YOUR DATA

Privacy Policy

AngryPixl is operated by Pixl Envy. We collect information needed to answer questions, run accounts and file transfers, and manage Studio subscriptions. We do not use Google Analytics or sell personal information.

Effective October 9, 2026 · Pixl Envy, Farragut, Tennessee, USA

What we collect

When you use our contact form, we receive the name, reply address, topic, and message you enter. We also process a security challenge and a short-lived, hashed network identifier to limit spam. Do not send passwords, card numbers, or private file links through the form.

For Studio accounts, we process your account email, authentication identity, workspace status, file names, sizes, types, transfer settings, share-link records, and support requests. Uploaded file contents are stored in a private Cloudflare R2 bucket so we can deliver them to people who have the link. Stripe processes paid subscription details; we receive transaction, customer, and subscription identifiers and statuses, but we do not need your payment card number. Some invited accounts have complimentary access.

For a transfer link, we use the sender's email, file name, link expiry, and the time a download first starts to send a download-start notice to the sender. For email delivery, we also use the recipient address, optional recipient name, sender name, optional message, and reminder status to send the initial link and daily expiry reminders. The optional recipient name identifies the intended recipient in the sender's notice; it does not verify who used a link that may have been forwarded. The optional message also appears on the recipient's download page. Reminders stop after the first valid download request, when the recipient opts out, or when the link expires or is revoked. A download-start notice does not prove that the recipient saved the complete file.

On a Studio creator’s receiving page, a client provides an email address and file without creating an account. We send a short-lived code to verify the email before upload. We store that address with the transfer, show it to the receiving Studio account so the creator can identify the file, and email the creator when the file is ready. We do not sell the address or use it for marketing. Cloudflare Turnstile, request limits, and the email code help reduce spam uploads. Received files use the account’s existing monthly upload and storage allowances and expire seven days after upload. Transfer and security records may remain longer as described below.

Our hosting and security providers may process ordinary technical information such as IP address, browser and device details, request time, security signals, and pages or endpoints requested. A person using a private download link may also send technical request information when retrieving a file.

Why we use it

  • Respond to requests and provide customer support.
  • Create and secure accounts, process subscriptions, and operate file transfers.
  • Detect spam, fraud, abuse, and service errors; enforce our terms and protect the service.
  • Meet accounting, dispute, and other legal obligations.

Cookies and browser storage

We have not installed Google Analytics or advertising trackers. “No analytics” does not mean “no cookies.” AngryPixl uses essential cookies for sign-in and temporary login verification. These include an application session lasting up to seven days and a login-flow cookie lasting up to ten minutes. Guest checkout uses a cookie that may last up to 30 days. The upload screen can also keep unfinished transfer details in your browser’s local storage so you can resume after a refresh; it does not store the file itself there. A client’s receiving-page upload screen may keep a limited upload token and unfinished transfer details in local storage for the same purpose.

Auth0 may set cookies on our branded login domain to run sign-in. Cloudflare may use security cookies or similar signals when protecting the site; our contact form uses Cloudflare Turnstile without pre-clearance. Stripe’s embedded payment form may set cookies and similar technologies for payment, authentication, fraud prevention, and analytics of its payment services. Blocking essential storage may prevent sign-in, checkout, or security checks from working. We do not currently change our own processing in response to a browser “Do Not Track” signal because we do not use cross-site advertising tracking.

The site’s display fonts are served from angrypixl.com rather than requested from Google Fonts.

Who receives information

We use Cloudflare for hosting, storage, security, and email delivery; Auth0 by Okta for account sign-in; and Stripe for payments and subscription management. Each receives information needed for its part of the service and has its own privacy practices. The person who receives a private transfer link can access the file and its displayed name while that link is valid. We may disclose information when required by law or to protect users and the service. We do not sell personal information or use it for targeted advertising.

These providers may process information outside your state or country. See Cloudflare’s privacy policy, Okta’s privacy policy, and Stripe’s privacy policy for their practices.

Storage, deletion, and security

Senders choose a three- or seven-day link lifetime. Access to an expired or revoked link ends immediately; deletion of the stored file follows through background cleanup and may take longer. Unfinished multipart uploads are subject to cleanup, including a seven-day bucket rule. Account, billing, transfer metadata, support messages, and security records may be retained longer where needed to run the service, resolve disputes, prevent abuse, or meet legal duties.

We use private file storage, encrypted connections, limited service credentials, account access checks, and hashed session identifiers. No online service can promise absolute security. Share links are bearer links: anyone you give a valid link to may be able to download the file, so share them carefully.

Your choices and requests

You can choose not to submit the contact form, create an account, or upload files. Senders can create a copy-only link without providing a recipient email. Recipients can stop daily reminders through the link in each email without disabling the file link. Account holders can revoke share links from their workspace; paid subscribers can manage renewal there. To request access, correction, or deletion of information we hold, use the contact form and choose “Account or billing.” We may need to verify your identity and may retain information where law or legitimate service needs require it. Rights vary by location.

Children and changes

AngryPixl is intended for adults and businesses, not children under 18. If you believe a child has provided personal information, contact us. We may update this policy as the service changes. We will post the new date here and give additional notice when required.

Privacy questions can be sent through our private contact form. The operator is Pixl Envy, Farragut, Tennessee, USA.