Privacy
Privacy policy.
How Pico handles your projects, photos and support requests.
Projects stay on your device
Pico stores your project information, text, editing preferences and imported image copies in local app storage. Signing in does not upload or sync your projects or photos.
You can view and edit this information in Pico. Device backup settings may affect app data; Pico does not operate its own project backup service.
Optional Pico account
If you choose to sign in, Pico collects your email address and creates an internal user identifier. It also stores short-lived sign-in transaction records and 30-day session records so it can send a one-time sign-in link, authenticate your device and protect the service from misuse. Pico does not use this information for advertising, tracking or analytics.
The account service runs on Google Cloud, account records are stored with MongoDB Atlas, and Amazon Simple Email Service delivers sign-in email. These providers may process account information outside Australia under their own privacy and security terms.
You can sign out from Settings. You can also choose Delete account in Settings to permanently delete your account, sign-in transactions and server sessions. This does not delete projects or photos stored locally on your device. Expired sign-in transactions and sessions are also removed automatically.
Photos and exports
Pico uses the device image picker to import photos. It copies imported images into its app storage so they can remain available to your projects. When saving finished images, it requests photo-library permission. You can manage these permissions in your device settings.
When you share an export through another app, that app receives the file you choose to share and handles it under its own policies.
Deleting projects
Projects moved to Trash can be restored for 7 days. Expired projects are removed when Pico checks Trash on opening, resuming or while in use. Pico attempts to clean up imported files that are no longer referenced by a project.
Exports in Photos or another app are separate copies. Deleting a Pico project does not delete those copies. Export work you want to keep before removing Pico or changing devices.
Support messages
If you email steve@wahlu.com, Wahlu Labs Pty Ltd receives your email address, message and any attachments through Google Workspace so it can respond to your request. Share only the information needed to explain the issue.
Support messages are kept only while reasonably needed to respond, maintain support records and meet legal obligations. You can use the same address to request access to or correction of information sent to support, request deletion, or raise a privacy concern. Some requests may require identity verification.
Google may process support information outside Australia under its own privacy and security terms.
Service logs, analytics and this website
Pico version 1.0 contains no advertising, behavioural analytics or third-party crash-reporting service. Apple may provide diagnostics only when you choose to share them under your device and App Store settings.
The Pico website and account API are hosted on Google Cloud in the United States. Google Cloud may process basic connection and request information, such as IP address, date, requested page or API route, and device or browser details, to deliver, operate and secure the services. Ordinary request logs are retained for 30 days and are not used for advertising or behavioural analytics.
The website serves its fonts and images locally and has no analytics scripts, forms or application cookies.
Who is responsible?
Pico is published by Wahlu Labs Pty Ltd, an Australian company. For privacy questions, access or correction requests, deletion requests, or complaints, contact steve@wahlu.com.
We will review privacy complaints and respond within a reasonable time. If you are not satisfied, you may contact the Office of the Australian Information Commissioner.