Privacy Policy
Last updated: May 22, 2025
Introduction
Pixalera ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at pixalera.in.
By using Pixalera, you agree to the terms of this Privacy Policy. If you do not agree with the terms, please discontinue use of our services.
Google API Services: Pixalera's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Information We Collect
We collect information you provide directly to us, such as:
- ▸Account information (name, email address, password)
- ▸Profile information (display name, profile picture)
- ▸Content you create or upload (posts, images, captions)
- ▸Connected social media accounts and their associated data
- ▸YouTube channel data, analytics, and video metadata (when you connect your YouTube account)
- ▸Payment information (processed securely via Razorpay — we do not store card details)
- ▸Communications you send us
We also collect certain information automatically when you use our services, including device information, IP address, browser type, and usage data.
Google & YouTube API Data
When you connect your YouTube or Google account to Pixalera, we request access to specific Google API scopes. Below is a complete description of what data each scope accesses and how it is used:
youtube.readonly
Data accessed: Basic YouTube channel information (channel name, ID, subscriber count, profile picture)
How we use it: Displayed in your Pixalera dashboard to confirm which channel is connected.
youtube
Data accessed: Full YouTube account access including channel management
How we use it: Required to read channel details and manage your YouTube presence from Pixalera.
youtube.upload
Data accessed: Ability to upload videos to your YouTube channel
How we use it: Allows you to schedule and publish video content to YouTube directly from Pixalera's content calendar.
youtube.force-ssl
Data accessed: Enforces HTTPS for all YouTube API requests
How we use it: Ensures all data transfers between Pixalera and YouTube are encrypted and secure.
yt-analytics.readonly
Data accessed: YouTube Analytics data: views, watch time, impressions, click-through rate
How we use it: Displayed in your Pixalera analytics dashboard so you can track content performance.
yt-analytics-monetary.readonly
Data accessed: YouTube monetization analytics: estimated revenue, ad performance
How we use it: Displayed in your analytics dashboard so creators can track earnings alongside other metrics.
Important: Limited Use of Google Data
Data obtained through Google APIs is used only to provide and improve the features described above. We do not:
- ✕Sell Google user data to any third party
- ✕Use Google data for advertising purposes
- ✕Allow humans to read your Google data unless required for security, legal compliance, or at your explicit request
- ✕Transfer Google data to third parties except as necessary to provide our service
Our use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements.
How We Use Your Information
We use the information we collect to:
- ▸Provide, operate, and improve our services
- ▸Display your YouTube channel analytics and statistics in your dashboard
- ▸Enable scheduling and publishing of content to your connected YouTube channel
- ▸Process transactions and send related information
- ▸Send administrative messages, updates, and security alerts
- ▸Respond to your comments and questions
- ▸Analyze usage trends to improve user experience
- ▸Comply with legal obligations
Information Sharing
We do not sell, trade, or otherwise transfer your personal information or Google API data to third parties without your consent, except in the following circumstances:
Service Providers
We may share information with trusted third-party service providers who assist us in operating our platform (e.g., payment processors, cloud infrastructure). These providers are contractually bound to keep your data confidential.
Social Platforms
When you connect your social accounts and schedule content, we transmit content to those platforms (YouTube, Instagram, Facebook) as directed by you.
Legal Requirements
We may disclose information when required by law, court order, or governmental authority, or to protect the rights and safety of Pixalera and its users.
Data Security
We implement industry-standard security measures to protect your personal information and any Google API data we access:
- ✓All data is transmitted over HTTPS/TLS encrypted connections
- ✓OAuth tokens are stored encrypted and never logged or exposed
- ✓Access to user data is restricted to authorized personnel only
- ✓Regular security audits and vulnerability assessments
- ✓Supabase Row-Level Security restrict data access per authenticated user
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide you services.
Account Data
Retained while your account is active. Deleted within 30 days of account deletion request.
