Saltar al contenido
Pexafy
Doc. de la API Precios Acerca de Herramientas Blog
Iniciar sesión Comenzar
Español
  • English
  • 简体中文
  • Español
  • العربية
  • हिन्दी
  • Português
  • Français
  • Русский
  • Deutsch
  • 日本語
  • Bahasa Indonesia
  • 한국어
  • Türkçe
  • Tiếng Việt
  • ไทย
  • فارسی
  • Polski
  • Italiano
  • Nederlands
  • Filipino
  • বাংলা
  • Kiswahili
  • اردو
Pexafy
Herramientas Doc. de la API Precios Acerca de
Iniciar sesión
Comience — gratis
Tema

On this page

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Cookie Policy
  • Licenses
  • Legal Notice
  • Security

Last updated: October 9, 2026

Privacy Policy

This Privacy Policy explains how Pexafy ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our website and API. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).

1. Data Controller

Pexafy is a service operated by OSCAR HOLDING, trading as DataMinds Solutions, a French société par actions simplifiée with share capital of €1,000, registered with the Paris Trade and Companies Register under number 995 337 763, whose registered office is at 50 avenue des Champs-Élysées, 75008 Paris, France. OSCAR HOLDING is the data controller for personal data processed through this Service. Full publisher details are on our Legal Notice page.

For any privacy-related inquiry, contact [email protected].

2. Data We Collect

Account Data

  • Email address — used for account creation, login, and communications
  • Password — stored as a bcrypt hash (never in plaintext)

Usage Data

  • API requests made with an API key — the time, the method, path and query string, which includes the text of a search (up to 512 characters, with anything that looks like a credential removed); the response code and duration; the key used; the IP address and user agent the request came from. Kept for 90 days, then deleted.
  • Page requests — the path and query string of pages you request, including the text of a search when it appears in the address (for example /?q=a quiet street at dawn), together with the referring page, response code and duration. Retained for 60 days, then deleted.

Technical Data

  • IP address — used for security, abuse prevention and rate-limiting. Kept in clear in the API call log (90 days) and with contact-form messages. Rate-limiting and abuse-prevention counters hold it, or a hash of it, for one minute to about a day, and the network block it belongs to for up to 7 days. Our security logs record it when we block a request as automated or abusive, or when an API key is used from a new address. Our visit statistics keep only a keyed hash of it.
  • User-Agent — browser/client information
  • Session cookies — Django session ID for authentication
  • Visitor cookie (pxf_vid) — a first-party identifier we set to recognise a returning browser and understand how people arrive at Pexafy. It carries a random identifier, not your name. Against it we keep the first page you landed on, the site that referred you, any campaign tag in the address, your country and language, and your browser's user-agent string. If you later create an account, that identifier is linked to your account so we can see which route led to a sign-up.

Contact Form Data

  • Name, email, subject, and message when you contact us
  • Retained for 1 year, then deleted by a purge that runs every day

3. How We Use Your Data

  • Provide the Service — authenticate you, process API requests, manage your subscription
  • Security — detect abuse, enforce rate limits, prevent unauthorized access
  • Communications — transactional emails (account-related, not marketing)
  • Analytics — anonymized, aggregated usage statistics to improve the Service
  • Legal obligations — comply with applicable law

4. Legal Basis (GDPR Article 6)

PurposeLegal basis
Account management, API accessPerformance of contract (Art. 6(1)(b))
Security, fraud preventionLegitimate interest (Art. 6(1)(f))
Transactional emailsLegitimate interest / Contract performance
Analytics (anonymized)Legitimate interest (Art. 6(1)(f))
Cookie consentConsent (Art. 6(1)(a)) — for non-essential cookies only

