Legal

Privacy Policy

We take your privacy seriously. This policy explains what data we collect, why we collect it, and how you can control it.

Last updated: April 2026

Privacy questions or requests?

Contact our privacy team directly.

support@usetestpilot.com

1. Data We Collect

We collect only the data necessary to provide and improve our service. This includes:

Account information

Your email address and username when you register. These are required to create and identify your account.

Puzzle progress

Piece positions, completion percentage, and time elapsed for each puzzle session. This allows you to save and resume your puzzles.

Uploaded content

Images you upload to create custom puzzles. These are stored securely on our servers and are private to your account.

Subscription data

Your plan type (free or premium) and subscription status. Payment details are handled directly by Stripe and are never stored on our servers.

Technical data

Standard server logs (IP address, browser type, pages visited, timestamps) used for security and performance monitoring. These are retained for 30 days.

2. How We Use Your Data

Your data is used exclusively for the following purposes:

  • Providing and operating the Peuzle puzzle service
  • Authenticating your account and maintaining your session
  • Saving and restoring your puzzle progress across devices
  • Processing subscription payments via Stripe
  • Sending transactional emails (account confirmation, password reset)
  • Analyzing aggregate, anonymized usage to improve the product
  • Ensuring the security and integrity of the platform

We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.

3. Third-Party Services

We use a limited number of trusted third-party services, each with its own privacy policy:

Stripe

Payment processing

When you subscribe to a premium plan, payment is processed securely by Stripe. Your card number, CVV, and full billing details are entered directly on Stripe's secure servers and are never transmitted to or stored by Peuzle.

View Stripe Privacy Policy →

Cloud hosting provider

Infrastructure (EU)

Our servers and databases are hosted within the European Union by a provider that is fully compliant with GDPR requirements.

4. Cookies

Peuzle uses only essential cookies necessary for the service to function. We do not use advertising cookies, tracking pixels, or analytics cookies that require consent.

access_token

Stores your JWT authentication token (httpOnly, 30 min)

refresh_token

Maintains your session across browser restarts (httpOnly, 30 days)

lang

Stores your language preference (EN or FR)

You can disable cookies in your browser settings, but doing so will prevent you from staying logged in to Peuzle.

5. Data Retention

We retain your data for as long as your account is active. Specifically:

  • Account data is kept until you request deletion
  • Puzzle progress is kept until you delete it or your account
  • Uploaded images are kept until you delete them or your account
  • Server logs are automatically deleted after 30 days
  • After account deletion, all personal data is purged within 30 days

6. Your Rights (GDPR)

As a resident of the European Union, you have the following rights regarding your personal data:

Right of access

Request a copy of all personal data we hold about you.

Right to rectification

Request correction of inaccurate or incomplete data.

Right to erasure

Request deletion of your account and all associated data ("right to be forgotten").

Right to restriction

Request that we limit the processing of your data in certain circumstances.

Right to portability

Receive your data in a structured, machine-readable format.

Right to object

Object to processing of your data for specific purposes.

To exercise any of these rights, please contact us at support@usetestpilot.com. We will respond within 30 days. If you believe we have not adequately addressed your request, you have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at cnil.fr.

7. Security

We implement industry-standard security measures including encrypted connections (HTTPS/TLS), hashed passwords (bcrypt), httpOnly cookies to prevent XSS, and regular security reviews. Despite these measures, no system is completely secure, and we encourage you to use a strong, unique password for your Peuzle account.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by prominently posting a notice on the platform. Continued use of Peuzle after changes take effect constitutes acceptance of the updated policy.