Privacy Policy
Last updated: 8 September 2026
This page describes what PierNode collects when you use the PierNode API and dashboard, why it is collected, and what happens to it. It describes how the service actually works today rather than every use the law might permit; when the service changes, this page changes with it.
In this policy, PierNode, we and us mean the operator of the service published at piernode.com. You means the person or organisation using it.
What we collect
Account details
When you create an account we store your email address and display name. If you sign in with a password, only a hash of it is stored — never the password itself. If you register a passkey we store its public key, and if you enable two-factor authentication we store the secret needed to verify your codes. We also keep a record of your active sign-in sessions so you can review and revoke them.
API credentials
Each account has one API key. We store a hash of the key together with its first characters and last four digits, which is what lets the dashboard show it to you in masked form. We cannot recover the key itself — if you lose it, the only option is to create a new one.
What you send to the API
We store the prompts and parameters you submit, and any image you upload as input to an image-to-image or image-to-video request. Uploads go directly from your client to our object storage using a short-lived link that we issue for a location we choose.
What the API produces
Generated images and videos are stored in our object storage and served back to you through links that expire after a short period.
Payments and balance
We store your wallet balance and a ledger entry for every movement in or out of it, including what each charge or refund was for.
Payments are processed by Plisio, a cryptocurrency payment provider. You make the payment on Plisio's own pages; we receive the resulting status, the amount, and identifiers for the invoice and the transaction. We do not see or store card numbers, wallet keys, or any other payment credentials.
Technical logs
For each API call we record the method, path, status code, duration, a request identifier, the time, the account, and which key was used. We do not log request or response bodies.
Support messages
When you send us a message through the help dialog or the contact page, we store the topic you chose, the address you asked us to reply to, the message itself, and — if you were signed in — which account it came from.
What we do not do
We do not run behavioural analytics or advertising trackers on our website or in the dashboard. We do not sell personal data, and we do not share it for advertising.
Why we hold it
- To run the service — authenticate you, execute your requests, return the results, and keep your balance correct.
- To bill accurately — reserve, charge and refund the right amounts, and be able to show you why.
- To keep the service working and honest — investigate failures, detect abuse, and reconcile payments that did not complete cleanly.
- To reply to you — answer support messages, and send transactional email such as sign-in links and verification.
Cookies
We use a session cookie to keep you signed in, and small preference cookies remembering your chosen language and colour theme. There are no advertising or tracking cookies.
Who else processes your data
We rely on a small number of service providers, each doing one job:
- Vercel — hosts the website and the application.
- Cloudflare R2 — stores uploaded and generated files.
- Resend — delivers our transactional email.
- Plisio — processes cryptocurrency payments.
- Managed infrastructure providers host our database, cache and background workers.
Prompts and input images are passed to the model-serving infrastructure that performs the generation. If you need the current, complete list of providers for a review, ask us and we will send it.
How long we keep things
Account records, wallet ledger entries and payment records are kept for as long as the account exists, because they are the record of what you were charged.
Uploads that are never completed are discarded automatically once their upload window closes. Generated results and their inputs are kept while your account exists so you can retrieve them.
Deleting your account removes the account, its API key, its uploads and its generated results. Deletion cannot be undone, so download anything you still need first.
Your choices
You can change your email address and display name, add or remove passkeys, turn two-factor authentication on or off, revoke sessions, replace your API key, and delete your account — all from the dashboard, without asking us.
Depending on where you live you may also have the right to ask for a copy of your data, to have it corrected, to have it erased, or to object to some of the processing described above. Write to us and we will act on it.
Security
Passwords are stored only as hashes and API keys only as hashes. Access to generated files is through links that expire; the files are not publicly addressable. Payment credentials never reach us.
No service can promise it will never be breached. What we can say is what we hold, which is described above — the less of it there is, the less there is to lose.
Children
PierNode is not intended for anyone under 16, and we do not knowingly create accounts for them.
Changes
If this policy changes we update the date at the top. Changes that materially affect you will be announced by email to the address on your account.
Contact
Questions about this policy, or a request about your data: support@piernode.com.