Your work. Your data. Your choices.
This privacy policy explains what Picrowd collects, why we use it, who receives it, and how to ask for access, correction, or deletion.
Who this policy is for
This policy covers Picrowd’s website, accounts, workspaces, apps, API, and connected features. Picrowd is operated by Nuare Studio Inc. “We” and “our” refer to Nuare Studio Inc. Contact us about privacy at hello@picrowd.com.
We decide how account, billing, support, and service-security information is used to run Picrowd. When an organization adds personal information to its workspace, that organization generally decides why it is used and who may access it. Picrowd processes that content to provide the service. Contact your workspace owner first about information they control; we can help direct your request.
External services you connect and websites you visit through links have their own privacy notices.
Information we collect
- Account details: your name, email address, profile image, sign-in provider identifiers, settings, and membership information. Another user may provide your email address when inviting you.
- Workspace content: projects, records, fields, checklists, notes, comments, files, images, audio, Whiteboards, reminders, shared links, and collaboration history. This includes information imported, submitted through the API, or added by collaborators.
- AI information: messages, attachments, responses, relevant workspace context, tool results, saved memories, and action history.
- Connection details: provider, account label, permissions, and credentials needed for a tool. These can include OAuth tokens, API keys, or an app password you supply. Signing in with Google, GitHub, or Apple does not give us that account’s password.
- Billing and support details: subscription and transaction references, billing status, and information you send when asking for help. Apple handles in-app subscription payments on iOS; Google Play handles subscriptions purchased through Google Play on Android; Stripe handles website payments. Picrowd stores subscription, transaction, and account references to verify access rather than full payment-card numbers.
- Technical information: request and error logs, IP addresses, browser or device information, sessions, and security events used to operate and troubleshoot the service. Supported device notifications also involve push tokens and notification preferences.
Why we use it
We use information to provide requested features, maintain accounts and subscriptions, sync work between collaborators, send invitations and reminders, provide support, investigate abuse, fix problems, and meet legal obligations. AI and integrations process the context needed for your request or configured automation.
Where a law requires a legal basis, these purposes can include performing our agreement with you, complying with legal obligations, consent for optional processing, and legitimate interests such as protecting and improving the service, subject to your rights. Organizations using Picrowd are responsible for their own legal basis for workspace content.
We do not sell personal information or use workspace content for targeted advertising. Service announcements are separate from optional marketing emails, which include an unsubscribe option.
Services involved in running Picrowd
- Vercel serves the website and frontend. Railway runs the backend and database. Cloudflare R2 stores uploaded files and related previews.
- Resend delivers emails such as sign-in links, invitations, and account-deletion confirmations. Apple processes iOS in-app subscriptions and sends signed purchase and renewal information to Picrowd. Google Play processes Android in-app subscriptions and sends purchase, renewal, cancellation, and refund information so Picrowd can verify access. Stripe processes website payments and manages website subscriptions.
- Google, GitHub, and Apple provide sign-in when you choose them. Sign-in alone does not connect your email, calendar, or files to Picrowd AI.
- AI processing can involve OpenAI or DeepSeek, depending on the configured route. The AI sections below explain Google-connected content and the limits of provider-data promises.
- Connected tools such as Gmail, Google Calendar, Drive, Docs, Sheets, Dropbox, and Box receive or return information when used. Optional media tools use the provider you connect, such as OpenAI, Google, ElevenLabs, fal.ai, Replicate, Stability AI, Ideogram, or Higgsfield.
- Supported mobile notifications use Apple Push Notification service or Firebase Cloud Messaging. Delivery involves a device token, app installation identifier, selected account, and notification payload. Expanded notifications can retrieve authorized previews of attached content. Push alerts follow the account selected on that installation; other signed-in accounts can show their own unread marks inside Picrowd. Device settings control lock-screen visibility.
AI features and your data
Picrowd AI sends your message and relevant context to a model provider. Context can include records, notes, supported files, conversation history, tool results, and saved memories. An AI mention or scheduled command can also start processing. Consider the surrounding record or conversation, not only the words in your prompt.
In the iOS and Android apps, Picrowd asks for permission before AI processing and identifies the services receiving your data. You can decline or withdraw that mobile permission in Settings. This stops new AI and translation requests from the apps and background tasks started there. Web and other clients do not show this additional mobile permission screen. Translation can send the selected text to Google Translate. Withdrawal does not erase information already processed, and a material change to the mobile disclosure requires renewed permission.
Picrowd does not train its own general-purpose models on workspace content. Provider retention and training rules are separate and depend on the provider, endpoint, and account agreement. We do not promise that every optional provider offers zero retention or excludes training. OpenAI’s API does not use inputs and outputs for training by default unless data sharing is enabled. Do not assume those same terms apply to DeepSeek or a media provider you connect.
Google-derived context requires a protected route, including in a follow-up or memory-based request. The default protected OpenAI route is separate from the everyday model. Protected requests stop if the route is not active or a provider is not approved for that data, instead of falling back to an unapproved route.
Picrowd Memory can save context for a user, project, or record. Conversations, memories, and tool audit records are separate from the model provider’s own logs. Disconnecting a tool does not automatically erase information already saved in those places.
Review AI outputs and actions you authorize. Some operations ask for confirmation; a configured automation may run without another prompt. Sending email or changing an external service may have effects that cannot be undone in Picrowd.
