1. Overview
This Privacy Policy describes how PicDo processes information when you visit picdo.ai or use its AI image tools. PicDo is currently a free beta: there are no user accounts, subscriptions, payment forms, advertising cookies, or email marketing lists.
PicDo only asks for an image or text prompt when the selected tool needs it. Files are stored privately and are configured to expire after one day. Cloudflare states that lifecycle deletion typically completes within 24 hours after the expiration time.
2. Information PicDo processes
Tool inputs and outputs.
- For background removal and enhancement, PicDo processes the image you upload, its filename, file type, size, and the resulting image.
- For image generation, PicDo processes your text prompt and the generated image.
- PicDo accepts JPG, PNG, and WebP uploads up to 10 MB for current upload-based tools.
Security and quota data.
- Your IP address is used to enforce upload limits, a shared daily task allowance, and abuse protection. PicDo stores a one-way SHA-256 hash rather than the original IP address in its quota data.
- Cloudflare may process the original IP address and request metadata as part of hosting, network security, logs, and Turnstile bot verification.
Anonymous product events.
PicDo stores an anonymous random session ID in your browser's session storage. It may be sent with the page path, selected tool, task ID, and events such as editor viewed, image selected, task submitted, task completed, download clicked, or editor error. PicDo does not use this ID for cross-site tracking.
3. Why PicDo uses this information
- To perform the image edit or generation you request.
- To return, display, and let you download the result.
- To prevent abuse, enforce limits, and protect the service.
- To diagnose failures and improve the current tool workflows.
- To comply with applicable legal and security obligations.
Depending on where you live, these purposes may correspond to providing the service you requested, PicDo's legitimate interests in operating and securing the service, or compliance with law.
4. Cloudflare services
PicDo runs on Cloudflare. Current processing may use Cloudflare Workers, R2, D1, Queues, Images, Workers AI, Turnstile, and platform observability. Uploaded images may be processed by Cloudflare Images; generation prompts and outputs may be processed by Cloudflare Workers AI.
Cloudflare describes customer prompts and outputs as customer content and states that it does not use that content to train Workers AI models or improve its services without explicit consent. Learn more in Cloudflare's Workers AI data usage documentation, Turnstile validation documentation, and privacy policy.
5. Retention and deletion
- Images: uploaded originals and generated results are stored in a private R2 bucket with lifecycle rules configured to expire them after one day. Cloudflare says removal typically occurs within 24 hours after the expiration time, although it can take longer.
- Task records:task IDs, file references, operation, status, and timestamps are deleted after two days. Generation prompts are passed to the processing queue and are not stored in PicDo's task database.
- Quota and abuse records: short upload windows are removed after one day; daily usage rows are removed after no more than eight days.
- Anonymous product events: server-side event rows are deleted after 90 days. The browser session ID remains in session storage until the browser session or tab is closed, subject to browser behavior.
Cloudflare may retain separate security, network, or observability records under its own settings and policies. The R2 lifecycle behavior is documented in Cloudflare's object lifecycle documentation.
6. Sharing and sale
PicDo does not sell personal information and does not share it for cross-context behavioral advertising. Information may be processed by Cloudflare to operate the service, disclosed when required by law, or used to investigate abuse and protect users, PicDo, or others.
7. Security
PicDo limits file access to same-origin application routes, serves file responses with private no-store caching instructions, validates accepted upload types and sizes, uses Turnstile, and automatically expires stored files. No online service can guarantee absolute security, so do not upload images or prompts that you cannot risk disclosing.
8. Your choices and rights
Do not submit an image or prompt if you do not want PicDo and Cloudflare to process it. Download any result you want to keep before the automatic deletion window. You can end the anonymous browser session by closing the tab or clearing site data.
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing. PicDo has no accounts and intentionally avoids storing the original IP address in its application database, so it may not be possible to connect an anonymous record to you.
9. Children
PicDo is not directed to children. A parent or legal guardian should supervise use by anyone who cannot legally agree to these terms. Do not upload an image of a child unless you have the authority and consent required by applicable law.
10. International processing
Cloudflare operates a global network. Your information may therefore be processed in countries other than the one where you live, subject to Cloudflare's contractual, legal, and security safeguards.
11. Changes to this policy
PicDo may update this policy as the beta, providers, or legal requirements change. Material changes will be reflected by a new date at the top of this page. Review this page before using new paid, account, or data-intensive features if they are introduced.
12. Contact status
PicDo does not currently publish a dedicated privacy mailbox, and the picdo.ai domain is not configured to receive email. A direct private contact channel must be added before PicDo introduces accounts, billing, or marketing email.
Until that channel is active, do not post private images, prompts, identity documents, or other sensitive information through public support channels.