Privacy Policy
Beta notice. This Policy applies to the Pictl beta. It has been prepared internally and has not yet been reviewed by an external solicitor — final review will take place before general public launch. If you have any concerns about how we handle your data, please contact us at legal@pictl.ai.
Last updated: 28 May 2026
The short version
This summary is not legally binding — it's here to help you understand the key points before reading the full Policy. The full Policy below governs how we handle your personal data.
- We don't sell your personal data. Not now, not in any future plan we're contemplating.
- Free plan = public. On the Free Tier, your Visuals appear on Explore (our public Discovery Layer) and may be indexed by search engines. Your username and profile are public alongside them.
- Paid plans = private by default. Plus and Pro Visuals are private by default. If you later downgrade, your existing Private Visuals stay private — see Section 4.
- AI generation involves third parties. Your prompts are processed by AI providers we name in Section 7. We do not use your prompts or Visuals to train third-party AI models without your opt-in consent.
- You have control. Access, correct, delete, export, or object to our use of your personal data — Section 11.
- Children. Pictl is open to users aged 13+. Under-18s use it under specific protections — Section 9.
- Where you live matters. UK, EU, California, other US states, Canada, and Australia all have extra rights — Sections 12–15.
We recommend reading this Policy alongside our Terms of Service and Cookie Policy.
1. Who we are
Art Skool Ltd ("Art Skool", "Pictl", "we", "us", "our") is a company registered in England and Wales (company number 16375309), with its registered office at 167–169 Great Portland Street, 5th Floor, London, England, W1W 5PF.
We operate the Pictl platform at pictl.ai and associated subdomains and applications (together, the "Service").
For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws, Art Skool Ltd is the controller of personal data processed in connection with the Service, unless we tell you otherwise (for example, where we act as a processor on behalf of an Enterprise customer).
Contact us about this Policy or your personal data:
- Email: legal@pictl.ai
- Post: Art Skool Ltd, 167–169 Great Portland Street, 5th Floor, London, England, W1W 5PF
We do not currently have a statutory obligation to appoint a Data Protection Officer (DPO) under Article 37 UK GDPR / EU GDPR. We will reassess this position as user numbers grow and following any change to the kinds of personal data we process.
EU/EEA representative. Pictl is currently offered to users worldwide on the basis of an English-language UI and pricing in GBP and USD. We are not actively targeting users in the EU/EEA during the beta. Where EU/EEA users do access the Service, we apply EU GDPR protections by default and will appoint a representative under Article 27 EU GDPR if and when our activity becomes targeted at the EU/EEA within the meaning of Article 3(2) EU GDPR.
UK representative for non-UK controllers. Not applicable — Art Skool Ltd is established in the UK.
2. Scope
This Policy applies to all personal data we process about people who:
- visit pictl.ai or any subdomain (including app.pictl.ai and explore.pictl.ai);
- view, share, embed, or Remix Public Content on the Discovery Layer (whether or not they have an account);
- create a Pictl account and use the Service;
- contact us for support, sales, partnership, or other reasons;
- apply for a role with us or otherwise interact with us in a business capacity.
This Policy does not apply to:
- third-party websites or services linked from Pictl — those operate under their own privacy policies;
- personal data processed by an Enterprise customer where we act as their processor — in that case, the customer's own privacy notice governs;
- personal data we are obliged to process by law in a way that displaces this Policy (for example, in response to a binding legal order).
Capitalised terms not defined here have the meaning given in our Terms of Service.
3. Personal data we collect
3.1 Data you give us
When you sign up for or use Pictl, you may provide us with:
- Identity data — your name or username.
- Contact data — your email address and (optionally) your postal address for billing.
- Account credentials — a password (stored hashed; we never see your plaintext password) or a third-party sign-in credential (e.g. Google OAuth).
- Profile data — profile picture, bio, and any optional information you add to your public profile.
- Content data — Prompts, Visuals, collections, edits, Remixes, and other Content you create or upload.
- Payment data — billing name, address, and payment instrument details. Card numbers are handled directly by our payment processor (Stripe) and are not stored on our servers.
