Legal
Photizon — Privacy Policy
Updated September 14, 2026: this version describes what we receive when you send us a message through a form, and adds our form provider to the list in Section 4.
1.Who we are and what this covers#
This Privacy Policy explains how PHOTIZON INC., a California corporation ("Photizon," "we," "us"), handles information when you use the Photizon website, simulation tools, Photizon Academy, and account features (collectively, the "Service"). It applies to visitors, registered users, and paid subscribers.
We collect the minimum personal information needed to run the Service. We do not sell your data. We do not run ad trackers, and we use a cookieless analytics tool that holds no personal data about you.
2.What we collect, and why#
2.1Account information (via Clerk)
When you register, our identity provider Clerk processes your account data on our behalf, which includes your email address, your name (if provided), and, if you sign in with a third-party provider (e.g., Google), the identifier and basic profile that provider returns. Clerk manages authentication, sessions, and credential security. We use this to create and secure your account and to communicate with you about the Service. This includes service email about your account, such as a notice before a free trial ends and a notice once it has ended; we send these to the email address held for your account, and not to an account that has already subscribed. Service email is sent through the email provider listed in Section 4, as plain text, with no images and with open and click tracking off. We do not send marketing email and we keep no mailing list, so there is nothing to unsubscribe from; service email about your own account is part of providing the Service and cannot be switched off on its own, though you can delete your account at any time (Section 6). Internally, your account is referenced by a Clerk user ID string.
When you first visit, your browser stores locally the page that referred you, any campaign tags in the link you followed, and, if a feature prompts you to sign in, which feature that was. This information stays in your browser unless you create an account; if you do, it is attached to your account record so we can understand how users find Photizon. It is not shared with third parties and is deleted with your account.
2.2Content you save
When you save content, we store it. This includes simulation configurations, custom material data, and any other files or data you upload or save through the Service. For saved designs, we also store recent versions of the design and automatic recovery drafts of unsaved edits, so you can restore earlier states; these are deleted when the design is permanently deleted or when your account is deleted.
These are stored in our own PostgreSQL database (hosted on Railway) and keyed to your Clerk user ID. You own the above content; we store it to provide the Service to you (see the Terms, Section 6). It is private by default and we do not make it public.
Some longer-running simulations execute as background jobs; for these, the simulation inputs and results are stored in our database in order to deliver the result back to you, are visible only to your account, and are removed when your account is deleted.
2.3Tool usage records
When you download or export results, we record a tool-usage event — which tool, a timestamp, and the design inputs and computed results associated with that download — to understand which tools are used and to guide product decisions. These events are recorded only when you are signed in, are tied to your account, and are deleted with your account.
2.4Payment metadata (via Stripe)
Payments are processed by Stripe. Photizon never receives or stores your full card number, CVC, or bank details; Stripe handles all card data as the payment processor. We store only:
- a Stripe customer reference and subscription reference linked to your account, and
- your subscription plan and tier, its status, and the current billing-period end date (to know what you have access to, and until when).
Stripe may collect billing information (name, billing address, card) directly from you under Stripe's own privacy terms.
2.5Analytics (via Plausible)
We use Plausible Analytics for aggregate usage statistics (page views, referrers, general country-level counts). Plausible is cookieless, is hosted in the EU, and does not collect personal data or track you across sites. It does not build a profile of you, and we do not use it for advertising. In addition to page views, we send Plausible a small number of custom interaction events (for example, that a tutorial's link to a tool was clicked); these carry no personal data.
2.6What we do not collect
- No advertising or third-party tracking cookies. The only cookies we use are the essential ones our identity provider needs to keep you signed in.
- No sale of your data. We do not sell, rent, or share your personal information or Your Content with data brokers or advertisers.
- No use of Your Content to train AI or machine-learning models. If we introduce AI-assisted features in the future, any use of your content in connection with those features will be opt-in, and we will not use your content to train AI or machine-learning models without your prior consent, obtained at that time (see the Terms of Service, Section 6).
