Privacy Policy
Last updated: May 9, 2026
1. Who we are
Visual Sandbox is a pay-per-use AI media platform operated from Ontario, Canada. This policy explains what personal information we collect when you use Visual Sandbox, how we use it, and what your rights are. Read alongside our Terms of Service. It’s written to align with the federal Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s Anti-Spam Legislation (CASL), and Quebec’s Act respecting the protection of personal information in the private sector (Law 25). To reach our Privacy Officer, write to [email protected].
2. What we collect
- Account info: email, password hash, optional name and avatar.
- Billing: handled by our payment processor. We store the customer ID, transaction records, and last 4 digits of card. We never see full card numbers.
- Usage: prompts, generation parameters, generated media, jobs, sandboxes, and credit transactions you create.
- Telemetry and analytics: IP address, user agent, referrer, page views, click events, sign-up and purchase conversions, and errors. Used to keep the service running, debug issues, measure marketing performance, and improve the product.
- Advertising signals: if our advertising pixels are loaded (see “Cookies and similar technologies” below), the ad network may receive a cookie ID, hashed email, page URL, and event type (e.g. “signed up”, “purchased credits”) to help us measure ad performance and build retargeting audiences.
3. How we use it
- Run the service (auth, generation, billing, support).
- Send transactional email (receipts, password resets, email verification, security notices). Under CASL, transactional email doesn’t need separate consent.
- Send product updates and marketing email only if you’ve given express CASL consent. You can unsubscribe in one click from any of those emails.
- Debug errors, prevent abuse, and improve the product.
- Comply with legal obligations.
We don’t sell your personal information for money. We do share limited analytics and advertising signals with the providers listed below, in line with the “Cookies and similar technologies” section. Some privacy laws (for example, California’s CCPA and Quebec’s Law 25) treat that kind of sharing as a “sale” or “cross-context behavioural advertising”; if you’re in one of those jurisdictions, you can opt out at any time by emailing [email protected] or refusing non-essential cookies in any consent mechanism we provide. We don’t train AI models on your prompts or outputs.
4. Who we share it with
We share personal information only with sub-processors who help us run the service, in the following categories:
- Payment processor — payments and billing.
- AI inference providers — the prompts and inputs you submit are sent to whichever provider runs your generation.
- Cloud storage — storage and delivery of generated media.
- Error monitoring — tracking and debugging service errors.
- Analytics provider — measuring usage, conversions, and product improvements.
- Advertising networks — for example Meta, Google, X, Reddit, TikTok, or LinkedIn — to measure ad performance and build retargeting audiences. Only loaded after you consent in jurisdictions where consent is required.
- Email provider — transactional and consented marketing email.
- Law enforcement or regulators when we’re legally required.
A current list of named sub-processors is available on request from [email protected].
5. Where your data lives (cross-border transfer)
Our application servers are in the European Union. Generated media is served from a global content-delivery network. Some of our payment, AI inference, error-monitoring, and email providers are based in or process data in the United States and other countries. By using Visual Sandbox you consent to your personal information being processed and stored outside of Canada, where it may be subject to the laws of those countries (including lawful access by foreign authorities). Quebec residents: this transfer is necessary to provide the service.
6. How long we keep it
We keep account data while your account is active. Generated media stays until you delete it or close your account. Billing and tax records are kept for 7 years to meet Canadian tax obligations. Application logs are kept for 30 days.
7. Your rights
Under PIPEDA and Quebec Law 25 you can ask us to:
- Access the personal information we hold about you.
- Correct it if it’s wrong.
- Delete it, port it to another service, or stop processing it, where the law allows.
- Withdraw consent for marketing email (one-click unsubscribe) or other optional processing.
Email [email protected] with your request. We’ll respond within 30 days. If you’re not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information.
8. Automated decisions
We don’t use your personal information to make automated decisions that produce legal or similarly significant effects on you within the meaning of Quebec’s Law 25. Generation runs are triggered by you, not by automated profiling. If that ever changes, we’ll update this policy and notify you in advance.
9. If you don’t want to share certain information
Most of what we collect is needed to run the service. If you don’t provide an email and password (or sign in with a third party), we can’t create an account for you. If you don’t provide billing information, you can’t buy credits. You can always opt out of marketing email and still keep using Visual Sandbox.
10. Deleting your account
You can delete your account anytime by emailing [email protected] from your account email. We’ll delete your account, your generated media, and your prompts within 30 days, except for billing records we’re required to keep for tax and accounting purposes (up to 7 years), and minimal logs needed for fraud prevention. Unused credits can be refunded on request before deletion, minus any payment-processor fees.
11. Security
We use HTTPS everywhere, hashed passwords, encrypted API keys, and access controls on production. No method of transmission or storage is 100% secure; if a breach involves a real risk of significant harm, we’ll notify you and the Privacy Commissioner as required by PIPEDA.
12. Cookies and similar technologies
We use cookies and similar technologies (local storage, pixels) in the following categories:
- Essential. Needed to log you in, keep you logged in, and protect against cross-site request forgery. The service won’t work without these.
- Analytics. Help us understand how the service is used (page views, conversion funnels, errors) so we can improve it. We use privacy-friendly analytics where possible.
- Advertising and marketing. We may use third-party advertising pixels (for example, from Meta, Google, X, Reddit, TikTok, or LinkedIn) to measure the performance of our ads, build audiences for retargeting, and reach users who might be interested in Visual Sandbox. These pixels can set or read cookies on your device and share limited data (such as a hashed email or browsing event) with the ad network.
You can refuse non-essential cookies at any time through your browser settings, your device’s ad-tracking controls, or any consent mechanism we provide. Refusing analytics or advertising cookies won’t affect your ability to use Visual Sandbox. If you’re in Quebec, the European Union, the United Kingdom, or another jurisdiction that requires opt-in for non-essential cookies, we’ll only set them after you consent through the appropriate mechanism.
13. Children
Visual Sandbox is not intended for users under 13. We don’t knowingly collect personal information from children. If you believe a child has given us their information, email [email protected] and we’ll delete it.
14. Changes to this policy
If we make material changes we’ll notify you by email or in-app notice before the change takes effect. The “last updated” date at the top of this page reflects the current version.
15. Contact
Email [email protected] with any privacy questions, access requests, or complaints. Visual Sandbox is operated from Ontario, Canada.
Questions? Email [email protected].