Note legali

Privacy Policy

You are uploading photos of people's faces. You deserve to know exactly what happens to them. This policy explains what we collect, why, who else touches it, how long we keep it, and how to get rid of it.

Ultimo aggiornamento: 21 September 2026

Le nostre policy sono pubblicate solo in inglese. La versione inglese è quella vincolante.

The short version

  • Your uploads are used to make the prank you asked for. Nothing else.
  • We do not train AI models on your photos, and we do not sell or share your personal data for money or for advertising.
  • We do not run facial recognition. We never try to work out who is in a photo.
  • You can delete any upload or result at any time, and deleting your account deletes them all.
  • We use Google Analytics and PostHog to measure site usage, catch errors, and (with masking) review sessions. No advertising cookies. Uploaded photos are not sent into analytics or replay. See our Cookie Policy.
  • PrankLab is for adults only — 18 and over.

The rest of this page is the detail behind those six points, including the parts that European and Californian law require us to spell out.

1. Who is responsible for your data

The data controller for PrankLab.io is Stack Max LLC, 30 N Gould St, Ste R, Sheridan, Wyoming 82801, United States. That means we decide what personal data is collected and why, and we are accountable for it.

PurposeContact
Privacy questions, access and deletion requestslegal@pranklab.io
General supporthello@pranklab.io
PostalStack Max LLC, 30 N Gould St, Ste R, Sheridan, Wyoming 82801, United States
Phone+1 (702) 359-3841

We are a small company and we do not have a statutory Data Protection Officer. Privacy requests go to a person, not a queue, and we answer them within 30 days.

2. What we collect

CategoryWhat it isHow we get it
Account dataEmail address, password hash, plan, account settings, language preferenceYou give it to us
Uploaded imagesThe photos you upload, including any faces in them, and any image metadata attached to the fileYou give it to us
Generated resultsThe prank photos and videos produced from your uploads, and which template made themCreated by the Service
Billing dataPlan, credit balance, transaction history, billing country, last four digits and card brand. Full card numbers are handled by Stripe and never reach us.You and Stripe
Waitlist dataEmail address, sign-up source, whether you confirmed, and whenYou give it to us
Usage and technical dataPages viewed, templates opened, generation success and failure, IP address, browser and device type, timestamps, error logsCollected automatically
CommunicationsEmails and reports you send us, including takedown and misuse reportsYou give it to us

We do not ask for and do not want your government ID, your health data, your precise location, or your contacts list. Please do not send them to us.

3. Face images — the part that matters most

A photo of a face is sensitive, and the law in several places treats it more strictly than ordinary data. Here is exactly what we do and do not do with it.

What we do: we send your uploaded image to an AI generation provider, which produces a new image or video from it, and we store the upload and the result in your library so you can download them again. That is the whole processing chain.

What we do not do:

  • We do not run facial recognition or facial identification. We never try to determine who a person in a photo is.
  • We do not create, store or compare faceprints, face templates, face geometry scans, or any other biometric identifier used to single out a specific individual.
  • We do not match faces across accounts, build a face database, or link a face to a name, an account, or any external source.
  • We do not sell, lease, trade or otherwise profit from biometric data, and we do not disclose it except to the providers listed in section 6.
  • We do not use your uploads or results to train, fine-tune or improve any AI model, ours or anyone else's, and our agreements with AI providers require the same of them.

Because we do not process face images for the purpose of uniquely identifying a person, we do not consider them biometric data under Article 9 of the GDPR. We nevertheless treat them as sensitive: access is restricted, they are encrypted at rest and in transit, and they are deleted on request. Where consent is required for us to handle an image of you — including under Illinois BIPA, Texas CUBI, and similar US state laws — you give that consent by uploading, and you may withdraw it at any time by deleting the image or your account.

If a photo of you was uploaded by someone else without your permission, you do not need an account to do something about it. Email legal@pranklab.io and we will find it, remove it, and confirm back to you. See our takedown policy.

4. Why we use your data, and our legal basis

If the GDPR or UK GDPR applies to you, we must have a lawful basis for each use. These are ours.

What we use it forData usedLegal basis (GDPR Art. 6)
Creating and running your accountAccount dataPerformance of a contract (6(1)(b))
Generating the prank you asked forUploaded images, generated resultsPerformance of a contract (6(1)(b))
Storing your library so you can download results againUploads, resultsPerformance of a contract (6(1)(b))
Taking payment and preventing payment fraudBilling dataContract (6(1)(b)) and legal obligation (6(1)(c))
Keeping the Service secure, and investigating abuse or misuse reportsUsage data, uploads, results, communicationsLegitimate interests (6(1)(f)) — protecting users and the Service
Fixing faults and improving reliabilityUsage and technical dataLegitimate interests (6(1)(f)) — running a working product
Service emails: receipts, security notices, policy changesAccount dataContract (6(1)(b)) and legal obligation (6(1)(c))
Waitlist and launch announcementsWaitlist dataConsent (6(1)(a)) — withdraw any time via the unsubscribe link
Meeting tax, accounting and legal obligationsBilling data, communicationsLegal obligation (6(1)(c))

Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time (see section 10). Where we rely on consent, withdrawing it is as easy as giving it and does not affect what we did before you withdrew it.

