R
Rexels

PRIVACY
POLICY

Last updated: January 2025

Privacy at a Glance

  • We collect only what's necessary to provide our AI generation services
  • Your generated content is stored securely and belongs to you
  • We do NOT use your content to train AI models without explicit consent
  • Face Library data is encrypted and never shared with third parties
  • You can delete all your data at any time from Settings

1. Information We Collect

1.1 Account Information

When you register for Rexels, we collect:

  • Email address — For account authentication and service communications
  • Display name — Optional, for personalization
  • Password — Stored using industry-standard bcrypt hashing (we never see your actual password)

1.2 Payment Information

Credit card details, billing addresses, and payment methods are processed and stored exclusively by Stripe, our PCI-DSS compliant payment processor. Rexels never receives or stores your full card number. We only retain a transaction reference ID and the last four digits of your card for your records.

1.3 Content You Create

When you use our AI tools, we process and store:

  • Text prompts — The descriptions and instructions you provide for thumbnail generation
  • Reference images — Images you upload for style reference or editing
  • Generated thumbnails — AI-created images stored in your account
  • Generated titles — AI-created title suggestions
  • YouTube metadata — Video titles and thumbnails you analyze (fetched from public YouTube data)

1.4 Face Library Data

Special Category Data: Facial images you upload to your Face Library are considered biometric data in certain jurisdictions. We treat this data with elevated security:

  • Face images are encrypted at rest using AES-256 encryption
  • Face data is stored separately from your account information
  • Face images are never shared with third parties
  • Face data is permanently deleted within 24 hours of account deletion
  • We do NOT perform facial recognition or build facial profiles

1.5 Automatic Data Collection

When you use Rexels, we automatically collect:

  • IP address — For security, fraud prevention, and approximate location (country-level)
  • Device information — Browser type, operating system, screen resolution
  • Usage data — Features used, generation counts, timestamps
  • Error logs — Technical errors to improve service reliability

2. How We Use Your Information

2.1 Service Delivery

  • Process your prompts through our AI systems to generate thumbnails and titles
  • Store and display your generation history
  • Process face swap requests using your Face Library
  • Manage your credit balance and transactions

2.2 Service Improvement

We analyze aggregated, anonymized usage patterns to:

  • Identify and fix bugs and performance issues
  • Understand which features are most valuable to users
  • Develop new features based on usage patterns
  • Optimize AI model parameters (without using your content for training)

2.3 Communications

We may send you:

  • Transactional emails — Account verification, password resets, purchase receipts (cannot be opted out)
  • Service updates — Important changes to features, terms, or policies (cannot be opted out)
  • Product updates — New features, tips, and promotional content (opt-out available)

3. AI Training & Your Content

We are transparent about AI training:

  • We do NOT use your prompts, images, or generated content to train or fine-tune AI models without your explicit, separate consent.
  • Anonymized metadata (e.g., "users generate 40% more thumbnails with style X") may be used for product analytics.
  • We will never sell your content or use it for advertising purposes.

4. Data Retention & Deletion

Data TypeRetention PeriodDeletion Trigger
Account dataUntil account deletionUser request via Settings
Generated contentUntil manually deletedUser deletion or account closure
Face LibraryUntil manually deletedImmediate deletion with account
Payment records7 years (legal requirement)Cannot be deleted for tax/legal compliance

5. Your Rights

Depending on your location, you have the following rights regarding your personal data:

5.1 Universal Rights (All Users)

  • Access — Request a copy of all data we hold about you
  • Correction — Update inaccurate personal information
  • Deletion — Delete your account and associated data via Settings > Privacy
  • Portability — Download your generated content

5.2 GDPR Rights (EU/EEA Users)

  • Restriction — Limit processing of your data
  • Objection — Object to processing based on legitimate interests
  • Withdraw consent — Where processing is based on consent
  • Complaint — Lodge a complaint with your local data protection authority

5.3 CCPA Rights (California Users)

  • Know — What personal information we collect and how it's used
  • Delete — Request deletion of personal information
  • Opt-out — We do not sell personal information
  • Non-discrimination — Equal service regardless of privacy choices

To exercise any right, email privacy@rexels.app or use the self-service options in Settings. We respond within 30 days.

6. Local Storage & Tracking

We use browser local storage to maintain your authentication session. This data is stored only in your browser and is cleared when you log out or clear your browser data.

  • Authentication token — Keeps you logged in between sessions

We do not use: Advertising cookies, cross-site tracking, or third-party analytics that profile users. We may use privacy-respecting analytics (e.g., Plausible, self-hosted) that do not track individuals.

7. Security Measures

We implement industry-standard security practices:

  • All data transmitted over HTTPS/TLS 1.3
  • Passwords hashed with bcrypt (cost factor 12)
  • Database encryption at rest
  • Regular security audits and penetration testing
  • Access controls and audit logging for internal systems
  • Incident response procedures with 72-hour breach notification

No system is 100% secure. If you discover a vulnerability, please report it to security@rexels.app.

8. Children's Privacy

Rexels is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at privacy@rexels.app, and we will delete it.

9. International Data Transfers

Rexels is based in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. For EU/EEA users, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for international transfers.

10. Changes to This Policy

We may update this Privacy Policy periodically. For significant changes, we will:

  • Email registered users at least 14 days before changes take effect
  • Display a prominent notice in the application
  • Update the "Last updated" date at the top of this page

Continued use of Rexels after changes take effect constitutes acceptance of the revised policy.

11. Contact Us

For privacy-related inquiries or to exercise your rights:

Email

privacy@rexels.app

Response Time

Within 30 days of receiving your request