Section 01
Introduction
Pixalera ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use our platform, website and connected services.
By using Pixalera you agree to this Privacy Policy. If you do not agree with it, please discontinue use of our services.
Google API Services
Pixalera's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Section 02
Information We Collect
We collect information you provide directly to us, such as:
- ▸Account information (name, email address, password)
- ▸Profile information (display name, profile picture, brand details)
- ▸Content you create or upload (posts, images, videos, captions, AutoDM flows)
- ▸Connected social accounts and their associated data (Instagram, Facebook Pages, YouTube, LinkedIn, X)
- ▸YouTube channel data, analytics and video metadata when you connect your YouTube account
- ▸Payment information processed securely via Razorpay — we never store card details
- ▸Support conversations and other communications you send us
We also collect certain information automatically when you use our services, including device information, IP address, browser type, referring pages and product usage events.
Section 03
Google & YouTube API Data
When you connect your YouTube or Google account to Pixalera we request specific Google API scopes. Each scope maps to a feature you explicitly enable:
| Scope | Data accessed | How we use it |
|---|---|---|
| youtube.readonly | Channel name, ID, subscriber count, profile picture | Shown in your dashboard to confirm the connected channel |
| youtube.upload | Video upload capability | Schedule and publish video content from the Pixalera calendar |
| youtube.force-ssl | Enforces HTTPS on API requests | Ensures all transfers between Pixalera and YouTube are encrypted |
| yt-analytics.readonly | Views, watch time, impressions, CTR | Powers your Pixalera analytics dashboard |
Limited Use of Google data
Data obtained through Google APIs is used only to provide the features above. We do not sell Google user data, do not use it for advertising, do not allow humans to read it (except for security, legal compliance or at your explicit request), and do not transfer it to third parties except as needed to run the service.
Section 04
Instagram & Facebook (Meta) Data
AutoDM, publishing and inbox features use the official Meta APIs. When you connect an Instagram professional account or a Facebook Page we access only what those features need.
- ▸Page and professional account profile details (name, ID, profile picture)
- ▸Comments and direct messages required to trigger and deliver automations you configure
- ▸Published media and insights used to show performance inside Pixalera
- ▸Long-lived access tokens, stored encrypted and revocable at any time
Pixalera never sends unsolicited messages. Automations only reply within Meta's messaging policy windows and to people who initiated contact with your account.
Section 05
How We Use Your Information
- ✓Provide, operate, secure and improve the platform
- ✓Publish and schedule content to the channels you connect
- ✓Run the AutoDM, inbox and lead automations you configure
- ✓Display analytics, statistics and revenue reporting
- ✓Process transactions and send related billing information
- ✓Send administrative messages, product updates and security alerts
- ✓Respond to your questions and support requests
- ✓Analyse aggregated usage trends and comply with legal obligations
Section 07
Sub-processors
| Processor | Country | Data accessed | Purpose |
|---|---|---|---|
| Supabase Auth | United States | Email, user ID, auth tokens | Authentication and session management |
| Supabase Database | United States | Profiles, posts, tokens, settings | Primary application database |
| Supabase Storage | United States | Uploaded images and media | File storage for user content |
| Google Gemini AI | United States | Prompts you submit | AI caption and content generation |
| Razorpay | India | Payment amount, order ID (no card data) | Payment processing and subscription billing |
All sub-processors operate under data processing agreements. None may use your data for their own commercial purposes. This page is updated whenever we add or remove a processor.
Section 08
Data Security
- ✓All data is transmitted over HTTPS/TLS encrypted connections
- ✓OAuth tokens are stored encrypted and are never logged or exposed
- ✓Access to production data is restricted to authorised personnel
- ✓Row-level security isolates each authenticated user's records
- ✓Regular security reviews and dependency vulnerability scans
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Section 09
Data Retention
Account data
Retained while your account is active and deleted within 30 days of a deletion request.
Platform API data
Tokens and cached channel data exist only while the channel is connected; disconnecting deletes them.
Analytics data
Aggregated, non-identifying usage analytics may be retained for up to 2 years.
Billing records
Invoices are retained as long as Indian tax and accounting law requires.
You can request deletion of your account and associated data at any time by writing to teams@pixalera.in.
Section 10
Your Rights
- ✓Access the personal information we hold about you
- ✓Correct inaccurate or incomplete information
- ✓Request deletion of your personal data and stored platform API data
- ✓Object to or restrict certain processing
- ✓Export your data in a portable format
- ✓Disconnect any social channel at any time from your settings
To exercise any of these rights, email teams@pixalera.in. We respond within 30 days.
Section 11
Revoking Access
From Pixalera
Dashboard → Settings → Connected Channels → Disconnect. This immediately removes stored tokens and cached data.
From Google
Visit myaccount.google.com/permissions, find Pixalera and click Remove Access.
From Meta
Instagram or Facebook Settings → Business integrations → remove Pixalera.
After revocation
All stored tokens and platform data associated with that channel are deleted within 30 days.
Section 13
Children's Privacy
Pixalera is not directed to individuals under 13. We do not knowingly collect personal information from children under 13 and will delete such data promptly if we become aware of it.
Section 14
Contact Us
Questions about this Privacy Policy, your data, or our API data practices? Email teams@pixalera.in (privacy and legal inquiries). Pixalera is operated from India.
We may update this policy as the product and regulations evolve. Significant changes will be communicated by email or in-app, and the date above always reflects the latest revision.