1. Information We Collect
Depending on how you use MorphPix, we may process:
- Account information, including your email address, authentication identifiers, account ID, locale, and account status.
- User content, including prompts, negative prompts, editing instructions, uploaded images, and support messages.
- Generated information, including generated or edited images, job identifiers, job status, selected models, operation settings, timestamps, and image metadata.
- Usage information, including credit balance, credit consumption, subscription status, current billing period, cancellation status, and feature activity.
- Billing records, including payment provider, provider-scoped order, subscription, transaction, refund, and dispute identifiers, payment status, amount, currency, and billing dates. MorphPix does not store complete card numbers or card security codes.
- Safety and security information, including moderation decisions, normalized safety categories, limited audit metadata, fraud signals, request timestamps, and security logs.
- Technical information that may be made available by hosting and infrastructure providers, including IP address, browser or device information, request logs, and error logs.
We do not intentionally collect information that is not reasonably needed to provide, secure, support, or legally operate MorphPix.
2. How We Use Information
We use personal information for the following purposes:
- To create and maintain accounts and authenticate users.
- To provide image generation, editing, background, upscaling, and related workflows.
- To process prompts, uploaded images, generated results, and account history.
- To calculate and enforce credits and subscription entitlements.
- To create and manage payments, cancellations, refunds, and billing records.
- To respond to support, privacy, abuse, and intellectual-property reports.
- To detect unsafe content, fraud, attacks, abuse, and attempts to bypass platform controls.
- To maintain security, reliability, performance, and legal compliance.
- To send necessary account, billing, security, and policy notices.
- To analyze aggregated or de-identified service performance.
Where applicable, these activities rely on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, protection of users and third parties, or consent where consent is legally required.
MorphPix does not currently sell personal information or use personal information for cross-site behavioral advertising.
3. Prompts, Uploaded Images, and Outputs
MorphPix applies its current automated input safety checks before creating image jobs. Uploaded files undergo server-side format, size, integrity, and dimension validation before model processing.
Prompts, editing instructions, uploaded images, and generated or edited outputs may be shared with service providers when reasonably necessary to perform the requested workflow, secure or support the service, investigate reports, or comply with law. The relevant provider categories and other disclosure circumstances are described below.
Completed outputs are saved to private MorphPix history when the product provides that function. Generated or edited outputs may be subject to safety controls provided by the relevant model or inference provider. Reports involving safety, abuse, rights, support, or legal concerns may trigger review of available outputs and records. Automated safety controls may not identify every unsafe or policy-violating result.
MorphPix does not use user content to train MorphPix-owned AI models without the user’s explicit consent. Third-party model and infrastructure providers may process content under their own terms and privacy policies.
4. Cookies and Similar Technologies
MorphPix uses cookies and similar technologies that are necessary for authentication, session management, security, locale preferences, and core product operation.
Based on the current product configuration, MorphPix does not use advertising cookies or cross-site behavioral advertising.
If optional analytics or marketing technologies are introduced in the future, this Privacy Policy and any required consent controls will be updated before those technologies are used.
5. Service Providers and Sharing
MorphPix may share information with service providers only as reasonably necessary to operate the service.
These providers may include:
- Supabase for authentication, database, and storage services.
- Vercel for hosting, content delivery, server execution, and operational logs.
- Replicate, when applicable, for model hosting or inference infrastructure.
- The model developer or model provider identified for the selected workflow.
- Waffo for new subscription payment processing and, where identified as the merchant of record at checkout or on the receipt, the applicable taxes, invoicing, refunds, and chargebacks for that transaction.
- Brevo, for authentication email and operational email delivery where configured.
- Email routing, support, security, and infrastructure providers used to operate MorphPix.
New MorphPix Pro subscriptions are processed through Waffo. The seller or merchant-of-record identity and transaction terms displayed at checkout or on the receipt govern the payment transaction. Where Waffo is identified as the merchant of record, Waffo handles the applicable payment processing, taxes, invoicing, refunds, and chargebacks for that transaction. MorphPix does not store complete payment card numbers or card security codes on its application servers.
MorphPix does not sell personal information.
MorphPix may also disclose information:
- When required by law, court order, or a valid government request.
- To investigate fraud, security incidents, abuse, or threats to users.
- In connection with a merger, acquisition, financing, reorganization, or transfer of the MorphPix service, subject to appropriate notice and protection.
- With your consent or at your direction.
