Back to MorphPix

Privacy Policy

Version 2.0 · Effective July 26, 2026

This Privacy Policy explains how Kai Liu, an individual developer operating MorphPix under the laws of the People’s Republic of China, collects, uses, stores, and shares personal information when you use MorphPix.

Data controller:

Kai Liu

Product:

MorphPix

Privacy contact:

support@morphpix.com

Data Protection Officer:

No Data Protection Officer has been appointed.

1. Information We Collect

Depending on how you use MorphPix, we may process:

  • Account information, including your email address, authentication identifiers, account ID, locale, and account status.
  • User content, including prompts, negative prompts, editing instructions, uploaded images, and support messages.
  • Generated information, including generated or edited images, job identifiers, job status, selected models, operation settings, timestamps, and image metadata.
  • Usage information, including credit balance, credit consumption, subscription status, current billing period, cancellation status, and feature activity.
  • Billing records, including payment provider, provider-scoped order, subscription, transaction, refund, and dispute identifiers, payment status, amount, currency, and billing dates. MorphPix does not store complete card numbers or card security codes.
  • Safety and security information, including moderation decisions, normalized safety categories, limited audit metadata, fraud signals, request timestamps, and security logs.
  • Technical information that may be made available by hosting and infrastructure providers, including IP address, browser or device information, request logs, and error logs.

We do not intentionally collect information that is not reasonably needed to provide, secure, support, or legally operate MorphPix.

2. How We Use Information

We use personal information for the following purposes:

  • To create and maintain accounts and authenticate users.
  • To provide image generation, editing, background, upscaling, and related workflows.
  • To process prompts, uploaded images, generated results, and account history.
  • To calculate and enforce credits and subscription entitlements.
  • To create and manage payments, cancellations, refunds, and billing records.
  • To respond to support, privacy, abuse, and intellectual-property reports.
  • To detect unsafe content, fraud, attacks, abuse, and attempts to bypass platform controls.
  • To maintain security, reliability, performance, and legal compliance.
  • To send necessary account, billing, security, and policy notices.
  • To analyze aggregated or de-identified service performance.

Where applicable, these activities rely on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, protection of users and third parties, or consent where consent is legally required.

MorphPix does not currently sell personal information or use personal information for cross-site behavioral advertising.

3. Prompts, Uploaded Images, and Outputs

Prompts, editing instructions, uploaded images, and generated or edited outputs are processed to perform the workflow you request.

This information may be transmitted to model developers, inference providers, hosting providers, or storage providers that are necessary to perform the workflow.

Content may be saved to your MorphPix history when the product provides that function. Content may also be subject to automated or provider safety controls and may be reviewed when a safety, abuse, support, or legal report requires investigation.

MorphPix does not use user content to train MorphPix-owned AI models without the user’s explicit consent.

Third-party model and infrastructure providers may process content under their own terms and privacy policies.

4. Cookies and Similar Technologies

MorphPix uses cookies and similar technologies that are necessary for authentication, session management, security, locale preferences, and core product operation.

Based on the current product configuration, MorphPix does not use advertising cookies or cross-site behavioral advertising.

If optional analytics or marketing technologies are introduced in the future, this Privacy Policy and any required consent controls will be updated before those technologies are used.

5. Service Providers and Sharing

MorphPix may share information with service providers only as reasonably necessary to operate the service.

These providers may include:

  • Supabase for authentication, database, and storage services.
  • Vercel for hosting, content delivery, server execution, and operational logs.
  • Replicate, when applicable, for model hosting or inference infrastructure.
  • The model developer or model provider identified for the selected workflow.
  • Waffo Pancake for new subscription payment processing, applicable taxes, invoicing, refunds, and chargebacks.
  • An earlier payment provider where necessary to manage an existing subscription until it ends.
  • Email routing, support, security, and infrastructure providers used to operate MorphPix.

New MorphPix Pro subscriptions are processed by Waffo Pancake, which acts as the merchant of record. Waffo Pancake handles payment processing, applicable taxes, invoicing, refunds, and chargebacks. MorphPix does not store complete payment card numbers or card security codes on its application servers.

Where applicable, a subscription created through an earlier payment provider may continue to be managed by that provider until the subscription ends.

MorphPix does not sell personal information.

MorphPix may also disclose information:

  • When required by law, court order, or a valid government request.
  • To investigate fraud, security incidents, abuse, or threats to users.
  • In connection with a merger, acquisition, financing, reorganization, or transfer of the MorphPix service, subject to appropriate notice and protection.
  • With your consent or at your direction.

