Legal

Privacy policy

How Piccaso collects, uses, and protects your data.

Last updated: September 10, 2026

1. Who we are

Piccaso ("we", "our", "us") is a visual skill builder for AI agents, built for ecommerce brands. We help teams design reusable visual workflows, run them on their own AI model API keys or on Piccaso-managed models, and produce studio-quality content at cost.

This policy explains what personal data we collect, why we collect it, how we handle it, and — in section 5 — exactly what we do with data from your Google account when you sign in with Google or connect Google Drive.

2. Data we collect

Account data: your name, business email address, and company name when you register. If you sign in with Google, we receive your name, email address, and profile picture from your Google account.

Billing data: payment method details are collected and processed by our payment provider, Dodo Payments. We never store raw card numbers on our servers.

Usage data: feature interactions, page views, session duration, and error logs used to improve the product, collected through PostHog. This data is pseudonymised where possible.

Workflow data: the skill configurations, node graphs, prompt templates, and settings you create inside Piccaso.

Asset data: product images, reference photos, and generated outputs you upload, import, or save to your Asset Library, and the conversations you have with the Piccaso agent.

API keys: the third-party AI model API keys you provide (OpenAI, Google Gemini, Flux, and others). Keys are stored encrypted at rest and are never logged or exposed in plaintext.

Integration credentials: when you connect a Google account, the OAuth tokens Google issues to Piccaso, stored encrypted at rest. See section 5.

3. How we use your data

To operate the service: authenticate your account, execute your skill workflows, run the Piccaso agent on your behalf, and store your assets.

To process payments: billing and subscription management via Dodo Payments.

To keep the service safe: images you upload are checked automatically by an AI model for content we do not allow, such as the likeness of public figures. This check runs on the image alone and its result is not used for anything else.

To improve the product: aggregate usage analytics help us prioritise features and fix bugs.

To communicate with you: transactional emails (account events, billing receipts) and product updates where you have opted in.

We do not sell your data. We do not use your content, assets, prompts, or any data from your Google account to train AI models, and we do not use it for advertising.

4. AI model processing

Bring Your Own Key: when you run a skill on your own API keys, your images and prompts are sent directly to the AI model APIs you have configured, using your credentials. Your content is then subject to the privacy and data retention policies of the providers you chose (for example OpenAI or Google). We recommend reviewing those policies before connecting a provider.

Managed models: when you run on Piccaso-managed models, your images and prompts are sent to the AI providers Piccaso contracts with (currently Microsoft Azure OpenAI and Google Cloud Vertex AI) under our agreements with them, which do not permit training on your content.

In both cases Piccaso acts as an orchestration layer. We keep the results you generate in your outputs, and we do not retain other copies of images processed through model APIs beyond what is saved to your library.

5. Google account and Google Workspace data

Sign in with Google. If you choose to sign in with Google, we ask Google for your basic profile: your name, email address, and profile picture. We use these only to create and identify your Piccaso account, and to link a Google sign-in to an existing account with the same email address.

Connecting Google Drive. A member of your workspace can connect a Google account under Settings → Integrations so that Piccaso and its agent can work with files in Google Drive, Google Docs, Google Sheets, and Google Slides. When you connect, Google asks you to grant Piccaso the following permissions, and we use each one only as described here.

Google Drive files you open or create with Piccaso (drive.file): to save generated outputs, folders, and cropped images into your Drive, and to read back files Piccaso created. Google Drive read access (drive.readonly): to list the folders and files you point the agent at, to show it an image so it can judge or crop it, and to import images you choose into your Asset Library. Google Docs (documents), Google Sheets (spreadsheets), and Google Slides (presentations): to read the documents, sheets, and decks you name — for example a brief in a Doc or a product list in a Sheet — and to write results into them or create new ones when you ask.

What we store. We store the OAuth tokens Google issues, encrypted at rest, so we can act on your behalf without asking you to sign in again, together with the email address and name of the connected Google account. The contents of your Drive files are processed in memory for the request you made and are not kept, with two exceptions you control: an image you ask Piccaso to import becomes an asset in your library, and a file Piccaso writes to your Drive is a copy of an output that already lives in your library. We do not keep a copy of your Drive, and we do not index or scan it beyond the folders and files you name.

Who can see it. Members of your workspace can run skills and use the agent with a connected Google account. No Piccaso employee reads your Google data. Google data is shared only with the AI providers described in section 4, only when you direct the agent to process a file, and only that file. It is never shared with advertisers, data brokers, or any other third party, and it is never sold.

Deleting and revoking. Disconnect a Google account at any time under Settings → Integrations; we delete its tokens immediately and ask Google to revoke them. You can also withdraw Piccaso's access from your Google account permissions page at https://myaccount.google.com/permissions, after which our stored tokens stop working, the connection shows as needing reconnection, and it can be removed under Settings → Integrations. Assets you imported stay in your library until you delete them, like any other asset.

Limited Use. Piccaso's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

6. Data sharing

We share data only with the following categories of sub-processors: payment processing (Dodo Payments), product analytics (PostHog), cloud infrastructure for hosting, storage, and databases (Amazon Web Services), managed AI model providers (Microsoft Azure OpenAI, Google Cloud Vertex AI), the AI model APIs you explicitly connect with your own keys, and Google APIs when you connect a Google account.

We may disclose data if required by law, court order, or to protect the rights and safety of Piccaso users.

7. Data retention

Account data is retained for the duration of your subscription and for 90 days after account deletion to allow recovery.

Assets and outputs saved to your library are retained until you delete them or close your account.

Google OAuth tokens are retained until you disconnect the account or revoke access, and are deleted when your account is deleted.

Billing records are retained for seven years as required by financial regulations.

You can request deletion of your account and all associated data at any time by contacting us at piccadotso@gmail.com.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. You may also object to or restrict certain processing.

To exercise any of these rights, email us at piccadotso@gmail.com. We will respond within 30 days.

9. Security

We use industry-standard encryption in transit (TLS) and at rest. API keys and integration tokens are encrypted with separate key material. Access to production systems is restricted to authorised personnel.

No system is perfectly secure. If you discover a vulnerability, please disclose it responsibly to piccadotso@gmail.com.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated via email or a notice inside the product at least 14 days before they take effect.

Questions about this policy? Contact us at piccadotso@gmail.com

Your brand deserves
better visuals.

Join hands with early adopters building a leaner, smarter creative system. Your key. Your models. Your output.

Ask AI about Piccaso

ChatGPTGeminiClaudePerplexityGrok