Privacy & Cookies
Last updated · 28 September 2026
This describes, in plain and complete terms, what pic2CAD does with your personal data, including the practical security promises in the Security and infrastructure section below.
1. Who we are
pic2CAD is operated by Vanessa Larsson (NIF Y8388099J), at Corredera Baja de San Pablo 15, 28004 Madrid, Spain. pic2CAD is the data controller for the personal information described in this policy. Contact: pic2cad@gmail.com and +1 862 703 0206.
2. Information we collect
When you use pic2CAD, we collect information you provide directly: your email address when you create an account, and the pictures you upload for conversion. If you subscribe or buy credits, we also keep your payment history (amounts and dates, never your card details). We also collect standard usage data (pages visited, features used) through our analytics provider. Browser analytics only run if you accept analytics cookies; we also record a small number of server-side events (a conversion started, a purchase completed) that do not depend on cookies, see Cookies below.
In more detail, this is what we hold about your account:
- Your email address and, if you sign in with Google, the account identifier Google gives us to recognise you (never your Google password).
- If you set your own password, only a hash of it (argon2id), never the password itself.
- If you create a public API key, only a hash of it; the full key is shown to you once and is not stored.
- The profession you choose in the short questionnaire after your first sign-in.
- Your date of birth, if you choose to enter it when creating a password account: it's optional, and its only purpose is to check and be able to prove you meet the minimum age.
- Your Stripe customer identifier, if you buy credits or subscribe.
- The creation date of your account and the usage dates of your API keys.
- The IP address your account was created from: yes, we store it, on the basis of our legitimate interest in detecting and stopping repeated account sign-ups meant to abuse the free quota (fraud and abuse prevention). Beyond that, your IP is also used only in memory to limit requests (for example, many requests in a row).
3. How we use your information
We use your information to:
- Provide the picture-to-line-drawing service
- Manage your account and credit balance
- Send transactional emails (sign-in links, purchase receipts)
- Improve the service through aggregated usage analytics
- Prevent abuse and enforce our Terms of service
Our lawful bases under the GDPR: performing our contract with you (providing the service, processing your pictures, billing); our legitimate interests (service security, abuse prevention, and aggregated server-side usage counts); your consent (analytics cookies in your browser, which you can withdraw at any time); and legal obligation (tax and accounting records).
4. Picture handling
Pictures you upload are sent to an external image-generation service to produce your line drawing. Your uploaded pictures and the finished drawings are stored in your account and are not shared with other users or made public, unless you decide to publish a drawing to the 2D Library (see below). We do not use your uploaded pictures to train AI models ourselves; see Security and infrastructure below for more detail on that promise and its limits.
Publishing a drawing to the 2D Library is your choice. It never happens by default. If you choose to publish a finished drawing from your account, it first goes through review by an administrator and, once approved, becomes visible to any visitor and can be downloaded for free by anyone with an account. The original picture you uploaded is never published, only the finished drawing. You can unpublish it at any time from your account, and it stops being available immediately; copies someone else already downloaded cannot be recalled.
5. Who else touches your data
- AI image-generation provider: your uploaded picture is sent to a third-party AI infrastructure provider to generate the line drawing. We do not name the specific provider on the public site: under GDPR Articles 13-14, a category of recipient can be disclosed instead of a specific name, provided the category is described precisely enough, which is what we do here. That provider processes your picture on pic2CAD's behalf, under a data processing agreement; see section 6 for the international transfer mechanism that applies to it. If you submit a formal data access request, we will disclose the provider's identity, as required by Article 15 GDPR.
- Google: if you sign in with Google. See Google's own privacy policy.
- Stripe: processes payments. We never see or store your card number; Stripe's privacy policy covers that data.
- Resend: sends the sign-in link if you log in by email instead of Google. See Resend's privacy policy.
- Railway: hosts the server and the database. Your files are not kept here. See Railway's privacy policy.
- Cloudflare (R2): stores your original pictures and the PNG, SVG and DXF files we generate, permanently; Railway's own disk is only used as scratch space while a picture is being processed. See Cloudflare's privacy policy.
- PostHog: counts visits and usage on their EU servers (Frankfurt). Analytics in your browser only run if you accept analytics cookies. In addition, our own server logs a small number of operational events (a sign-up, a purchase, a generation, a failure, a download). Alongside your account identifier, these events include your email address, your name if you have given one, the professional profile you declare in the questionnaire, and the campaign you arrived through (utm, gclid or fbclid) if you came via an ad or campaign link. We log them on the basis of our legitimate interest in operating the service and understanding where our users come from; they are hosted in the EU and are not used for advertising (see Cookies below). See PostHog's privacy policy.
6. International transfers
Every provider we work with has its own data processing agreement (DPA) and, where relevant, its own international transfer mechanism:
- Stripe: you contract with Stripe Payments Europe, Ltd., based in Ireland (EU); its US parent is certified under the EU-US Data Privacy Framework.
- Google (if you sign in with Google): handled by Google Ireland Limited; Google is certified under the EU-US Data Privacy Framework.
- Cloudflare (R2): certified under the EU-US Data Privacy Framework.
