Private photos. Sharing by choice.
How the current product handles information, keeps it, and lets you manage it.
Account and creation information
Sign-in processes your email or identity information returned by Google and uses necessary session cookies. Drafts store the template, parameters, quote and photo checks. Submitting a photo processes private inputs, generation prompts and results. Orders, point entries and feedback support delivery, reconciliation and issue handling.
Local previews and cloud storage
Home-page previews do not upload photos. Local copies can restore a photo within 10 minutes; expired copies are removed on your next visit, and you can remove them yourself. Uploaded photos are orientation-corrected, stripped of metadata and converted to static images.
Private inputs and private outputs each expire 7 days after their own creation. Temporary uploads use a one-day cleanup threshold. Access ends at expiry; physical deletion runs in batches and may occur later. Download images you want to keep before expiry.
Service providers
Cloudflare provides runtime, storage and image processing. Generation sends the processed photo and prompt to OpenAI. Safety checks also send these inputs and the generated result to OpenAI. Resend delivers verification and opted-in notification emails. Google sign-in and available WeChat payments involve those providers when you use them.
Providers handle data under their own rules. Picfork file-cleanup periods do not specify third-party retention. We do not infer zero retention or a particular processing region from our own cleanup policy.
Underlying AI models
Generation and safety checks call OpenAI models: OpenAI GPT Image · gpt-image-1.5; OpenAI GPT Image · gpt-image-2.5-sunburst for image generation, OpenAI Omni Moderation · omni-moderation-2024-09-26 for content safety checks and OpenAI GPT-5.4 mini · gpt-5.4-mini-2026-03-17 to recognize the pet in an uploaded photo and to draft a story book's words. These are the full model names used in our calls, not shortened.
Create and the template catalog label the model each template actually uses. Beyond those models, we do not send your photo, prompt or generated result to any other model provider.
Sharing and deletion
Photos and results are private by default. Publishing a share creates a separate watermarked copy accessible to anyone with the link. Published copies remain accessible while shared, beyond the private image’s 7-day expiry. Revoke shares you no longer want public.
A whole book can be given as a gift link: once you confirm, we keep a web-resolution copy of every page (no watermark, including the photos and words in the book) that anyone with the link can view without signing in. These copies are kept until you close the link or delete the book, beyond the 7-day expiry; we record only how many times and when the link was opened, never who opened it.
Revocation or task deletion immediately ends the corresponding access; background cleanup removes files. Task deletion also clears personal inputs and prompt snapshots, while necessary order, points, dispute and audit records remain. Downloaded copies and third-party caches cannot be recalled.
Content safety records
Photos and prompts are checked before generation; results are checked before delivery. Records contain the task reference, content hashes, model and policy versions, verdicts and scores, request identifiers and timestamps, without extra photo or prompt copies. Records are cleaned in batches after 30 days and removed when the task is deleted. Blocked results cannot be downloaded or shared and are cleaned up in the background after task failure.
Automated checks can make mistakes and cannot establish copyright or likeness permissions or detect every impersonation. Use the email below with a task ID, public link and explanation to request review or report abuse. Do not include passwords, verification codes or unnecessary original photos.
Public image review records
Public watermarked images are sent to OpenAI for periodic safety review. This review does not read private originals or prompts. Records contain task references, image hashes, share versions, model and policy versions, decisions, request identifiers and timestamps; no extra image copies are stored.
General review records are cleaned in batches after 30 days. Evidence for a current sharing restriction remains until the restriction is lifted or the work is deleted. Task deletion erases the associated review records. After human restoration, the relevant image hash and policy version are kept to prevent repeat automated removal under the same policy; later reviews may update this marker and task deletion clears it.
Content reports and decisions
Reports store the reporting account reference, category, explanation, internal work reference and image hash, decision and necessary operation records. Reporters see their own reports and decisions; creators see sharing restrictions and their explanation. Internal review notes are not disclosed to other users. Do not include unnecessary personal information.
Sharing appeals separately retain the account and task references, the relevant restriction and original explanation, appeal details, decisions and necessary audit records. Creators see only their own appeals; internal evidence is not public. Closed appeals are retained for 30 days before batched cleanup; pending cases remain until resolved. Deleting a work does not immediately erase submitted appeals.
Pending reports remain until resolved. Closed reports are retained for 30 days and then cleaned up in batches. Revoking or deleting a work does not immediately erase submitted reports or restore removed links. Cleaning report records does not lift sharing restrictions; lifting requires appeal approval. Deleting the work clears its public decision text. Reporting does not create extra image copies.
Operational records and measurement
The service keeps necessary security, error and task-processing records and short-lived abuse-prevention markers. Optional visit and entry-event metrics collect fixed aggregate dimensions only when enabled, without visitor-tracking cookies. Those aggregates use 30-day retention with batched cleanup. Task-related business and financial records are stored separately.
Completion emails are off by default. Only an explicit subscription sends a result-page link to your linked, verified email.
Requests and details still to be published
You can delete tasks and revoke shares yourself, or send privacy and account-deletion requests to the published contact. We need to verify the request’s connection to the account.
Operator details, service regions and the support and privacy email are listed below. Specific retention rules for account, financial and audit records still need to be established before a formal launch. The formal policy will be completed alongside those rules.
Operator and contact
- Operator
- Riffael
- Main service regions
- 全球 / Worldwide
- Support and privacy requests
- support@picfork.com