Pablit

Privacy Policy of Pablit.com

Effective Date: May 3, 2026  ·  Last Updated: July 29, 2026

1. Introduction

Pablit.com (“Pablit,” “we,” “us”) is operated by Ethereal Software Services LLC, a New York limited liability company. This Privacy Policy explains what personal information we collect when you use the Pablit platform, how we use and share that information, the third parties that process information on our behalf, the rights you have over your information under U.S. and international privacy law, and how to contact us about your data.

This Policy is incorporated into our Terms of Service. Capitalized terms not defined here have the meanings given to them in the Terms of Service.

2. Information We Collect

We collect the following categories of personal information:

  • Account information — name, username, email address, password (stored as a salted hash), profile photo or avatar, country of residence (auto-derived from your IP if you do not supply it), date of birth (used only to verify minimum age and then discarded from the profile if the form does not surface it), and B2B-tier flag where applicable.
  • Authentication identifiers — if you sign in with Google OAuth, the OAuth subject identifier and email address Google returns to us, plus session cookies that keep you signed in.
  • Network and device data — the IP address used to register (registration_ip), the IP address used on each subsequent login (last_login_ip), country code derived from the CF-IPCountry Cloudflare header, browser user-agent string, and approximate device characteristics.
  • Generation inputs and outputs — text prompts you submit, reference images you upload, and the AI-generated images we return. Prompts and outputs are stored against your account so you can revisit them.
  • Marketplace and order data — designs you publish, public posts, products you list, items in your cart, shipping address, billing details, and order history.
  • Payment data — we do not store full payment-card numbers. Card processing is handled by Stripe and Shopify (see Section 5). We retain transaction identifiers, the last four digits of the card, the cardholder name, and the billing country for receipts, fraud prevention, and tax reporting.
  • Credit and transaction history — your Pablit Credits balance, every credit purchase, usage, refund, bonus, or admin grant (audit trail required for accounting and dispute resolution).
  • Communications — emails you send to support, bug reports, in-platform notifications you read or dismiss.
  • Usage and analytics data — pages visited, features used, generation success/failure events, click and scroll patterns. Where this information is collected via cookies, see Section 6.

3. How We Use Your Information

We use your information to:

  • provide the platform — generate images, fulfill orders, run the marketplace, manage your credit balance and refunds;
  • authenticate you and keep your account secure (including verifying that login attempts come from contexts consistent with your registration);
  • communicate with you — transactional emails (order confirmations, shipping updates, payment receipts, password resets), service announcements, and, only if you have opted in, periodic newsletters;
  • detect, investigate, and prevent fraud, abuse, intellectual-property complaints, and Terms-of-Service violations;
  • operate, debug, and improve the platform — including using aggregate, de-identified usage data to inform product decisions;
  • comply with applicable laws, court orders, valid law-enforcement requests, and tax obligations.

Legal bases (EU/UK users). We rely on the following GDPR/UK-GDPR legal bases: contract (to provide the service you signed up for), legitimate interests (security, fraud prevention, product analytics), consent (marketing emails, non-essential cookies), and legal obligation (tax, accounting, valid government requests).

4. Data Retention

We retain personal information only as long as necessary for the purposes described above. Specific retention periods:

  • Account data — for the lifetime of your account, plus up to 30 days after deletion to allow recovery of accidentally deleted accounts.
  • Order, invoice, and payment records — up to 7 years after the transaction, to comply with U.S. federal and state tax recordkeeping rules and Shopify/Stripe reconciliation.
  • Connected-app & API access logs — 13 months from the date of the recorded action, then automatically purged.
  • Generation inputs and outputs — for the lifetime of your account; you may delete individual designs at any time.
  • Server access logs — up to 90 days, then rotated out.
  • Backups — encrypted backups may persist for up to 90 days after deletion before being overwritten in their normal lifecycle.
  • Anonymized analytics — may be retained indefinitely once stripped of identifiers.

We may also retain limited information beyond these periods where required by law (e.g., to respond to subpoenas, defend legal claims, or maintain a record of repeat-infringer accounts under 17 U.S.C. § 512).

5. Third-Party Service Providers

We share personal information with the following processors only as needed for them to perform services for us. Each is contractually bound to use the data only on our instructions and to comply with applicable privacy law.

