PIC Privacy Policy
Effective date: 21 August 2026 | Version: 1.0
This Privacy Policy explains how PIC (People Instant Choice) collects, uses, discloses, and retains personal data. It also explains the choices and rights available to you.
PIC is a binary polling service where users post photographs and other users choose between them. Photographs, votes, and the rules governing who can see those votes are therefore central to this policy.
Please also read the Terms of Service, which govern your use of PIC.
Summary
- We collect the information needed to create and secure your account, the content and votes you submit, your social connections, app sessions, and information about how you interact with polls. We use this activity for aggregate product analytics as described below.
- We do not sell personal data, display advertising, or use third-party advertising, attribution, or analytics SDKs.
- Our database, backend servers, and photograph storage are configured in the European Union.
- Photographs may be checked automatically before publication and may be refused.
- Voting is attributed, not anonymous. Everyone permitted to see a poll's results can see your profile identity beside your vote. Section 5 explains the audience and the exceptions.
- If you send us feedback from inside the app, the report is filed in our issue tracker and is retained independently of your account. Section 6 explains what it contains.
- You may delete your account through the app or our public account-deletion page. Section 8 explains what is deleted and what remains after deletion.
- You may contact us at [email protected] or complain to a data protection authority.
1. Controller and contact details
PIC is provided by the following individual, who is the data controller:
- Daniele Marinelli
- via Antonio Gramsci, 98
- 20013 Magenta (Milano)
- Italy
- [email protected]
Use this email address for privacy questions, requests concerning your rights, and notices under the Digital Services Act. It is the electronic point of contact for both users and authorities.
2. Personal data we process
The categories below follow the terminology used by Google Play's Data safety section so that this policy and the app-store declarations can remain aligned.
| Category | What we process | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Personal information - name | Username and display name | Creating your account and identifying you on profiles, polls, and the votes you cast (section 5) | Contract | While your account exists; the normalized username is temporarily reserved after deletion as described in section 8 |
| Personal information - email | Email address | Account verification, sign-in support, password reset, security messages, and safety notices | Contract | While your account exists; an address on the email suppression list may remain after deletion as described in section 8 |
| Personal information - identifiers | Your opaque account reference | Referring to your account without exposing a sequential internal database identifier while it exists; preserving a reconcilable historical count of accounts created after deletion | Contract while the account exists; legitimate interests in product analytics for the limited record retained after deletion | While your account exists; after deletion, limited retained records use a fresh replacement reference that is not connected to your deleted profile, as described in section 8 |
| Personal information - other | Date of birth; the country inferred from your registration IP address and a marker recording that source; the accepted Terms version and acceptance time; and a timezone offset used during registration to calculate age | Creating and administering your account, applying minimum-age requirements, recording acceptance of the Terms, and preserving a reconcilable historical count of accounts created | Contract while the account exists; legitimate interests in product analytics for the creation instant retained after deletion | Date of birth, inferred country, its source, and Terms acceptance while your account exists; the timezone offset is used during registration and is not stored in your account record; after deletion, only the account-creation instant is retained under the replacement reference as described in section 8 |
| Photos and videos | For a poll: a display image and, where useful, a normalized unframed image, together with crop coordinates. For a profile photo: a single square image, cropped on your device before it is uploaded, so we never receive the original or the crop coordinates | Creating, displaying, and animating your polls; showing your profile photo where your account appears | Contract | While your account exists |
| App activity - user-generated content | Poll questions, option labels, votes, and pins | Operating polls and calculating, displaying, and attributing results; preserving reconcilable historical poll and vote counts after deletion | Contract while the account exists; legitimate interests in product analytics for content-free poll records and votes retained after deletion | Poll questions, option labels, photographs, and pins while your account exists; after deletion, content-free poll records and votes are retained for aggregate product metrics as described in section 8 |