- No cross-site tracking, no ad pixels, no social-media trackers.
- No collection of card or bank data by us (Stripe holds it, Section 2.4).
2.7Messages you send us
When you send us a message through a form on the Service, we receive the name, email address, and message you provide, along with any other fields that form asks for, such as an organization name, a subject category, or which page the form was on. We use this only to read and answer your message. The form is handled by Formspree, listed in Section 4, which delivers the message to our inbox and keeps a copy of it in our account under its own terms; Formspree stores and processes this data in the United States. If you would rather not use a form, you can email us at the address in Section 12.
3.Cookies#
We use only essential cookies required for authentication and session management, set by Clerk. Because Plausible is cookieless and we run no advertising or analytics cookies, we do not display a cookie-consent banner. These cookies are strictly necessary for the Service to function, and applicable law does not require consent for strictly necessary cookies. If we introduce any non-essential cookies in the future, we will implement a consent mechanism before doing so.
4.Subprocessors#
We rely on the following third-party providers to run the Service. Each processes data under its own terms and, where applicable, a data-processing agreement:
| Subprocessor | Purpose | Data it handles |
|---|---|---|
| Clerk | Authentication and accounts | Email, name, OAuth identifiers, session data |
| Stripe | Payment processing | Card and billing data (directly from you), customer/subscription references |
| Plausible | Analytics (cookieless, EU-hosted) | Aggregate, non-personal usage statistics |
| Railway | Backend and database hosting | Saved designs, custom materials, usage events, subscription references |
| Vercel | Frontend hosting | Request and edge logs (IP, standard web-server data) |
| Cloudflare | DNS, content delivery, security, and email routing | Visitor IP addresses and request metadata; contents of email sent to our published addresses, processed in transit to route and deliver that email |
| Resend | Transactional email (service notices, US-hosted) | Email address; the subject and content of the service email we send you |
| Formspree | Contact and inquiry form delivery | The name, email address, and message you submit through a contact or inquiry form, and which page the form was on |
Provider privacy terms: [Clerk](https://clerk.com/legal/privacy), [Stripe](https://stripe.com/privacy), [Plausible](https://plausible.io/data-policy), [Railway](https://railway.com/legal/privacy), [Vercel](https://vercel.com/legal/privacy-policy), [Cloudflare](https://www.cloudflare.com/privacypolicy/), [Resend](https://resend.com/legal/privacy-policy), [Formspree](https://formspree.io/legal/privacy-policy/).
Legal compliance and protection. We may preserve or disclose your personal information if we believe in good faith that doing so is required by law, subpoena, or other legal process, or is reasonably necessary to enforce our Terms of Service, to protect the security or integrity of the Service, or to protect the rights, property, or safety of Photizon, our users, or others.
Business transfers. If Photizon is involved in a merger, acquisition, financing, reorganization, or sale of some or all of its assets, personal information may be transferred as part of that transaction. If that happens, we will require the recipient to honor the commitments in this policy or we will notify you and provide any choices required by applicable law before your personal information becomes subject to a different policy.
5.Where your data is processed#
Our hosting providers (Railway, Vercel) and other providers may process data in the United States and other regions; Plausible is EU-hosted. If you access the Service from the EU or UK, your data may be transferred to and processed in the US by our US-based providers under recognized transfer safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and, for providers certified under it, the EU–U.S. Data Privacy Framework and its UK Extension.
6.Your rights and choices#
You can:
- Access and view your account data and stored content by signing in.
- Edit your profile through the account page.
- Delete individual saved designs and custom materials from your dashboard at any time. Deleting a custom material removes that row from our database. Deleting a design moves it to your trash, where you can restore it for at least 30 days; after 30 days it becomes eligible for permanent deletion and may be permanently removed at any time thereafter. You can also permanently delete a design immediately using "Delete permanently" in your trash. Permanent deletion removes the design, together with its version history and recovery drafts, from our database.
