Privacy Policy
You are uploading photos of people's faces. You deserve to know exactly what happens to them. This policy explains what we collect, why, who else touches it, how long we keep it, and how to get rid of it.
Ostatnia aktualizacja: 21 September 2026
Nasze zasady publikujemy wyłącznie po angielsku. Wersja angielska jest wiążąca.
The short version
- Your uploads are used to make the prank you asked for. Nothing else.
- We do not train AI models on your photos, and we do not sell or share your personal data for money or for advertising.
- We do not run facial recognition. We never try to work out who is in a photo.
- You can delete any upload or result at any time, and deleting your account deletes them all.
- We use Google Analytics and PostHog to measure site usage, catch errors, and (with masking) review sessions. No advertising cookies. Uploaded photos are not sent into analytics or replay. See our Cookie Policy.
- PrankLab is for adults only — 18 and over.
The rest of this page is the detail behind those six points, including the parts that European and Californian law require us to spell out.
1. Who is responsible for your data
The data controller for PrankLab.io is Stack Max LLC, 30 N Gould St, Ste R, Sheridan, Wyoming 82801, United States. That means we decide what personal data is collected and why, and we are accountable for it.
| Purpose | Contact |
|---|---|
| Privacy questions, access and deletion requests | legal@pranklab.io |
| General support | hello@pranklab.io |
| Postal | Stack Max LLC, 30 N Gould St, Ste R, Sheridan, Wyoming 82801, United States |
| Phone | +1 (702) 359-3841 |
We are a small company and we do not have a statutory Data Protection Officer. Privacy requests go to a person, not a queue, and we answer them within 30 days.
2. What we collect
| Category | What it is | How we get it |
|---|---|---|
| Account data | Email address, password hash, plan, account settings, language preference | You give it to us |
| Uploaded images | The photos you upload, including any faces in them, and any image metadata attached to the file | You give it to us |
| Generated results | The prank photos and videos produced from your uploads, and which template made them | Created by the Service |
| Billing data | Plan, credit balance, transaction history, billing country, last four digits and card brand. Full card numbers are handled by Stripe and never reach us. | You and Stripe |
| Waitlist data | Email address, sign-up source, whether you confirmed, and when | You give it to us |
| Usage and technical data | Pages viewed, templates opened, generation success and failure, IP address, browser and device type, timestamps, error logs | Collected automatically |
| Communications | Emails and reports you send us, including takedown and misuse reports | You give it to us |
We do not ask for and do not want your government ID, your health data, your precise location, or your contacts list. Please do not send them to us.
3. Face images — the part that matters most
A photo of a face is sensitive, and the law in several places treats it more strictly than ordinary data. Here is exactly what we do and do not do with it.
What we do: we send your uploaded image to an AI generation provider, which produces a new image or video from it, and we store the upload and the result in your library so you can download them again. That is the whole processing chain.
What we do not do:
- We do not run facial recognition or facial identification. We never try to determine who a person in a photo is.
- We do not create, store or compare faceprints, face templates, face geometry scans, or any other biometric identifier used to single out a specific individual.
- We do not match faces across accounts, build a face database, or link a face to a name, an account, or any external source.
- We do not sell, lease, trade or otherwise profit from biometric data, and we do not disclose it except to the providers listed in section 6.
- We do not use your uploads or results to train, fine-tune or improve any AI model, ours or anyone else's, and our agreements with AI providers require the same of them.
Because we do not process face images for the purpose of uniquely identifying a person, we do not consider them biometric data under Article 9 of the GDPR. We nevertheless treat them as sensitive: access is restricted, they are encrypted at rest and in transit, and they are deleted on request. Where consent is required for us to handle an image of you — including under Illinois BIPA, Texas CUBI, and similar US state laws — you give that consent by uploading, and you may withdraw it at any time by deleting the image or your account.
If a photo of you was uploaded by someone else without your permission, you do not need an account to do something about it. Email legal@pranklab.io and we will find it, remove it, and confirm back to you. See our takedown policy.
4. Why we use your data, and our legal basis
If the GDPR or UK GDPR applies to you, we must have a lawful basis for each use. These are ours.
| What we use it for | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and running your account | Account data | Performance of a contract (6(1)(b)) |
| Generating the prank you asked for | Uploaded images, generated results | Performance of a contract (6(1)(b)) |
| Storing your library so you can download results again | Uploads, results | Performance of a contract (6(1)(b)) |
| Taking payment and preventing payment fraud | Billing data | Contract (6(1)(b)) and legal obligation (6(1)(c)) |
| Keeping the Service secure, and investigating abuse or misuse reports | Usage data, uploads, results, communications | Legitimate interests (6(1)(f)) — protecting users and the Service |
| Fixing faults and improving reliability | Usage and technical data | Legitimate interests (6(1)(f)) — running a working product |
| Service emails: receipts, security notices, policy changes | Account data | Contract (6(1)(b)) and legal obligation (6(1)(c)) |
| Waitlist and launch announcements | Waitlist data | Consent (6(1)(a)) — withdraw any time via the unsubscribe link |
| Meeting tax, accounting and legal obligations | Billing data, communications | Legal obligation (6(1)(c)) |
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time (see section 10). Where we rely on consent, withdrawing it is as easy as giving it and does not affect what we did before you withdrew it.
