Home

Privacy Policy

Beta notice. This Policy applies to the Pictl beta. It has been prepared internally and has not yet been reviewed by an external solicitor — final review will take place before general public launch. If you have any concerns about how we handle your data, please contact us at legal@pictl.ai.

Last updated: 28 May 2026

The short version

This summary is not legally binding — it's here to help you understand the key points before reading the full Policy. The full Policy below governs how we handle your personal data.

We recommend reading this Policy alongside our Terms of Service and Cookie Policy.

1. Who we are

Art Skool Ltd ("Art Skool", "Pictl", "we", "us", "our") is a company registered in England and Wales (company number 16375309), with its registered office at 167–169 Great Portland Street, 5th Floor, London, England, W1W 5PF.

We operate the Pictl platform at pictl.ai and associated subdomains and applications (together, the "Service").

For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws, Art Skool Ltd is the controller of personal data processed in connection with the Service, unless we tell you otherwise (for example, where we act as a processor on behalf of an Enterprise customer).

Contact us about this Policy or your personal data:

We do not currently have a statutory obligation to appoint a Data Protection Officer (DPO) under Article 37 UK GDPR / EU GDPR. We will reassess this position as user numbers grow and following any change to the kinds of personal data we process.

EU/EEA representative. Pictl is currently offered to users worldwide on the basis of an English-language UI and pricing in GBP and USD. We are not actively targeting users in the EU/EEA during the beta. Where EU/EEA users do access the Service, we apply EU GDPR protections by default and will appoint a representative under Article 27 EU GDPR if and when our activity becomes targeted at the EU/EEA within the meaning of Article 3(2) EU GDPR.

UK representative for non-UK controllers. Not applicable — Art Skool Ltd is established in the UK.

2. Scope

This Policy applies to all personal data we process about people who:

  1. visit pictl.ai or any subdomain (including app.pictl.ai and explore.pictl.ai);
  2. view, share, embed, or Remix Public Content on the Discovery Layer (whether or not they have an account);
  3. create a Pictl account and use the Service;
  4. contact us for support, sales, partnership, or other reasons;
  5. apply for a role with us or otherwise interact with us in a business capacity.

This Policy does not apply to:

  1. third-party websites or services linked from Pictl — those operate under their own privacy policies;
  2. personal data processed by an Enterprise customer where we act as their processor — in that case, the customer's own privacy notice governs;
  3. personal data we are obliged to process by law in a way that displaces this Policy (for example, in response to a binding legal order).

Capitalised terms not defined here have the meaning given in our Terms of Service.

3. Personal data we collect

3.1 Data you give us

When you sign up for or use Pictl, you may provide us with:

3.2 Data we collect automatically

When you use the Service, we automatically collect:

3.3 Data from third parties

We may receive limited personal data from:

We do not buy personal data from data brokers.

3.4 Sensitive / special category data

We do not ask you to provide special category data (such as data about your health, race, sexual orientation, political opinions, or religious beliefs). You may inadvertently include such data in a Prompt or Visual. Where you do, you are responsible for that disclosure, and we will treat it under the safeguards in Section 8 (Security). We do not use such data for profiling, targeting, or model training.

4. The public-by-default model

Pictl operates a public-by-default content model for the Free Tier. This is a structural feature of the Service — not a toggle you can switch off on the Free Tier — and is described in Section 6 and Section 7 of our Terms of Service.

The following are publicly visible on the Free Tier and accessible to any internet user (including search engines):

  1. your username and public profile;
  2. all Visuals you generate;
  3. the Prompts used to generate those Visuals;
  4. any collections you choose to make public;
  5. AI-generated metadata (titles, descriptions, tags) attached to your Visuals.

Paid Tier behaviour. On Plus, Pro, and Enterprise Tiers, Visuals are Private by default. You can choose to make individual Visuals public.

Downgrade behaviour. If you downgrade from a Paid Tier to the Free Tier, your existing Private Visuals become Legacy Private Content and remain Private. They are not pushed onto the Discovery Layer. New Visuals you create on the Free Tier after downgrading are Public. See Section 6.6 of the Terms of Service for the full rule.