  • Stripe, Inc. — payment processing for credit purchases. Receives your name, email, billing address, and payment-card details (which never touch our servers). See stripe.com/privacy.
  • Shopify Inc. — checkout, invoicing, and order management for marketplace purchases. Receives your shipping/billing details, item selection, and payment data through Shopify-hosted checkout. See shopify.com/legal/privacy.
  • Print-on-demand fulfillment vendor(s) — produces, packages, and ships the physical products you order. Receives the design files for ordered items, your shipping address, recipient name, and contact email so the items can be produced and delivered. We may change vendors over time without prior notice.
  • Cloudflare, Inc. — content delivery, DDoS protection, and TLS termination. Receives request metadata (IP, headers, timing) for every request to the platform. We use Cloudflare's CF-IPCountry header to populate your country field at registration. See cloudflare.com/privacypolicy.
  • Google LLC — (a) Google OAuth for sign-in if you choose that path; (b) Google Analytics 4 (loaded only after you accept analytics cookies) for aggregate usage statistics; (c) Google Cloud (Imagen) and Gemini APIs as AI generation backends when you select those models. See policies.google.com/privacy.
  • OpenAI, L.L.C. — AI generation backend (GPT Image / gpt-image-2 family, GPT-5 reasoning) when you select those models. Your prompts and any reference images you submit are sent to OpenAI to produce the requested output. Per our agreement with OpenAI, your prompts and outputs are not used by OpenAI to train its models. See openai.com/policies/privacy-policy.
  • Stability AI Ltd. — AI generation, upscaling, and image editing backends (Stable Image, SDXL, conservative/creative upscale, search-and-replace). Receives prompts and source images for the requested operation. See stability.ai/privacy-policy.
  • Black Forest Labs GmbH — AI generation backend (FLUX.2 Max, FLUX Klein 9B). Receives prompts and reference images for the requested operation. See blackforestlabs.ai/privacy-policy.
  • Ideogram AI, Inc. — AI generation backend (Ideogram 4.0). Receives prompts for image generation. See about.ideogram.ai/legal/privacy-policy.
  • Amazon Web Services, Inc. (S3) — storage backend for generated images and uploaded reference images. See aws.amazon.com/privacy.
  • Email delivery providers — transactional and (if opted in) marketing email is sent through third-party email infrastructure. They receive your email address and message content for the purpose of delivering the email.

We do not sell your personal information to advertisers or data brokers, and we do not share it with third parties for their independent marketing purposes.

Other disclosures. We may disclose information when (a) compelled by valid legal process (subpoena, court order, search warrant) and we believe disclosure is required by law; (b) necessary to protect the rights, safety, or property of Pablit, our users, or the public; (c) part of a corporate merger, acquisition, financing, reorganization, or asset sale (in which case we will notify affected users by email and/or in-platform notice).

6. Cookies and Tracking

We use cookies and similar technologies for three purposes: (i) strictly necessary — session, authentication, CSRF protection, cart state, cookie-consent state itself; (ii) functional — remembering preferences such as theme, language, and dismissed prompts; (iii) analytics — Google Analytics 4 to understand aggregate usage. Strictly necessary cookies are always on; functional and analytics cookies load only after you accept on the cookie banner. See our Cookies Policy for the cookie inventory.

7. Your Rights

Depending on your jurisdiction, you have the following rights with respect to your personal information.

All users: the right to (a) access a copy of the personal information we hold about you; (b) correct or update inaccurate information; (c) delete your account and associated data, subject to the retention exceptions in Section 4; (d) export a portable copy of your designs, posts, and account data; (e) close your account at any time.

Residents of the EEA, UK, and Switzerland (GDPR / UK-GDPR): in addition, the right to restrict or object to processing, the right to withdraw consent at any time (without affecting processing already done in reliance on prior consent), and the right to lodge a complaint with your national data-protection authority. Our lead supervisory contact is [email protected].

Residents of California (CCPA / CPRA): the right to know what personal information we collect, use, disclose, and (if applicable) sell or share; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of the “sale” or “sharing” of personal information; the right to limit use of sensitive personal information; the right to non-discrimination for exercising any of these rights. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. To exercise any California right, email [email protected] with the subject “CA Privacy Request.” You may designate an authorized agent to make a request on your behalf.

We will respond to verifiable requests within the time frames required by law (generally 30 days for GDPR, 45 days for CCPA, extendable once where permitted). To verify your identity we may ask you to log in or to confirm information already on file.

8. Children's Privacy (COPPA)

Pablit is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us personal information, please contact [email protected] and we will delete the information and close any associated account. The signup form requires a date of birth and rejects accounts that do not meet the minimum age.

9. International Data Transfers

Pablit is operated from the United States. If you access the platform from outside the United States, your personal information will be transferred to, processed in, and stored in the United States and in the regions where our service providers operate. The U.S. and other countries may have data-protection laws that differ from those in your country. Where required, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent mechanisms with our processors to provide appropriate safeguards for international transfers.

10. Security

We use a combination of technical and organizational measures to protect your information, including TLS encryption in transit, encrypted storage at rest, hashed passwords (argon2id for API keys, salted bcrypt-style hashing for account passwords), strict access controls on production systems, audit logging on sensitive operations, and routine security reviews. No system is perfectly secure, however, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the appropriate authorities as required by applicable law.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last Updated” date at the top of this page and, where appropriate, notify you by email or in-platform banner before the change takes effect. Your continued use of the platform after the effective date constitutes acceptance of the updated Policy.

12. Contact Us

For privacy questions, requests, or complaints, contact us at:

Ethereal Software Services LLC — Privacy Office
Email: [email protected]
General support: [email protected]
Copyright/DMCA: [email protected]
Other legal: [email protected]

13. Corporate Information

Pablit.com is operated by Ethereal Software Services LLC, a limited liability company organized under the laws of the State of New York, United States.

© 2026 Pablit. AI-generated designs are yours to keep.