Legal
Privacy built around local files.
What Pedify expects to process for the first version and where that information lives.
Draft product terms. Review with qualified counsel before accepting live payments.
Ped files stay local
Ped files are processed on your device and are not uploaded to Pedify, unless you choose to send them with a crash report, as the next section describes.
Model files, textures and generated geometry remain in your browser storage or in a folder you choose. Pedify may ask you to reconnect the original files when a local working copy is unavailable.
Files sent with a crash report
When the crash check finds faults in an export that it could not put right, you get a warning with an error code. If you tick Send the ped’s files to Pedify in that warning, the files the export built (the ped's models, textures and resource files, in one zip file) are sent from your browser to Pedify's private file storage at Vercel, linked to the error code. Nothing is sent unless you tick the box, and it costs no credits.
The files are used only to find and fix the fault. Only Pedify's staff can see them: they are kept in private storage that no link can open, and are only downloaded through Pedify's admin panel, where every download is logged.
The files are deleted automatically after 30 days. The error code and the export report stay like other export reports, without the files.
Face photos
Create face from photo reads a photo of a face, and such a photo may count as biometric data. In the On this device mode the photo is processed only on your device, in the browser. It is never sent to Pedify or to anyone else, and Pedify does not compare it with other faces. The AI 3D mode sends the photo on, as the next section describes.
The photo itself and the points found in the face are not stored, neither in your browser storage nor by Pedify. What remains is the finished skin in the head’s texture and the head’s new shape, in the project on your device and in the files you export.
The face is found by MediaPipe, a face detection from Google that Pedify serves itself and that runs in your browser. Its usage statistics are switched off, so nothing is sent to Google.
AI face in 3D
The AI 3D (sends the photo) mode of Create face from photo is only turned on for some accounts. In that mode your photos, one to five, are first sent from your browser through Pedify’s server to fal.ai, where the image model FLUX.2 from Black Forest Labs makes a picture from the front of them. Once you have approved the picture, only it is sent through Pedify’s server to fal.ai, which processes it, and on to the model maker Tripo, which makes a head in 3D from it. fal.ai and Tripo are outside the EU. Nothing is sent until you have agreed to it in the dialog, and you are asked every time.
The picture from the front is made so that Tripo gets one clean photo straight from the front, rather than photos from different angles. fal.ai makes it with the image model FLUX.2 from Black Forest Labs when you press Make picture for 3D, at most three times per try and ten times an hour, and it costs no credits. The picture comes straight back in the answer, and Pedify asks fal not to keep the photos or the picture. Pedify stores neither the photos nor the picture, and logs only your account id, the try’s id, how long it took and whether it worked. Google does not make the picture. It only compares the face with your photos after the job.
Pedify does not store the photos or the picture. The server reads them in memory and passes them on in the same request, and they are not written to any database, log or disk. For the job, Pedify logs the job’s id, your account id, the picture’s size in bytes and fal’s response code, but never the picture.
fal.ai stores the picture and the head while the job runs. Pedify asks fal to delete the job’s data as soon as the head has been fetched, and when the job fails, takes too long or is cancelled. Anything still left at fal, such as a file on fal’s CDN the deletion does not reach, can only be removed by fal’s support.
How long and where Tripo stores the picture is governed by Tripo’s terms. According to Tripo, input and output are not used to train the model.
After the job, up to three of your photos are sent to Google (Gemini API) again, together with two pictures of the game head, from the front and from the side. Google compares the face with the photos and suggests adjustments. This happens right after the job and at most three times per job, through Pedify’s server. With Include hair, up to three of the photos are sent once more, together with pictures of the game’s hairstyles, and Google chooses the hairstyle and hair colour most like the hair. This happens at most twice per job. Pedify stores neither the photos nor Google’s answers, and logs only the job’s id, the round, the score, which hairstyle was chosen and how long it took. Google processes the pictures under Google’s terms for the Gemini API, and Google’s servers may be outside the EU.
The head in 3D is fetched by your browser straight from fal.ai and stored only locally, in the browser’s storage on this device, until you use it or throw it away. It is removed when you delete the project and is never uploaded to Pedify. What remains after Apply is the finished skin and the head’s new shape, as for a photo on the device.