5. Data Retention

  • Account data — retained until you delete your account
  • API call log, including the text of searches — 90 days
  • MCP connector request log — 90 days
  • Allowance counters (connector use without an account) — up to about three months after their last use
  • Selections made in the connector's results grid — about one hour, in memory
  • Page requests, including search text in the address — 60 days, then deleted by a purge that runs every day
  • Visitor and session records (the aggregate counts and first-visit details described above, and the link to your account if there is one) — deleted, with the visits recorded under them, once the browser has gone 25 months without visiting Pexafy or signing in; a visit recorded without the visitor cookie is deleted 25 months after it ended. The same daily purge applies this, and you can ask us to erase them sooner
  • Contact messages — 1 year, then deleted by the same daily purge
  • Billing records — 7 years (legal obligation)

6. Data Sharing

We do not sell your personal data. We share data only with:

  • Creem (Armitage Labs OÜ) — our reseller and Merchant of Record for paid plans. When you subscribe, Creem collects your payment and billing details (name, email, billing address, payment method) to charge you, issue your invoices and collect taxes, as an independent controller under Creem's Privacy Notice. We receive your subscription status and the email address you paid with, never your card details.
  • Brevo — delivery of transactional email (account activation, password reset). Receives your email address and the message we send you.
  • Cloudflare — content delivery, caching and protection against abuse. Every request to Pexafy passes through it, so it processes your IP address and request metadata on our behalf.
  • Google and GitHub — only if you choose to sign in with one of them. We receive the email address of the account you sign in with; we do not receive your password.
  • Infrastructure providers — servers hosted in the European Union (Germany and France)
  • Legal authorities — only when required by law

7. Your GDPR Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of your data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to portability — receive your data in a machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to restrict processing — limit how we use your data

To exercise any right, email [email protected] with the subject "GDPR Request". We respond within 30 days. You may also contact your local data protection authority (in France: CNIL).

8. Cookies

We use essential cookies for authentication, and one first-party cookie (pxf_vid) to recognise a returning browser and measure how people find Pexafy, as described in section 2. We set no third-party advertising or tracking cookies, and we do not share this data with advertisers. See our Cookie Policy for details.

9. Children's Privacy

The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us immediately.

10. International Transfers

Your data is stored within the European Union. Two of the services above operate globally: Cloudflare serves requests from the edge location nearest to you, and Creem processes payments on its own international infrastructure. Where that involves a transfer outside the EU, it takes place under the safeguards those providers offer (Standard Contractual Clauses or equivalent).

11. Security Measures

We implement appropriate technical and organizational measures to protect your data, including:

  • HTTPS/TLS encryption for all data in transit
  • bcrypt password hashing (cost factor 12+)
  • API keys hashed before storage
  • Redis sessions with short TTL
  • Regular security audits

12. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notice. Continued use of the Service after changes constitutes acceptance.

13. AI Assistants and the MCP Connector

Pexafy can be used from an AI assistant — ChatGPT, Claude, Codex or any other client of the Model Context Protocol — through our MCP server at https://mcp.pexafy.com/mcp (the "connector"). Its source code is public at https://github.com/Pexafy/pexafy-mcp. This section describes what the connector processes; the rest of this policy applies to it too.

How you connect. With a Pexafy account, connecting opens a Pexafy sign-in page and asks you to approve read access. Once you approve, Pexafy gives the connector an API key of its own, separate from your password, and your searches then count against your plan. Without an account, the connector can serve a small daily allowance in ChatGPT and in apps that call it directly from your device, such as Claude Code. On claude.ai and in Claude's apps, you always connect with an account.

Counting an allowance without an account. We use the anonymized user identifier that ChatGPT sends with each request ("openai/subject") or, failing that, the IP address the request comes from. The connector counts the allowance under a keyed hash (HMAC) of it, and our API keeps that hash in its counters and call log.

What reaches us.