| App activity - interactions | Polls shown to you and polls you skip or share; a random app session identifier for each period of use; server-side session start and recent-activity times; the session link on a poll, vote, or interaction event; and, for each interaction event, a random delivery identifier and the device-clock time of the action. The random app session identifier is not derived from your device, installation, or account. | Avoiding unnecessary repetition in the feed, selecting future polls, providing aggregate performance information to posters, producing accurate engagement counts, and measuring aggregate active users, session counts and length, and release adoption | Legitimate interests in operating, measuring, and improving PIC | The History Viewed list while your account exists and deleted on account deletion; interaction events are retained after deletion for aggregate product metrics as described in section 8; app-session records are scheduled for deletion 13 months from the session start and removed during the next regular cleanup; the session link on a poll, vote, or interaction event for as long as that poll, vote, or event remains under its own retention rule |
| App activity - social | Following relationships, followers, pending requests, approved followers, and the accounts you have blocked | Operating profiles, private-account visibility, the Following feed, and applying the blocks you create | Contract | While your account exists, and a block until you remove it; block records are deleted on account deletion as described in section 8 |
| Device or other identifiers | Native push-notification token, the platform stored with that registered token, locale, and device time zone | Delivering notifications in the appropriate language and deciding which local day a notification counts toward | Consent | While the token remains registered; it is removed on account deletion and may also be removed on sign-out or when the provider reports it as invalid |
| App info and performance | Platform and app version are included with every app request while signed in and stored with the app session, together with server-side session start and recent-activity times. | Measuring aggregate product use and release adoption | Legitimate interests in operating, measuring, and improving PIC | App-session records are scheduled for deletion 13 months from the session start and removed during the next regular cleanup |
| Authentication and security | A salted one-way password hash, access and refresh tokens, server-side authentication session records, one-time-code records, and code-send records | Authenticating you, maintaining sessions, verifying email changes, resetting passwords, and preventing abuse of verification flows | Contract and legitimate interests in account security | Password and authentication session records while your account exists; codes become unusable after their validity or use window; account-linked code records are removed when the account is deleted |
| Safety and moderation | Reports you make, reports concerning your account or polls, moderation decisions, appeals, and safety-state records | Investigating reports, restricting harmful or unlawful content, handling appeals, and maintaining an audit trail | Legitimate interests in protecting users and the service | While your account exists and, for the limited records identified in section 8, after deletion |
| Automated image classification | Evidence generated when an automated image check is performed, which may include moderation labels and confidence scores, a content hash, classifier and policy versions, the result, timing, and related account, poll, or stored-image references where available | Applying and auditing the publication safety gate, calibrating its thresholds, and detecting repeated submission of previously refused content | Legitimate interests in preventing harmful or unlawful images from being published | While your account exists and, in re-keyed form, after deletion as described in section 8; refused image bytes are not retained |
| Technical and operational data | The source IP address used at registration and for rate limiting; for failed requests, the route identifier, HTTP status, failure code, duration, and your opaque account reference when you were signed in | Inferring an approximate country at registration to apply the minimum-age rule; preventing brute-force attempts, flooding, and other abuse; diagnosing service failures | Contract for minimum-age enforcement; legitimate interests in service and account security | The IP address for the applicable rate-limit and cleanup window; only the inferred country code remains with the account; failure logs for the hosting provider's applicable log-retention window |
| Feedback you send | Your written report, the screen you were on, your platform, app version, device name, and your username, together with a screenshot of that screen unless you remove it before sending; your account reference, to check whether your account is enrolled | Receiving, understanding, and resolving reported faults and suggestions | Legitimate interests in diagnosing and fixing faults | For as long as the report remains useful, independently of your account, as described in section 8 |
We do not collect device location. At registration, we use your network IP address to infer an approximate country, not a precise location or a location reading from your device. The inference may fail, in which case no country is stored. We do not ask for financial information, health information, contacts, messages, calendar data, device files, or browsing history.
