Back to titox.io PixelPop legal documentation

Privacy Policy

Last Updated: August 13, 2026

Effective date: August 13, 2026

This Privacy Policy explains how TitoniumLab (“TitoniumLab,” “we,” “us,” or “our”) handles information when you use PixelPop and related services (the “Service”). It is intended to describe the current product behavior, including optional account, community, image-processing, analytics, notification, and subscription features.

1. Information we handle

Account and sign-in information

When you sign in, we may receive and use a Firebase user identifier and information provided by your sign-in method, such as your name, email address, profile image, provider identifier, and whether the account is anonymous. Google and Apple may process sign-in information under their own policies.

Artwork and community content

Depending on what you choose to do, the Service may handle:

  • photos selected from your gallery or captured with your camera;
  • original images, pixel-art versions, completed versions, templates, generated variants, exports, and progress thumbnails;
  • painting progress, completion status, repaint status, timestamps, selected settings, and your chosen PixelPop app language;
  • community posts, tags, comments, favorites, follows, profile details, and other social activity; and
  • content you share through your device or publish to the PixelPop community.

Images used only for local painting can remain on your device. Images and progress are sent to our service when you choose cloud-backed templates, cloud progress, community publishing, or an image-processing feature that requires server processing. Community content may be visible to other users according to the feature’s design.

Device, notification, and service information

We may handle device and app information needed to deliver the Service, such as device platform, app version, language or regional settings, push-notification registration token, connectivity and request information, and security or abuse-prevention signals. If you enable notifications, a notification provider may process your device token and notification delivery information.

Usage and diagnostics

When enabled for the release version, analytics services may receive information about screens, actions, feature use, and general interaction with the Service. Crash reporting may receive technical information about failures, device state, app version, and relevant diagnostics. We use these tools to understand reliability, improve the product, and protect the Service. PostHog analytics is only active when the app is configured with a PostHog key.

Advertising and rewarded ads

PixelPop may use Google AdMob to display banner, native, interstitial, and rewarded ads to people without an active Premium entitlement. AdMob may process device identifiers, IP address, general location, app interaction, ad-view, consent, and fraud-prevention information under Google’s policies. Where required, PixelPop asks for advertising consent through Google’s User Messaging Platform before requesting ads. Depending on your consent choices and applicable law, ads may be personalized or non-personalized. You can revisit available advertising privacy choices from Settings.

If you choose to watch a rewarded ad, Google sends PixelPop a signed completion record containing your PixelPop account identifier and a unique ad-transaction identifier. We use it only to verify the reward, prevent replay or fraud, and credit the displayed in-app benefit.

Marketing measurement and App Tracking Transparency

In production builds, PixelPop may use Meta App Events to measure marketing campaigns and attribute installs or subscription conversions. On iOS, PixelPop asks for App Tracking Transparency permission before enabling this feature. If you allow tracking, Meta may receive your device advertising identifier, PixelPop account identifier, and limited events such as onboarding, first paint, paywall views, checkout, trials, subscriptions, and other bounded campaign events for advertising measurement. If you deny or later withdraw permission, PixelPop disables this Meta tracking path and does not send those events to Meta. On Android, the applicable Google advertising-consent result controls whether Meta marketing measurement is enabled. Firebase Analytics may still receive product and permission-result events for app functionality, reliability, and aggregate product measurement.

Purchases and subscription information

If you use premium features, the relevant app store and our subscription-management provider may process purchase, subscription, entitlement, restore, and transaction information. We do not receive your full payment-card number through PixelPop. Apple, Google, and the subscription provider handle payment processing under their own policies.

2. How we use information

We use information to:

  • provide, authenticate, personalize, and secure PixelPop;
  • save and sync templates and painting progress when you request those features;
  • process images, generate Paint Polish variants, and return requested results;
  • publish and display community content, comments, profiles, follows, favorites, and repaint activity;
  • deliver notifications and respect notification preferences;
  • provide premium entitlements, restore purchases, and prevent purchase or usage abuse;
  • display ads, honor advertising privacy choices, verify rewarded-ad completion, and prevent advertising fraud;
  • measure marketing campaigns and attribute installs or subscription conversions when the required consent is granted;
  • diagnose crashes, monitor reliability, measure feature use, and improve the Service;
  • respond to support, privacy, safety, and legal requests; and
  • comply with law, enforce our Terms of Use, and protect users, TitoniumLab, and the public.

