Privacy policy

Last updated: 10 September 2026

In short

Pixel Garage needs no sign-up, does not know your name and does not measure your behaviour. There are no ads and no tracking.

Your photo leaves the device only for the transformation. What comes out of it is yours and lives on your device.

Which apps this covers

This policy covers Pixel Garage on iPhone (App Store) and Pixel Garage on Android (Google Play). Both apps use the same server and the same transformation. Wherever the platforms differ, it says so below.

Controller

Niklas Albrecht Rießnerstraße 51 99427 Weimar Germany

Email: kontakt@niklasxskyz.de

The photo and the transformation

When you want to create a vehicle, the selected photo is sent to our server (Supabase, data centre Frankfurt am Main, region eu-central-1). From there it goes to OpenAI's image interface, which draws your pixel vehicle. If that route fails, we use Google's image interface (Gemini API) instead. Only ever one of the two services is involved.

What goes up is not the file from your gallery. The app cuts the vehicle out on the device first, places it on a flat background and re-encodes that as a new JPEG (longest edge 2048 pixels at most). All metadata falls away in the process: no GPS location, no device model, no capture date leaves the device. If the cut-out finds no vehicle, the photo itself goes up — re-encoded as well, and without metadata.

The photo goes to OpenAI exactly once — for the drawing. A second, small step afterwards only looks at the generated pixel image (which way it faces, what kind of vehicle it is); your photo is no longer involved in that.

We do not keep the photo ourselves: it exists only for the duration of the processing. All we store is a checksum of the photo (SHA-256), so that the same photo does not have to be drawn — and paid for — twice within 24 hours. The photo cannot be reconstructed from that checksum.

OpenAI states that data passed to its interface is kept for up to 30 days for abuse detection and deleted afterwards, and is not used to train its models. Google states the same principle for its paid interface: data is not used for training and is kept only briefly for abuse detection.

The legal basis is Art. 6 (1) (b) GDPR — this processing is the core of the service you pay for. Both providers act as processors on our behalf.

Both also process data in the United States. Google LLC is certified under the EU-US Data Privacy Framework; the European Commission's standard contractual clauses apply in addition. For the transfer to OpenAI we rely on the European Commission's standard contractual clauses, which are part of our data processing agreement with OpenAI.

The preview before you buy

Before the purchase, the server draws two proposals from your photo and you pick one. The first round is free; every delivered purchase grants another one.

These preview images are cached on our server (a non-public storage area, reachable only through our server, never through a public address). That is needed so the purchase can then unlock exactly the proposal you chose — even if the app goes to the background or restarts in between. For each round we also store a row containing a random round identifier, the identifier of your anonymous account, the checksum of the photo, the number of proposals and, after the purchase, which proposal was unlocked with which transaction.

The preview images are pixel drawings, not photos. They stay in that storage area until we delete them; there is no scheduled clean-up yet. You can write to us at any time and we will clear out the images belonging to your account.

Your account without sign-up

So that a paid purchase can be matched to the right device, the app creates an anonymous account on first launch. It consists of a random string — no name, no email address, no phone number. It lives only in the app's own settings on that device and deliberately does not survive a reinstall.

For a purchase we store the store's transaction number, the identifier of that anonymous account, the processing state, the time and the number of attempts. This is necessary so that a paid purchase is not lost and cannot be redeemed twice (Art. 6 (1) (b) GDPR).

We use no advertising identifier, no device identifier and no fingerprint of your device.

Purchase through Apple (on iPhone)

The purchase runs entirely through Apple. We receive a signed confirmation of the transaction from Apple, but no payment details. Which data Apple processes is set out in Apple's privacy policy.

If Apple asks us about a refund request, we answer Apple with information about that one purchase: whether the vehicle was delivered, how old the anonymous account is, and which of Apple's amount tiers that account's purchases so far fall into. The legal basis is Art. 6 (1) (f) GDPR — reviewing refund requests is our legitimate interest, and Apple requires these details for the review.

Revenue overview (on iPhone only)

On iPhone we additionally report a completed purchase to RevenueCat, Inc. (USA). That is our revenue overview: it tells us how many purchases come in. What is sent is the purchase and the identifier of the anonymous account — no name, no email address, no photo, no usage data from the app. RevenueCat does not carry out the purchase and unlocks nothing; that is decided solely by Apple's receipt.

The legal basis is Art. 6 (1) (f) GDPR — we have a legitimate interest in keeping an overview of our revenue. RevenueCat acts as a processor on our behalf; the European Commission's standard contractual clauses cover the transfer to the United States. The Android app is not connected to it.

