AI Pizza ← Back to dashboard

Privacy Policy

AI Pizza · Version 1.1 · Effective 2026-08-04

1. INTRODUCTION

1.1 This Privacy Policy explains how Blackbox Global Limited, a company incorporated in the Republic of Seychelles (company number 241614, registered office at 306, Victoria House, Victoria, Mahe, Seychelles) ("we", "us", "the Operator"), collects, uses, discloses and protects personal data in connection with the AI Pizza service at aipizza.app (the "Service"). "AI Pizza" is a brand of the Operator. We handle personal data in accordance with the data-protection laws applicable to us.

1.2 This Policy forms part of the Terms of Service. By using the Service you consent to the collection, use and disclosure of your personal data as described here.

2. WHAT WE COLLECT

  • Account data — email address, a one-way hash of your password (we never store the password itself), optional display name, and interface-language preference.
  • Subscription data — your plan, billing status and period dates, and Stripe customer/subscription identifiers. Card and bank details are collected and processed by Stripe, not by us; we never see or store full card numbers.
  • Sign-in and security data — session records and the IP address and time of sign-ins and sensitive actions, kept for authentication, rate-limiting and abuse prevention.
  • Content you create — the personal tags and watchlists you enter, stored against your account and visible only to you.
  • Operational logs — standard server logs (request path, timestamp, status, IP) generated when you use the Service.

We do not collect data from data brokers, do not run advertising trackers, and do not profile you for marketing.

3. WHAT WE USE IT FOR

We use personal data only to: (a) operate the Service and authenticate you; (b) administer subscriptions and billing; (c) secure the Service — including fraud, abuse and unauthorised-access prevention; (d) send service communications such as password-reset emails and material notices about the Service or these policies; and (e) comply with legal obligations. We do not send marketing email unless you separately opt in.

4. COOKIES AND LOCAL STORAGE

4.1 The Service uses a single first-party session cookie to keep you signed in, and browser local storage for interface preferences (for example language choice and notice acknowledgements). These are essential to the Service's operation.

4.2 We do not use advertising cookies or third-party analytics trackers. Stripe may set its own cookies on its checkout pages under its own policy.

5. WHO WE SHARE IT WITH

5.1 We do not sell or rent personal data. We disclose it only to service providers who process it on our behalf under contract, currently:

  • Stripe — payment processing and billing (subject to Stripe's own privacy policy);
  • Vultr — cloud hosting of the Service and its databases;
  • Resend — delivery of transactional email (e.g. password resets);
  • Cloudflare R2 — encrypted storage of operational backups.

5.2 We may also disclose personal data where required by law, regulation, legal process, or to protect the rights, safety or property of the Operator or others, and to a successor in a business transfer, subject to this Policy.

6. INTERNATIONAL TRANSFERS

6.1 Our servers and service providers may be located outside the Operator's country of incorporation and outside your country of residence. Where applicable law limits cross-border transfers of personal data, we take steps to ensure a comparable standard of protection, including contractual safeguards with our providers.

7. RETENTION

7.1 Account and subscription data are kept while your account exists and for a reasonable period afterwards for legal, accounting and dispute purposes. Security and operational logs are kept for a limited rolling window. Encrypted backups rotate on a fixed schedule. Data no longer needed is deleted or anonymised.

8. SECURITY

8.1 We protect personal data with measures appropriate to its nature: encryption in transit (TLS), one-way password hashing, least-privilege access to production systems, and encrypted backups. No system is perfectly secure; you use the Service at your own risk and must keep your credentials confidential.

9. YOUR RIGHTS

9.1 Subject to applicable data-protection law, you may request access to or correction of your personal data, and may withdraw consent to its processing by closing your account (after which we retain only what the law allows or requires). Requests can be sent to the contact below and will be handled within a reasonable time. Deleting your account ends your subscription per the Terms of Service.

10. CHILDREN

10.1 The Service is not directed at persons under 18 and we do not knowingly collect their personal data. If you believe a minor has provided us personal data, contact us and we will delete it.

11. CHANGES TO THIS POLICY

11.1 We may amend this Policy. Material changes will be notified inside the Service or by email at least fourteen (14) days before they take effect. The current version and its effective date are shown at the top of this page.

12. CONTACT

12.1 Data-protection enquiries and requests: [email protected].