Legal basis. The legal basis for public display under UK/EU GDPR is performance of contract (Article 6(1)(b)) — public visibility is a defining feature of the Free Tier that you agree to when you sign up. We make this clear before you generate your first Visual.

We process personal data only where we have a lawful basis to do so. The table below sets out each purpose, the data categories involved, and the legal basis under UK/EU GDPR.

PurposeData categoriesLegal basis (UK/EU GDPR Art. 6)
Creating and managing your accountIdentity, contact, credentialsPerformance of contract (6(1)(b))
Providing the Service, including generating VisualsIdentity, content, usagePerformance of contract (6(1)(b))
Public display of Free Tier Content on the Discovery LayerProfile, content, promptsPerformance of contract (6(1)(b)) — public visibility is a core feature of the Free Tier
Processing payments and managing subscriptionsIdentity, contact, paymentPerformance of contract (6(1)(b)); Legal obligation (6(1)(c)) for tax records
Sending transactional emails (receipts, password resets, security alerts)Identity, contactPerformance of contract (6(1)(b))
Sending marketing communicationsIdentity, contactConsent (6(1)(a)); soft opt-in under PECR where applicable
Analytics and platform improvementUsage, device, cookie dataConsent for non-essential cookies (6(1)(a) / PECR); Legitimate interests for server-side analytics (6(1)(f))
Security, fraud prevention, and abuse detectionAll categoriesLegitimate interests (6(1)(f)); Legal obligation (6(1)(c)) for reportable offences
Automated content moderation and AUP enforcementUsage, content, deviceLegitimate interests (6(1)(f)); Legal obligation (6(1)(c)) for illegal content under the UK Online Safety Act / EU DSA
Responding to your rights requestsIdentity, contact, all relevant categoriesLegal obligation (6(1)(c))
Defending or pursuing legal claimsAll relevant categoriesLegitimate interests (6(1)(f)); Legal obligation (6(1)(c))
AI model training using identifiable user ContentContent, promptsConsent (6(1)(a)) — opt-in only. We do not currently use identifiable user Content to train any AI model. See Section 7.
Aggregated, anonymised analytics and trend analysisDe-identified usage and content dataNot personal data once anonymised; for any residual personal data, legitimate interests (6(1)(f))
Compliance with regulators, courts, and law enforcementAll relevant categoriesLegal obligation (6(1)(c)); Legitimate interests (6(1)(f))

Copies of our Legitimate Interests Assessments are available on request at legal@pictl.ai.

6. How we use cookies and similar technologies

We use cookies, local storage, and similar technologies as described in our Cookie Policy. In summary:

7. AI processing

The Service is powered by artificial intelligence. When you submit a Prompt and request a Visual, your Prompt and certain metadata are sent to one or more AI model providers as part of the generation pipeline.

Current AI providers. Google (Gemini family of models). We will update this list before each material release to reflect the providers in use.

Logging. Your Prompts and Visuals may be logged for safety, quality assurance, abuse detection, debugging, and compliance with our regulatory duties (UK Online Safety Act, EU DSA, EU AI Act).

Training. We do not currently use your individual Prompts or Visuals to train or fine-tune our own or any third-party AI model. If we introduce a programme that uses identifiable user Content for training, we will give clear notice and obtain your opt-in consent before including your Content. Where Content has already been incorporated into an anonymised aggregated dataset, extracting an individual contribution may be technically impractical, and we will say so when we ask for your consent.

Automated decisions and content moderation. Some moderation actions (such as refusing to generate a Visual that trips a safety filter, or temporarily restricting an account that triggers an abuse signal) are made by automated systems. These may have significant effects on you, including loss of access. You have the right to:

  1. request human review of any such decision;
  2. express your point of view; and
  3. contest the outcome.

We explain how to do this in Section 9.5 of the Terms of Service and Section 11 of this Policy. Human review is targeted within five business days of a request.