- Communications data — the content of messages you send us via email, support, or in-product channels.
- Preferences and settings — language, theme, notification preferences, and similar choices.
3.2 Data we collect automatically
When you use the Service, we automatically collect:
- Usage data — pages viewed, features used, Visuals generated, Prompts submitted, Remixes made, interactions with the platform.
- Device and technical data — IP address, browser type and version, operating system, device identifiers, locale and time zone, screen size, and similar diagnostics.
- Log data — server logs, error reports, crash reports, and performance metrics.
- Cookie and similar-technology data — as described in our Cookie Policy.
3.3 Data from third parties
We may receive limited personal data from:
- Authentication providers — if you sign in using Google or another identity provider, we receive the basic profile data they release to us (name, email, profile photo).
- Payment processors — Stripe confirms the status of your subscription and may share billing-country and risk-indicator data with us.
- Analytics providers — usage data, generally pseudonymised or aggregated.
- Trust and safety partners — reports, hashes, or signals about illegal or harmful content (for example, from a hash-matching provider for CSAM detection).
- Publicly available sources — for example, when investigating an abuse report, we may consult open records.
We do not buy personal data from data brokers.
3.4 Sensitive / special category data
We do not ask you to provide special category data (such as data about your health, race, sexual orientation, political opinions, or religious beliefs). You may inadvertently include such data in a Prompt or Visual. Where you do, you are responsible for that disclosure, and we will treat it under the safeguards in Section 8 (Security). We do not use such data for profiling, targeting, or model training.
4. The public-by-default model
Pictl operates a public-by-default content model for the Free Tier. This is a structural feature of the Service — not a toggle you can switch off on the Free Tier — and is described in Section 6 and Section 7 of our Terms of Service.
The following are publicly visible on the Free Tier and accessible to any internet user (including search engines):
- your username and public profile;
- all Visuals you generate;
- the Prompts used to generate those Visuals;
- any collections you choose to make public;
- AI-generated metadata (titles, descriptions, tags) attached to your Visuals.
Paid Tier behaviour. On Plus, Pro, and Enterprise Tiers, Visuals are Private by default. You can choose to make individual Visuals public.
Downgrade behaviour. If you downgrade from a Paid Tier to the Free Tier, your existing Private Visuals become Legacy Private Content and remain Private. They are not pushed onto the Discovery Layer. New Visuals you create on the Free Tier after downgrading are Public. See Section 6.6 of the Terms of Service for the full rule.
Legal basis. The legal basis for public display under UK/EU GDPR is performance of contract (Article 6(1)(b)) — public visibility is a defining feature of the Free Tier that you agree to when you sign up. We make this clear before you generate your first Visual.
5. Why we use your data (purposes and legal bases)
We process personal data only where we have a lawful basis to do so. The table below sets out each purpose, the data categories involved, and the legal basis under UK/EU GDPR.
| Purpose | Data categories | Legal basis (UK/EU GDPR Art. 6) |
|---|---|---|
| Creating and managing your account | Identity, contact, credentials | Performance of contract (6(1)(b)) |
| Providing the Service, including generating Visuals | Identity, content, usage | Performance of contract (6(1)(b)) |
| Public display of Free Tier Content on the Discovery Layer | Profile, content, prompts | Performance of contract (6(1)(b)) — public visibility is a core feature of the Free Tier |
| Processing payments and managing subscriptions | Identity, contact, payment | Performance of contract (6(1)(b)); Legal obligation (6(1)(c)) for tax records |
| Sending transactional emails (receipts, password resets, security alerts) | Identity, contact | Performance of contract (6(1)(b)) |
| Sending marketing communications | Identity, contact | Consent (6(1)(a)); soft opt-in under PECR where applicable |
| Analytics and platform improvement | Usage, device, cookie data | Consent for non-essential cookies (6(1)(a) / PECR); Legitimate interests for server-side analytics (6(1)(f)) |
| Security, fraud prevention, and abuse detection | All categories | Legitimate interests (6(1)(f)); Legal obligation (6(1)(c)) for reportable offences |
| Automated content moderation and AUP enforcement | Usage, content, device | Legitimate interests (6(1)(f)); Legal obligation (6(1)(c)) for illegal content under the UK Online Safety Act / EU DSA |
| Responding to your rights requests | Identity, contact, all relevant categories | Legal obligation (6(1)(c)) |
| Defending or pursuing legal claims | All relevant categories | Legitimate interests (6(1)(f)); Legal obligation (6(1)(c)) |
| AI model training using identifiable user Content | Content, prompts | Consent (6(1)(a)) — opt-in only. We do not currently use identifiable user Content to train any AI model. See Section 7. |
| Aggregated, anonymised analytics and trend analysis | De-identified usage and content data | Not personal data once anonymised; for any residual personal data, legitimate interests (6(1)(f)) |
| Compliance with regulators, courts, and law enforcement | All relevant categories | Legal obligation (6(1)(c)); Legitimate interests (6(1)(f)) |
Copies of our Legitimate Interests Assessments are available on request at legal@pictl.ai.
