Privacy Policy
Last updated: September 4, 2025
This Privacy Policy explains how we collect, use, and protect information when you use our app and website (the “Service”). By using the Service, you agree to the practices described here.
We value your privacy and are committed to protecting your information. This policy explains what data we collect, how we use it, how it is stored, and your rights.
Information We Collect
- Account info via Pi authentication: Pi provides a unique user ID (UID) that is generated specifically for our app. This UID can be revoked by Pi if you revoke permissions. We also request access to the payments scope (to allow you to make payments to the platform) and your wallet address (to allow us to send payments from the platform to you, such as passing buyer payments minus fees to sellers).
- Content you upload: uploaded images and related metadata (titles, tags, species information, notes you provide, and file metadata such as timestamps or device info). Uploaded images are encrypted at rest, and smaller preview versions with watermarks are generated for display purposes.
- Usage data: logs such as pages viewed, actions taken (uploads, purchases, licensing activity), device/browser information, and IP address. Cloudflare, which hosts our infrastructure, may log request data such as IP addresses for performance and security purposes, but these logs are not linked to account data and cannot identify specific users.
- Reports & moderation data: submissions, appeals, and decisions tied to your account.
- Transaction data: Pi payment transactions, including blockchain transaction IDs and provenance records linked to copyright or licenses.
How We Use Information
- Authenticate you, operate the Service, and enable uploads, purchases, sales, and licensing.
- Verify ownership, manage transactions, and maintain provenance and copyright records.
- Provide proof of purchase or transaction details if requested in connection with copyright disputes.
- Improve safety, prevent abuse, and comply with legal obligations.
- Analyze aggregated usage to improve features and performance.
Storage & Security
- Uploaded images are encrypted at rest. Preview images are watermarked and may be publicly accessible for display within the Service.
- We issue short-lived JWTs for sessions. Pi access tokens are stored securely server-side and are not exposed to other users.
- Blockchain transaction records (Pi Network) are public by design, but we store supplemental proofs and references to help resolve disputes if needed.
Sessions & Authentication
We do not use cookies or localStorage. Instead, authentication relies on session tokens stored in memory. If you refresh the page, you will be logged out. You remain logged in during navigation within the app (e.g., using client-side routing).
Sharing of Information
- We do not sell, rent, or share your personal information with third parties.
- Infrastructure: the Service is hosted on Cloudflare (workers, durable objects, D1, and R2). Cloudflare may log request data for operational purposes, but this data is not linked to user accounts and cannot identify individuals.
- Legal & safety: we may disclose information only to comply with law, enforce our terms, or protect users and the Service.
- Public content: images or profile elements you mark as public may be visible to others and searchable.
- Transactions: Pi blockchain records are publicly accessible. We may share additional transaction proofs with you or third parties in the context of copyright or licensing disputes.
Data Retention
We retain account, transaction, and provenance records for as long as your account is active or as needed for legal, accounting, or audit purposes. You may request deletion of your account; some records (such as on-chain or legal transaction logs) may be retained where required.
Your Rights
Depending on where you live, you may have rights to access, correct, export, or delete your data. Contact us to exercise these rights.
Children's Privacy
The Service is not directed to anyone under 18 (or the minimum age in your country, if higher). We do not knowingly collect personal data from minors.
International Transfers
We may process and store information in countries outside your own. We implement safeguards consistent with applicable law.
Changes to This Policy
We may update this policy from time to time. We will post the new date at the top of this page and, where appropriate, provide additional notice.