PIC does not use facial recognition and does not process photographs to identify people. Please do not upload photographs that reveal sensitive information about you or another person, such as health, religious belief, political opinion, or sexual orientation.
3. Legitimate interests
Where we rely on legitimate interests, those interests are:
- Safety and moderation: preventing harassment and harmful or unlawful content, investigating reports, and preserving the integrity of moderation decisions.
- Automated image classification: when automated screening is enabled, preventing prohibited images from being published, auditing the safety gate, and improving its accuracy without retaining refused image bytes.
- Service and account security: preventing brute-force attempts, flooding, and other abuse, and diagnosing failed requests. IP addresses and operational logs used for these purposes are not used to build advertising profiles or track you across services.
- Feed and interaction processing: avoiding polls you have already seen, improving feed usability, and providing posters with aggregate information about poll performance. A poster's own interactions are excluded from the aggregates shown to that poster.
- Product analytics: keeping historical counts of accounts created, polls, votes, and activity reconcilable over time, and understanding aggregate active use, session frequency and duration, accurate engagement, and release adoption so PIC can be operated, measured, and improved. We limit product analytics to first-party operational and product metrics. We do not use this data for advertising or cross-service tracking, and we apply the retention and account-deletion safeguards described in sections 2 and 8.
- Feedback: receiving, understanding, reproducing, and resolving the faults and suggestions you choose to send us.
We limit this processing to what is reasonably necessary for those purposes. You may object to processing based on legitimate interests as explained in section 11.
4. Information required to register
The registration form requires a username, display name, email address, password, date of birth, and acceptance of the current Terms. The timezone offset supplied by your device is used to calculate age against your local calendar date. Registration cannot be completed without this information. PIC also attempts to infer a country from your registration IP address so that it can apply a higher minimum age where required; if the inference fails, the platform minimum applies.
Other activity is optional. You may use PIC without posting a poll, voting, following another account, or enabling push notifications. You may turn off notification delivery through your device settings without losing access to the rest of PIC.
5. Who can see your information
Profiles and polls
Any signed-in user may see the basic identity associated with an account, including its username, display name, profile photo where one is set, public or private status, and profile counts. If your account is private, only you and approved followers may see your polls and other private profile content. Polls from public accounts may be seen by other PIC users.
Your email address, date of birth, inferred country, authentication data, and Terms acceptance record are not displayed to other users.
Results and vote counts
While a poll is live, its percentage split and vote count are visible to the poster and to users who have already voted on it. After the poll closes, they are visible to anyone who is permitted to see the poll.
Vote attribution
Voting is attributed, not anonymous. When you vote, your username, display name and profile photo are shown beside the option you chose to every user permitted to see that poll's results. While a poll is live, that audience is its poster and users who have already voted; after it closes, it is anyone permitted to see the poll.
There is no anonymous voting setting and no per-vote override. While your account exists, you cannot change or withdraw an individual vote or make its attribution anonymous. If you would prefer not to be identified on a poll, do not vote on it. Skipping a poll is always available and has no effect on your account.
Users who are not permitted to see a poll's results see no voter identities and no vote count for it. Accounts separated by a block are also not shown to one another in the voter list, although their existing votes still count.
PIC does not publish a service-wide list of polls you have voted on. A vote may appear only on the poll where it was cast and only under the rules above.
If a voter's account has been deleted, their vote continues to count toward the poll's result but is shown without a profile identity, as described in section 8.
Accounts you have blocked
A block is visible to the account that created it and is never disclosed to the blocked account. The accounts you have blocked are listed for you in the app's settings, where you can remove any of them. A blocked account receives no notification and is not told that a block exists; to it, the blocking account's profile and polls appear to be unavailable.
While a block is in place, the two accounts' content is mutually unreachable and no following relationship or pending follow request between them can exist. Section 8 of the Terms of Service describes the effect in full.
Reports you make
A report is never disclosed to the person reported. They are not told that a report exists, who made it, or how many have been made. Neither an in-app notification nor an email about a moderation decision identifies a reporter.