6. How we use cookies and similar technologies
We use cookies, local storage, and similar technologies as described in our Cookie Policy. In summary:
- Strictly necessary cookies keep the Service working. These do not require your consent.
- Analytics and functional cookies are only set with your consent, which you can withdraw at any time through the cookie settings link in our footer.
- Marketing cookies. We do not currently use third-party marketing or advertising cookies.
7. AI processing
The Service is powered by artificial intelligence. When you submit a Prompt and request a Visual, your Prompt and certain metadata are sent to one or more AI model providers as part of the generation pipeline.
Current AI providers. Google (Gemini family of models). We will update this list before each material release to reflect the providers in use.
Logging. Your Prompts and Visuals may be logged for safety, quality assurance, abuse detection, debugging, and compliance with our regulatory duties (UK Online Safety Act, EU DSA, EU AI Act).
Training. We do not currently use your individual Prompts or Visuals to train or fine-tune our own or any third-party AI model. If we introduce a programme that uses identifiable user Content for training, we will give clear notice and obtain your opt-in consent before including your Content. Where Content has already been incorporated into an anonymised aggregated dataset, extracting an individual contribution may be technically impractical, and we will say so when we ask for your consent.
Automated decisions and content moderation. Some moderation actions (such as refusing to generate a Visual that trips a safety filter, or temporarily restricting an account that triggers an abuse signal) are made by automated systems. These may have significant effects on you, including loss of access. You have the right to:
- request human review of any such decision;
- express your point of view; and
- contest the outcome.
We explain how to do this in Section 9.5 of the Terms of Service and Section 11 of this Policy. Human review is targeted within five business days of a request.
AI-generated content labelling. All Visuals are marked as AI-generated through visible indicators, embedded content provenance metadata (C2PA or equivalent), and — on Free Tier downloads — watermarking. This supports our obligations under Article 50 of the EU AI Act.
8. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- TLS encryption in transit;
- encryption at rest within our managed database and storage providers;
- industry-standard password hashing (e.g. argon2id or bcrypt);
- role-based access controls limiting internal access to a need-to-know basis;
- logging and monitoring of administrative actions;
- background checks and confidentiality obligations for staff with production access;
- periodic security reviews, penetration testing, and dependency scanning, in line with our risk profile as a beta-stage service.
We follow the principle of data minimisation (Article 5(1)(c) UK/EU GDPR) — we collect only what is adequate, relevant, and limited to what is necessary for the purpose.
No system is 100% secure. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 UK/EU GDPR. Our procedures are set out in our internal Data Breach Response Plan.
9. Children and young people
Our Service is open to users aged 13 and over. The Terms of Service (Section 2.2) require:
- Under 13: must not create an account.
- 13–17: may use the Service only with verifiable consent from a parent or legal guardian.
- 18+: may use the Service in their own right.
Browsing the Discovery Layer does not require an account and is designed to be appropriate for general audiences.
Where we discover under-13 use. We will suspend the account, delete the associated personal data without undue delay, and (where lawful) notify a parent or guardian.