Depending on the law that applies, our legal grounds may include providing a service you request, your consent for optional permissions or communications, our legitimate interests in security and product improvement, and compliance with legal obligations. You can withdraw permission for camera, photo-library, or notification access through your device settings, although related features may stop working.

3. When information is shared

We may share information with service providers that process it for us, including:

  • Firebase for authentication, analytics, crash reporting, remote configuration, app protection, and messaging;
  • Google or Apple when you choose their sign-in or use their app-store billing;
  • RevenueCat or a comparable subscription service to manage premium entitlements and restore purchases;
  • Google AdMob and Google’s User Messaging Platform to deliver ads, record consent choices, verify rewarded ads, and prevent advertising fraud;
  • Meta for consented App Events, campaign measurement, and attribution; on iOS, this sharing occurs only after App Tracking Transparency authorization;
  • PostHog when product analytics is configured;
  • hosting, storage, image-processing, security, customer-support, and infrastructure providers that help operate PixelPop; and
  • authorities, advisors, or other parties when reasonably necessary to comply with law, enforce rights, prevent abuse, or handle a corporate transaction.

We do not sell personal information. We do not use your private, unshared photos as advertising material. We may display content you deliberately publish to the community and may use de-identified or aggregated information to understand product performance.

4. Local storage and deletion

PixelPop may store painting projects, progress, thumbnails, preferences, and cached data on your device. You can remove local app data by using the device’s app controls or by clearing the relevant in-app content where available. Uninstalling an app may not remove every item retained by the operating system, app store, or connected sign-in provider.

Cloud account data and published content are handled separately from local storage. You can initiate account deletion in PixelPop from My Profile → Settings → Delete account. Registered accounts must recently sign in again; anonymous accounts can confirm deletion directly. The deletion process removes the Firebase identity and PixelPop profile, social relationships, comments, favorites, progress, device tokens, subscription state, owned community content, and associated cloud media. The app reports a failure if the deletion cannot be completed so you can retry safely.

You may also request deletion or help through hello@titox.io. We may need to verify that you control the account. We retain only information that is lawfully necessary, such as de-identified transaction markers used to prevent duplicate rewards or purchase-event replay. A limited deletion-completion record may be retained for up to 30 days for retry and support purposes. Other records may be retained when required for fraud prevention, legal obligations, unresolved disputes, accounting, tax, or security, and are deleted or de-identified when that need ends.

5. Retention

We keep information for as long as reasonably necessary for the purposes described in this Policy. Account and community information is generally retained while the account or published content remains active. Purchase and transaction records may be retained for accounting, tax, fraud-prevention, and legal purposes. Analytics and crash data are retained according to the configuration and retention rules of the applicable provider. Local data remains on your device until you remove it, the app removes it, or the operating system clears it.

6. International processing and security

TitoniumLab and its providers may process information in countries different from where you live. Where required, we use appropriate safeguards for cross-border transfers.

We use reasonable administrative, technical, and organizational safeguards, including authenticated requests, provider security controls, access restrictions, and token handling. No internet transmission, device, or storage system is completely secure, and we cannot guarantee absolute security.

7. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, and to withdraw consent. You may also control photo, camera, notification, and iOS tracking permissions through your device, manage subscriptions through the app store used for purchase, revisit available advertising privacy choices in PixelPop Settings, and delete your PixelPop account in-app.

To make a privacy request, email hello@titox.io. You may also have the right to complain to your local data-protection authority.

8. Children

PixelPop is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and take appropriate action.

9. Third-party policies

Google, Google AdMob, Apple, Firebase, Meta, PostHog, RevenueCat, app stores, device manufacturers, and other providers may collect or process information under their own privacy policies. PixelPop does not control their independent practices. Review the policies that apply to the sign-in, advertising, device, tracking, and purchase options you use.

10. Changes to this Policy

We may update this Privacy Policy when the Service, law, or our data practices change. We will post the updated version with a new effective date. Your continued use of PixelPop after the update means you acknowledge the revised Policy to the extent permitted by law.

11. Contact

For privacy questions, data requests, or concerns, contact TitoniumLab at hello@titox.io.