Skip to content

Privacy policy

How Thinkbix Technologies handles personal data when you use pixbix. Written to be read — the plain-English summary in each section is what actually happens.

Effective
15th August 2026
Entity
Thinkbix Technologies
The short version. We collect the minimum needed to run your account: who you are, what you make, and what you pay. We do not sell your data, we do not train models on your content, and we do not use your designs for anything other than rendering them for you. You can export or delete your data at any time.

1Who we are#

pixbix is operated by Thinkbix Technologies(“we”, “us”). Under India’s Digital Personal Data Protection Act, 2023 we are the Data Fiduciary and you are the Data Principal. Under the UK and EU GDPR the same roles are called controller and data subject. Both name the same arrangement, and this policy uses whichever is clearer in context.

Where we render on your instructions — your templates, your uploads, your API calls — we act as a Data Processor for that content. The data processing addendum governs that relationship.

Who you are dealing with

Operating entity
Thinkbix Technologies
Service
pixbix (pixbix.app)
Registered address
3, Rathi Market, Tilak Chowk, Vidisha, Madhya Pradesh 464001
GSTIN
23AUPPA7629A1ZY
Contact for this policy
hello@pixbix.app
Grievance officer
Sunil Palhello@pixbix.app
Governing law
India — courts at Pune, Maharashtra

For privacy questions, data requests, or to reach our grievance officer, write to hello@pixbix.app. We acknowledge every request within 72 hours.

2What we collect#

Three categories, and nothing beyond them.

CategoryWhat it includesWhy we need it
Account dataMobile number, name, optional email address, profile picture, workspace name and roleTo create your account, identify you at sign-in, and control who can act in a workspace
Content dataTemplates, designs, uploaded images, video, audio and fonts, render outputs, and the field values you submitTo store your work and render it. This is your content — see clause 4
Usage and billing dataRender history, credit ledger, API key usage, IP address, browser and device type, payment records and invoicesTo operate the service, meter credits, prevent abuse, issue invoices and meet tax obligations

We do not collect location beyond the country implied by your IP address, contacts, biometrics, or any special-category data. We do not use third-party advertising trackers on our product surfaces.

3How we use it#

  • To provide the service — authenticate you, store your templates and media, render your outputs, and deliver them.
  • To meter and bill — count credits, apply plan limits, process payments through our payment processor, and issue GST-compliant invoices.
  • To keep the service safe — rate limiting, abuse detection, fraud prevention and security investigation.
  • To support you — answer your messages and investigate faults you report. We access your content only when you ask us to, or when required to investigate a specific abuse report.
  • To tell you things you need to know — service notices, security alerts, billing receipts and plan changes. These are transactional and you cannot unsubscribe from them while you hold an account.
  • Marketing, only if you opt in — product updates and announcements. Unsubscribe any time; it does not affect your account.
We do not train on your content. pixbixis a rendering engine, not a model. Your templates, media and outputs are never used to train machine learning systems, ours or anyone else’s, and are never shared with a third party for that purpose.

4Your content stays yours#

You own everything you upload and everything you generate. We claim no ownership over your templates, media or render outputs.

We hold a limited licence to store, process and transmit that content strictly to operate the service for you — to render a template, deliver a file, or show you a preview. That licence ends when you delete the content or close your account.

The one exception is content you deliberately publish. If you set a template to public, you are asking us to list it in the shared library and allow other accounts to render from it. You can unpublish at any time, which removes it from the library going forward.

5Legal bases for processing#

Where the GDPR or a similar regime applies, we rely on:

  • Contract — account, content and billing data are necessary to provide the service you signed up for.
  • Legitimate interests — security, abuse prevention, and improving reliability, balanced against your rights.
  • Legal obligation — tax records and invoices, which we must retain regardless of your preferences.
  • Consent — marketing email and non-essential cookies only. Withdraw it at any time.

Under India’s Digital Personal Data Protection Act, 2023, we process personal data for the lawful purposes described above, with your consent or as a legitimate use permitted by that Act.

6Who we share it with#

We do not sell personal data. We share it only with processors who help us run the service, each bound by contract to protect it and use it only on our instructions.

