Effective date: 9 August 2026
Pedesta is operated by Alomooi (Pty) Ltd, registration number 2024/296178/07, of 131 Sol Plaatjie, Potchefstroom, North West, 2530, South Africa.
For any privacy question, or to exercise any right described below, contact pieter@pedesta.studio.
Alomooi (Pty) Ltd is the responsible party for your personal information under the Protection of Personal Information Act 4 of 2013 (POPIA), and the data controller for the purposes of the UK and EU GDPR where those apply.
Information you give us:
Information created when you use Pedesta:
Pedesta keeps a request log for 30 days. Each entry records the date and time, the method and the page path requested, the response status and size, and the IP address and country that Cloudflare reports for the request. It does NOT record query strings or anything you send us, so it never contains an upload, an email address or a link to your images. Entries are deleted automatically after 30 days. Besides that log we store only your email address, your images, your credit balance and your order history. Your browser and device type and the pages you visit are also seen by Cloudflare, which routes and protects our traffic, and by Google Analytics and Meta where those load, as described in section 4.
Payment information:
Images you upload, and the images Pedesta generates from them, are used to provide the service to you and to investigate failures. We use them for nothing else unless you tick the advertising box beside a result, in which case section 3a applies. We do not sell them. We do not use them to train machine learning models, and we require the same of our processors.
Retention: a photograph you upload before you have given us your email address is kept for 7 days and then deleted, because there is no account it belongs to and no way for you to ask us to remove it. Once you give us your email address that photograph becomes part of your account, and from then on your photographs and the images Pedesta makes from them are kept for 12 months after the last version, then deleted. This applies to your original photograph and to every image generated from it. The Settings page in the app has a Delete my images control that removes everything immediately, leaving your credits and your purchase history intact. If you have given consent for an image to be used in our marketing, our copy is kept for the same 12 months and no longer, and consent can be withdrawn at any time from Settings in the app. None of your images are kept past these periods.
If you tick the advertising box beside a result, you allow us to show your original photograph next to that result in Google search ads and on comparison pages on pedesta.studio. That is the only purpose and those are the only channels. We never publish your name, your email address or anything else about you. Consent is per result and off unless you tick it. You can withdraw it at any time from Settings in the app or by writing to pieter@pedesta.studio, it is as easy to withdraw as it is to give, and withdrawing costs you nothing.
An image you have consented to is kept while the consent lasts, which can be longer than the retention periods in section 3. When you withdraw, we stop using it, remove it from anything we are still running, and delete our copy on the next retention sweep or immediately if you ask.
Pedesta uses:
Pedesta also stores, in your own browser, the campaign information contained in the link you arrived by (for example utm_source, gclid or fbclid), the time you arrived, and the value of the _fbp cookie that the Meta Pixel sets on this site. This stays on your device and is sent to us only if you make a purchase, so we can tell which advertising produced a sale. It is kept for 30 days. If you are in the European Union, the United Kingdom, Norway, Iceland, Liechtenstein or Switzerland, none of this is stored at all.
Your browser also keeps, on your own device and nowhere else, the email address you last used here, a token that lets this browser reach the shoots it created, and where you had got to in the guided first run. This is what lets the app show your credits and your work when you come back, instead of asking you to type your address again every time. None of it is a login and none of it proves who you are: it is convenience, and anyone using this browser has it. There is a link beside the email field, "Not you?", that clears all three from this device at once. Clearing your browser data does the same. Neither deletes anything on our side, and you can get back in from any browser with the emailed link.
When you buy, we send Meta a record of that purchase from our server as well as from your browser, so that a purchase is still counted if your browser blocks the Pixel. That record contains the amount, the currency, an identifier we generate for the sale, and the two values Meta itself issued: the click identifier from the link you arrived by, and the _fbp cookie its Pixel set. Both came from Meta in the first place, and returning them is what lets Meta tell which advertisement led to a sale. We do not send your email address, your name, your phone number, your address or your IP address.
Google Analytics and Meta Pixel are not strictly necessary. You can block them with a browser tracker blocker, by using Google's opt-out browser add-on, or by adjusting your ad settings with Meta. There is no cookie banner, because none is needed: if you are in the European Union, the United Kingdom, Norway, Iceland, Liechtenstein or Switzerland, neither Google Analytics nor the Meta Pixel is loaded at all, so no analytics or advertising cookie is set and nothing is sent to Google or Meta.
When a request is refused, we keep a record of the refusal, its category and the account concerned. These records are kept indefinitely as evidence of our content enforcement, which we are required to demonstrate to our payment provider and may be required to demonstrate to a regulator. They contain no uploaded image.
We use the following processors, and share only what each needs:
We do not sell your personal information. We do not share it for cross-context behavioural advertising beyond the pixel described in section 4.
We may disclose information where we are legally required to, or to protect our rights or the safety of others.
Our processors are located outside South Africa, mainly in the United States and the European Union. Where we transfer your personal information out of South Africa we do so on the basis of section 72 of POPIA, relying on contractual terms with each processor that require a comparable level of protection.
Under POPIA you may ask us to confirm what personal information we hold about you, to correct or delete it, and to object to its processing. Write to pieter@pedesta.studio and we will respond within a reasonable time and in any event within 30 days.
If the UK or EU GDPR applies to you, you also have the right to a copy of your data in a portable format, to restrict processing, and to withdraw consent where we rely on it.
If you are a California resident, you may request disclosure of the categories of personal information collected, request deletion, and opt out of sale or sharing. We do not sell personal information.
You will not be treated differently for exercising any of these rights.
Traffic to Pedesta is encrypted in transit. Access to production systems is restricted to the operator of the business. No system is completely secure, and we cannot guarantee absolute security.
Pedesta is not intended for anyone under 18 and we do not knowingly collect information from children.
We will post any change to this policy on this page and update the effective date above. Material changes will be posted here with a new effective date.
If you are not satisfied with how we have handled your personal information you may complain to the Information Regulator of South Africa, JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, or by email to complaints.IR@justice.gov.za.