Effective 13 September 2026 · Last updated 13 September 2026
The short version: PixelThat collects nothing. It has no account, no analytics, no advertising identifier and no networking code of any kind. Your photos are read, turned into pixel art and written back, entirely on your device. Nothing is sent to CS42 or to anyone else, because the app cannot send anything anywhere.
This policy covers the PixelThat app for iPhone and iPad, published by CS42 ("we", "us"). It does not cover the CS42 website, which has its own privacy policy.
None. We collect no personal data, no usage data, no diagnostics and no identifiers. In App Store terms, the app's privacy label is Data Not Collected.
This is not a policy choice that could quietly change in the background: the app contains no code for making network requests. You can put your device in airplane mode and every feature still works.
When you pick a photo, iOS hands the app a copy of that one image. It is decoded in memory, framed, cut out and turned into pixel art on the device's own processor, using Apple's Vision framework for face detection and subject separation. The photo is never uploaded, never shared and never written anywhere except where you ask.
The app requests access to your photo library only when you tap to choose a picture. If you use the limited selection iOS offers, the app sees only what you select.
When you save, share or keep a result, the app stores that pixel-art picture and the settings that made it in its own private storage on your device (the app's Application Support folder). This is how the Recents strip can put old settings back on a new photo.
Saving a finished picture needs add-only permission to your photo library. The app can add the picture you asked it to save; it cannot read your library through that permission.
The app does not request the camera, microphone, location, contacts, calendars, health data, Bluetooth, local network or notifications.
None. The app does not contact CS42, an analytics provider, an advertising network, a crash reporter or any other service. No content delivery network, no remote configuration, no fonts fetched at runtime.
The app bundles no third-party SDKs. It uses only Apple's own frameworks, which run on the device. Because nothing is collected, nothing is shared with anyone.
The app does not track you as Apple's App Tracking Transparency defines it, and it never presents a tracking permission prompt, because there is nothing to track. No advertising identifier is read or used.
PixelThat is rated 4+ and is safe for children to use. It collects no data from anyone, of any age, so it does not knowingly or unknowingly collect personal information from children under 13 (or the equivalent age in your country).
We hold nothing, so there is nothing for us to retain or delete. What the app stores stays on your device until you remove it or delete the app.
Privacy laws such as the GDPR, the UK GDPR and the CCPA give you rights to access, correct, port and delete personal data held about you. We hold no personal data about you, so there is nothing to produce or erase. You are welcome to write to hello@cs42.org to confirm this, and we will answer.
We do not sell or share personal information, because we do not have any.
Everything the app stores lives inside its iOS sandbox, protected by the device's own encryption and file protection. Nothing is transmitted, so there is no transport to intercept.
If the app ever changes in a way that affects this policy, the new version is posted here with a new date, and the change is described in the App Store release notes. Material changes will not be applied retroactively to data already on your device.
Write to CS42 at hello@cs42.org. We usually answer within a day or two.