AI-generated content labelling. All Visuals are marked as AI-generated through visible indicators, embedded content provenance metadata (C2PA or equivalent), and — on Free Tier downloads — watermarking. This supports our obligations under Article 50 of the EU AI Act.

8. Security

We implement appropriate technical and organisational measures to protect personal data, including:

We follow the principle of data minimisation (Article 5(1)(c) UK/EU GDPR) — we collect only what is adequate, relevant, and limited to what is necessary for the purpose.

No system is 100% secure. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 UK/EU GDPR. Our procedures are set out in our internal Data Breach Response Plan.

9. Children and young people

Our Service is open to users aged 13 and over. The Terms of Service (Section 2.2) require:

Browsing the Discovery Layer does not require an account and is designed to be appropriate for general audiences.

Where we discover under-13 use. We will suspend the account, delete the associated personal data without undue delay, and (where lawful) notify a parent or guardian.

UK Age Appropriate Design Code. We operate the Service in line with the ICO's Age Appropriate Design Code (the Children's Code, DPA 2018 s.123) for users likely to include under-18s. This includes data-minimisation by default for under-18 accounts, no nudges to weaken privacy settings, and high-privacy defaults.

COPPA (US). Because the Service is not directed to children under 13 and we do not knowingly collect personal data from children under 13, the Children's Online Privacy Protection Act (COPPA) substantive obligations do not generally apply to us. Where we become aware of a US user under 13, we delete the data as described above.

Other jurisdictions. We honour equivalent obligations under the EU GDPR (Article 8 — digital consent age set by member state, typically 16, lower in some states), Canada's PIPEDA, and Australia's Privacy Act, including parental involvement requirements where applicable.

10. Sharing your data

We share personal data only as described below.

10.1 Service providers (processors)

We use trusted third-party providers to operate the Service. Each is bound by a Data Processing Agreement (DPA) requiring them to process data only on our instructions and to maintain appropriate security.

ProviderPurposeData sharedLocation
SupabaseDatabase hosting, authentication, storageAccount, content, usage dataEU (Frankfurt) / US
VercelApplication hosting, CDN, edge functionsUsage data, IP addresses, contentGlobal (US-based CDN)
Google Cloud Platform / Google Gemini APIAI inference, cloud infrastructurePrompts, generated Visuals, usage metadataGlobal (US-headquartered)
StripePayment processingIdentity, contact, payment instrumentUS / EU
ResendTransactional email deliveryIdentity, contact (email)US
Loops.soMarketing email (consent-based)Identity, contact (email)US
PostHogProduct analyticsPseudonymised usage dataEU (Frankfurt) — EU Cloud preferred
CloudflareDDoS protection, DNS, edge securityIP address, request metadataGlobal

A current sub-processor list, including DPA references and transfer mechanisms, is published at pictl.ai/subprocessors and maintained in our internal Sub-Processor Register. We will give at least 30 days' notice before adding a new sub-processor that handles personal data, except where the change is required by law or to address a security threat.

10.2 Other sharing

We may also share personal data:

  1. with professional advisers (lawyers, accountants, auditors, insurers) where reasonably necessary;
  2. with law enforcement, regulators, or courts where required by a valid legal request, an obligation under applicable law, or to protect the safety of users or the public;
  3. with trust and safety partners to detect, prevent, and respond to illegal or harmful content (for example, sharing hashes of CSAM with bodies such as the Internet Watch Foundation or the National Center for Missing and Exploited Children);
  4. in connection with a corporate transaction (merger, acquisition, sale of assets, reorganisation, or financing), subject to confidentiality and a continuation of materially equivalent protections;
  5. with your consent or at your direction.

10.3 What we don't do

11. Your rights

You have rights over your personal data. The scope of these rights depends on where you live, but as a global controller we will honour the core set of rights below for all users wherever you are — including where local law would give you a narrower right.

