top of page

Privacy

Last updated:

Sep 25, 2026

Magipic.ai
Last updated: September 25, 2026

Magipic.ai ("Magipic", "we", "us", "our") provides AI photo and video experiences for events. This policy explains, in plain language, what personal data we handle, why, who we share it with, how long we keep it, and your rights. It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR, Israel's Protection of Privacy Law, and Quebec's Act respecting the protection of personal information in the private sector (Law 25).

1. Who We Are and How to Reach Us

Magipic.ai is operated by Magipic AI, LLC (United States) and Magipic AI (Israel).

Privacy contact: [email protected]
Person in charge of the protection of personal information (Quebec Law 25) and privacy lead: Felicity Kay, Co-founder, [email protected]

We have not appointed a Data Protection Officer because our processing does not meet the Article 37 GDPR thresholds.

2. Two Kinds of People, Two Roles

Account holders are the businesses and individuals who sign up for Magipic (photobooth companies, event agencies, brands, developers using our API). For their account data, Magipic is the data controller.

Guests are the people who take part in an event experience run by an account holder: they take a photo, receive an AI image or video, and sometimes leave a name or email to get their result. For guest data, the account holder (the event organizer or their client) is the data controller and Magipic is the data processor. We process guest data only to deliver the experience the account holder has configured, and only on their instructions. The account holder is responsible for informing guests and for obtaining any consent required by law.

3. What Personal Data We Collect

From account holders: name, email address, company, login credentials, billing and transaction data (handled by our payment providers; we do not store full card numbers), support messages, and usage data (IP address, browser and device type, session logs).

From guests: the photo or short video they capture, the AI image or video generated from it, and, where the account holder has enabled it, an email address to deliver the result. If the account holder runs a lead capture form at the event, the fields they configure (for example name, company or job title). We do not ask guests for anything else.

From website visitors: cookie and analytics data as described in our Cookie Policy.

4. Why We Process It and on What Legal Basis

To run the platform and deliver AI results to guests (guest photos, outputs, delivery details)
Legal basis: We act as processor on the account holder's instructions (Article 28 GDPR). The account holder's own basis is usually consent or legitimate interest.

To provide and manage accounts, API access and credits (account data)
Legal basis: Performance of a contract

To process payments and issue invoices (billing data)
Legal basis: Performance of a contract, legal obligation

To keep the platform secure, prevent abuse and fix bugs (usage data, logs and technical metadata only)
Legal basis: Legitimate interests

To improve the product (aggregated, anonymized usage statistics only. Never guest photos, videos or generated outputs)
Legal basis: Legitimate interests

To provide support and service communications (contact data, support messages)
Legal basis: Legitimate interests, performance of a contract

To send marketing emails to account holders (email address)
Legal basis: Consent, which you can withdraw at any time

5. AI Models and Training: Our Commitment

Notwithstanding anything else in this policy or in our Terms:

Guest photographs, videos and the images or videos we generate from them are never used to develop, train, fine-tune, evaluate or improve any machine learning or artificial intelligence model, whether the model is ours or a third party's.

We do not sell, license or share guest content for those purposes, and we do not permit our AI providers to do so. Guest content is used for one thing only: generating the result the guest asked for and delivering it to them.

The same applies to any photos or videos account holders upload as samples or test content, unless the account holder explicitly agrees otherwise in writing.

6. Biometric Data: What We Do and Do Not Do

Our AI filters transform a photo into a stylized image or video. To do that, the AI model needs to see the face in the photo. Here is exactly what that means:

  • We do not identify or verify anyone's identity from their face.

  • We do not create, extract or store facial templates, faceprints, face embeddings or any other biometric identifier.

  • We do not build or maintain a biometric database, and we do not compare faces across photos, events or accounts.

  • We do not use facial recognition to tag, search for or profile individuals.

The photo is used as a transient input to the image or video model and is not analysed for the purpose of uniquely identifying a person. We run no face detection, face landmarking or face matching of our own, before, during or after generation.

On that basis we do not process special category (biometric) data within the meaning of Article 9 GDPR, and the biometric database disclosure requirement under Quebec law does not apply to our processing. Account holders who plan to use our platform for anything that would change this must contact us first.

7. Who We Share Personal Data With

We use a small number of service providers, each bound by a written data processing agreement and permitted to use data only to provide its service to us. By category:

  • Cloud infrastructure and AI generation: our cloud and API providers (for image and video generation, and for storing photos and outputs while an event gallery is live), located in the United States, plus a small number of specialist AI model providers used for certain video filters. Every AI provider we use is bound by terms that prohibit using our customers' content to train or improve models, and receives guest content only for the moment of generation.