Google / YouTube API Data
OAuth access tokens are stored only as long as you have an active connected YouTube account in Pixalera. When you disconnect your YouTube account or delete your Pixalera account, all associated Google API tokens and cached data are permanently deleted.
Analytics Data
Aggregated usage analytics may be retained for up to 2 years for product improvement purposes.
You may request deletion of your account and associated data at any time by contacting teams@pixalera.in.
Your Rights
You have the right to:
- ✓Access the personal information we hold about you
- ✓Correct inaccurate or incomplete information
- ✓Request deletion of your personal data and any stored Google API data
- ✓Object to processing of your personal data
- ✓Export your data in a portable format
- ✓Disconnect your Google/YouTube account at any time from your Pixalera settings
To exercise any of these rights, contact us at teams@pixalera.in.
Revoking Access
You can revoke Pixalera's access to your Google or YouTube account at any time through two methods:
Method 1 — From Pixalera
Go to your Pixalera dashboard → Settings → Connected Channels → Click "Disconnect" next to your YouTube account. This immediately removes all stored tokens and cached YouTube data.
Method 2 — From Google Account
Visit myaccount.google.com/permissions → Find "Pixalera" → Click "Remove Access". This revokes all OAuth permissions granted to Pixalera.
Upon revocation, we will delete all stored OAuth tokens and any YouTube data associated with your account within 30 days.
Children's Privacy
Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take immediate steps to delete it. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at teams@pixalera.in.
Contact Us
If you have any questions about this Privacy Policy, your data, or our Google API data practices, please contact us at:
We are committed to resolving any privacy concerns promptly. For Google API-related data requests, we will respond within 30 days.
Sub-processors & Service Providers
The following third-party companies ("sub-processors" or "data processors") may access Platform Data we receive from Meta and other platforms on your behalf, solely to provide Pixalera's services to you. Each processor is contractually bound to keep your data confidential and process it only as instructed.
| Processor | Company / Entity | Country | Data Accessed | Purpose |
|---|---|---|---|---|
| Supabase Auth | Google LLC | United States | Email, UID, auth tokens | User authentication & session management |
| Supabase Database | Google LLC | United States | User profiles, posts, tokens, settings | Primary database — stores all platform data |
| Supabase Storage | Google LLC | United States | Uploaded images and media files | File storage for user-uploaded content |
| Google Gemini AI | Google LLC | United States | Text prompts provided by user | AI-powered caption & content generation |
| Razorpay | Razorpay Software Pvt. Ltd. | India | Payment amount, order ID (no card data stored) | Payment processing & subscription billing |
All sub-processors are bound by Data Processing Agreements. No sub-processor is permitted to use your data for their own commercial purposes, sell it, or share it with other parties outside of providing Pixalera's service. If we add, change, or remove a sub-processor, this page will be updated accordingly.
Law Enforcement Requests
Pixalera may receive requests from government authorities or law enforcement agencies for user data or Platform Data. We take such requests seriously and have the following policies and processes in place:
Legality Review
Every request from a public authority is reviewed by us to verify its legal basis before any data is disclosed. We will not comply with requests that are unlawful, overbroad, or lack proper legal authority (e.g., a valid court order or statutory requirement under applicable Indian law).
Right to Challenge
We reserve the right to challenge requests that we believe are unlawful, disproportionate, or inconsistent with applicable data protection laws. Where legally permissible, we will notify affected users before disclosing their data.
Data Minimization
We only disclose the minimum amount of data that is strictly necessary to comply with a lawful request. We do not provide broad or speculative access to user databases.
Documentation
We maintain internal records of all government and law enforcement requests received, including: the nature of the request, the legal basis cited, the data provided (if any), and the date of response. These records are retained for a minimum of 3 years.
Transparency
Pixalera has not provided personal data or Platform Data to any national security authority in the past 12 months. We will update this page if this status changes, to the extent permitted by law.
Contact for legal requests: Law enforcement agencies or government authorities seeking user data must submit a formal written request to teams@pixalera.in. All requests must cite the applicable legal authority and be signed by an authorized official.