5. What we never do with your data
- We do not sell personal data, and we never have.
- We do not "share" personal data for cross-context behavioural advertising, as California defines that term.
- We do not use your uploads or results to train AI models.
- We do not put your photos or results in a public gallery, in our marketing, or in advertising without asking you first and getting a yes.
- We do not profile you or make automated decisions that produce legal or similarly significant effects about you.
- We do not run advertising cookies. We do use Google Analytics and PostHog for usage measurement, error tracking, and privacy-masked session replay — see our Cookie Policy.
6. Who else processes your data
We use a small number of providers to run the Service. They act on our written instructions only, under contracts that include the data protection terms the GDPR requires, and they may not use your data for their own purposes.
| Provider | What they do | Data they process | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication and file storage | Account data, uploads, generated results, waitlist data | United States |
| Railway Corp. | Application hosting and server logs | Usage and technical data, IP addresses | United States |
| Stripe, Inc. | Payment processing, subscription billing, fraud prevention | Billing data, email address, card details (handled entirely by Stripe) | United States |
| AI generation provider | Produces the prank image or video from your upload | Uploaded images, generated results | United States |
| Email delivery provider | Sends transactional and waitlist email | Email address, message content | United States |
| Google LLC (Google Analytics) | Measures how visitors use the site (page views and related usage) | IP address (as processed by Google), device and browser type, pages viewed, approximate location, timestamps | United States |
| PostHog, Inc. | Product analytics, error tracking, and privacy-masked session replay | Device and browser type, pages viewed, product events, error details, approximate location, timestamps. Session replays mask form inputs and block images, video, and canvas so uploaded photos and generated results are not recorded. | United States |
We will name our AI generation and email providers on this page as soon as they are live, and we will update this table whenever a provider changes.
Beyond those providers, we disclose personal data only when we must: to comply with a law, court order or valid legal request; to enforce our Terms or Acceptable Use Policy; to protect the rights, safety or property of a user, a third party or us; or to a buyer if the business is sold, in which case we will tell you before your data moves and this policy continues to apply until you are notified otherwise.
7. International transfers
We are a United States company and our providers are in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to and processed in the US.
For those transfers we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where the UK GDPR applies, together with additional technical measures — encryption in transit and at rest, and access controls that limit who can see uploads. You can request a copy of the relevant transfer safeguards from legal@pranklab.io.
8. How long we keep things
| Data | Kept for |
|---|---|
| Uploaded images and generated results | Until you delete them, or 30 days after your account closes |
| Account data | For as long as your account is open, then deleted within 30 days of closure |
| Waitlist email addresses | Until you unsubscribe, or 24 months after sign-up if PrankLab has not launched |
| Billing and transaction records | 7 years from the transaction, to meet tax and accounting law |
| Server and security logs | Up to 12 months, then deleted automatically |
| Misuse reports, takedown notices and enforcement records | Up to 3 years, so we can recognise repeat offenders and defend legal claims |
| Records of accounts banned for serious violations | Retained as a minimal block record so a banned user cannot immediately return |
Deletion means deletion from live systems immediately and from encrypted backups as those backups age out, within 90 days. If a law requires us to keep something for longer — a tax record, or content subject to a live legal hold — we keep only that, and only for as long as we must.
9. How we protect it
- Everything is encrypted in transit (TLS) and at rest.
- Access to uploads and account data is limited to the few people who need it to run the Service, and is logged.
- Passwords are hashed, never stored in a readable form, and we cannot see them.
- Card details never touch our servers — Stripe handles them end to end.
No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify the relevant supervisory authority within 72 hours and tell you directly without undue delay, as the GDPR and applicable US state laws require.
10. Your rights
Wherever you live, you can ask us to show you your data, correct it, export it, or delete it. Under the GDPR and UK GDPR you specifically have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted (the right to be forgotten).
- Restriction — have us pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable format, or have it sent to another provider.
- Object — object to processing based on legitimate interests, including at any time.
- Withdraw consent — for anything we do on the basis of consent.
- Complain — lodge a complaint with your national data protection authority. We would rather you came to us first, but it is your right either way.
To exercise any of these, use your account settings where the option exists, or email legal@pranklab.io from the address on your account. We respond within 30 days, free of charge. We may ask you to confirm your identity before acting on a request about someone's personal data, and we will not charge you for that.
11. If you live in the United States
California, Virginia, Colorado, Connecticut, Utah, Texas and a growing list of other states give residents similar rights: to know what is collected, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of sale, sharing or targeted advertising.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but every other right above is available to you, and we honour them for residents of every US state, not only those with a law in force.
Californians may also designate an authorised agent to make a request on their behalf. We will never discriminate against you for exercising a privacy right: your plan, price and service stay exactly the same. Requests go to legal@pranklab.io.
13. Children
PrankLab is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we delete the account and its content promptly.
If you believe a person under 18 has given us data, email legal@pranklab.io and we will remove it. You must also never upload a photo of a child to PrankLab, whoever you are — see our Acceptable Use Policy.
14. Changes to this policy
When this policy changes we update the date at the top of the page. For changes that materially affect your rights or how we use your data, we email account holders at least 30 days before the change takes effect, and where the law requires consent we will ask for it rather than assume it.