You have the right to:

  1. Access the personal data we hold about you and receive a copy.
  2. Rectify inaccurate or incomplete data.
  3. Delete your data (subject to lawful retention and the Public Content carve-out in Section 17 of the Terms of Service).
  4. Restrict processing in certain circumstances (e.g. while we verify an accuracy or objection claim).
  5. Port the personal data you've given us in a structured, machine-readable format.
  6. Object to processing based on legitimate interests or for direct marketing (we will stop direct marketing without question).
  7. Withdraw consent at any time, where we rely on consent. This does not affect processing carried out before withdrawal.
  8. Not be subject to a solely automated decision with legal or similarly significant effects — including the right to request human review, express your point of view, and contest the outcome.
  9. Complain to a data protection authority. The UK supervisory authority is the Information Commissioner's Office (ICO) — ico.org.uk, 0303 123 1113. For EU users, you may contact your national authority. For California users, see Section 12.

How to exercise your rights. Email legal@pictl.ai with the subject line "Privacy Request" and tell us which right you want to exercise. During the beta, all rights requests are handled by email. We are progressively introducing self-service tools for the most common requests (data export, account deletion, marketing opt-out) and will update this Policy when those tools are available in your account settings.

Verification. We will take reasonable steps to verify your identity before acting — usually by confirming control of the email address linked to your account.

Timing. We aim to respond within one month of receiving a valid request. We may extend this by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.

Fees. We do not charge for reasonable requests. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive (for example, repetitive).

Authorised agents. You may use an authorised agent to make a request on your behalf — we will need written proof of authority. In California, authorised agent requests follow the CCPA/CPRA process.

12. Notice for California residents

This section applies if you are a California resident under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, CCPA/CPRA).

Categories of personal information we collect. Identifiers (name, email, IP address); commercial information (subscription history); internet/network activity (usage data, cookies); geolocation (approximate, derived from IP); user-generated content (Prompts, Visuals); inferences derived from the above (e.g. preferred topics). Sources are described in Section 3. Purposes are described in Section 5.

Categories disclosed for a business purpose. All categories listed above may be shared with the service providers in Section 10.1 strictly to deliver the Service.

Sale or sharing. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of consumers under 16.

Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under Cal. Civ. Code § 1798.121.

Your CCPA/CPRA rights:

To exercise these rights — email legal@pictl.ai with the subject line "California Privacy Request" or use the Do Not Sell or Share My Personal Information link in our footer.

Retention. Retention periods are set out in Section 16.

Complaints. You may contact the California Attorney General's office (oag.ca.gov) or the California Privacy Protection Agency (cppa.ca.gov).

13. Notice for other US state residents

We honour materially similar rights for residents of US states with comprehensive privacy laws (currently including Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia). We update this list as further state laws come into effect. These rights generally include access, correction, deletion, portability, and (where applicable) opt-out of targeted advertising, sale, and certain profiling. To exercise them, email legal@pictl.ai with the subject line "US Privacy Request".

14. Notice for users in Canada

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec's Law 25 apply. You may:

To exercise these rights, email legal@pictl.ai with the subject line "Canada Privacy Request". You may also complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

15. Notice for users in Australia

If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles (APPs) apply. You may access and correct your personal information by emailing legal@pictl.ai. You may also complain to the Office of the Australian Information Commissioner (oaic.gov.au).

16. Data retention

We retain personal data for as long as we need it for the purposes set out in Section 5, unless a longer period is required by law.

Data categoryRetention periodBasis
Account data (identity, contact, credentials)Duration of account + 2 years for legal claims and abuse handlingLegitimate interests / legal obligations
Private Content and Legacy Private ContentDuration of account; deleted 30 days after account closure (after export window)Performance of contract
Public ContentIndefinitely — see Section 17.3 of the Terms of Service (attributed to "Anonymous" after account closure)Public interest / legitimate interests
Payment and billing records7 years from transaction dateLegal obligation (HMRC; equivalent tax authorities elsewhere)
Marketing consent recordsDuration of consent + 3 yearsLegal obligation (PECR / equivalent)
Usage and analytics data (identifiable)13 months, then aggregated or deletedLegitimate interests
Support correspondence3 years from resolutionLegitimate interests / legal claims
Security, fraud, and abuse logs12 months (longer for active investigations)Legitimate interests / legal obligation
Trust and safety case files (illegal content)Up to 6 years from final actionLegal obligation (Online Safety Act / DSA record-keeping)
BackupsUp to 35 days (rolling)Operational necessity

Where the law sets a minimum retention period (e.g. tax records), we follow that period. Where the law sets a maximum, we follow that maximum.