The people who review reports can see your username, display name and account reference while your account still exists. They do not receive your email address, date of birth, inferred country, or other private account information as part of the report. After your account is deleted, a retained report no longer resolves to your profile.
The note you write with a report is part of it. A reviewer reads it and can see that it came from you, so keep it to what is wrong with the content or account and do not include unnecessary personal details.
6. Service providers and other recipients
Providers acting on our instructions receive only the data needed to perform their function. We require them to protect personal data to the same or an equivalent standard as this policy through contractual data-protection obligations. App stores may act as independent controllers for their own relationship with you.
| Provider | Role | Primary configured location |
|---|---|---|
| Neon | Database hosting for accounts, polls, votes, social relationships, reports, and notifications | European Union |
| Render | Backend hosting, operational logs, and key-value storage for security controls | Frankfurt, Germany |
| Cloudflare R2 | Private storage for poll photographs and profile photos | European Union |
| Amazon Web Services SES | Account, security, moderation, and safety email delivery | European Union |
| Amazon Web Services Rekognition | Automated image classification when that safety check is enabled, as described in section 10 | European Union |
| Expo / EAS | App builds, distribution support, and over-the-air software updates | United States |
| Google Firebase Cloud Messaging | Delivery of Android push notifications | United States and European Union |
| Apple Push Notification service | Delivery of iOS push notifications | United States and European Union |
| Google Play and Apple App Store | App distribution; each acts as an independent controller for its relationship with you | Global |
| Atlassian (Jira) | Hosting the issue tracker that receives feedback reports you choose to send | Global |
International transfers
Our production database, backend servers, and photograph storage are configured in the European Union. App distribution, software updates, push-notification delivery, and feedback hosting may involve processing in the United States or other countries outside the European Economic Area.
Where an adequacy decision does not apply, we rely on the European Commission's Standard Contractual Clauses and, where applicable, a provider's certification under the EU-US Data Privacy Framework, as incorporated into the provider's data-processing terms.
You may request a copy of the safeguards relevant to your data by emailing [email protected].
Sending feedback
PIC includes an in-app feedback reporter for sending us a fault report or a suggestion. In store builds it is available only to accounts we have enrolled as testers.
Nothing is sent unless you submit the form. A report contains what you write, the screen you were on, your platform, app version, device name, and your username. A screenshot of that screen is captured and included with the report; the form shows it to you and you can remove it before sending.
Reports are filed in our issue tracker, which is hosted by Atlassian. A report you have submitted is retained independently of your account, as described in section 8.
Development and internal testing
Development and internal-test builds may contain diagnostic tools that are not present in store builds.
7. Security
Passwords are stored as salted one-way hashes and are not logged in readable form. Sign-in attempts are rate limited by source address and account. PIC uses short-lived access tokens, private image storage, encrypted network connections, and expiring image links.
In the production deployment, photograph files are stored in Cloudflare R2 rather than on the backend server's local disk. The backend temporarily handles image bytes in memory while validating and preparing them for storage, and while classifying them when automated image screening is enabled.
If a personal-data breach occurs, we will notify the competent supervisory authority and affected individuals when applicable law requires us to do so.
8. Account deletion and retention after deletion
You may permanently delete your account through the app or the public account-deletion page. Deletion is not a temporary deactivation and cannot be reversed.
Deletion begins immediately by destroying the account's identifying and authentication records and starting cleanup of the remaining data. A background process then removes or replaces identifying references in those remaining records. The deletion receipt records when that process completes.
