Transmission and processing
The site and its API use HTTPS for the exchanges between your browser and the service. Images are processed on the server: the service and its host can process their content; this is not end-to-end encryption. Previews are built locally from the files you download.
Access to files
Each uploaded file, result and processing record is private: the permission rules allow only the owning account to read and delete it, and every processing goes through a server function that checks the identity of the account and the ownership of the file before reading it.
Files cannot be reached at a public address, and the service offers no sharing link.
Sign-in
Sign-in uses a one-time code sent by email, valid for fifteen minutes, together with a verification phrase shown in the browser. No password is stored. Code requests and attempts are rate-limited by the platform.
An email informs you of every new sign-in to your account, with the device, the IP address and the country of the connection.
From your account, you can add an authenticator app as a second factor. Its 6-digit code is then requested after the email code; recovery codes, shown once, let you sign in if you lose the app.
Sign out on a shared device.
Retention and backups
Files and records are deleted 90 days after their creation by a cleanup that runs every 5 minutes. Images are not backed up: the history is not an archive. Deletion requests are described in the privacy policy.
Database backups
The database of processing records is backed up daily, with copies retained for seven days. These backups include neither image files nor authentication accounts. Deleted database records may remain in a backup until it expires; they are not accessible through the application.
Processing protections
The engine checks the real format of each file and refuses animations, multipage files, files over 20 MiB and images over 40 million pixels. No external program is run on your files. Each user is limited to 30 processing jobs per five-minute period. Engine logs contain neither images nor file names.
Choosing what you upload
Before uploading an image, check that its content can be entrusted to a hosted service. Metadata is removed by default; keeping it is an explicit option. This page is not a security or compliance certification.
The location of the storage is not, on its own, enough to rule out any access from abroad. See the information on hosting and transfers.
Reporting a problem
In the event of abnormal access, exposed data or a suspected vulnerability, use the security contact page. Describe the problem with an example without real data and limit your checks to your own data.