- Manage or cancel your subscription via the Stripe customer portal, linked from your account page, and request your billing records.
- Export your saved designs.
Account deletion. You can delete your account and all associated stored content — saved designs (including anything in your trash), custom materials, usage records, and subscription references — directly from your account settings. You can also request deletion by contacting support@photizon.com; we will process the request and confirm when it is complete. We complete verified deletion requests within the timeframes required by applicable law (generally within 30 to 45 days).
Depending on where you live, you may have additional rights (access, correction, deletion, portability, objection, restriction). To exercise any right, contact support@photizon.com; we will respond within the timeframes required by applicable law. We will not discriminate against you for exercising your rights.
7.Legal bases and regional rights#
For EU and UK users. We process personal data on the following bases: performance of a contract (running your account and the features you sign up for), legitimate interests (securing the Service, understanding aggregate usage via cookieless analytics, preventing abuse), and legal obligation (e.g., retaining payment records where required). You have the rights listed in Section 6. You also have the right to lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office).
For California users. We do not sell or share your personal information as those terms are defined by the CCPA, and we do not use it for cross-context behavioral advertising. California residents may request access to, or deletion of, their personal information via Section 6.
For residents of other US states. If you live in a state with a comprehensive privacy law (for example, Colorado, Connecticut, Texas, or Virginia), you may have rights to access, correct, delete, and obtain a copy of your personal data, and to appeal a decision we make on a request. You may exercise these rights via Section 6 above. If we decline a request, you may appeal by replying to our response, and we will answer your appeal within the time your state's law requires.
Other regions. Wherever you live, if local law grants you privacy rights (for example, Canada's PIPEDA, Brazil's LGPD, or Australia's Privacy Act), you may contact us via Section 6 above and we will honor your request as that law requires.
8.Data retention#
- Account and content data is retained while your account is active. When you delete your account, your content is removed from our live database, and residual copies in routine backups age out within 7 days. A design you delete individually remains in your trash until it is permanently deleted (Section 6); once permanently deleted, the same 7-day backup aging applies.
- Service email records (which notice we sent about your account and when, whether it went out or was skipped and why, and our email provider's identifier for the message; never the message body and never your email address) are retained while your account exists and are deleted with your account. Our email provider retains the content and delivery logs of each message for 30 days.
- Messages you send through a form are retained in our email inbox for as long as needed to answer them and to keep a record of the exchange. Our form provider keeps its own copy in our account under its retention terms, and we can delete an individual submission from that account; you can ask us to do so using Section 6.
- Payment and billing records are retained for seven years as required for tax, accounting, and legal purposes. This retention applies notwithstanding a deletion request, to the extent required by law.
- Analytics and aggregate data is non-personal and is retained indefinitely in that form. This includes aggregate statistics we derive about how the Service is used (for example, which tools are most used, or typical parameter ranges). These aggregates contain no personal data and are not linked to any individual account, and they are retained after an account is deleted.
9.Security#
We use reasonable technical and organizational measures to protect your data: authentication and credential security via Clerk, encrypted transport (HTTPS), payment isolation via Stripe (we never hold card data), and access controls that ensure a user can only read or delete their own content. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach of security affecting your personal data, we will notify you and any regulators entitled to notice without undue delay, consistent with applicable law. Keep your own copies of work that is critical to you.
10.Children's privacy#
The Service is a professional and educational engineering tool and is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact support@photizon.com and we will delete it.
11.Changes to this policy#
We may update this Privacy Policy. Material changes will be reflected in an updated effective date and, where appropriate, an in-product or email notice. Continued use after changes take effect constitutes acceptance.
12.Contact#
Privacy questions or requests: support@photizon.com
Data controller: PHOTIZON INC., PO Box 90301, Santa Barbara, CA 93190