Deleted as part of the deletion process
The process deletes:
- your active account and public profile, including display name, email address, date of birth, inferred country, country-source marker, Terms acceptance record, password hash, authentication session records, and outstanding account-linked verification records;
- the question, option labels, and stored photographs from every poll you created; the content-free poll record is retained only as described below and is never shown to anyone;
- following relationships, pending requests, and private-account approvals involving your account;
- every block record involving your account, both the accounts you blocked and any account that blocked you, so that no account is left blocked by an account that no longer exists;
- your notifications, notification preferences, and push tokens;
- your History Viewed list; the underlying interaction events are retained only as described below;
- your pins and other users' pins of polls you created;
- reports concerning polls you created; and
- account-related records for an email change that was still in progress.
Retained with identifying account links removed or replaced
Some records remain so that historical aggregate product metrics, other users' poll results, safety protections, or the history of a platform rule stay reliable. Where a retained record still needs to distinguish one contributor from another, your account reference is replaced with the same fresh random replacement reference created for the deletion. That reference does not resolve to a profile or sign-in, and PIC does not retain a mapping from it to your deleted profile. Where nothing depends on that distinction, the reference is removed outright.
The affected records are:
- a minimal account-creation record containing the creation instant and no other account attribute; it is stored under the replacement reference and deliberately contains no deletion date, so it cannot be joined to the deletion receipt to reconnect the two references;
- a content-free record of each poll you created, retaining its poll type, creation time, expiry window and time, status, and the app-session link described in section 2; its author is changed to the replacement reference, its question, option labels, and stored photographs are deleted, and the poll is never shown to anyone;
- votes other users cast on polls you created, which are retained unchanged under those users' own references; they are never shown because the poll is not viewable;
- votes you cast on other users' polls, because removing them would change those polls' results; your reference is replaced with the replacement reference;
- your interaction events recording views, skips, and shares, including the client-reported time and app session; your reference is replaced with the replacement reference;
- other users' interaction events on polls you created, which are retained unchanged under those users' own references;
- app-session records used for product metrics, which are scheduled for deletion 13 months from the session start and removed during the next regular cleanup; your reference is replaced with the replacement reference;
- reports you filed concerning content or accounts that remain on PIC, and account reports concerning you, because report counts and moderation history must remain reliable;
- automated image-classification evidence, including technical decision metadata and hashes, but not refused image bytes; and
- if you held a staff role, the record of any change you made to a country's minimum signup age. The country, the age, the date and the reason recorded for the change are kept because that record determines the country's current minimum age; the reference identifying you as the person who made the change is removed.
The content-free poll records, retained votes, interaction events, and minimal account-creation record have no scheduled deletion date. They are kept for as long as needed to preserve reconcilable historical counts of accounts, polls, votes, and activity for the legitimate product-analytics interest described in section 3. They are not used to restore or display the deleted account.
Reports concerning a poll you created are deleted as stated above. The deletion receipt retains the original account reference and dates but is deliberately not linked to the replacement reference.
Retained without changing their original reference
The following limited records may retain the original opaque account reference after the profile and identifying account record have been destroyed:
- the append-only moderation action log, which records both the moderator and the subject of a decision;
- the append-only staff role-assignment log, which preserves who held administrative or moderation authority;
- minimal suspension and safety-state records needed to preserve prior moderation outcomes; and
- the deletion receipt, containing the account reference and completion time after its temporary processing fields have been removed.
These records are retained for as long as necessary to preserve the integrity and auditability of safety, authority, and deletion decisions. The opaque reference no longer resolves to an account profile after deletion.
Feedback reports
A feedback report is filed in our issue tracker when you submit it, outside the account database, so deleting your account does not delete it. It retains what you sent, which includes your username and any screenshot you did not remove. You may ask us to remove a report you submitted by emailing [email protected].
Email suppression list
If your email address is on our suppression list because messages bounced or were marked as spam, the address remains in readable form after account deletion. It is retained so that PIC does not resume sending mail to an address that must not receive it. It is kept for as long as necessary to enforce that suppression.
Backups and username reservation
Deleted information may remain recoverable for a limited period within the database provider's point-in-time recovery window. The length of that window depends on the active hosting plan.
