Scope and who is responsible
This Privacy Policy explains how PikoReels handles personal data through the PikoReels marketing site at https://pikoreels.com, the application at https://app.pikoreels.com, and related support, billing, generation, scheduling, publishing, analytics, and automation services.
PikoReels is the controller of account, product, and website data described here. When you use PikoReels on behalf of a client or upload information about someone else, you may also be a controller of that information and are responsible for having a lawful basis to give it to us.
Questions and privacy requests can be sent to [email protected]. The operator's registered legal name and address must be added before this draft is final.
Personal data we collect
The data we collect depends on the features you use. It can include:
- Account data: your Google account identifier, name, email address, profile image, account dates, plan, and account preferences.
- Session and security data: session identifiers, IP address, browser and device information, approximate city and country, sign-in times, and active-device records.
- Workspace and brand data: workspace names, brand name and handle, website URLs, public website content you ask us to analyse, niche, brand voice, content pillars, platform defaults, and onboarding answers.
- Connected-platform data: provider and account identifiers, channel or profile name, username, avatar, granted scopes, OAuth access and refresh tokens, token expiry, profile responses, channel statistics, and performance data for posts.
- Content and generation data: prompts, captions, schedules, automation settings, uploaded images, video and audio, generated media, edits, templates, model choices, and technical metadata such as file type, size, dimensions, and duration.
- Billing and credit data: plan, billing interval, Polar customer, subscription and order identifiers, payment status, renewal dates, credit balances, grants, top-ups, auto-refill settings, and usage. PikoReels does not store full card details.
- Communications data: feedback, support messages, rights requests, notification preferences, and related account and page context.
- Referral data: referral code, referral link visits, attribution, conversion status, and credit rewards.
- Usage and diagnostic data: features used, quotas and credits consumed, publishing attempts and errors, API requests, and standard server logs.
Where the data comes from
We receive data directly from you when you sign in, configure a workspace, upload content, write a prompt, schedule a post, change a preference, make a purchase, or contact support.
We receive account, channel, token, post, and performance data from Google, YouTube, TikTok, and Instagram when you choose to connect them. We receive subscription and order status from Polar. If you ask us to analyse a website, we receive the public pages and brand information returned by the website-scraping service.
We collect security, session, referral, and usage data automatically from your browser, device, network, and interactions with the Service.
Why we use data and our legal bases
We use personal data only for defined purposes. Where the GDPR, UK GDPR, or a similar law applies, we rely on the following legal bases:
- Contract: to create and secure your account; provide workspaces, generation, storage, scheduling, publishing, analytics, billing, credits, and support; and carry out your instructions.
- Legitimate interests: to operate and improve the Service, understand feature use, diagnose failures, prevent fraud and abuse, protect accounts, enforce terms, and communicate about the product, provided those interests are not overridden by your rights.
- Consent: to connect optional third-party accounts, use permissions that require consent, store non-essential cookies if introduced, or send optional marketing where consent is required. You may withdraw consent, although that does not affect earlier lawful processing.
- Legal obligation: to keep required tax and transaction records, answer lawful requests, protect legal rights, and comply with applicable law.
Google sign-in, YouTube API Services, and Google user data
Google sign-in provides your basic identity information so we can create and recognise your account. PikoReels does not receive your Google password and does not request access to Gmail, Google Drive, or Google Contacts for sign-in.
PikoReels uses YouTube API Services. If you separately connect YouTube, we receive the scopes and data shown in Google's consent screen. Depending on the scopes you approve, that can include your Google profile, YouTube channel identity and statistics, permission to read post performance, and permission to upload or publish content.
Because those features run on YouTube API Services, using them also means agreeing to be bound by the YouTube Terms of Service. What Google itself does with your data, as opposed to what we do with it here, is described in the Google Privacy Policy.
PikoReels' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only for the user-facing features you request, security, legal compliance, and other uses that policy permits. We do not sell it, use it for advertising, or use it to train a general-purpose AI model.
Besides disconnecting the channel in PikoReels and asking us to delete what we hold, you can revoke this app's access to your Google and YouTube data at any time on the Google security settings page at https://myaccount.google.com/permissions, which is also reachable at https://security.google.com/settings/security/permissions. When access is revoked there, or when you ask us to delete the data, we delete the YouTube API data stored under that consent within 7 days, which is shorter than the account-closure window below. Deleting data held by PikoReels does not change anything stored by YouTube itself; remove that in YouTube.
Human access to Google user data is limited to cases where you give specific permission for support, access is necessary for security or legal compliance, or the data is aggregated and de-identified for permitted internal operations.
AI and website processing
When you generate or edit content, we send the selected prompt, instructions, brand context, and required reference files to the model provider chosen for that job. PikoReels currently uses Google Gemini for tasks such as text, analysis, embeddings, and structured creative decisions, and fal.ai infrastructure for image and video model jobs.
Reference files can be copied to provider-hosted storage so a model can retrieve them. Generated results are then returned to PikoReels and may be stored in your workspace or media library. Providers process these inputs under their own service terms and data commitments.
When you ask PikoReels to analyse a public website, the URL and crawl options are sent to a scraping service, and the returned public page content is used to build your brand context. Do not submit a private or restricted site unless you have authority to process its content.
PikoReels does not use your private content or Google user data to train a general-purpose PikoReels model.