17. International data transfers

Several of our processors are based in or transfer data to countries outside the UK, EU/EEA, and other countries where you may reside.

Mechanisms we use. Where we transfer personal data outside the UK or EU/EEA to a country without an adequacy decision, we put in place appropriate safeguards, including:

We also conduct transfer impact assessments for transfers to higher-risk destinations. A copy of the safeguards relevant to a specific transfer is available on request to legal@pictl.ai.

18. Marketing communications

We send marketing emails only where you have given us consent or where the soft opt-in applies (an existing customer for a similar product, with an unsubscribe option in every message).

You can withdraw consent at any time by:

  1. clicking the unsubscribe link in any marketing email; or

  2. emailing legal@pictl.ai with the subject line "Unsubscribe".

We are introducing in-account communication preferences during the beta and will add that route here when it is available.

Withdrawing marketing consent does not stop transactional messages (receipts, password resets, security alerts, service announcements).

The Service may contain links to, or embeds of, third-party websites and services. We are not responsible for those third parties' privacy practices. Please review their privacy policies.

20. Changes to this Policy

We may update this Policy from time to time. When we make material changes we will:

  1. post the updated Policy with a new effective date;
  2. notify you by email and/or by a prominent in-product notice at least 30 days before the changes take effect;
  3. where legally required, seek your fresh consent before the changes apply to processing of your data.

Material changes include: new categories of personal data; new purposes or legal bases; new categories of recipient (other than routine sub-processor changes); material changes to retention periods; changes to your rights or how to exercise them; and changes required by new law or regulator guidance. Non-material updates (typos, contact-detail tweaks) take effect when posted.

21. Governing law and jurisdiction

This Policy is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales, except where applicable consumer or data protection law gives you the right to bring proceedings in the courts of your country of residence, or to complain to the data protection authority where you live, work, or where the alleged infringement took place.

22. Contact us

If you have any question about this Policy, wish to exercise a right, or want to make a complaint, contact us:

Art Skool Ltd 167–169 Great Portland Street, 5th Floor London, England, W1W 5PF

Email: legal@pictl.ai

We aim to respond to enquiries within 14 business days, and to formal rights requests within the statutory deadlines (typically one month). Urgent matters — for example, ongoing data breaches, child-safety concerns, or imminent threats — will be prioritised.

23. Effective date and review

This Policy is effective from: 2026-05-28.

Review triggers:

  1. any material change to the data we collect or how we use it;
  2. appointment of a DPO or EU/EEA representative;
  3. launch of any AI-training programme using identifiable user Content;
  4. changes to applicable law or regulator guidance (UK GDPR, EU GDPR, CCPA/CPRA, PIPEDA, Law 25, Privacy Act, ePrivacy/PECR, AI Act, DSA, OSA);
  5. annually, at minimum.

Next scheduled review: 2027-05-15 or earlier if triggered above.


Beta status. This Policy (v1.0) has been prepared internally to align with Terms of Service v1.5, and to extend coverage from a UK-only frame to a global "catch-all" baseline (UK / EU / US / Canada / Australia). It has not yet been reviewed by a qualified solicitor. External legal review is planned before general public launch.

Change Log

VersionDateSummary
v0.1–v0.4Apr 2026Initial UK-only drafts; AI training contradictions resolved; ADM disclosure added.
v1.02026-05-15Realigned with Terms of Service v1.4 (Art Skool Ltd, legal@pictl.ai, 13+ age, Legacy Private Content downgrade behaviour); extended to global catch-all (UK/EU/CCPA/CPRA/PIPEDA/Quebec Law 25/Australia); added sub-processor table; clarified AI training opt-in; rewrote retention table to include Public Content and trust-and-safety; added international transfer mechanisms; added DPF/Data Bridge; aligned style with ToS v1.4.