L1.01
Who this policy covers
This policy applies to everyone who interacts with Pixelnode, Inc. (“Pixelnode”, “we”, “us”): visitors to pixelnode.ai, customers of our private beta, capture participants — the experts whose work sessions are recorded through the Capture Suite — and organizations running Pixelnode inside their own infrastructure.
Where an enterprise deploys Pixelnode on-premise, that organization is the data controller for capture data produced inside its walls, and its own privacy notices apply alongside this one. This policy describes what Pixelnode itself does with data we process.
- Site visitors — people browsing pixelnode.ai
- Beta customers — labs, talent platforms, and enterprises using the platform
- Capture participants — experts who record work sessions
- Enterprise deployments — on-premise installations operated by customers
L1.02
Consent-first capture
Nothing is recorded without explicit, informed, session-level consent. Before any capture begins, the participant is shown what will be recorded — which screens, which input streams, which applications — and must actively start the session. There is no passive or background recording mode anywhere in the product.
Recording state is always visible. An active session displays a persistent recording indicator, and the participant can pause or stop capture at any moment. Consent is revocable: a participant may withdraw a completed session, and we remove it from the capture store and propagate the removal to datasets still under our control, as described in the retention section below.
L1.03
Data we collect
Capture sessions are the heart of the product, and they are collected only with the consent described above. A session may include screen video, input events (cursor, keyboard timing, stylus, and peripheral signals), spoken rationale where the participant enables audio, application events, file artifacts and intermediate versions, and environment state such as restore points.
Separately from capture, we collect account data (name, work email, organization, authentication records) needed to operate the platform, and limited site analytics described in the cookies section. We do not collect data from participants’ devices outside an active, consented session.
L1.04
Window-level privacy and redaction
Capture is scoped, not total. Participants and administrators can exclude specific applications, windows, or screen regions before a session starts; excluded surfaces are never written to the capture stream — they are not recorded-then-hidden, they are simply not recorded.
After capture, sessions pass through a redaction pipeline before they can enter any dataset. Automated detection flags credentials, personal messages, financial details, and other sensitive material for masking or removal, and flagged segments are reviewed under access controls. Automated privacy modes can also blank capture whenever a designated application gains focus.
L1.05
How session data is used
Captured sessions are used for exactly what participants consent to: constructing structured training datasets, authoring and verifying RL environments, and the quality-assurance work required to do both — session review, structuring, labeling, and verifier evaluation.
We do not use capture data for advertising, we do not build advertising or behavioral profiles of participants, and we do not sell personal data. Account data is used to operate, secure, and support the service, and to communicate with you about it.
L1.06
Legal bases for processing
Where data-protection law such as the GDPR applies, we process capture data on the basis of consent — the session-level consent described above. We process account data as necessary to perform our contract with you or your organization, and we process security logs and site analytics on the basis of our legitimate interest in operating a safe, functioning service.
Where we rely on consent, withdrawing it does not affect the lawfulness of processing that happened before withdrawal, but it does stop further use as described in the retention section.
L1.08
Data residency and on-premise deployments
Customers can pin capture and dataset storage to a geographic region, and cross-region transfers happen only under recognized transfer mechanisms.
For on-premise deployments, capture data never leaves the customer’s infrastructure: recording, storage, redaction, and fine-tuning all run inside the customer’s walls. Pixelnode receives operational telemetry only if the customer enables it, and never receives the underlying capture content.
L1.09
Retention and deletion
Raw capture sessions are retained for the period stated at consent time, then deleted or reduced to the structured dataset form the participant agreed to. Account data is kept while your account is active and for a limited period afterwards as required for legal and security purposes.
When a participant withdraws a session or requests deletion, we remove it from our capture store and propagate the removal to every dataset version still under our control. Where a dataset has already been delivered to a customer, our contracts require the customer to honor propagated removals in subsequent dataset versions.
L1.10
Security
Capture data is encrypted in transit and at rest. Access to raw sessions is restricted to personnel who need it for the processing described in this policy, gated by role-based access controls and hardware-backed authentication, and every access is written to an audit log.
Capture environments and training environments are isolated from one another, and from the open internet, by default. We test our controls continuously and treat any confirmed incident affecting personal data as notifiable to affected users and regulators as the law requires.
L1.11
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, restrict or object to certain processing, and withdraw consent at any time. Capture participants can exercise session-level rights — review, withdrawal, deletion — directly from the Capture Suite, or by writing to us.
To exercise any right, contact privacy@pixelnode.ai. We respond within the timelines the applicable law sets, and we will never penalize you for exercising a right. If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority.
L1.13
Children
Pixelnode is a professional tool. Our services are not directed at anyone under 18, capture participants must be adults with legal capacity to consent, and we do not knowingly collect data from minors. If you believe a minor’s data has reached us, contact privacy@pixelnode.ai and we will delete it.
L1.14
Changes and contact
We version this policy, and material changes are announced to account holders and capture participants before they take effect — a change never retroactively expands what an already-given consent covers.
Questions, requests, or concerns: privacy@pixelnode.ai. Pixelnode, Inc. — postal address available on request while our offices are being finalized during the private beta.