1. Introduction
OptimizeYourImage ("we", "us", "our") operates the OptimizeYourImage website. This Privacy Policy explains how we handle data when you use our Service. We are committed to transparency and to protecting your privacy.
2. Client-Side Image Processing
The free image optimizer, format converter, background remover, and text-behind-object tools process images in your browser using client-side technologies such as Canvas API, Web Workers, WebAssembly, WebGPU, and Transformers.js. Images selected in these browser tools are not intentionally uploaded to our servers. Once you close or refresh the tab, browser-held image data is cleared. This local-processing promise does not apply when you deliberately submit an image to the developer API. API processing is described separately below.
3. Accounts and API Processing
You do not need an account for the free browser tools. If you create an API account, we process account details supplied by our authentication provider, such as your email address, display name, and avatar. The API receives the image you submit, processes it synchronously, and returns the result. Unless you request an opt-in store option (see Section 4), source and output files are not placed in persistent storage. We retain operational metadata such as request ID, account ID, formats, byte counts, timing, status, and credits used, but not filenames, image bytes, or image metadata. Security logs may include a shortened or hashed network address and user agent.
4. Stored Results (Opt-In)
By default, store=none returns image bytes synchronously without persistent storage of source or output images. store=temp stores only the optimized result and returns JSON with a download link valid for 2 hours. Link expiry is separate from physical deletion, which follows storage lifecycle cleanup; no fixed deletion deadline is guaranteed. store=cdn returns JSON with a public URL and stores only the optimized result until user deletion, Terms enforcement, or plan/subscription lifecycle cleanup. Stored results are held in Cloudflare R2. We never store original uploads, and we never store any results unless you set the store parameter.
6. Third-Party Services
We use Cloudflare for network security, API and image-processing infrastructure, temporary result storage, CDN storage, caching, content delivery, and cookie-free web analytics; Supabase for authentication and account data; and Polar for checkout, subscriptions, invoices, tax handling, and the customer portal. These providers process data under their own privacy terms. Payment-card details are submitted to the hosted billing provider and are not stored by OptimizeYourImage. We also use Google Analytics 4 for optional analytics after consent; its advertising features remain disabled. We use Resend to deliver transactional email, including sign-in links and account notices; it processes recipient email addresses and message content.
7. Purposes and Legal Bases
We process personal data for the following purposes: • Account operation — email, display name, avatar, and account identifiers, to create and manage your account (performance of a contract). • API processing — submitted image bytes and request options, to fulfil the request you send (performance of a contract). • Hosted storage — optimized outputs you ask us to store, object metadata, and storage usage (performance of a contract). • Billing — subscription, order, and invoice metadata processed with our merchant of record (contract and legal obligations). • Security and reliability — request metadata, shortened or hashed network addresses, and rate-limit counters, to prevent fraud and abuse (legitimate interests). • Support — messages you send us, to answer your request (contract and legitimate interests). • Analytics — aggregate Cloudflare statistics are processed for legitimate interests; optional Google Analytics measurement is processed only with your consent.
8. Data Retention
• Browser-tool images: never received by us. • By default, store=none returns image bytes synchronously without persistent storage of source or output images. • store=temp stores only the optimized result and returns JSON with a download link valid for 2 hours. Link expiry is separate from physical deletion, which follows storage lifecycle cleanup; no fixed deletion deadline is guaranteed. • store=cdn returns JSON with a public URL and stores only the optimized result until user deletion, Terms enforcement, or plan/subscription lifecycle cleanup. • Edge caches: a deleted object can remain in distributed edge caches for up to approximately 24 hours. • Idempotency fingerprints: a cryptographic hash of a submitted request may be retained for up to 24 hours; it is not the image and cannot be used to reconstruct it. • Operational and security metadata: retained while your account is active and for as long as necessary for billing integrity, security, and abuse prevention. • Account data: retained until account deletion, after which personal data is removed except records we must keep by law. • Billing records: retained for the statutory accounting period. • Support messages: retained as long as needed to resolve the request. • Analytics: Cloudflare reports are aggregate. GA4 event-data retention is 2 months and Google user-data retention is 14 months; we do not send user IDs. Your consent choice stays in localStorage until you change it or clear browser data.
9. International Data Transfers
Our service providers operate global infrastructure, so data may be processed in data centers outside your country, including outside the EU/EEA. Where required, transfers rely on safeguards such as standard contractual clauses offered by the providers listed in Section 6.
10. Your Rights
Depending on the law that applies to you, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to processing, and to withdraw consent where processing is based on consent. You can delete stored CDN objects at any time through the API, and you can request account deletion by contacting [email protected]. You also have the right to lodge a complaint with your data-protection supervisory authority.
11. Children's Privacy
The free browser tools can be used without an account. Paid API accounts and purchases are not directed to children, and a child must not create a paid account without the authorization required in their country. Contact us if you believe a child's account data was provided improperly.
12. Security and Image Privacy
Browser tools: Optimization, background removal, text effects, and HEIC conversion run locally in your browser. The decoder or AI model may be downloaded, but your selected image is not intentionally uploaded. Production Image API: API images are processed synchronously. Unless a store option is requested (see Section 4), source and output files are not placed in persistent storage, and temporary resources are removed after the response. Credentials: Treat API keys like passwords. Keys are displayed once when created, stored as hashes, and can be revoked from the developer dashboard. Reporting: Report a vulnerability privately to [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post any changes on this page with an updated revision date. We encourage you to review this page periodically.
14. Language
This Privacy Policy is drafted in English. Translations are provided for convenience only; if a translation conflicts with the English version, the English version prevails.
15. Contact Us
If you have any questions about this Privacy Policy, please contact us at: [email protected]