UK Age Appropriate Design Code. We operate the Service in line with the ICO's Age Appropriate Design Code (the Children's Code, DPA 2018 s.123) for users likely to include under-18s. This includes data-minimisation by default for under-18 accounts, no nudges to weaken privacy settings, and high-privacy defaults.
COPPA (US). Because the Service is not directed to children under 13 and we do not knowingly collect personal data from children under 13, the Children's Online Privacy Protection Act (COPPA) substantive obligations do not generally apply to us. Where we become aware of a US user under 13, we delete the data as described above.
Other jurisdictions. We honour equivalent obligations under the EU GDPR (Article 8 — digital consent age set by member state, typically 16, lower in some states), Canada's PIPEDA, and Australia's Privacy Act, including parental involvement requirements where applicable.
10. Sharing your data
We share personal data only as described below.
10.1 Service providers (processors)
We use trusted third-party providers to operate the Service. Each is bound by a Data Processing Agreement (DPA) requiring them to process data only on our instructions and to maintain appropriate security.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Database hosting, authentication, storage | Account, content, usage data | EU (Frankfurt) / US |
| Vercel | Application hosting, CDN, edge functions | Usage data, IP addresses, content | Global (US-based CDN) |
| Google Cloud Platform / Google Gemini API | AI inference, cloud infrastructure | Prompts, generated Visuals, usage metadata | Global (US-headquartered) |
| Stripe | Payment processing | Identity, contact, payment instrument | US / EU |
| Resend | Transactional email delivery | Identity, contact (email) | US |
| Loops.so | Marketing email (consent-based) | Identity, contact (email) | US |
| PostHog | Product analytics | Pseudonymised usage data | EU (Frankfurt) — EU Cloud preferred |
| Cloudflare | DDoS protection, DNS, edge security | IP address, request metadata | Global |
A current sub-processor list, including DPA references and transfer mechanisms, is published at pictl.ai/subprocessors and maintained in our internal Sub-Processor Register. We will give at least 30 days' notice before adding a new sub-processor that handles personal data, except where the change is required by law or to address a security threat.
10.2 Other sharing
We may also share personal data:
- with professional advisers (lawyers, accountants, auditors, insurers) where reasonably necessary;
- with law enforcement, regulators, or courts where required by a valid legal request, an obligation under applicable law, or to protect the safety of users or the public;
- with trust and safety partners to detect, prevent, and respond to illegal or harmful content (for example, sharing hashes of CSAM with bodies such as the Internet Watch Foundation or the National Center for Missing and Exploited Children);
- in connection with a corporate transaction (merger, acquisition, sale of assets, reorganisation, or financing), subject to confidentiality and a continuation of materially equivalent protections;
- with your consent or at your direction.
10.3 What we don't do
- We do not sell personal data.
- We do not "share" personal data for cross-context behavioural advertising (in the sense used by California's CPRA).
- We do not use your personal data for third-party advertising or profiling.
11. Your rights
You have rights over your personal data. The scope of these rights depends on where you live, but as a global controller we will honour the core set of rights below for all users wherever you are — including where local law would give you a narrower right.
You have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Delete your data (subject to lawful retention and the Public Content carve-out in Section 17 of the Terms of Service).
- Restrict processing in certain circumstances (e.g. while we verify an accuracy or objection claim).
- Port the personal data you've given us in a structured, machine-readable format.
- Object to processing based on legitimate interests or for direct marketing (we will stop direct marketing without question).
- Withdraw consent at any time, where we rely on consent. This does not affect processing carried out before withdrawal.
- Not be subject to a solely automated decision with legal or similarly significant effects — including the right to request human review, express your point of view, and contest the outcome.
- Complain to a data protection authority. The UK supervisory authority is the Information Commissioner's Office (ICO) — ico.org.uk, 0303 123 1113. For EU users, you may contact your national authority. For California users, see Section 12.
How to exercise your rights. Email legal@pictl.ai with the subject line "Privacy Request" and tell us which right you want to exercise. During the beta, all rights requests are handled by email. We are progressively introducing self-service tools for the most common requests (data export, account deletion, marketing opt-out) and will update this Policy when those tools are available in your account settings.
