools, refunds after a failure, temporary holds while a job runs, credits taken back after a payment refund, compensation credits we grant, compensation credits we take back, and remaining credits forfeited when an account is deleted), with the time, number of points and reason. Top-ups also store the Stripe Checkout Session ID, and credits taken back after a refund store the Stripe Refund ID, so we can reconcile payments and handle support requests. For each payment we also record the amount paid, the processing fee Stripe actually charged, the payment IDs, and the country of the billing address and the country that issued the card, so we can calculate refunds under Section 11.6 of our Terms of Service (refunds deduct the fee, with different rules for users in the EU, the EEA and the UK). To decide whether the EU rule applies: Stripe's payment details also include your name, email address and address, but we only use and store the country (of the billing address and of the card issuer) and discard the rest, and we do not record the card number. When this information is missing from our database (for example for older payments), we look up from Stripe, read-only, that payment's fee and countries, and use them only to calculate refunds. While we process your refund request, we pause paid features on your account (paid tools and buying credits are unavailable, free tools keep working) and record the reason, the start time and our note, so that the refund is calculated on the credits you have not used at that point; the record is deleted once the refund is done or when you delete your account. For every payment we also store a one-way hash of the payment method's fingerprint: an opaque identifier that Stripe assigns to each card (or Alipay/WeChat Pay account) and that is only meaningful within our Stripe account. It cannot be turned back into a card or account number or any card details. We use it only to prevent fraud and to enforce Section 11.9 of our Terms of Service: to recognise accounts and payment methods that have had a chargeback and stop the linked ones, including after an account is deleted and a new one is created, or when switching to another payment method the account has used. This applies only to new payments made after this section takes effect; earlier payments are not back-filled. The credits page says so before the payment button. We keep these hashes for as long as credit and payment records (see Section 5). If you dispute a payment with your bank (a chargeback), we record the dispute (Stripe's dispute ID, the amount, the status, the times and the hash of that payment method's fingerprint), pause paid features on your account in the same way, and take back the unused credits of that purchase (Section 11.9 of our Terms of Service). If you repay the disputed amounts and we restore the account, we note the time of the restoration and the repayment reference on the dispute records.

Images you process

  • Free tools: images are read and processed only in your browser and are never sent to us or anyone else. Generating a paid collage with the 3×3 template also happens in your browser; our server only records the points charged and never receives the image.
  • Background removal: when you start it, the image is relayed through our server to Photoroom and the result is returned to you. Our server keeps neither the image nor the result. Photoroom states that images processed through its API are neither stored nor used for training.
  • Upscaling: your browser uploads the image directly to fal.ai's storage for processing. We set the original to expire after 1 hour(s) and the result after 24 hours, so you can fetch the result again during that window. Our server only reads a small chunk at the start of the upload to confirm its dimensions and price the job; it does not keep the image. When fal.ai finishes, it notifies our server, which then deducts the points and keeps the result's download link (not the image itself) for up to 23 hours from the start of processing, so you can fetch it from "My results" even if you closed the page. We also record the job's tool, points, status and times (a paid-job record) for settlement, reconciliation and abuse prevention.
  • Style transfer: your browser first shrinks the image and converts it to a standard-colour JPEG, then uploads it directly to fal.ai's storage. fal.ai passes the image, together with a style description we wrote in advance, to the provider of a generative AI model (ByteDance's Seedream for the standard tier, Google's Nano Banana 2 for the premium tier), which generates new images. Expiry times, the small header read to confirm the dimensions, and the stored download links work exactly as for upscaling. The paid-job record also notes the style you chose, the image type (person, pet or scenery) and the billing units fal.ai reports, for settlement, reconciliation and improving the style descriptions. The results carry the AI-generated label and C2PA provenance information written by the provider, which we keep unchanged. Please only upload photos of yourself or of people who agreed to it.

Information stored in your browser

  • Paid results are kept in your browser's IndexedDB so you can download them again. They expire after 7 days; expired results are deleted the next time you open "My results", save a new result or log out, and logging out with the site's "Log out" button clears all of them. They are never uploaded to us.
  • Your language choice is kept in localStorage. Dismissing the in-app browser banner (for example inside WeChat) is remembered in sessionStorage for that session.

