Privacy & Trust Center
Privacy Policy
Transparency and user trust are core to Pack My Tools. Learn how we protect your data, secure your AI prompts, and safeguard your creative assets.
Effective Date: January 1, 2026 • GDPR & CCPA Compliant
1. Overview & Commitment
Pack My Tools ("we", "us", "our") operates a multi-tool AI workspace used by individuals, creators, and businesses worldwide. This Privacy Policy explains what data we collect, why we collect it, how it is protected, and the rights you have over it.
We are committed to full compliance with international data protection frameworks, including the EU General Data Protection Regulation (GDPR), the UK Data Protection Act, the California Consumer Privacy Act (CCPA), and the Brazilian LGPD.
By using our platform, you agree to the practices described in this policy. If you do not agree, please discontinue use of the service.
Privacy Protections
We never sell, rent, or trade your personal data.
Your prompts, uploads, and generated content remain yours — we claim no ownership over them.
2. Information We Collect
We collect only the information required to operate the platform, deliver AI tools, and keep your account secure.
• Account Information: Name, email address, hashed password, profile avatar, and account preferences.
• Billing Information: Subscription tier, payment history, and last four digits of the payment method. Full card numbers are handled exclusively by our PCI-DSS-compliant payment processors and never touch our servers.
• User Content: Text prompts, uploaded documents, images, and audio you submit when generating outputs. This content is stored under your account so you can revisit past generations.
• Usage Data: Token consumption, feature usage, timestamps, and error logs used for billing accuracy and product reliability.
• Technical Data: IP address, browser and device type, operating system, referring URLs, and approximate location derived from IP (country/region only).
• Support Communications: Emails, live chat transcripts, and support tickets you send us.
Privacy Protections
Payment card data is processed by Stripe and PayPal under their PCI-DSS Level 1 certifications. We never see or store full card numbers.
We do not collect biometric data, precise GPS location, or data from your device's camera or microphone without explicit permission.
3. AI Model Training & Data Isolation
We understand that data privacy around AI model training is one of the most important concerns for users of AI platforms. Here is exactly what happens to your data:
1. Your Content Is Not Used for Training. Prompts, uploads, and generated outputs on paid plans are never used to train, fine-tune, or improve public AI models — not ours and not our providers'.
2. Third-Party Frontier Models. When you use tools powered by external providers (OpenAI, Anthropic, Google Gemini, and similar), your input is transmitted only to generate the specific output you requested. These providers operate under enterprise non-training agreements that contractually prohibit them from training models on your data.
3. Enterprise Isolation. Enterprise workspaces operate in dedicated cloud environments with zero-data-retention (ZDR) settings on every provider endpoint.
4. No Cross-User Leakage. Your generations are isolated to your account. Other users cannot access, view, or infer the contents of your prompts or outputs.
Privacy Protections
Zero-data-retention (ZDR) endpoints are enforced for all paid tiers — your prompts are discarded immediately after generation.
We do not build profiles of you for advertising or share your content with data brokers.
4. How We Use Your Information
We use your information strictly for the following purposes:
• Service Delivery: To authenticate your account, route requests to the correct AI model, and return generated content to you.
• Token Accounting: To calculate token usage in real time and deduct balances accurately after each generation.
• Billing & Invoicing: To process subscription payments, issue receipts, and handle payment disputes.
• Security & Fraud Prevention: To detect anomalous activity, block abusive automated traffic, and prevent account takeover.
• Product Improvement: To understand which tools are used most, identify performance bottlenecks, and fix bugs. This analysis uses aggregated, anonymized data.
• Transactional Communications: To send password resets, security alerts, billing receipts, and important product updates.
• Optional Marketing: To send product announcements or promotional offers — only if you opted in. You can unsubscribe at any time.
Privacy Protections
You can disable all non-essential communications from Account Settings → Notifications.
We never use your personal data for automated decision-making that produces legal or similarly significant effects.
6. Data Sharing & Third-Party Vendors
We share your information only with service providers necessary to operate the platform. Every vendor is contractually bound by a Data Processing Agreement (DPA).
• Cloud Infrastructure: Vercel (hosting), Supabase (database), and AWS (file storage and backups).
• AI Model Providers: OpenAI, Anthropic, Google Cloud — used only when you invoke tools powered by those models.
• Payment Processors: Stripe, PayPal, Flutterwave, Razorpay, and Paystack for payment execution.
• Email Delivery: Transactional email providers used to send password resets, receipts, and verification links.
We do not sell your personal data to any third party, under any circumstances. We do not share your data with advertising networks, data brokers, or analytics resellers.
Privacy Protections
All vendors hold SOC 2 Type II and/or ISO 27001 certifications.
We disclose data to law enforcement only when legally compelled by a valid court order, subpoena, or equivalent legal process.
7. Your Rights & Data Controls
Depending on your jurisdiction, you have the following rights over your personal data:
• Right to Access: Request a full copy of the personal data we hold about you.
• Right to Rectification: Correct any inaccurate or outdated information in your profile.
• Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your account and all associated content.
• Right to Data Portability: Export your prompts, generations, and account metadata in machine-readable JSON or CSV format.
• Right to Restrict Processing: Ask us to limit how we use your data while a dispute is investigated.
• Right to Object: Opt out of marketing communications or any processing based on legitimate interest.
• Right to Non-Discrimination: Exercise your privacy rights without losing access to the service.
To exercise any of these rights, use the account tools or contact our Data Protection Officer at the email listed below. We respond to all verified requests within 30 days.
Privacy Protections
Account deletion is available immediately in Account Settings → Security → Delete Account. All personal data is purged within 30 days.
Export your content at any time via Account Settings → Data Export.
8. Security, Retention & International Transfers
We protect your data using industry-standard security controls and continuously audit our infrastructure.
• Encryption in Transit: All traffic is encrypted using TLS 1.3.
• Encryption at Rest: Databases, backups, and file storage are encrypted with AES-256.
• Authentication Security: Passwords are hashed with bcrypt. Optional 2FA, login attempt throttling, and session expiry controls are provided.
• Infrastructure Monitoring: Automated vulnerability scanning, log monitoring, and regular penetration testing.
• Incident Response: Documented breach notification procedures. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours.
Data Retention: We retain account data for as long as your account is active. After deletion, personal data is permanently scrubbed within 30 days. Billing records are kept for 7 years to comply with tax and financial regulations.
International Transfers: Your data may be processed in the United States, European Union, or other regions where our vendors operate. All transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards.
Privacy Protections
All backups are encrypted with AES-256 and stored in geographically redundant locations.
We never store plaintext passwords, full card numbers, or security answers.