ProcessorPurposeData involved
RazorpayPayment processing and subscription billingName, email, phone, billing address, GSTIN, payment metadata
Cloud hosting and object storageRunning the application and storing media and render outputsAll account and content data
GoogleWeb fonts used during renderingNo account data — fonts are requested at render time
Meta / WhatsApp Business APIDelivering one-time sign-in codesPhone number and the code itself
Email delivery providerTransactional email — receipts, invitations, alertsEmail address and message content

We may also disclose data where legally compelled, to enforce our terms, or to protect the rights and safety of our users. Where the law permits, we will tell you before we do.

If our business is acquired or merged, data may transfer to the acquirer. You will be notified before that happens and before any change to this policy takes effect.

7Where data is stored#

Data is stored primarily in India. Some processors — notably payment, email and font delivery — operate globally, so limited personal data may be processed outside India.

Where data leaves the country, we rely on standard contractual clauses or an equivalent safeguard appropriate to the destination.

Enterprise customers can request data residency in a specific region. Contact hello@pixbix.app.

8How long we keep it#

DataRetention
Account dataFor as long as your account is open, then 30 days after deletion
Templates, designs and mediaUntil you delete them, or 30 days after account closure
Render outputsPer your plan — 7 days on Free, up to 365 days on Scale, then permanently deleted
Credit ledger and render history7 years, as billing records
Invoices and payment records8 years, as required by Indian tax law
Security and access logs12 months
Support correspondence3 years from last contact

Backups are retained for up to 35 days. Deleted data may persist in a backup for that window before being overwritten, but it is not restored to live systems.

9Your rights#

You can exercise all of these from your account settings, or by writing to us.

  • Access — get a copy of the personal data we hold about you.
  • Correction — fix anything inaccurate or incomplete.
  • Deletion — close your account and have your data erased, except records we must legally keep.
  • Portability — export your templates and designs in a machine-readable format.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it while a dispute is resolved.
  • Withdraw consent — for marketing or non-essential cookies, at any time.
  • Nominate — under the DPDP Act, nominate someone to exercise your rights if you are unable to.
  • Complain — to us first, and then to your supervisory authority or the Data Protection Board of India.

We respond to requests within 30 days. We may ask you to verify your identity first — that check protects you from someone else requesting your data.

10Security#

What we do to keep your data safe:

  • TLS in transit and encryption at rest for stored content
  • API credentials stored only as SHA-256 hashes — a database leak cannot be replayed as keys
  • Scoped API keys with optional IP allowlists and expiry
  • Role-based access within workspaces, so members see only what their role permits
  • HMAC-signed webhooks with timestamps, so delivered payloads cannot be forged or replayed
  • Strict egress controls on our render workers, preventing them from reaching internal or private addresses
  • Least-privilege internal access, granted per incident and logged

No system is perfectly secure. If a personal data breach occurs we will tell you what we know, what we are doing about it and what you should do — on these timelines:

  • Within 72 hours of becoming aware, to the relevant supervisory authority where the UK or EU GDPR applies.
  • Without delay, to the Data Protection Board of India and to affected Data Principals, as the DPDP Act requires.
  • Directly to you where the breach is likely to result in a high risk to your rights — we will not wait to be told to.
  • A follow-up once the investigation closes, describing the cause and what changed as a result.

To report a vulnerability, email hello@pixbix.app. We will not pursue action against good-faith research that respects user privacy and avoids service disruption.

11Cookies#

We use the minimum necessary — session, preference and basic analytics. There are no advertising or cross-site tracking cookies. Full detail is in the cookie policy.

12If you are in the United States#

Several US states — California, Colorado, Connecticut and Virginia among them — grant residents rights that closely mirror those in section 9. You may exercise all of them the same way, and we will not treat you differently for doing so.

Two points specific to California, under the CCPA as amended by the CPRA:

  • We do not sell or share your personal information as those terms are defined there, and have not in the preceding twelve months. There is therefore no “Do Not Sell or Share” link to offer, because there is nothing to opt out of.
  • We do not use sensitive personal information to infer characteristics, so the right to limit its use does not arise.

You may appoint an authorised agent to make a request for you. We will ask for proof of that authorisation and separately verify your identity — that check exists to stop someone else collecting your data.

13Children#

pixbix is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.

14Changes to this policy#

We will post any change here with a new effective date. For material changes we will email account holders at least 14 days before they take effect, so you have time to object or close your account.

15Grievance officer#

In accordance with India’s Information Technology Act, 2000 and the rules made under it, and the DPDP Act, 2023, complaints may be addressed to our grievance officer at hello@pixbix.app.

We acknowledge complaints within 24 hours and resolve them within 15 days, or explain why more time is needed.