The processing rests on your consent. You can choose not to use AI 3D and use the On this device mode instead, where the photo never leaves your computer.
AI texture
Edit with AI in the texture editor is only turned on for some accounts. When you send a message, what you write, the pictures you attach and a preview of the texture (at most 1024 pixels, with the garment’s parts numbered) go from your browser through Pedify’s server to Google (Gemini API), which works out the change. When you ask for a drawing, a crop of the texture (at most 2048 pixels) is sent too. Nothing is sent before you have ticked the box in the AI tab.
Pedify does not store the messages, the pictures or the texture. The server reads them in memory and passes them on in the same request. Pedify logs your account id, the step’s id, which model answered, how long it took and how large the answer was, but never the content. What the AI does becomes layers in your project on your device.
Google processes the content under the terms of the Gemini API’s paid services, where content is not used to improve Google’s products. How long and where Google keeps it for a while is set by Google’s terms, and Google’s servers may be outside the EU. Pictures Gemini draws carry Google’s invisible SynthID watermark.
Only attach pictures you have the right to use, and no pictures of other people without their permission.
Signing in
You sign in with an email address and a password, with Google, or with Discord, and you can connect more than one of them to the same account.
With an email and a password, Pedify stores your address, whether you have confirmed it, and a hash of your password (scrypt, salted). The password itself is never stored or logged. To check that a new password isn’t in a known data breach, Pedify sends the first five characters of its SHA-1 hash to Have I Been Pwned; neither the password nor your address leaves Pedify.
With Google, Google tells Pedify your Google account’s id, your name, your email address, whether Google has verified it, and your profile picture. Pedify asks for nothing else and does not use Google’s access to your account for anything but signing in.
With Discord, Discord tells Pedify your Discord id, your name, your email address, whether Discord has verified it, and your avatar. Pedify’s Discord bot also reads whether you are a member of Pedify’s server and have the Verified role. If you have bought credits, the bot gives you the Customer role in the server, and takes it away if the purchases are refunded.
While you are signed in, Pedify keeps a session with the time it was made and last used, your IP address and your browser’s user agent, to keep you signed in, to limit password guessing and to show you your signed-in devices. A session ends after 7 days without use, when you sign out, or when your password is changed.
Account email
Resend (Resend, Inc., USA) sends Pedify’s account email for us as a processor: the link to confirm your address, the link to choose a new password, and the notices when your password or email address changes or someone tries to create an account with your address. Resend receives the address the email goes to and the email’s content, including the link. Pedify sends no marketing email.
Account and project records
When you sign in, Pedify stores your account identifier, your Discord membership status in Pedify’s server (whether you are a member with the Verified role, and when that was last checked), your referral code and the account that invited you, project names, timestamps, local-availability status, edit events, credit entries, export receipts and export reports (whether an export succeeded or what went wrong, how many garments it had and how long it took, never the files themselves unless you choose to send them with a crash report). Once you buy something, it also stores your Stripe customer id. These records help reconnect projects, pay each bonus once and prevent duplicate charges; they do not contain ped or texture binaries.
Local browser storage
The project’s whole edit history is stored in your browser on this device, so the project can be opened again as you left it. Undo reaches the last 25 steps, but every step is stored. When the history passes 300 steps, a step that paints counting as 4, the steps are written together into a saved copy of the ped’s files. If the history ever has to be cut short, a copy of it is kept first, at most 3 per project.
Your browser also stores the ped’s files and the garments you have added, pictures of the garments, the texture editor’s drafts, the catalog from your game folder, the eye files you have picked and heads in 3D from the AI. None of this is uploaded to Pedify. Clearing site data can remove that local copy.
Accounts and payments
Discord or Google provides sign-in information when you sign in with them, and Pedify’s Discord bot reads whether you are a member of Pedify’s server and have the Verified role, and gives the Customer role to anyone who has bought credits. Stripe is the payment processor: it handles checkout and card details, and Pedify receives purchase status, transaction references and your Stripe customer id rather than card details. Final retention periods must be confirmed before live payments are accepted.