5. What we never do with your data

  • We do not sell personal data, and we never have.
  • We do not "share" personal data for cross-context behavioural advertising, as California defines that term.
  • We do not use your uploads or results to train AI models.
  • We do not put your photos or results in a public gallery, in our marketing, or in advertising without asking you first and getting a yes.
  • We do not profile you or make automated decisions that produce legal or similarly significant effects about you.
  • We do not run advertising cookies. We do use Google Analytics and PostHog for usage measurement, error tracking, and privacy-masked session replay — see our Cookie Policy.

6. Who else processes your data

We use a small number of providers to run the Service. They act on our written instructions only, under contracts that include the data protection terms the GDPR requires, and they may not use your data for their own purposes.

ProviderWhat they doData they processLocation
Supabase, Inc.Database, authentication and file storageAccount data, uploads, generated results, waitlist dataUnited States
Railway Corp.Application hosting and server logsUsage and technical data, IP addressesUnited States
Stripe, Inc.Payment processing, subscription billing, fraud preventionBilling data, email address, card details (handled entirely by Stripe)United States
AI generation providerProduces the prank image or video from your uploadUploaded images, generated resultsUnited States
Email delivery providerSends transactional and waitlist emailEmail address, message contentUnited States
Google LLC (Google Analytics)Measures how visitors use the site (page views and related usage)IP address (as processed by Google), device and browser type, pages viewed, approximate location, timestampsUnited States
PostHog, Inc.Product analytics, error tracking, and privacy-masked session replayDevice and browser type, pages viewed, product events, error details, approximate location, timestamps. Session replays mask form inputs and block images, video, and canvas so uploaded photos and generated results are not recorded.United States

We will name our AI generation and email providers on this page as soon as they are live, and we will update this table whenever a provider changes.

Beyond those providers, we disclose personal data only when we must: to comply with a law, court order or valid legal request; to enforce our Terms or Acceptable Use Policy; to protect the rights, safety or property of a user, a third party or us; or to a buyer if the business is sold, in which case we will tell you before your data moves and this policy continues to apply until you are notified otherwise.

7. International transfers

We are a United States company and our providers are in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to and processed in the US.

For those transfers we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where the UK GDPR applies, together with additional technical measures — encryption in transit and at rest, and access controls that limit who can see uploads. You can request a copy of the relevant transfer safeguards from legal@pranklab.io.

8. How long we keep things

DataKept for
Uploaded images and generated resultsUntil you delete them, or 30 days after your account closes
Account dataFor as long as your account is open, then deleted within 30 days of closure
Waitlist email addressesUntil you unsubscribe, or 24 months after sign-up if PrankLab has not launched
Billing and transaction records7 years from the transaction, to meet tax and accounting law
Server and security logsUp to 12 months, then deleted automatically
Misuse reports, takedown notices and enforcement recordsUp to 3 years, so we can recognise repeat offenders and defend legal claims
Records of accounts banned for serious violationsRetained as a minimal block record so a banned user cannot immediately return

Deletion means deletion from live systems immediately and from encrypted backups as those backups age out, within 90 days. If a law requires us to keep something for longer — a tax record, or content subject to a live legal hold — we keep only that, and only for as long as we must.

9. How we protect it

  • Everything is encrypted in transit (TLS) and at rest.
  • Access to uploads and account data is limited to the few people who need it to run the Service, and is logged.
  • Passwords are hashed, never stored in a readable form, and we cannot see them.
  • Card details never touch our servers — Stripe handles them end to end.

No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify the relevant supervisory authority within 72 hours and tell you directly without undue delay, as the GDPR and applicable US state laws require.

10. Your rights

Wherever you live, you can ask us to show you your data, correct it, export it, or delete it. Under the GDPR and UK GDPR you specifically have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted (the right to be forgotten).
  • Restriction — have us pause processing while a dispute is resolved.
  • Portability — receive your data in a machine-readable format, or have it sent to another provider.
  • Object — object to processing based on legitimate interests, including at any time.
  • Withdraw consent — for anything we do on the basis of consent.
  • Complain — lodge a complaint with your national data protection authority. We would rather you came to us first, but it is your right either way.

To exercise any of these, use your account settings where the option exists, or email legal@pranklab.io from the address on your account. We respond within 30 days, free of charge. We may ask you to confirm your identity before acting on a request about someone's personal data, and we will not charge you for that.

11. If you live in the United States

California, Virginia, Colorado, Connecticut, Utah, Texas and a growing list of other states give residents similar rights: to know what is collected, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of sale, sharing or targeted advertising.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but every other right above is available to you, and we honour them for residents of every US state, not only those with a law in force.

Californians may also designate an authorised agent to make a request on their behalf. We will never discriminate against you for exercising a privacy right: your plan, price and service stay exactly the same. Requests go to legal@pranklab.io.

12. Cookies and analytics

We set the cookies strictly needed to make the site work — remembering your language and, once accounts are live, keeping you signed in — and we run Google Analytics and PostHog to measure how the site is used, diagnose errors, and review privacy-masked sessions. We do not run advertising cookies. We do not send uploaded photos or generated prank media into analytics or session replay.

Full detail, including exactly which cookies exist, is in our Cookie Policy.

13. Children

PrankLab is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we delete the account and its content promptly.

If you believe a person under 18 has given us data, email legal@pranklab.io and we will remove it. You must also never upload a photo of a child to PrankLab, whoever you are — see our Acceptable Use Policy.

14. Changes to this policy

When this policy changes we update the date at the top of the page. For changes that materially affect your rights or how we use your data, we email account holders at least 30 days before the change takes effect, and where the law requires consent we will ask for it rather than assume it.