Payment providers process payment data under their own privacy policies. Complete card numbers and card security codes are not stored on MorphPix application servers.
6. Data Security
MorphPix uses measures appropriate to the current service architecture, including HTTPS and TLS, authenticated access, Supabase row-level security where configured, separation of server-side service credentials, restricted environment secrets, provider-scoped billing records, and payment webhook verification where applicable.
No internet service can guarantee absolute security. You are responsible for protecting access to your email account and MorphPix credentials.
If a security incident creates a legal notification obligation, MorphPix will provide notices within the time and manner required by applicable law.
MorphPix does not claim ISO 27001 certification, SOC 2 certification, or any other security certification unless expressly stated on the website.
7. Data Retention
MorphPix does not publish one universal deletion deadline for every data category. Retention depends on the purpose for which information was collected and on technical, legal, security, fraud-prevention, and payment-provider requirements.
- Account and authentication data is retained while the account remains active and afterward only as needed for legitimate operational, security, legal, or dispute purposes.
- Saved prompts, uploaded images, generated images, and workspace history remain in private MorphPix storage while the user keeps them or while the relevant storage feature is provided.
- Transaction, refund, tax, subscription, and payment-dispute records may be retained as needed for billing, accounting, fraud prevention, disputes, and legal obligations.
- Support, safety, moderation, fraud, and security records may be retained while a request, investigation, dispute, abuse pattern, or legal obligation remains active.
- Account deletion requests are reviewed and handled for eligible active-system data, subject to the exceptions above; backups and provider-managed copies follow their normal replacement or deletion cycles.
Replicate states that API-created prediction inputs, outputs, output files, and logs are automatically removed after one hour by default. MorphPix may save a completed result in its own private Supabase history before that provider window ends.
MorphPix may retain aggregated or de-identified information that no longer reasonably identifies a user.
8. Your Privacy Rights
Depending on applicable law, you may have the right to:
- Know what personal information MorphPix processes.
- Request access to your personal information.
- Request correction of inaccurate information.
- Request deletion of eligible information.
- Request restriction of processing.
- Request a portable copy of eligible information.
- Object to certain processing based on legitimate interests.
- Withdraw consent where processing depends on consent.
- Complain to a competent data-protection or consumer authority.
Send requests to support@morphpix.com.
MorphPix aims to respond to verified privacy requests within 30 calendar days. This period may be extended where permitted by law because of complexity, volume, identity verification, security, or legal obligations.
MorphPix may request limited information necessary to verify that the requester is entitled to exercise the relevant right.
Do not send passwords, complete payment card data, card security codes, or unnecessary government identity documents by email.
9. International Data Transfers
MorphPix users, infrastructure, model providers, hosting providers, storage providers, and payment providers may be located in different countries.
Personal information may therefore be processed in the United States, the People’s Republic of China, or other countries where relevant providers operate.
Where applicable law requires a legal transfer mechanism, MorphPix and the relevant provider will rely on an available lawful mechanism, contractual protection, adequacy decision, or other legally recognized safeguard.
MorphPix does not claim that a particular transfer agreement or certification applies unless it has actually been implemented.
10. Children’s Privacy
MorphPix is intended only for users who are at least 18 years old.
MorphPix does not knowingly provide accounts to, or intentionally collect personal information from, persons under 18.
If you believe a person under 18 has provided information to MorphPix, contact support@morphpix.com. MorphPix may remove the information and terminate the related account where appropriate.
Child-safety reports receive priority review.
11. Necessary Communications
MorphPix may send necessary emails or notices about account access, payments, subscriptions, cancellations, refunds, security, service availability, policy changes, and support requests.
These operational messages are different from optional marketing communications.
MorphPix does not currently operate a separate promotional email subscription program. If such a program is introduced, users will receive a clear opt-in and unsubscribe method.
12. Changes to This Policy
MorphPix may update this Privacy Policy when the product, providers, law, or data practices change.
For material changes, MorphPix aims to provide at least 14 days’ advance notice through email, the Dashboard, or a website notice, unless a shorter period is reasonably necessary for security, legal, or urgent operational reasons.
The current version and effective date are shown on this page.
13. Contact
Data Controller: Kai Liu
Product: MorphPix
Website: https://morphpix.com
Privacy and data requests: support@morphpix.com
Data Protection Officer: Not appointed
Related policies:
Terms of Service: /terms
Acceptable Use Policy: /acceptable-use
Refund Policy: /refund