Google user data
You choose whether to connect Gmail, Google Calendar, Google Contacts, Google Drive, Google Docs, or Google Sheets. OAuth connections use the permissions shown during authorization. A Gmail app-password connection uses the mail access provided by that app password. Available read and write capabilities also depend on the connection’s settings.
We use Google content to provide features you request or configure, such as finding an email, drafting a reply, managing an event, or working with a document. Credentials keep the connection working. Results may remain in your AI conversation, saved memory, audit history, or workspace when the feature or your instruction saves them.
The default protected provider for AI processing of Google content is the OpenAI API. Google-derived summaries and memories receive the same protected classification. Requests containing this data use store: false. This setting does not mean that Zero Data Retention is enabled: provider security and abuse-monitoring retention may still apply.
Picrowd’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of raw or derived user data received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
- We do not use Google user data to develop, improve, or train generalized AI or machine learning models, and do not opt this data into model-training data sharing.
- We do not sell Google user data or use it for advertising. Transfers are limited to those permitted by Google’s applicable policies, including providing the connected feature and complying with applicable law.
- People at Picrowd may read Google user data only with your affirmative agreement for specific content, when necessary for security, or where required by law, within the exceptions permitted by Google’s policies.
- Disconnecting a tool disables its connection and clears stored credentials. You can also revoke OAuth access in your Google Account, or revoke an app password with Google. This does not delete previously saved copies or completed actions.
- Request deletion of retained Google user data, including conversations or memories, at hello@picrowd.com. We handle requests without undue delay and within applicable legal requirements.
Public sharing and content review
When public screening is enabled, text you choose to publish through public record, project or whiteboard links is checked by OpenAI before publication. Picrowd reviewers check flagged content and content that cannot be covered automatically, including attachments, canvases and linked media. The public-sharing panel explains this before you enable it. Private fields, private AI sessions and unshared workspaces are excluded from this publication check.
New or changed public content stays unavailable to public visitors until approved. Your private workspace remains available. Existing links without the public-sharing acknowledgement require human review and are not automatically sent to a new processor. Reports and review decisions are restricted to administrators and recorded for abuse handling. Contact hello@picrowd.com to ask about a decision.
Storage and international processing
Information may be processed outside your country, where legal protections and government-access rules may differ. We do not offer a general promise that everything stays in one country. DeepSeek’s public policy describes processing in China; its terms for downstream applications must be assessed separately from its consumer privacy notice.
We use HTTPS for data in transit and application-level encryption for stored connected-tool credentials. Picrowd is not end-to-end encrypted: the service processes content for search, collaboration, previews, and AI. No online service can guarantee absolute security.
Contact us before using Picrowd if you require a particular storage region, data-processing agreement, transfer safeguard, or regulated-data arrangement. This policy is not a claim that those requirements have been met for your use.
Retention, cancellation, and deletion
Canceling a paid subscription stops its renewal; it does not delete your account or workspace. Deleting content, disconnecting a tool, canceling billing, and deleting an account are separate actions.
Start account deletion in Settings → Account → Delete account. You confirm the selected email address; other signed-in accounts remain available. Access ends immediately and file/provider cleanup continues with retries, including a final sweep after previously issued upload links expire. Picrowd sends a completion email and then clears the encrypted delivery address and cleanup credentials. Copies still used by other accounts remain available to them. Cancel Apple or Google Play subscriptions separately through the store where you subscribed; website subscription cancellation is included in cleanup.
Retention depends on the information and its purpose. Active workspace content supports your use of the service. Connection credentials are cleared when you disconnect. Billing, security, support, and audit records may need to remain for legal obligations, abuse investigations, or disputes.
Account or record deletion does not necessarily erase every associated copy immediately. Files, previews, backups, AI history, and data retained by external providers have separate lifecycles. Copies in another person’s workspace or outside Picrowd may remain. We do not promise immediate deletion from every backup or external system.
You can request account and data deletion without installing the app or signing in: email hello@picrowd.com from your Picrowd account email with the subject “Delete my Picrowd account”. We verify ownership before deletion; never send a password or sign-in code. For a broader data request, describe the information involved. We explain any limits or required retention and respond within the time required by applicable law. Export anything you need first.
Your choices and privacy rights
You can manage collaborators, links, tokens, tools, and notifications, and use available export and deletion controls, subject to your permissions. Project exports may not include every file, AI conversation, or operational record; contact us if you need help obtaining your personal information.
Depending on applicable law, you may have rights to access, correct, delete, or receive a portable copy of personal information; restrict or object to processing; withdraw consent; and complain to a privacy regulator. Withdrawal does not affect earlier lawful processing. Legal exceptions or a workspace owner’s responsibilities may affect a request.
Email hello@picrowd.com to exercise your rights. We may need to verify your identity and authority. Do not send passwords, tokens, or unnecessary identity documents. We will not discriminate against you for exercising rights provided by law.
Children, changes, and contact
Picrowd is designed for work and collaboration, not as a service directed to children. If you believe a child has provided personal information without the required authorization, contact us so we can investigate and take appropriate action.
We update the date on this page when the policy changes and provide additional notice or obtain consent where required by law. Questions about this policy or a privacy request can be sent to hello@picrowd.com.
Last updated September 29, 2026. Contact: hello@picrowd.com