Privacy Notice
Effective August 25, 2026 · Version 2026-08-25
What PixoraHQ processes
We process account email and name, security credentials in protected form, account and device security events, profile and circle information, connections, posts, replies, drafts, message read settings, media, reports, moderation records, notifications, and technical records needed to operate and protect the service. If you use Budget, we also process the household names, account labels and balances, transactions, categories, recurring bills and income, savings goals, imported CSV contents, settings, and Planner calendar items that you choose to sync.
If a signed-in member asks PixoraHQ to send a Connect invitation, we process the recipient mobile number only to deliver that one invitation. Pixora does not add the number to an alert or recurring-message list and does not retain it in the member's Connect profile. Our messaging provider may retain limited delivery and opt-out records.
PixoraHQ does not sell, rent, or share mobile numbers or messaging data with third parties or affiliates for marketing or promotional purposes. We share this information only with telecommunications and service providers as necessary to deliver the one invitation requested by a member and honor opt-outs. Message and data rates may apply.
Budget privacy
Pixora Budget does not ask for online-banking usernames or passwords and does not connect directly to a financial institution in this version. Budget data belongs to the Pixora household account and is limited to authenticated household owners and adults. Selected bill, payday, and goal information is copied to the adult-only portion of the household’s Planner calendar when a user chooses calendar sync. CSV files are parsed to create transactions; users should remove sensitive columns that are not needed before importing.
Age assurance
For a self-managed account, you provide birth month and year so we can determine whether you are at least 18. We retain only an age category, the method and policy version, and the time of the check—not your birth month, year, or full birth date. For a parent-managed profile, the parent provides the month and year; we retain only whether the person is under 13, age 13–15, or age 16–17, plus the parent’s consent record. Age screening is not government-ID identity verification. Parent-managed profiles for ages 13–17 require the parent to reauthorize with their adult account. Under-13 profile creation is unavailable unless PixoraHQ has enabled a reviewed verifiable-parental-consent process; an ordinary checkbox or account password is not treated as that consent.
How information is used
We use information to provide and personalize PixoraHQ, deliver content to selected audiences, support parent and group controls, authenticate users, detect abuse and security threats, process reports, troubleshoot, improve reliability, comply with law, and communicate service or security notices. Age information is used only for eligibility and safeguards.
Automated safety screening
Before Connect delivers a post, reply, Private Room message, edited message, supported image, or attachment caption, it sends the submitted content to OpenAI's moderation service to check for serious safety concerns. This check applies even in Private Rooms. A flagged submission is not delivered and may be retained in a restricted moderation record for authorized Pixora administrators to review. Pixora does not use this screening alone to make automatic permanent-ban or law-enforcement decisions. When the first check does not flag a submission, a second context-aware check may also review the new text together with up to six recent conversation snippets to distinguish credible safety concerns from support, prevention, recovery, news, or fictional discussion. This second check uses OpenAI's GPT-5.4 nano model and returns a short, structured safety classification; it does not publish or reply to the conversation.
Sharing
Content is shared with the people or circles selected by the user, subject to blocks and safeguards. We may use hosting, email, security, and other processors to operate the service; disclose information with consent; respond to valid legal process; or protect people, rights, and the service. We do not promise that recipients will not copy or redistribute content.
Service providers and integrations
PixoraHQ uses service providers only for defined operating purposes. These currently include Render for application hosting, databases, and key-value infrastructure; configured object storage for encrypted backups and Connect media; Resend for account and safety email; OpenAI for the safety screening and optional assistant features described in this notice; Shopify and its payment providers for the storefront, checkout, subscription, and billing records; and Google for AdSense on the public PixoraHQ storefront. When a user enables an integration, Pixora may also send the information needed for that request to the selected provider, such as Amazon, Google Photos, SmartThings, Home Assistant, Hubitat, Pushover, Telegram, Slack, Discord, or a user-configured webhook. If Pixora text messaging is enabled, Pixora sends the destination number and message content to its registered telecommunications provider solely to deliver and manage those messages. Those providers process information under their own terms and privacy notices. Pixora does not give an integration access to unrelated Planner or Connect information.
Some providers process information in the United States or other countries. Their contractual, organizational, and technical safeguards apply to those transfers. Contact PixoraHQ for the current provider list or questions about a particular transfer.
Advertising
Connect does not currently display active advertising. The public PixoraHQ Shopify storefront includes Google AdSense code while that site is reviewed for advertising. Google and its advertising partners may receive ordinary device, browser, IP address, page-view, cookie, and consent information under Google's privacy terms. For visitors in the EEA, the UK, and Switzerland, Pixora uses a Google-certified consent message and does not request personalized advertising without the required consent signal. Before advertising is enabled inside Connect, ads must be clearly labeled as sponsored, frequency-limited, and reportable. Parent-managed child accounts will not receive personalized advertising; their profile, posts, circles, messages, precise location, and sensitive characteristics must not be used to target ads.
Retention and security
We retain information as needed for service operation, security, moderation, legal obligations, dispute resolution, and backups. Expiring content is removed from ordinary access after its timer, but copies may persist temporarily in backups, logs, recipients’ devices, or legal holds. We use safeguards designed to protect information, but no system is completely secure.
Active account and workspace information is kept until the user deletes it, closes the applicable feature, or deletes the Pixora account, unless a shorter product timer applies. Connect report snapshots and preserved report media have a two-year deletion date unless a documented legal hold requires longer preservation. Connect safety events are limited to the most recent 2,000 records. School verification expires after 180 days. Account deletion removes credentials, sessions, devices, Planner, Student, Budget, Care, and Connect working data associated with the account. Limited copies may remain temporarily in encrypted backups, provider logs, fraud and security records, legally required transaction records, or legal holds and are isolated from ordinary product use until their applicable schedule expires.
When you withdraw text-message consent, Pixora removes the active mobile number from ordinary alert use and retains a limited record of the consent and withdrawal as needed to honor the opt-out, demonstrate compliance, prevent unwanted messages, and resolve disputes.
When a Pop-up Circle closes, ordinary messages and working media are deleted. Its empty Circle record and limited activity metadata are deleted after a seven-day recovery period. Separately stored report evidence or material under a legal hold may be retained for the stated safety or legal period. A recipient may already have made a copy.
School email verification
A school email verification proves control of an address at the shown domain; it does not prove current enrollment, age, identity, or school endorsement. Verification expires after 180 days. School Circles are independent communities and are not operated or endorsed by the named school. Verified adults may create lasting College Circles inside that school community. Their names, descriptions, and member counts are visible only to adults with a current verification at the same school; posts remain visible only to members. PixoraHQ does not use university seals to imply affiliation.
Choices and parent controls
Users can use audience controls, blocks, filters, reports, deletion, and security settings. Parents control approved contacts and safeguards for managed children. A verified parent or guardian may review or export a managed child’s information, revoke permissions, and request correction or deletion. We will give the parent direct notice before materially changing the information collected from a child. Applicable law may provide additional access, correction, deletion, objection, appeal, or portability rights.
Connect settings provide a private JSON export and Connect-only deletion. Student provides its own export and deletion controls. The account-security page provides complete Pixora account deletion. A user may also contact PixoraHQ to request access, correction, deletion, portability, restriction, objection, or an appeal of a privacy request decision where applicable. Pixora will verify the request and respond within the period required by applicable law.
Contact
Email info@pixorahq.com or use the contact information published at pixorahq.com for privacy requests. PixoraHQ's published mailing address is 1219 Lakeview Ave, Dracut, MA 01826, United States. We may need to verify the requester’s identity or authority before acting.