Verification. We will take reasonable steps to verify your identity before acting — usually by confirming control of the email address linked to your account.
Timing. We aim to respond within one month of receiving a valid request. We may extend this by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.
Fees. We do not charge for reasonable requests. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive (for example, repetitive).
Authorised agents. You may use an authorised agent to make a request on your behalf — we will need written proof of authority. In California, authorised agent requests follow the CCPA/CPRA process.
12. Notice for California residents
This section applies if you are a California resident under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, CCPA/CPRA).
Categories of personal information we collect. Identifiers (name, email, IP address); commercial information (subscription history); internet/network activity (usage data, cookies); geolocation (approximate, derived from IP); user-generated content (Prompts, Visuals); inferences derived from the above (e.g. preferred topics). Sources are described in Section 3. Purposes are described in Section 5.
Categories disclosed for a business purpose. All categories listed above may be shared with the service providers in Section 10.1 strictly to deliver the Service.
Sale or sharing. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of consumers under 16.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under Cal. Civ. Code § 1798.121.
Your CCPA/CPRA rights:
- Right to know what personal information we collect, use, disclose, and (if any) sell or share.
- Right to delete your personal information.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing (we do not sell or share — but this right is reflected in your account settings and our "Do Not Sell or Share" link).
- Right to limit use of sensitive personal information.
- Right to data portability.
- Right to non-discrimination for exercising any CCPA/CPRA right.
To exercise these rights — email legal@pictl.ai with the subject line "California Privacy Request" or use the Do Not Sell or Share My Personal Information link in our footer.
Retention. Retention periods are set out in Section 16.
Complaints. You may contact the California Attorney General's office (oag.ca.gov) or the California Privacy Protection Agency (cppa.ca.gov).
13. Notice for other US state residents
We honour materially similar rights for residents of US states with comprehensive privacy laws (currently including Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia). We update this list as further state laws come into effect. These rights generally include access, correction, deletion, portability, and (where applicable) opt-out of targeted advertising, sale, and certain profiling. To exercise them, email legal@pictl.ai with the subject line "US Privacy Request".
14. Notice for users in Canada
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec's Law 25 apply. You may:
- access and correct your personal information;
- withdraw consent (subject to reasonable notice);
- in Quebec, request portability of data and information about any automated decision used to make a decision about you.
To exercise these rights, email legal@pictl.ai with the subject line "Canada Privacy Request". You may also complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
15. Notice for users in Australia
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles (APPs) apply. You may access and correct your personal information by emailing legal@pictl.ai. You may also complain to the Office of the Australian Information Commissioner (oaic.gov.au).
16. Data retention
We retain personal data for as long as we need it for the purposes set out in Section 5, unless a longer period is required by law.
| Data category | Retention period | Basis |
|---|---|---|
| Account data (identity, contact, credentials) | Duration of account + 2 years for legal claims and abuse handling | Legitimate interests / legal obligations |
| Private Content and Legacy Private Content | Duration of account; deleted 30 days after account closure (after export window) | Performance of contract |
| Public Content | Indefinitely — see Section 17.3 of the Terms of Service (attributed to "Anonymous" after account closure) | Public interest / legitimate interests |
| Payment and billing records | 7 years from transaction date | Legal obligation (HMRC; equivalent tax authorities elsewhere) |
| Marketing consent records | Duration of consent + 3 years | Legal obligation (PECR / equivalent) |
| Usage and analytics data (identifiable) | 13 months, then aggregated or deleted | Legitimate interests |
| Support correspondence | 3 years from resolution | Legitimate interests / legal claims |
| Security, fraud, and abuse logs | 12 months (longer for active investigations) | Legitimate interests / legal obligation |
| Trust and safety case files (illegal content) | Up to 6 years from final action | Legal obligation (Online Safety Act / DSA record-keeping) |
| Backups | Up to 35 days (rolling) | Operational necessity |
Where the law sets a minimum retention period (e.g. tax records), we follow that period. Where the law sets a maximum, we follow that maximum.
17. International data transfers
Several of our processors are based in or transfer data to countries outside the UK, EU/EEA, and other countries where you may reside.