Usage statistics

Feature statistics (only with your consent): we collect nothing until you agree, and nothing at all before you sign in. After your first sign-in we ask you once whether to allow it, and you can agree or decline; we do not ask again after you choose. You can change your choice at any time on the Settings page; turning it off immediately stops any further collection, on all your devices. Statistics already recorded are not linked to your account, so they cannot be found or deleted per person; they are deleted automatically when the retention period ends. If you agree, we use Cloudflare Workers Analytics Engine to count how often each feature is used, together with the following kinds of options and outcomes, so we can see which features work well and where things go wrong:

  • which tool was opened;
  • how an image was opened (chosen or dropped), its size bracket (a rough pixel-count range, not the exact dimensions), its format and color type (standard, wide-gamut or CMYK), and why an image was refused;
  • options chosen in a tool (such as output format or upscale factor), whether processing succeeded or failed and the kind of failure, and how and in what format a result was downloaded;
  • which kind of notice was shown and, for in-app browser notices, which app's browser it was (for example WeChat);
  • actions on the "My results" page (view, download, delete);
  • how far a credit purchase got, which pack was chosen, and the point tier of a paid action;
  • the sign-in method (when you sign in again after agreeing), and how often pages are visited.

These statistics are not linked to your account and contain no information that directly identifies you (no user ID, image content, file names, exact image size, email address or IP address). They are kept for 3 months.

Security and abuse prevention

  • To stop bulk sign-ups, registrations are rate-limited per IP address; resending verification emails and password-reset requests are counted per email address; paid tools are counted per account.
  • After repeated sign-ups from the same IP address, or repeated password-reset requests for the same email address, the page shows a Google reCAPTCHA challenge, which collects device and browser information and sends it to Google to check that you are human.
  • Cloudflare automatically keeps technical logs for each request containing request details and network metadata (such as the URL, time and result, and possibly your IP address, approximate location and browser information); diagnostic messages we log on errors may include an account ID. These logs are used for troubleshooting and kept for about 3 days.
  • If something goes wrong in a paid flow (for example a job fails after points were charged, or a refund fails), our system emails an alert to our administrator. It may contain an account ID, Stripe Checkout Session, charge and refund IDs, and point amounts, but not your email address or images.

2. Cookies and similar technologies

We only use the cookies needed for signing in; we use no analytics or advertising cookies.

  • Sign-in cookie (essential): after you sign in we store a signed, encrypted session token in your browser to recognise you, valid for up to 30 days, plus a few security cookies used during sign-in (cross-site request forgery protection and the page to return to). You cannot sign in without them.
  • Google reCAPTCHA (only when a challenge is shown): Google may set its own cookies while the challenge loads.
  • For localStorage, sessionStorage and IndexedDB, see "Information stored in your browser" above.

You can clear or block cookies in your browser settings; blocking the sign-in cookie means you cannot sign in.

3. Who processes your information

We share only what each service needs to do its job. Each processes the information under its own privacy policy:

  • Cloudflare (United States): hosting, global network, database (Cloudflare D1, which holds accounts, credits and the abuse-prevention counters described above), technical logs and feature statistics. Cloudflare Privacy Policy
  • Stripe (United States; under its privacy policy, data may be processed in countries including the United States and India): processes credit top-up payments. You enter your card or other payment details directly on Stripe's checkout page; Stripe processes and stores them, and we never receive your card number. When a payment completes, Stripe notifies us of the result, and that notification also includes details you entered on the checkout page such as your email address, name and country. We read the payment status and the account ID and pack details we attached ourselves to add your credits. We also look up and store the payment's processing fee, billing-address country and card-issuing country, and a one-way hash of the payment method's fingerprint, from Stripe (see "Credits and purchases" above); we do not store the payer's email address, name, address or other details. Stripe Privacy Policy
  • Photoroom (France): background removal; receives the images you submit. Photoroom Privacy Policy
  • fal.ai (Features & Labels Inc., United States): upscaling and style transfer; receives and temporarily stores the images you submit and the results, and for style transfer passes the images to the generative model's provider (ByteDance, Google). fal.ai Privacy Policy
  • Resend (United States): sends verification, password-reset and administrator alert emails; receives the recipient address and email content. Resend Privacy Policy
  • Google (United States): Google sign-in and, when needed, reCAPTCHA. Google Privacy Policy
  • GitHub (United States): GitHub sign-in. GitHub Privacy Statement

We do not sell or rent your personal information and do not use it for advertising. We disclose information only when the law or a competent authority requires it, or when it is genuinely necessary to protect the safety or property of you, other users or the public, and then only as much as needed.

4. International transfers

The services above are all outside mainland China: mostly in the United States, with Photoroom in the European Union, and some providers also process data in other countries under their own privacy policies. Cloudflare's network and database nodes are spread worldwide; Cloudflare automatically chooses where the primary database copy lives, which may not be your country. Using the Service therefore means your account information, credit records and any images you submit to the paid AI tools are transferred abroad for processing. The name, location, purpose and contact details of each recipient are listed in the previous section and its linked policy, and you can exercise your rights with us (Section 6) or with the recipient directly. If you do not agree to these transfers, please do not sign up for or use the Service.

