ImagEditorAI
Back to home

Privacy Policy

How ImagEditorAI handles images, prompts, account data, payments, and privacy requests.

Last updated: 2026-08-29

1. What This Policy Covers

This Privacy Policy explains how ImagEditorAI collects, uses, shares, retains, and deletes information when you use our website, image editor, account features, and paid services (the “Service”). It applies whether you use the Service as a guest or through a registered account.

The short version: image editing is not fully local. To complete an edit, your images and prompt are sent securely to our servers and to the selected third-party AI provider. Guest images are not added to a personal gallery. Images and results associated with a registered account may be saved in My Creations until you delete them or your account.

2. Information We Collect

Account information

When you create an account, we collect your email address and the profile information you provide. If you sign in with Google, Google may provide your name, email address, and profile image. We do not receive your Google password.

Guest identity and free-credit eligibility

Guests receive a random first-party identifier in an HttpOnly cookie named imag_editor_guest. The cookie can remain for up to 12 months unless you clear it. We store a cryptographic hash of the identifier, not the raw secret, so the Service can determine guest free-credit eligibility and associate uploads and tasks with the correct browser session.

For eligible guests, we use the identifier and credit ledger to refresh the daily free-credit allocation to 9 at the start of each UTC day. For signed-in accounts, the daily free-credit allocation refreshes to 15. The previous daily free allocation is replaced rather than accumulated; purchased credit-pack credits and subscription credits use separate ledger entries and are not reduced by this refresh.

To protect free credits and the Service from abuse, we also process limited network and device-derived signals. These may include the IP address used to create a guest session, keyed hashes of an IP address or IP prefix, and a keyed hash of a browser-generated device digest based on browser version, language, hardware concurrency, reported device memory, touch capability, platform, screen properties, and time zone. We also review request rates, failed requests, and credit-grant patterns.

We do not collect Canvas output, WebGL renderer details, installed font lists, audio fingerprints, browser plugin lists, or cross-site advertising identifiers for this purpose. These limited signals support risk decisions; they are not treated as proof of a person’s identity.

Images, prompts, and results

We collect the images you upload, the editing instructions you submit, task settings such as model and resolution, and generated results. This information is required to perform the edit you requested.

Usage, account, and transaction information

We record credit grants and consumption, task state, error categories, account actions, saved creations, share links you create, support requests, and security events. For paid services, we keep order, subscription, amount, currency, status, and payment-provider reference information.

Payment information

Payments are handled by third-party payment providers. We do not store complete payment-card numbers. The provider processes your payment details under its own privacy policy and returns the transaction information needed to confirm payment, manage renewal or cancellation, prevent fraud, and handle refunds or disputes.

3. How Your Images Are Handled

During an edit

  1. Your browser uploads the selected images to Cloudflare R2 object storage controlled for the Service. The objects are reachable through unlisted public URLs with randomly generated paths.
  2. We create time-limited access URLs so the selected AI provider can retrieve the inputs required for your task.
  3. We send the prompt, model settings, and input references to the provider currently used for generation (KIE).
  4. The provider processes the request and returns a result. We copy successful results into R2 so they can be delivered to you and, when you are signed in, shown in My Creations.

Do not upload an image unless you have the right to use it and are comfortable sending it to these systems.

Guest edits

Guest uploads and results use a separate transient storage class and are not added to My Creations. Guest upload records are marked to expire approximately one hour after upload. Storage cleanup and provider deletion may occur later according to their technical lifecycle, so we do not promise that every server or provider copy disappears exactly at the one-hour mark.

When you generate an edit, we save the submitted prompt with that task record. The same rule applies to guest and registered-account tasks: completing or failing a task does not automatically clear its prompt. We may clear restricted provider-response data separately. A result displayed in your browser may remain in browser memory or cache until you delete the task or clear local browser data. Clearing browser data does not delete copies already sent to our systems or the provider.

Registered-account edits

For signed-in users, inputs, prompts, task information, and successful results may be retained so My Creations can display and reuse them across devices. Image object URLs are not listed in normal task or creation responses, but anyone who obtains an underlying public R2 URL may be able to access that object until it is deleted. You can delete an individual creation; doing so removes it from active application access and invalidates its share link. You can also delete your account as described in Section 9.

4. How We Use Information

We use information to:

  • provide image editing, storage, downloads, sharing, and account features;
  • calculate, grant, deduct, and restore credits;
  • process payments, subscriptions, cancellations, refunds, and disputes;
  • secure accounts and detect duplicate or repeated free-credit eligibility claims, fraud, abuse, and attacks;
  • diagnose failures, maintain reliability, and respond to support requests; and
  • comply with accounting, tax, legal, and regulatory duties.

We do not sell your personal information. We do not use your images or prompts to train models of our own. A third-party AI provider’s use and retention of request data is governed by that provider’s terms and the configuration available to us at the time of processing.

5. When We Share Information

We share only the information needed for the relevant purpose with:

  • AI generation providers, currently KIE, to perform requested edits;
  • cloud hosting and object-storage providers;
  • authentication, email, and support providers;
  • payment providers, banks, and fraud-prevention services; and
  • public authorities or other parties when required by law or reasonably necessary to protect users, the Service, or legal rights.

These providers may process information in countries other than your own. Their independent legal obligations and privacy terms may also apply.

6. Cookies and Similar Storage

We use:

  • imag_editor_guest, an essential guest identifier stored for up to 12 months;
  • authentication and security cookies that keep you signed in and protect your session; and
  • preference storage, such as your selected appearance theme.

You can clear cookies and site storage through your browser. Doing so may sign you out and may make guest credits associated with that browser unavailable.

7. Retention

We keep information only for as long as it is needed for the purposes described here, subject to the following practical rules:

  • guest cookies can remain for up to 12 months;
  • hashed grant-eligibility signals and related guest records may be retained to prevent repeated grants and investigate abuse;
  • guest image assets are marked as transient, although deletion from storage, provider systems, logs, and backups may lag behind the application record;
  • account creations remain until you delete them or delete your account;
  • subscription, order, refund, fraud, security, and accounting records may be kept after account deletion when required for tax, chargeback, dispute, or legal purposes; and
  • deleted information may remain in restricted backups until the applicable backup cycle expires.

8. Security

We use encrypted network connections, randomly generated R2 object paths, application access controls, input validation, and audit records for sensitive administrative actions. R2 image objects are accessible to anyone who obtains their unlisted public URL. No online service can guarantee absolute security. Keep your account credentials private and contact us if you believe your account has been compromised.

9. Your Choices and Privacy Rights

You can update account information, delete creations, revoke share links, cancel a subscription, or delete your account through the Service. Account deletion removes account-owned images from active storage before the account record is removed. If storage deletion fails, the account remains available so the deletion can be retried safely.

Depending on where you live, you may also have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a data-protection authority. These rights may be subject to legal exceptions. Submit a privacy request through the support channel in your account. We may need to verify that the request relates to you.

Deleting an account does not automatically create a refund request. If you may qualify for an annual-subscription refund, request it under the Refund Policy before deleting the account.

10. Children

The Service is not directed to children under 18 or under the applicable age of majority. We do not knowingly collect personal information from children. If you believe a child has provided information to the Service, contact us so we can review and remove it.

11. Changes to This Policy

We may update this policy as the Service, providers, or legal requirements change. We will change the “Last updated” date and provide additional notice when a change materially affects how we use your images or personal information.

12. Contact

For privacy questions or requests, use the support channel available in your account. Include enough information for us to identify the relevant account or transaction, but do not send passwords, complete card numbers, or sensitive images in the request.