Payment providers process payment data under their own privacy policies. Complete card numbers and card security codes are not stored on MorphPix application servers.

6. Data Security

MorphPix uses measures appropriate to the current service architecture, including HTTPS and TLS, authenticated access, Supabase row-level security where configured, separation of server-side service credentials, restricted environment secrets, provider-scoped billing records, and payment webhook verification where applicable.

No internet service can guarantee absolute security. You are responsible for protecting access to your email account and MorphPix credentials.

If a security incident creates a legal notification obligation, MorphPix will provide notices within the time and manner required by applicable law.

MorphPix does not claim ISO 27001 certification, SOC 2 certification, or any other security certification unless expressly stated on the website.

7. Data Retention

MorphPix applies the following general retention periods, subject to technical, legal, security, fraud-prevention, and payment-provider requirements:

  • Account and authentication data is retained while the account remains active.
  • After a verified account deletion request, eligible data in active systems is generally targeted for deletion or anonymization within 30 days, except where retention is required for billing, fraud prevention, disputes, security, or law.
  • Saved prompts, uploaded images, generated images, and workspace history are retained until the user deletes them, requests account deletion, or MorphPix stops providing the relevant storage feature.
  • Transaction, refund, tax, and payment-dispute records may be retained for up to 7 years, or longer when required by applicable law or an unresolved dispute.
  • Support records may be retained for up to 24 months after the last communication.
  • Safety, moderation, fraud, and security audit records are generally retained for up to 12 months, but may be retained longer when connected to an investigation, dispute, legal requirement, or repeated abuse.
  • Backups and provider-managed copies may remain until they are overwritten under normal backup and retention cycles.

MorphPix may retain aggregated or de-identified information that no longer reasonably identifies a user.

8. Your Privacy Rights

Depending on applicable law, you may have the right to:

  • Know what personal information MorphPix processes.
  • Request access to your personal information.
  • Request correction of inaccurate information.
  • Request deletion of eligible information.
  • Request restriction of processing.
  • Request a portable copy of eligible information.
  • Object to certain processing based on legitimate interests.
  • Withdraw consent where processing depends on consent.
  • Complain to a competent data-protection or consumer authority.

Send requests to support@morphpix.com.

MorphPix aims to respond to verified privacy requests within 30 calendar days. This period may be extended where permitted by law because of complexity, volume, identity verification, security, or legal obligations.

MorphPix may request limited information necessary to verify that the requester is entitled to exercise the relevant right.

Do not send passwords, complete payment card data, card security codes, or unnecessary government identity documents by email.

9. International Data Transfers

MorphPix users, infrastructure, model providers, hosting providers, storage providers, and payment providers may be located in different countries.

Personal information may therefore be processed in the United States, the People’s Republic of China, or other countries where relevant providers operate.

Where applicable law requires a legal transfer mechanism, MorphPix and the relevant provider will rely on an available lawful mechanism, contractual protection, adequacy decision, or other legally recognized safeguard.

MorphPix does not claim that a particular transfer agreement or certification applies unless it has actually been implemented.

10. Children’s Privacy

MorphPix is intended only for users who are at least 18 years old.

MorphPix does not knowingly provide accounts to, or intentionally collect personal information from, persons under 18.

If you believe a person under 18 has provided information to MorphPix, contact support@morphpix.com. MorphPix may remove the information and terminate the related account where appropriate.

Child-safety reports receive priority review.

11. Necessary Communications

MorphPix may send necessary emails or notices about account access, payments, subscriptions, cancellations, refunds, security, service availability, policy changes, and support requests.

These operational messages are different from optional marketing communications.

MorphPix does not currently operate a separate promotional email subscription program. If such a program is introduced, users will receive a clear opt-in and unsubscribe method.

12. Changes to This Policy

MorphPix may update this Privacy Policy when the product, providers, law, or data practices change.

For material changes, MorphPix aims to provide at least 14 days’ advance notice through email, the Dashboard, or a website notice, unless a shorter period is reasonably necessary for security, legal, or urgent operational reasons.

The current version and effective date are shown on this page.

13. Contact

Data Controller: Kai Liu

Product: MorphPix

Website: https://morphpix.com

Privacy and data requests: support@morphpix.com

Data Protection Officer: Not appointed

Related policies:

Terms of Service: /terms

Acceptable Use Policy: /acceptable-use

Refund Policy: /refund