ImgPhotoEditor Back to editor

ImgPhotoEditor Privacy Policy

Effective date: August 17, 2026

This Policy explains how ImgPhotoEditor handles personal data when you use imgphotoeditor.ai and related services.

1. Data we collect

  • Google account data: Google subject identifier, email address, display name, avatar, and sign-in timestamps.
  • Creative content: uploaded images, prompts, generation settings, AI outputs, thumbnails, and technical task events.
  • Payment data: Stripe customer, subscription, checkout, invoice, payment, refund, and dispute identifiers. We do not store complete card numbers.
  • Credit and usage data: grants, purchases, spends, refunds, balances, model choices, task status, and creation-retention tier.
  • Device and security data: a pseudonymous browser identifier, security cookies, hashed or HMAC-protected network identifiers, coarse request metadata, risk events, and audit records. We avoid storing raw IP addresses in application audit records.
  • Support data: messages and information you provide when requesting assistance.
  • Optional analytics: Google Analytics loads only after you accept analytics cookies. We do not enable PostHog analytics.

2. Why we use data

We use data to authenticate users; grant and protect free credits; process image-generation tasks; store and deliver results; operate subscriptions and purchases; prevent fraud and abuse; provide support; send transactional notices; monitor reliability; comply with law; and, with consent, understand aggregate product usage.

Our legal bases, where applicable, include performing our contract with you, legitimate interests in security and service operation, legal obligations, and consent for optional analytics.

3. Service providers

We disclose only the data needed for a provider's role. Current categories include Google for authentication, Kie.ai and its underlying model providers for AI generation, Cloudflare for Pages hosting, network protection, and R2 storage, Stripe for billing, Resend for transactional email, Sentry for redacted error monitoring, and Google Analytics after consent. Providers may process data in other countries under their own contractual and legal safeguards.

Do not upload sensitive personal data or content you are not authorized to process. Prompts and images sent to AI providers are governed by our provider arrangements and may also be subject to the provider's applicable service terms.

4. Retention

  • Guest results are retained for up to 24 hours.
  • Free signed-in accounts retain up to 60 creations for 7 days.
  • Accounts that bought a Credit Pack retain up to 300 creations for 30 days.
  • Active subscribers retain up to 1,000 creations for 90 days.
  • Daily Free Credits reset at UTC 00:00. Subscription credit lots expire at the monthly refresh. Permanent Credit Pack lots remain until used, refunded, or the account/service is closed.
  • Transaction, ledger, security, fraud, and immutable operator-audit records may be retained longer when needed for tax, accounting, disputes, security, or legal obligations.

When you manually delete a creation, it immediately enters an asynchronous physical-deletion queue. Signed download URLs are short-lived.

5. Account deletion

You can request deletion in Account Settings after recent Google verification. Access and new generation are disabled immediately; active subscription renewal is canceled; media is queued for deletion; and profile data is scheduled for anonymization after 30 days. Login identities and credentials are removed during anonymization. Payment and audit records may remain with personal profile fields detached when retention is legally or operationally required.

6. Cookies and analytics choices

Strictly necessary cookies keep sessions secure, prevent cross-site request forgery, and enforce guest-credit limits. They cannot be disabled through our banner because the Service cannot work safely without them. Google Analytics is optional and is not loaded until you select Accept analytics. You can change this choice by clearing the site's local storage and revisiting the site.

7. Security

We use encrypted transport, private object storage, short-lived signed URLs, restricted operator access, append-only mutation audits, secrets management, rate limits, and redaction of prompts, tokens, cookies, raw network identifiers, and credentials from routine logs and error reports. No system is completely secure.

8. Your rights

Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also complain to your local data-protection authority. Email [email protected] from your account email; we may need to verify your identity. Some records cannot be deleted immediately where law or fraud-prevention needs require retention.

9. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. Contact us if you believe a minor has used the Service.

10. Changes and contact

We may update this Policy and will post the revised effective date. Privacy questions and requests: [email protected].

TermsPrivacyRefundsAcceptable Use
[email protected]