PRIVACY
POLICY
Last updated: January 2025
Privacy at a Glance
- ■We collect only what's necessary to provide our AI generation services
- ■Your generated content is stored securely and belongs to you
- ■We do NOT use your content to train AI models without explicit consent
- ■Face Library data is encrypted and never shared with third parties
- ■You can delete all your data at any time from Settings
1. Information We Collect
1.1 Account Information
When you register for Rexels, we collect:
- Email address — For account authentication and service communications
- Display name — Optional, for personalization
- Password — Stored using industry-standard bcrypt hashing (we never see your actual password)
1.2 Payment Information
Credit card details, billing addresses, and payment methods are processed and stored exclusively by Stripe, our PCI-DSS compliant payment processor. Rexels never receives or stores your full card number. We only retain a transaction reference ID and the last four digits of your card for your records.
1.3 Content You Create
When you use our AI tools, we process and store:
- Text prompts — The descriptions and instructions you provide for thumbnail generation
- Reference images — Images you upload for style reference or editing
- Generated thumbnails — AI-created images stored in your account
- Generated titles — AI-created title suggestions
- YouTube metadata — Video titles and thumbnails you analyze (fetched from public YouTube data)
1.4 Face Library Data
Special Category Data: Facial images you upload to your Face Library are considered biometric data in certain jurisdictions. We treat this data with elevated security:
- Face images are encrypted at rest using AES-256 encryption
- Face data is stored separately from your account information
- Face images are never shared with third parties
- Face data is permanently deleted within 24 hours of account deletion
- We do NOT perform facial recognition or build facial profiles
1.5 Automatic Data Collection
When you use Rexels, we automatically collect:
- IP address — For security, fraud prevention, and approximate location (country-level)
- Device information — Browser type, operating system, screen resolution
- Usage data — Features used, generation counts, timestamps
- Error logs — Technical errors to improve service reliability
2. How We Use Your Information
2.1 Service Delivery
- Process your prompts through our AI systems to generate thumbnails and titles
- Store and display your generation history
- Process face swap requests using your Face Library
- Manage your credit balance and transactions
2.2 Service Improvement
We analyze aggregated, anonymized usage patterns to:
- Identify and fix bugs and performance issues
- Understand which features are most valuable to users
- Develop new features based on usage patterns
- Optimize AI model parameters (without using your content for training)
2.3 Communications
We may send you:
- Transactional emails — Account verification, password resets, purchase receipts (cannot be opted out)
- Service updates — Important changes to features, terms, or policies (cannot be opted out)
- Product updates — New features, tips, and promotional content (opt-out available)
3. AI Training & Your Content
We are transparent about AI training:
- ✓We do NOT use your prompts, images, or generated content to train or fine-tune AI models without your explicit, separate consent.
- ✓Anonymized metadata (e.g., "users generate 40% more thumbnails with style X") may be used for product analytics.
- ✕We will never sell your content or use it for advertising purposes.
4. Data Retention & Deletion
| Data Type | Retention Period | Deletion Trigger |
|---|---|---|
| Account data | Until account deletion | User request via Settings |
| Generated content | Until manually deleted | User deletion or account closure |
| Face Library | Until manually deleted | Immediate deletion with account |
| Payment records | 7 years (legal requirement) | Cannot be deleted for tax/legal compliance |
5. Your Rights
Depending on your location, you have the following rights regarding your personal data:
5.1 Universal Rights (All Users)
- Access — Request a copy of all data we hold about you
- Correction — Update inaccurate personal information
- Deletion — Delete your account and associated data via Settings > Privacy
- Portability — Download your generated content
5.2 GDPR Rights (EU/EEA Users)
- Restriction — Limit processing of your data
- Objection — Object to processing based on legitimate interests
- Withdraw consent — Where processing is based on consent
- Complaint — Lodge a complaint with your local data protection authority
5.3 CCPA Rights (California Users)
- Know — What personal information we collect and how it's used
- Delete — Request deletion of personal information
- Opt-out — We do not sell personal information
- Non-discrimination — Equal service regardless of privacy choices
To exercise any right, email privacy@rexels.app or use the self-service options in Settings. We respond within 30 days.
6. Local Storage & Tracking
We use browser local storage to maintain your authentication session. This data is stored only in your browser and is cleared when you log out or clear your browser data.
- Authentication token — Keeps you logged in between sessions
We do not use: Advertising cookies, cross-site tracking, or third-party analytics that profile users. We may use privacy-respecting analytics (e.g., Plausible, self-hosted) that do not track individuals.
7. Security Measures
We implement industry-standard security practices:
- All data transmitted over HTTPS/TLS 1.3
- Passwords hashed with bcrypt (cost factor 12)
- Database encryption at rest
- Regular security audits and penetration testing
- Access controls and audit logging for internal systems
- Incident response procedures with 72-hour breach notification
No system is 100% secure. If you discover a vulnerability, please report it to security@rexels.app.
8. Children's Privacy
Rexels is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at privacy@rexels.app, and we will delete it.
9. International Data Transfers
Rexels is based in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. For EU/EEA users, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for international transfers.
10. Changes to This Policy
We may update this Privacy Policy periodically. For significant changes, we will:
- Email registered users at least 14 days before changes take effect
- Display a prominent notice in the application
- Update the "Last updated" date at the top of this page
Continued use of Rexels after changes take effect constitutes acceptance of the revised policy.
11. Contact Us
For privacy-related inquiries or to exercise your rights:
privacy@rexels.app
Response Time
Within 30 days of receiving your request