5. How long we keep information

  • Account information: for as long as your account exists. When your account is deleted (by you, or by us on your request; see Section 6), we delete the information that identifies you (email address, name, profile picture, password and linked Google or GitHub accounts) and forfeit any remaining credits; other devices where you are signed in are signed out on their next action (within about 10 seconds).
  • Credit and payment records (including each payment's fee and country records): kept after deletion in de-identified form (linked only to an internal ID that no longer maps to any email address) for reconciliation and to meet legal obligations.
  • Chargeback records and the payment-method fingerprint hashes of each payment: kept for as long as credit and payment records, and also kept after deletion in de-identified form, for reconciliation, to meet legal obligations, and to stop the limits in Section 11.9 of our Terms of Service being avoided by deleting the account and signing up again with the same payment method.
  • Database backups: automatic database backups may still contain data from before the deletion for up to 30 days, after which they expire.
  • Images: our own servers keep none. Upscaling and style transfer originals and results expire at fal.ai after 1 hour(s) and 24 hours respectively; Photoroom states that background-removal images are not stored.
  • Download links to upscaling and style transfer results: kept on our server for up to 23 hours from the start of processing, then cleared automatically; cleared immediately when your account is deleted.
  • Paid-job records (tool, points, status and times; no result links): kept for 90 days and then deleted automatically; after account deletion they are kept in de-identified form until then.
  • Results in your browser: expire after 7 days and are deleted the next time you open "My results", save a new result or log out. You can also delete them at any time with your browser's "clear site data".
  • Verification and reset links: email verification links expire after 24 hours and password-reset links after 1 hour(s); used links are deleted immediately, and records of expired links are kept for 90 days; older records are deleted automatically on later requests.
  • Abuse-prevention counters (including the IP address used to sign up, the email address used to request a reset, and the account ID for paid tools): kept for 90 days; older records are deleted automatically on later requests.
  • Feature statistics: 3 months. Technical logs: about 3 days.

6. Your rights

Depending on where you live (for example under China's Personal Information Protection Law or the EU General Data Protection Regulation), you have the right to:

  • access and get a copy of your personal information, including in a portable format;
  • correct inaccurate information;
  • have your personal information deleted, or delete your account;
  • withdraw consent (this does not affect processing already carried out), and object to or restrict certain processing;
  • ask us to explain anything in this policy;
  • complain to the data protection authority where you live.

You can do two things yourself on the Settings page after signing in. Export your personal data: download a JSON file with your profile, sign-in methods, credit balance and history, pending credit holds, payment records, any paid-feature pause, chargeback records (without the payment-method hash), paid-job records (without result download links), your feature-statistics choice, and the abuse-prevention counters kept under your account or email address. Delete your account, under "Danger zone" at the bottom of the page: for your security, you must have signed in within the last 15 minutes (otherwise sign in again first) and type delete to confirm, and you cannot delete it while a paid operation is still in progress. Section 5 explains what deletion does; it forfeits any remaining credits, so ask for a refund under Section 11.6 of our Terms of Service first if you want one. For any other request, or if you cannot sign in, contact us as described in Section 10 with your request and the email address you signed up with. We will verify your identity, act on the request as soon as possible and reply within the time limit set by law.

7. How we protect your information

The whole site uses HTTPS; passwords are stored only as hashes; session tokens are signed so they cannot be forged, and stop working as soon as the account is deleted; we collect only what the Service needs; and images sent to the paid tools are not kept on our servers. No online service can be perfectly secure, however. If a personal data breach occurs, we will notify you and the authorities as the law requires and take steps to limit the harm.

8. Children

The Service is intended for users aged 14 and over. Children under 14 must not sign up or use it, and users who are at least 14 but under 18 should use it with a parent's or guardian's consent and guidance. If we learn that we have collected personal information from a child under 14 without guardian consent, we will delete it promptly.

9. Changes to this policy

We may update this policy when the Service changes or the law requires it. The updated version will be posted on this page with a new effective date; for significant changes (such as collecting a new type of information or adding a new service provider) we will show a prominent notice on the site.

10. Contact us

If you have questions about this policy or want to exercise your rights, contact us:

  • Email: privacy@pic.jinlab.com (preferred for privacy, account deletion and refund requests);
  • WeChat Official Account: tap the WeChat Official Account icon at the bottom of any page, scan the QR code, follow the account and send us a message;
  • X (formerly Twitter): send a direct message to @mosjinX.

Please include the email address you signed up with (never send your password).