  • The search sentence the assistant composes, and the shape filter (landscape, portrait or square) if there is one.
  • For a search by image: the image you provide, a link to it, which our server then downloads, or the identifier of a Pexafy photo.
  • The photographs you like in the results grid: their identifiers, in the order you liked or arranged them, with their public details (description, photographer, source, licence, size, credit line and links), so that the assistant can read them back.
  • The technical data every request carries: the network address it comes from (for ChatGPT and claude.ai, that of the assistant's servers; for an app that calls the connector directly, such as Claude Code, yours), the name and version of the client and, from ChatGPT, the identifiers it attaches to the user and to the conversation. When the grid is shown, your browser also loads its thumbnails from our servers and sends us the photographs you like.

We do not receive the rest of your conversation, only what the assistant puts in its requests to the connector, which may repeat your words.

What we keep, and for how long.

  • Each search: the time, the request, including the search text and the shape filter, the response code and duration, the network address it is recorded with, and the key used or, without an account, the keyed hash and the name of the app. Kept for 90 days in our API call log, for usage accounting, abuse prevention, support and aggregated statistics, then deleted.
  • The daily and monthly counters of an allowance used without an account: deleted within about three months of their last use. With an account, searches count toward your plan's usage like any other API request.
  • Reference images: used only to run the search, never stored. The results of a search by image are cached for five minutes under a fingerprint of the image.
  • Your selection in the grid: held in the connector's memory for about an hour after its last change, never written to disk. Outside ChatGPT, the grid also keeps its view there for the same hour: the photographs on screen, the words of the search or the link of the image, and the photographs you liked.
  • For each request to the connector: the time, the client's name and version, the protocol session identifier, the response code and sizes and, from ChatGPT, one-way hashes of the user and conversation identifiers. Kept for 90 days. Like any request to our servers, it also enters our visit statistics (sections 2 and 5).
  • Markers that spare you a repeated prompt — that you have seen the grid's short guide, or signed in from an app on your device: kept as hashes, for 400 days at most.
  • Short-lived caches of search results and of the encoding of the search text: one hour at most.

Links. Links to pexafy.com that the results grid opens, and the links to Pexafy photo pages that the grid passes to the assistant, carry campaign tags (utm_source, which names the app the grid is shown in, utm_medium and utm_campaign) so that we can count the visits that come from the connector. After a text search, the grid's link that opens it on pexafy.com also carries the words of that search in its address. Such a visit is then handled like any other visit to the website (section 2).

Who processes it. Our own servers, including the server that encodes images and search text, all in the European Union (section 6), and Cloudflare, through which requests pass. We do not sell this data or use it for advertising. The operator of your assistant — OpenAI, Anthropic or whoever runs it — handles your conversation under its own privacy policy; the photographs and credit lines we return become part of that conversation.

Your controls. Remove the connector in your assistant, and it stops calling Pexafy. Or revoke its key from your Pexafy dashboard (API keys): every assistant you connected by signing in shares that key, and all of them lose access at their next request. To access or delete the data above, write to [email protected] (section 7). Data we hold only as a hash can be found only if you give us the identifier it was made from.

14. Contact

For all data protection inquiries: [email protected]

Producto

  • Buscar imágenes
  • Herramientas de imagen
  • Precios
  • Documentación de la API
  • Conector de Claude & ChatGPT
  • Página de estado

Empresa

  • Acerca de Pexafy
  • Contáctenos
  • Preguntas frecuentes
  • Blog
  • Press & Brand

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Cookie Policy
  • Legal Notice
  • Licenses
Pexafy © 2026 Pexafy. Todos los derechos reservados.
Español
  • English
  • 简体中文
  • Español
  • العربية
  • हिन्दी
  • Português
  • Français
  • Русский
  • Deutsch
  • 日本語
  • Bahasa Indonesia
  • 한국어
  • Türkçe
  • Tiếng Việt
  • ไทย
  • فارسی
  • Polski
  • Italiano
  • Nederlands
  • Filipino
  • বাংলা
  • Kiswahili
  • اردو

Utilizamos solo cookies esenciales para que Pexafy funcione. Sin rastreo, sin anuncios.

Política de cookies