- Railway: certified under the EU-US Data Privacy Framework, backed by standard contractual clauses.
- Resend: certified under the EU-US Data Privacy Framework.
- PostHog (analytics): hosts data in the European Union (Frankfurt), so there is no international transfer.
- AI image-generation provider (not named here, see section 5): certified under the EU-US Data Privacy Framework.
If you need more detail on a specific provider for your own compliance records, email us.
7. Cookies
We use technical cookies that are necessary for the site to work (your session, the free trial and your cookie choice). They do not need your permission.
We also use these:
| Cookie | What it does | Duration | First / third party |
|---|---|---|---|
| p2c_utm | Remembers the campaign (utm, gclid or fbclid) you arrived through | 30 days | First party |
| pc_ref | Remembers who invited you, to credit them | 30 days | First party |
| p2c_bid | Technical and security cookie: identifies your browser to prevent abuse of free accounts. Stores a random identifier, no personal data | 13 months | First party |
| ph_* | Usage analytics (PostHog); only set if you accept | Until you clear it | Third party |
You can change your choice at any time: .
8. Data retention
Your pictures and drawings stay in your account until you delete them yourself, either one at a time from My drawings, or by deleting your whole account from your account page. Deleting a drawing removes the corresponding files and records from our active systems, database and storage right away; deleting your account cancels any active subscription immediately and removes the rest after 7 days, unless you log back in before then. Billing records are kept in Stripe for as long as tax law requires.
On top of our active systems, we keep a daily database backup, retained for a maximum of 14 days before it rotates out; that backup sits outside the service's ordinary use and we would only use it to recover from a serious failure. Beyond that backup rotation, we do not run an automatic deletion schedule based on age or a fixed number of days. The only exception: if our storage were ever critically low, we might manually remove the oldest drawings to free space.
9. Your rights
Under the GDPR you have the right to access, correct, delete, and receive a portable copy of your personal data, to restrict or object to its processing, and to withdraw consent where processing is based on consent. You can delete your account, and everything in it, at any time from your account page. To exercise any other right, the single channel is pic2cad@gmail.com; we respond within a general deadline of one month from receiving the request, and to protect you we may ask for reasonable proof of your identity before handling it. You also have the right to lodge a complaint with the Spanish data protection authority, the Agencia Española de Protección de Datos.
10. Business transfers
If the pic2CAD business is transferred to a successor entity that carries on the business, your personal data may transfer with it under the same protections; we will notify you of any such transfer.
11. Changes to this policy
If we materially change this policy, we will post the change here with a new date, and where the change is significant, try to reach you by email as well.
12. Consent
By uploading a picture, you contractually warrant, under our Terms of service, that you hold the rights and authorisations needed for it, including those of anyone appearing in it. pic2CAD processes the personal data of those third parties on your behalf, under this policy.
13. Security and infrastructure
This section covers the practical, day-to-day promises that sit alongside the policy above: what we do, what our providers do, and what we do not do.
What we promise:
- We do not use your pictures, or the drawings made from them, to train AI.
- We apply technical and organisational measures aimed at keeping your pictures and drawings private to your account, with no access by other customers.
- We apply technical and organisational measures aimed at automatic processing, with no human review of your pictures in normal operation (see section 15 for the cases where our small team can access them).
Turning your picture into line art happens through the third-party image-generation service described in section 5, which processes your pictures on pic2CAD's behalf under its own data processing agreement. It is a paid service, and under its terms for paid customers, that provider does not use your pictures, prompts or outputs to improve its own products, and only logs them for a limited period to prevent abuse. If you need more detail for your use case, for example client-confidential work, email us at pic2cad@gmail.com and we will tell you plainly what we know.
14. Account and platform security
- HTTPS everywhere. We apply technical measures aimed at encrypting (TLS) every connection between your browser and pic2CAD.
- Encrypted storage. The providers who hold your files and database (Cloudflare and Railway) encrypt data at rest by default, as is standard for their services.
- Access checked per request. We apply technical and organisational measures aimed at checking your session and ownership of the file before serving every download and every generation; we do not publish public links to your files.
- No card data on our side. Payments go straight to Stripe. We never see or store your card number.
- Your password, if you set one. You can sign in with Google, with a one-time link sent to your email, or with a password. If you choose a password we never keep the password itself, only an argon2id hash of it, which cannot be turned back into what you typed.
- Found a problem? Email pic2cad@gmail.com. We are a two-person team, so reports go straight to the people who can fix them.
15. Who can see your pictures
- No other customer, unless you publish it. Every drawing is scoped to your account; a request for someone else's drawing is rejected before it reaches storage. The only exception is one you choose yourself: a drawing you publish to the 2D Library (see section 4).
- The free trial without an account is browser-bound. It is tied to the browser that generated it with a cookie, not to any account, so treat it as visible to whoever holds that browser until you claim it.
- Machines, not people, in normal operation. Your picture is processed automatically. Nobody on our side looks at it to generate your drawing.
- Our small team can access any drawing. pic2CAD is run by two people. We can open any drawing on the platform to fix a failed generation, answer a support question, or investigate abuse. We do not keep a separate audit log of when we do this today.