Your username is removed from the active account and public profile, but its normalized form and reservation timestamps are retained temporarily to reduce the risk of another person immediately taking the name and being mistaken for you. Once the configured reservation period ends, the username becomes available for registration even if an expired reservation record has not yet been physically removed.
Unless a different rule is stated above, data associated with an active account is retained for the life of that account.
9. Children
The minimum age for PIC is 14, or a higher age where the law applicable to you requires it. We use the date of birth and timezone information you provide during registration, together with the country inferred from your registration IP address, to apply the relevant minimum. If country inference fails, the platform minimum of 14 applies. PIC is not directed at children below the applicable minimum.
If you believe that a child below the applicable minimum has created an account, contact [email protected].
10. Automated photograph checks
PIC may assess photographs automatically before publication as part of its safety checks. When automated image screening is enabled, it applies to each photograph submitted for a poll or as a profile photo before the photograph is stored. PIC currently uses Amazon Rekognition for this purpose, sending the submitted photograph to the service and receiving content labels and confidence scores. The classification request does not include your email address, password, or other account details.
If an automated assessment identifies a prohibited category at or above the applicable confidence threshold, the submission is refused: the poll is not published, or the profile photo is not set. A temporary technical failure may also prevent publication until the check can be completed. The assessment uses the photograph, not your identity or previous activity.
When a check is performed, PIC records evidence of its result as described in section 2. When a submission is refused, PIC does not store the photograph bytes. A refusal affects that submission only and is not, by itself, an account penalty.
PIC may replace or discontinue the automated screening service. If automated screening is disabled, submitted photographs are not sent to Amazon Rekognition for classification. The Content rules and post-publication moderation described in the Terms continue to apply.
PIC does not use automated image screening to determine your eligibility for the service or to suspend or terminate your account. If you believe an image was refused incorrectly, email [email protected]. A human will review the refusal. The current app does not provide an in-app appeal flow.
11. Your rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- access your personal data and receive a copy;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests;
- receive data you provided in a structured, commonly used, machine-readable format where the right to portability applies;
- withdraw consent at any time, without affecting processing carried out before withdrawal; and
- receive the protections applicable to decisions based solely on automated processing that produce legal or similarly significant effects.
You may delete your account directly as described in section 8. For any other request, email [email protected]. We will normally respond within one month. That period may be extended where the law permits, and we will tell you if an extension is necessary. Requests are normally handled without charge, subject to the exceptions allowed by law.
You may also complain to a data protection authority. In Italy, the supervisory authority is the Garante per la protezione dei dati personali at garanteprivacy.it. You may instead contact the authority where you live or work.
12. Cookies, analytics, and tracking
PIC does not contain third-party advertising, attribution, or analytics SDKs, and we do not track you across other apps or websites. The PIC website does not use advertising or analytics cookies.
PIC processes the first-party view, skip, share, and app-session data described in section 2. This data is used within PIC for feed operation, accurate engagement counts, aggregate poll-performance information, aggregate metrics for active users, session counts and length, and release adoption. It is not used for cross-service tracking or advertising.
PIC creates a new random app session identifier when you sign in, when the signed-in account changes, and when you return after more than 30 minutes in the background. Signing out clears the current identifier so it is not reused.
The app stores the current session identifier and last-background time on your device. It also keeps a queue of at most 500 undelivered interaction events for no more than seven days so they can be delivered after a temporary connection failure. Events that have not been delivered within seven days are never sent and are deleted the next time the app runs. The queue is deleted when you sign out.
The app stores authentication tokens and preferences on your device so that it can keep you signed in and remember your settings.
13. Changes to this policy
We will update this policy when our processing changes. During PIC's pre-release drafting period, corrections and clarifications may be incorporated into version 1.0 without a new history entry. After that period, a material change, such as a new purpose, a new category of data, or a change to vote visibility, will receive a revised effective date and version, together with notice in the app before or when the change takes effect as appropriate.
Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 21 August 2026 | First publication |