1. What We Collect
Data controller: HEYPRO YAPIM LİMİTED ŞİRKETİ (operating as Pixel Office; Beykoz Vergi Dairesi, VKN 4621020776; Riva Mah. Maraşal Mustafa Kemal Cad. Bl 05/50 No: 741 İç Kapı No: 2 Beykoz/İstanbul, Türkiye). Categories collected:
• Account information (name, email) — via Clerk • Service usage (office name, vertical, which Pixmates you use, brief content, output) • Technical data (IP, browser, OS, anonymous session metrics) • Cookies and similar (session management, preferences)
3. Third-Party Service Providers
We use these providers to deliver the service:
• Clerk (auth) — see clerk.com privacy policy • Anthropic (AI) — see anthropic.com privacy policy • Google (AI) — see policies.google.com privacy policy • OpenAI (AI) — see openai.com privacy policy • Fireworks AI (AI) — see fireworks.ai privacy policy • Whop (payments, Merchant of Record) — see whop.com privacy policy • Vercel + Railway + Neon (infrastructure) • Sentry + PostHog (observability)
None of these providers use your data for their own marketing; we have signed Data Processing Agreements (DPAs).
4. AI Training Data
Your briefs, files, or output are NOT used to train Anthropic or OpenAI models. We call the Anthropic API in 'no training' mode and opt out of OpenAI's training pipeline.
Pixel Office itself doesn't train models on user data either. Aggregated, anonymised usage metrics (e.g. "which Pixmate is hired most often") are used for platform improvements only.
4a. Google Workspace API Usage
Through the Google account you connect, we access only the data you EXPLICITLY consent to in /profile's consent screen. No data is used for marketing, profiling, or third-party advertising.
• Calendar (calendar.events + calendar.readonly): read events, create events, find free slots. Used by Personal Assistant + Kai + meeting-facilitator. Data isn't stored in Pixel Office's DB; every call hits Google's API at request time.
• Gmail (gmail.modify): list/read threads, send mail, modify labels. Powers Personal Assistant inbox-zero and b2b-sales reply tracking. Email content is NOT persisted on Pixel Office servers; it is processed transiently in memory only to produce the current Pixmate's response.
• Sheets (spreadsheets): read ranges, append rows, update cells. For CRM/tracker Pixmate flows. Sheet content isn't persisted.
• Drive (drive.readonly): list files, read content (Docs / Sheets / Slides export + text/* files). For document-parser and editorial-producer intake flows. File content isn't persisted; binary files (PDF / media) aren't even fetched.
• Analytics (analytics.readonly): GA4 traffic / source / conversion reports. For marketing/analyst Pixmate reports. Read-only; we don't write to GA4.
• Search Console (webmasters.readonly): no site management rights — only query/click/impression/position data. For Ava SEO Pixmate reports.
Retention: Google data flows through the request-response chain only; it isn't cached long-term. OAuth tokens (access_token + refresh_token) are stored Fernet-encrypted in the tenant_integrations table — decrypted only inside tool invocations, never logged in plaintext.
4b. Google API Limited Use Disclosure
Pixel Office's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means: • We use Google data only to complete the work the user's Pixmate is performing. • We do NOT use Google data for advertising, profiling, or transfer to third-party marketers. • We do NOT use Google data for AI model training — neither Anthropic / OpenAI's training, nor any Pixel Office model. • We do NOT read Google data with human eyes (outside the user's explicit consent for debug/support). • We do NOT share Google-sourced data with any other SaaS, partner, or affiliate.
4c. Data Deletion + Account Termination
You can disconnect your linked Google account at any time via the 'Disconnect' button on /profile. On disconnect: • Your OAuth tokens are deleted from the tenant_integrations table immediately. • Subsequent Pixmate calls can no longer access Google data. • To fully revoke the authorization on Google's side as well, visit https://myaccount.google.com/permissions and remove Pixel Office.
To delete your entire account, do it yourself from your Profile page under "Danger Zone → Delete account": re-type your email to confirm, then delete. Deletion happens IMMEDIATELY: • Every OAuth / integration token is best-effort revoked at the provider and deleted from our database. • The offices you SOLELY own and everything in them (brief content, Pixmate output, uploaded documents, credit/token history, subscription + payment records) are deleted. • For offices with other owners, only your membership is removed; rows in those offices that referenced you (e.g. payment orders you created) are anonymised (your user link is nulled). • Your user row (name, email, identity) is deleted entirely. • Full deletion from backups can take an additional 90 days (rolling backup retention).
If your JWT carries no usable email (legacy accounts), the self-serve delete may not work; in that case email an 'account deletion' request to alperen@pixel-office.com.
5. AI Inputs and Outputs: Retention + Lifecycle
Your briefs and Pixmate chat history are retained according to your office's plan (see KVKK Disclosure §5: 30 days / 90 days / unlimited). Generated output (documents, images, analyses) stays in your account until you delete it or close your account.
Output may reflect your inputs: information you write into a brief can appear inside the generated document. Keep this in mind when sharing highly confidential information.
We do not request special-category personal data (health, religion, biometric data, etc.); we recommend you keep such data out of your briefs and chats.
6. Security
• HTTPS everywhere (HSTS active) • Sensitive DB fields (API keys) encrypted with Fernet • Optional 2FA via Clerk • Anomalous-session detection (Sentry + Clerk Client Trust)
No system is 100% secure — please report suspected breaches to our privacy team.
7. Children's Privacy
Pixel Office doesn't serve users under 18. If we learn an account belongs to a minor, it will be deleted.
8. International Data Transfers
Data may be processed on servers outside Turkey (notably the EU and US). Such transfers happen under Standard Contractual Clauses (SCCs) and Article 9 of the Turkish KVKK.
9. Marketing Communications and Your Choices
Service notices (billing, security, critical changes) are part of the service and require no separate consent. Promotional emails, on the other hand, are sent only if you have opted in, per Turkish Law No. 6563; you can opt out at any time via the link in each email or by writing to alperen@pixel-office.com. Opting out does not affect service notices.
10. Aggregated and Anonymised Data
We may use data that has been aggregated or anonymised so it no longer qualifies as personal data (e.g. "the most-hired Pixmate this month") for product development, statistics, and reporting. This data cannot be re-linked to you.
11. Transfers in a Merger or Acquisition
If Pixel Office becomes party to a merger, acquisition, reorganization, or asset sale, personal data may be transferred to the other party to the transaction, provided they remain bound by the protections in this policy. If such a transaction would materially change how your data is processed, you will be informed in advance.
12. Policy Changes
We may update this policy from time to time; the current version is always published on this page with its "last updated" date. Material changes are announced by email or in-app notification; continuing to use the service after a change constitutes acceptance of the updated policy.
13. Contact
Privacy questions: alperen@pixel-office.com
We respond within 30 days.