Privacy Policy
Last updated: July 27, 2026
Pipe2.ai (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at pipe2.ai and the Pipe2.ai mobile apps (together, the “Service”). Where the website and the Pipe2.ai Android app behave differently, this policy says so.
You can ask us to delete your account and data at any time — see Delete Your Account for the steps, what is deleted, and what we keep.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password. Passwords are hashed and never stored in plain text.
Payment Information
Payments are processed by Stripe, our payment processor. We do not store your credit card number, bank account details, or other payment credentials. We receive transaction confirmations including plan type, amount, and subscription status.
Purchases are made on the Pipe2.ai website. The Pipe2.ai Android app does not process payments and does not offer in-app purchases.
User Content
When you use our Pipelines, we temporarily process the images, audio, and text you upload (“Input Content”) to generate results (“Output Content”). See Section 4 for our data retention practices.
Usage Data
We collect information about how you use the Service, including Pipeline runs, credit consumption, page views, and feature usage. We use self-hosted analytics to understand usage patterns.
Referral Information
When you open Pipe2.ai through a referral link, we collect and store the referral code associated with that link. We use it to attribute registrations and purchases, provide referral benefits, prevent abuse, and operate our affiliate program.
Device, Browser, and Diagnostic Information
We automatically collect technical information such as your IP address, browser type, operating system, app version, device type and model, crash reports, diagnostic events, and identifiers used to operate and secure the Service. Where push notifications are enabled, this also includes the push notification token issued to your device by the platform.
We use this information to maintain sessions, deliver notifications, diagnose errors, prevent fraud and abuse, understand feature usage, and improve the reliability of the Service.
2. How We Use Your Information
- Provide the Service: process your inputs through AI Pipelines and deliver generated content
- Account management: authenticate your identity, manage subscriptions, and track credit balances
- Billing: process payments, issue receipts, and manage subscription renewals via Stripe
- Referral and affiliate attribution: associate registrations and eligible purchases with referral links, provide referral benefits, calculate commissions where applicable, and prevent referral abuse
- Product improvement: analyze usage patterns to improve Pipeline quality and user experience
- Communication: send account-related emails including verification, password reset, and billing notifications
- Security: detect and prevent fraud, abuse, and unauthorized access
3. Third-Party Services
We share data with third-party services only as necessary to operate the Service:
- AI Providers (Google Gemini, xAI, Volcengine, ElevenLabs, OpenAI): receive your Input Content for processing. Each provider has its own privacy policy governing how they handle data.
- Stripe: payment processing and subscription management
- Self-hosted Analytics: product analytics (anonymized usage data, stored on our infrastructure)
- Object storage: cloud storage for uploaded and generated content, held on infrastructure we operate
We do not sell your personal information to third parties.
4. Data Retention
- Account data: retained for the lifetime of your account. Deleted upon account deletion request.
- Input Content: stored in your asset library for quick reuse. You can delete uploaded files at any time from your dashboard, or they are deleted when your account is terminated.
- Output Content: stored in your asset library until you delete it or your account is terminated. You can delete generated assets at any time from your dashboard.
- Pipeline run history: retained for the lifetime of your account for your reference.
- Usage analytics: product events and session records, identified by internal identifiers rather than your name or email, retained for up to 24 months.
- Operational logs: retained for up to 30 days for debugging and security purposes.
After you delete your account
Deleting your account permanently removes your profile, credentials, content, Pipeline history, stored API keys, and referral records after a 30-day grace period during which you can still cancel.
A limited set of records survives deletion where we are legally required to keep it or need it to keep the Service secure: payment and transaction records (for tax and accounting law), append-only credit ledger entries, records of administrative actions with the link to your account removed, and usage analytics identified by internal identifiers rather than your name or email, which age out on their own retention schedule. If we are under a legal obligation to preserve data — for example an active law-enforcement request — deletion is suspended for the affected data until that obligation ends.
Delete Your Account sets out the full list, the reasons, and the retention period for each category.
5. Data Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted via TLS/HTTPS
- Passwords are securely hashed and never stored in plain text
- Database access is restricted and authenticated
- Row-level security ensures users can only access their own data
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate personal data
- Deletion: request deletion of your account and associated data — see Delete Your Account for the steps
- Portability: request your data in a machine-readable format
- Objection: object to processing of your data for certain purposes
To exercise any of these rights, contact us at privacy@pipe2.ai.
7. Cookies and Local Device Storage
Web Service
When you use Pipe2.ai through a web browser, we use cookies and browser storage, including local storage, to maintain your authenticated session, remember preferences, protect the Service, and support first-party analytics.
Specifically:
- Session: your authentication token is held in browser local storage to keep you signed in.
- First-party analytics: two cookies, one holding an anonymous visitor identifier and one holding your account identifier while you are signed in, each lasting up to 365 days, plus a session identifier held in session storage that expires after 30 minutes of inactivity.
- Referral: a cookie recording the referral code you arrived with, which expires after 90 days.
All of these are first-party. We do not use third-party advertising cookies and we do not use your data for advertising.
Android App
The Pipe2.ai Android app does not use browser cookies or browser local storage for its native functionality. Instead, it stores limited information locally on your device using Android application storage.
This may include:
- authentication session credentials, encrypted with a key held in the Android Keystore;
- application settings and preferences;
- a referral attribution code when you open or register through a referral link;
- a push notification token when push notifications are enabled;
- an anonymous analytics identifier used to measure product usage;
- temporary cache data, including media previews and any pending diagnostic reports, required to display or process content.
The app does not store your account password on the device. Signing out removes your stored session credentials. The anonymous analytics identifier is deliberately kept across sign-out and account deletion so usage measurement stays consistent for the same device; you can remove it by clearing the app’s data or uninstalling the app.
Uninstalling the app does not by itself delete your account — see Delete Your Account.
We do not use advertising identifiers and we do not use your data for advertising.
8. Children’s Privacy
The Service is not intended for users under 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
9. International Transfers
Your data may be processed in countries other than your own. By using the Service, you consent to the transfer of your data to the United States and other jurisdictions where our service providers operate.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised “Last updated” date. Continued use of the Service constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or requests, contact us at privacy@pipe2.ai.