Mechanisms we use. Where we transfer personal data outside the UK or EU/EEA to a country without an adequacy decision, we put in place appropriate safeguards, including:
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses;
- EU Standard Contractual Clauses (Module 2 — controller to processor, or Module 3 — processor to processor);
- UK–US Data Bridge for transfers to US providers certified under the UK extension to the EU–US Data Privacy Framework;
- EU–US Data Privacy Framework for transfers from the EU to certified US providers;
- where appropriate, derogations under Article 49 UK/EU GDPR (for example, explicit consent for occasional transfers).
We also conduct transfer impact assessments for transfers to higher-risk destinations. A copy of the safeguards relevant to a specific transfer is available on request to legal@pictl.ai.
18. Marketing communications
We send marketing emails only where you have given us consent or where the soft opt-in applies (an existing customer for a similar product, with an unsubscribe option in every message).
You can withdraw consent at any time by:
-
clicking the unsubscribe link in any marketing email; or
-
emailing legal@pictl.ai with the subject line "Unsubscribe".
We are introducing in-account communication preferences during the beta and will add that route here when it is available.
Withdrawing marketing consent does not stop transactional messages (receipts, password resets, security alerts, service announcements).
19. Third-party links and embeds
The Service may contain links to, or embeds of, third-party websites and services. We are not responsible for those third parties' privacy practices. Please review their privacy policies.
20. Changes to this Policy
We may update this Policy from time to time. When we make material changes we will:
- post the updated Policy with a new effective date;
- notify you by email and/or by a prominent in-product notice at least 30 days before the changes take effect;
- where legally required, seek your fresh consent before the changes apply to processing of your data.
Material changes include: new categories of personal data; new purposes or legal bases; new categories of recipient (other than routine sub-processor changes); material changes to retention periods; changes to your rights or how to exercise them; and changes required by new law or regulator guidance. Non-material updates (typos, contact-detail tweaks) take effect when posted.
21. Governing law and jurisdiction
This Policy is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales, except where applicable consumer or data protection law gives you the right to bring proceedings in the courts of your country of residence, or to complain to the data protection authority where you live, work, or where the alleged infringement took place.
22. Contact us
If you have any question about this Policy, wish to exercise a right, or want to make a complaint, contact us:
Art Skool Ltd 167–169 Great Portland Street, 5th Floor London, England, W1W 5PF
Email: legal@pictl.ai
We aim to respond to enquiries within 14 business days, and to formal rights requests within the statutory deadlines (typically one month). Urgent matters — for example, ongoing data breaches, child-safety concerns, or imminent threats — will be prioritised.
23. Effective date and review
This Policy is effective from: 2026-05-28.
Review triggers:
- any material change to the data we collect or how we use it;
- appointment of a DPO or EU/EEA representative;
- launch of any AI-training programme using identifiable user Content;
- changes to applicable law or regulator guidance (UK GDPR, EU GDPR, CCPA/CPRA, PIPEDA, Law 25, Privacy Act, ePrivacy/PECR, AI Act, DSA, OSA);
- annually, at minimum.
Next scheduled review: 2027-05-15 or earlier if triggered above.
Beta status. This Policy (v1.0) has been prepared internally to align with Terms of Service v1.5, and to extend coverage from a UK-only frame to a global "catch-all" baseline (UK / EU / US / Canada / Australia). It has not yet been reviewed by a qualified solicitor. External legal review is planned before general public launch.
Change Log
| Version | Date | Summary |
|---|---|---|
| v0.1–v0.4 | Apr 2026 | Initial UK-only drafts; AI training contradictions resolved; ADM disclosure added. |
| v1.0 | 2026-05-15 | Realigned with Terms of Service v1.4 (Art Skool Ltd, legal@pictl.ai, 13+ age, Legacy Private Content downgrade behaviour); extended to global catch-all (UK/EU/CCPA/CPRA/PIPEDA/Quebec Law 25/Australia); added sub-processor table; clarified AI training opt-in; rewrote retention table to include Public Content and trust-and-safety; added international transfer mechanisms; added DPF/Data Bridge; aligned style with ToS v1.4. |