No sale, behavioural advertising, or data brokerage
We do not sell personal data for money, share it for cross-context behavioural advertising, rent mailing lists, or disclose it to data brokers. We do not use Google user data, connected-platform data, or private content to target third-party advertisements.
If those practices ever change, we will update this policy before the change, provide any notice or consent the law requires, and make legally required opt-out controls available.
International processing
PikoReels and its providers operate across countries, so personal data may be processed outside the country where you live, including in the United States. Privacy protections and government-access rules can differ in those locations.
Where applicable law requires a transfer mechanism, we rely on an adequacy decision, approved standard contractual clauses, or another lawful safeguard. You may request information about the safeguard relevant to your data by contacting us.
Retention and deletion
We keep data only for as long as reasonably necessary for the purpose collected, to provide an active account, to meet legal and accounting duties, to resolve disputes, and to protect the Service. The exact period depends on the data and why it is held:
- Account, workspace, brand, content, and generation records are generally kept while your account or the relevant item remains active.
- Deleting a reel, upload, slideshow, or supported generation removes its active database record and associated PikoReels media object where the product's delete action provides that behavior. Scheduled or published dependencies may need to be cancelled first.
- Disconnecting a social account clears its usable tokens, while the account label and historical publishing records may remain to preserve your audit trail and analytics.
- YouTube API data is on a shorter clock: data stored under your YouTube consent is deleted within 7 days of you revoking that consent or asking us to delete it.
- Session records remain until they expire or are revoked. You can review and revoke other sessions in the app's Security settings.
- Billing, transaction, credit, fraud-prevention, and legal records are kept for the period required by tax, accounting, payment, chargeback, and other applicable rules.
- Referral attribution and reward records are kept while needed to administer and audit the referral programme.
- Operational logs, cached location labels, failed-job details, and diagnostic records are retained according to operational and security need, then deleted or de-identified.
- Residual copies may remain temporarily in backups or a provider's systems after deletion and are removed or overwritten through the applicable backup and provider lifecycle.
Closing an account
PikoReels does not currently expose a self-service account-deletion control. To close an account and request deletion, email [email protected] from the Google email address associated with the account. We may ask you to verify the request before acting, and we complete a verified request within 30 days.
Step-by-step instructions for that request, and for the narrower deletions the app does offer, are on the data deletion page.
Account closure is different from subscription cancellation. Cancel recurring billing in the billing portal as well if it is still active. We will delete or de-identify personal data associated with the closed account unless we need to retain a limited record for billing, fraud prevention, security, dispute resolution, or another legal obligation.
Closing PikoReels does not delete content already published to TikTok, Instagram, or YouTube. You must manage that content with the relevant platform.
Your privacy rights
Depending on where you live and the legal basis involved, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; opt out of certain sharing; or appeal a decision about a request. You may also complain to your local data-protection or privacy authority.
Send a request to [email protected] from the email associated with your account and describe what you want us to do. We may verify your identity and authority before disclosing or deleting data. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
An authorised agent may submit a request where local law allows it, but we may require proof of authority and direct identity verification. Some rights have exceptions, including records we must retain by law or need to establish, exercise, or defend legal claims.
Security
We use administrative, technical, and organisational measures designed to protect personal data, including HTTPS in transit, restricted server-side access to credentials and OAuth tokens, scoped workspace queries, short-lived OAuth state controls, and the ability to revoke sessions and connected accounts.
No online service can guarantee absolute security. OAuth tokens and other credentials remain sensitive even when access is restricted, so contact us immediately if you suspect compromise. If a breach creates a legal duty to notify you or an authority, we will do so as required.
Children
PikoReels is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from a child through the Service. If you believe a child has provided personal data, contact us so we can investigate and delete it where required.
Changes to this policy
We may update this policy as the Service, providers, or law changes. The latest revision date appears at the top. If a change materially expands how we use personal data, we will provide additional notice or obtain consent before the new use where required.
Contact
Privacy questions, rights requests, account-deletion requests, and complaints can be sent to [email protected].
End of privacy policy
Read the Terms of Service
TikTok, Instagram, and YouTube connections
When you connect an account on TikTok, Instagram Reels, YouTube Shorts, PikoReels stores the OAuth token and the account information returned under the permissions you approve. We use that information to show the connected account, schedule and publish to it, refresh access, report failures, and retrieve available performance metrics.
We do not use a connected account to read direct messages. We do not intentionally publish outside the schedule, automation, or posting action you configure.
Each platform's own rules keep governing your account there and what that platform does with your data. They are set out in TikTok's Terms of Service and TikTok's Privacy Policy, in Instagram's Terms of Use and Instagram's Privacy Policy, and, for YouTube, in the YouTube Terms of Service and Google's Privacy Policy.
You can disconnect an account in Settings, and you can revoke this app's access from the platform itself at any time, which works even when you cannot reach PikoReels: in the TikTok app under Settings and privacy, then Security, then Manage app permissions; on Instagram under Settings, then Apps and websites, at https://www.instagram.com/accounts/manage_access/; and for YouTube on the Google security settings page at https://myaccount.google.com/permissions.
Disconnecting clears the usable access and refresh tokens in PikoReels. To preserve an understandable calendar, audit trail, and analytics history, the account label and past publishing records can remain after disconnection, and the data deletion page explains how to remove those as well.