Trust at Pixbun
Privacy
What Pixbun processes
When you generate an image, Pixbun sends your prompt, style, aspect ratio, and a browser-created session identifier to the Pixbun server. The server sends the prepared prompt and ratio to BytePlus ModelArk to create the image.
Pixbun uses your IP address to enforce the daily quota and bind a generation session to one client. SQLite stores only a one-way SHA-256 hash of that address for quota and session records, not the plain address.
Quota responses include the next UTC reset instant. The browser formats that instant in your local time and, while an exhausted page remains open, uses one page-local timer to refresh the authoritative quota status at that boundary. The reset instant and timer add no browser storage, account identifier, analytics event, or client-side quota decision.
Images and sharing
Generation metadata and watermarked image files are stored on Pixbun’s server. A generation is private by default and is excluded from Explore, public image pages, and the sitemap until you choose Share.
Sharing publishes the image, prompt, style, ratio, and timestamps at a public URL. Before first publication, Pixbun asks you to confirm that the image and prompt become public and that saved copies cannot be recalled. The browser that created the image can later choose Unpublish while it still holds the private management capability in local History.
Publish remaining applies that same disclosure and per-image authorization to every eligible private image in the current batch. Each confirmed image receives its own public page; Pixbun creates no batch URL and copies no link. If a request result is unconfirmed, the local image and management capability remain available for an idempotent retry.
Unpublish removes the generation from Explore, its public image page, the public API, and the sitemap. It cannot recall links, image URLs, screenshots, or copies that other people may already have saved.
Unpublish public applies that same per-image authorization to every manageable public image in the current batch. Confirmed images become private one at a time; private, failed, and capability-lost public images are skipped. If a response is unconfirmed, the browser keeps the image marked public with its management capability so the idempotent operation can be retried.
History separately offers Unpublish all public for every manageable public record in the complete retained History, regardless of its current search or All/Shared/Saved filter. Confirmed records leave Explore, their public pages, the public API, and the sitemap without deleting stored images or changing quota; unconfirmed records remain locally public for retry, and public records whose creator capability was lost are not changed.
The originating browser can also choose Delete permanently. Pixbun then removes the stored original and derived images and clears the prompt, style, ratio, image links, and public state. A content-free tombstone containing the generation ID, session ID, slot index, and creation time remains to enforce quota and prevent a deleted slot from being generated again.
History also keeps Clear from this browser separate from Delete all from Pixbun. The permanent action confirms the complete eligible History count, deletes those creations one at a time, removes successful items from local and public views, and keeps any failed records and private management capabilities in History so you can retry them.
Delete cannot recall screenshots, downloads, copied prompts, third-party copies, or files already retained in browser or network caches. It is not a quota refund and cannot be undone through Pixbun.
Data stored in your browser
History, private sharing-management capabilities, saved-image identifiers, minimum Saved Explore display snapshots (image links, prompts, style, and aspect ratio), theme, and language preferences are stored in your browser using localStorage. History keeps the newest 50 records, all available through local search and All/Shared/Saved filtering; Pixbun does not send those records, search terms, filters, favorite identifiers, Saved snapshots, or capabilities to the server. Pixbun does not treat the public gallery as your personal History.
History keeps each run’s selected 1/2/4 image target with its prompt and options. Slot labels use that target, target-inconsistent records remain separate, and a run download appears only when the complete target contains at least two locally retained valid slots. Older records without a target retain four-image behavior. These checks derive presentation and download eligibility only; they do not upload, delete, or rewrite History.
Pixbun also keeps the most recently edited non-empty composer prompt, style, aspect ratio, and 1/2/4 image target as one browser-local draft. It restores that draft only when you open the homepage without a prompt, style, or ratio link; a creation link uses its own values with the four-image default and does not combine them with the private draft. Clearing the prompt removes the stored draft. The draft is not included in a History backup and is not sent to Pixbun or BytePlus until you choose Generate. Browser storage can be unavailable or cleared, so this is a recovery convenience rather than guaranteed storage.
Before Generate, Re-run, or Retry can replace the oldest retained records, Pixbun asks whether to continue, states the maximum number at risk, and points to the backup option. Cancelling starts no generation or retry. Continuing may remove the local capability needed to Share, Unpublish, or Delete an affected creation; it does not delete that creation from Pixbun’s server.
Pixbun asks for confirmation before clearing a non-empty History and warns that you may lose the ability to Share, Unpublish, or Delete those creations. Confirming removes the local History records but does not delete server files or recall public copies. You can recover cleared records and capabilities only if you exported a versioned History backup first. New version 2 exports also include browser-local Saved identifiers and minimum Saved display snapshots, while valid version 1 History-only files remain restorable. Export and import happen locally and the backup contents are not sent to Pixbun. The file includes prompts, image links, style, aspect-ratio and image-count details, private sharing-management capabilities, and Saved identifiers, so protect it like a password and import it only on a device you trust.
Aggregate product analytics
Every Pixbun HTTP response receives an opaque request reference that the server writes into the matching access-log row. A generation failure may show that reference so you can quote it when asking for help. Pixbun does not accept the value from the browser or store it in local History, History backups, aggregate analytics, cookies, accounts, or the application database. It can locate a request only while operator-controlled access logs retain the matching row and does not by itself create a support channel or response guarantee.
Pixbun records aggregate daily counts for generation starts, successes, failures, explicit cancellations, quota exhaustion, downloads, shares, unpublishes, prompt reuse, applied local prompt refinements, and applied starter templates. Event requests contain the event name only and are not stored with a user or session identifier.
The server also records fixed daily counters for completed, reused, quota-rejected, capacity-rejected, provider-configuration-rejected, storage-rejected, provider-success, provider-quota, provider-rate-limit, provider-error, provider-cancelled, and internal-error outcomes, provider-call capacity reservations, plus four provider-latency buckets. These operational counters do not contain prompts, IP addresses, session identifiers, provider configuration values, filesystem paths, free-space values, or individual request records.
At protected metrics read time, Pixbun also counts how many existing generation sessions began on each UTC day and how many produced at least one image. It returns only those aggregate integers: no session identifier or row is added to analytics or the response. Multiple slots count once, and a content-free deletion tombstone continues to show that the session previously succeeded.
The protected operator metrics view derives daily percentages and bounded multi-day series from those aggregate counts and existing session/generation state. An authenticated operator can export the same aggregate values as CSV or a human-readable Markdown window review; the export adds no prompt, IP address, session identifier, or request row. The view creates no additional user, session, prompt, or request record, labels browser-derived figures as best-effort, and does not claim to measure unique people or retention.
Retention and your choices
Pixbun has no automated deletion schedule for generation records or image files today. Unpublish changes public discoverability without deleting the stored content; Delete permanently removes that generation’s stored content while retaining the minimal quota tombstone described above. Avoid entering confidential or personal information in prompts.
A public support destination is shown in the site footer only when the operator has configured a working support channel.