Purchase through Google Play (on Android)

The purchase runs entirely through Google. The app hands us the purchase token, and we check it against the Google Play Developer API — Google then confirms to us that the purchase is valid and tells us the order ID. We store that order ID as the transaction number of the purchase. We receive no payment details: no card number, no address, no name, no Google account identifier. Which data Google processes for the purchase itself is set out in Google's privacy policy.

Sharing and gifting by link

You can give a vehicle away. There are two routes for that.

By file: the app writes a .pixelcar file and hands it to your device's share dialogue. This route does not involve our server.

By link: for this the app puts the package on our server (a non-public storage area) and gets back a code that goes into the link. The package holds the finished pixel sheet of your vehicle and the name you gave it — not your photo. The database row alongside it holds the vehicle's random identifier, the code, the identifier of your anonymous account, the number of redemptions, and the creation and expiry times.

A link expires after 30 days and can be redeemed at most three times. A nightly clean-up job deletes expired packages together with their row. The code is twelve characters from an alphabet of 31, and it is listed and searchable nowhere — without the link, nobody finds the gift. The legal basis is Art. 6 (1) (b) GDPR, because without that storage the link does not work.

The Workshop

In the Workshop you load a pixel image you made yourself into the app as a PNG. This route stays entirely on the device: the app checks the image itself (size, transparency, colour distribution), and neither the image nor the result of that check goes to our server. That is also why a vehicle from the Workshop cannot be given away by link.

The one-time purchase that unlocks the Workshop is checked only against the store you bought it from — on Android, that means directly against Google Play, without our server.

Camera and photos

On Android the app asks for no camera and no photo permission. You take a photo in your device's camera app, which the app opens through a system call; you pick an image from your gallery in the system picker, which hands us only that one image. On iPhone the same flow runs through Apple's photo picker and camera.

Checking the photo on the device

Before a photo is uploaded at all, the app checks on the device whether there is a vehicle in it, and cuts it out. On Android that is done by Google's ML Kit components, which run entirely on the device: the image content does not leave the device. One component (the cut-out) is delivered by Google Play services — the device downloads a model from Google for that, but no image data is sent to Google. On iPhone, Apple's own image analysis does the same job, likewise on the device.

Backup of your vehicles

On iPhone the app stores a backup in your private iCloud (CloudKit, container iCloud.de.pixelgarage.app), so that your vehicle survives a reinstall and a new device. That backup sits in your Apple account — we have no access to it and can neither read nor delete it.

On Android there is no such backup. The app is excluded from Android's cloud backup (allowBackup=false): your vehicles live only in the app's storage on that one device. Delete the app and they are gone. To move a vehicle to another device, use the .pixelcar file or the link.

The vehicle outside the app

On Android your vehicle stands in a home screen widget. The widget works entirely on the device: it reads your vehicle's images from the app's storage and derives the time of day (morning, day, evening, night) from the device clock alone. There is no server connection, no location access and no Lock Screen part.

On iPhone there is also the vehicle on your Lock Screen. So that it keeps driving while the app is closed, the app registers an identifier of the running Live Activity with our server and with Apple's push service. For that we store the identifier, the identifier of your anonymous account, the number of frames and timestamps — not your vehicle's name and not its image. When the activity ends, the identifier is deleted; if no sign of life arrives for 72 hours, the server clears it out by itself.

Made by AI

The pixel vehicle is created by an AI image model. It is a new drawing, not an edited photo.

What there isn't

No ads. No tracking across apps or websites, no advertising identifier. No behavioural analytics: we do not measure which buttons you press, how long you stay in the app or which vehicles you look at. No crash reporting service. No push notifications on Android. No sharing with third parties beyond what is described above. No profiling. No selling of data.

Retention

Photos: only for the duration of the transformation. Photo checksum: together with the preview row. Preview images and preview rows: until we delete them, on request immediately. Purchase data: as long as needed for handling the purchase and for statutory retention periods. Shared packages: 30 days, then removed by the nightly clean-up job. Lock Screen activity identifiers: until the activity ends, at the latest 72 hours after the last sign of life. Purchase reports in the revenue overview: as long as the account there exists.

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Just send us an email at kontakt@niklasxskyz.de.

Because the account is anonymous, we need the number of your purchase to match it: on iPhone the transaction number from your purchase history at Apple, on Android the order ID from your order history at Google Play (it starts with "GPA."). Without that number we cannot tell which rows belong to you — and would otherwise hand out someone else's data.

You also have the right to lodge a complaint with a data protection authority, for example the Thuringian Commissioner for Data Protection.

This website

The site itself sets no cookies and embeds no external fonts, maps or analytics. When you visit, our host processes technically necessary access data (IP address, time, page requested) for delivery and security, Art. 6 (1) (f) GDPR.