  • Application hosting and delivery: a hosting provider for our application and API, and a transactional email provider that sends guests their result when they ask for it by email. Both located in the United States.

  • Payments: PCI-compliant payment processors. We never store full card numbers.

  • Account communications and internal tools: email marketing, automation, website, support and analytics providers. None of these receive guest photos or outputs.

Business clients can request our full sub-processor list, with locations and contract terms, under a Data Processing Agreement (see Section 14).

About our cloud and API providers. Our AI generation runs on our cloud and API providers' enterprise services under their standard terms and data processing addenda. These terms state that the provider will not use customer data to train or fine-tune any AI/ML model without the customer's prior permission or instruction. We have not given, and will not give, that permission. We have no separate agreement with any provider that changes these terms. Under the standard terms, a provider may temporarily log prompts for abuse monitoring and cache inputs and outputs in memory for up to 24 hours to serve requests; this data is isolated to our account and is not used for training.

Developers and partners who access our AI generation through API credentials we issue are covered by the same provider terms and the same commitment in Section 5.

Where a specific video filter runs on another AI provider, that provider is named in Annex 2 of our Data Processing Agreement, together with its no-training and retention terms.

We do not sell personal data and we do not share guest content with advertisers, data brokers or anyone outside these categories. We may disclose data if required by law or to protect our rights, and we will notify the affected account holder where we are permitted to.

8. International Transfers

Magipic operates from Israel and the United States and our providers process data in the United States and the European Union. For personal data from the EEA and the UK, transfers to Israel are covered by the EU and UK adequacy decisions; transfers to the United States rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses (and the UK Addendum). For personal data from Quebec, please note that guest photos and outputs are processed outside Quebec, in the United States; account holders should reflect this in their own privacy notices and assessments.

9. How Long We Keep Data

  • Guest photos, generated images and videos, event galleries: deleted automatically 30 days after the event ends. Account holders can request earlier deletion at any time, and we delete within 7 days of a verified request.

  • Guest email used to deliver a result, and lead capture entries: deleted with the guest's photo and result, unless the account holder has already exported them.

  • Account data: kept while the account is active, deleted within 30 days of account closure, except records we must keep for tax and accounting purposes (up to 7 years).

  • Support messages: 24 months.

  • Usage logs and security logs: up to 12 months.

  • Backups: encrypted, rotated and overwritten within 30 days.

Nothing is kept for training, research or product development.

10. Your Rights

If you are in the EEA or UK you can ask us to access, correct, delete, restrict or export your personal data, object to processing based on legitimate interests, and withdraw consent at any time. You can also complain to your data protection authority. In Quebec you have the right to access, rectify and request deletion (de-indexing) of your personal information, and to complain to the Commission d'accès à l'information. Similar rights apply under other laws.

Guests: because the event organizer is the controller of your data, the fastest route is to contact them. You can also write to us at [email protected] and we will act on your request directly where we can, and pass it to the organizer where we must. We respond within 30 days.

We will never ask for more data than we need to verify who you are.

11. Children

Accounts are for people aged 18 and over. Our event experiences are not directed at children under 16, but children may take part in events run by our account holders (for example a family day). In that case the event organizer is responsible for obtaining parental or guardian consent where the law requires it. If we learn that a child's photo has been processed without the required consent, we delete it.

12. Automated Decision-Making

We use AI to generate images and videos from the photo a guest provides. We do not make any automated decisions that produce legal or similarly significant effects on anyone, and we do not profile guests or account holders.

13. Security

We protect personal data with encryption in transit (TLS) and at rest, access controls and least-privilege permissions for our team and contractors, separate credentials per client integration, and secure deletion at the end of the retention period. If we become aware of a personal data breach that affects an account holder's data, we notify that account holder without undue delay and, where reasonably practicable, within 24 hours of confirming it, so they can meet their own notification duties (72 hours under GDPR, "promptly" under Quebec Law 25).

14. Data Processing Agreement

Business clients who need a signed Data Processing Agreement (GDPR Article 28, UK GDPR, Quebec Law 25 service-provider contract) can request one at [email protected]. Our standard DPA includes the commitments in Sections 5, 6, 9 and 13 of this policy and the current sub-processor list. See also our Data Processing & GDPR page.

15. Changes to This Policy

We will post any changes here and update the date at the top. If a change materially reduces your rights or changes how we use guest content, we will notify account holders by email at least 14 days before it takes effect. Continued use after that date means you accept the updated policy.

bottom of page