Privacy & Your Data

Privacy Policy

This policy explains how ImgtoImg handles your images, prompts, account details, payments, and website activity when you use imgtoimg.co.

Last updated:

1. Who We Are

ImgtoImg provides image-to-image editing, text-to-image generation, image combining, and photo-to-painting tools at imgtoimg.co. ImgtoImg Team operates this service. In this policy, “we,” “us,” and “our” refer to ImgtoImg Team, responsible for the personal information we process to run it.

For privacy questions or requests, contact support@imgtoimg.co or use our contact form. This policy covers our website and services; third-party websites linked from ImgtoImg have their own policies.

2. Information We Collect

  • Account and sign-in information: Email address, name, profile image, account identifiers, and authentication and session records. Google sign-in provides profile and identity information needed to authenticate you. Where password sign-in is available, authentication records include a password hash, not your plain-text password.
  • Creative content: Images you upload, prompts, editing instructions, area annotations, settings, generated images, thumbnails, and version history. Images or their embedded metadata may contain information about you or other people.
  • Credits and purchases: Credit balances, signup and daily check-in rewards, credit usage, selected packs, order and customer identifiers, transaction amounts and currencies, payment status, refunds, and related records. Payment details are entered with the payment provider; our checkout does not ask you to send us a full card number or card security code.
  • Support messages: Name, email address, subject, message, and information you choose to provide when contacting us, requesting a refund, or exercising a privacy right.
  • Technical and security information: IP address, browser and device information, session timestamps, verification results, request and error information, and records needed to detect misuse and keep the service working.
  • Optional usage information: If you accept analytics, visitor and session identifiers, pages visited, traffic-source information, device information, and interactions such as tool use, checkout, and purchase outcomes. See Cookies, Local Storage, and Analytics.

Providing information is your choice, but we cannot provide account access, image processing, payments, or support without the information needed for that feature. Rejecting optional analytics does not prevent you from using the tools.

3. How and Why We Use Information

We use information to authenticate users; generate and edit images; preserve work and settings; manage credits, check-in rewards, purchases, and refunds; answer support requests; send password-reset and other service messages; and prevent fraud, unsafe content, and misuse. Optional analytics help us understand usage and improve the service.

Where the GDPR or UK GDPR applies, the processing purposes and legal bases are:

Providing the service — performance of a contract
Account access, requested image processing, saved work, purchases, credits, and support needed to provide the service you request.
Security and reliability — legitimate interests
Protecting accounts, preventing abuse and fraud, moderating content, troubleshooting errors, and maintaining reliable services, subject to your interests and rights.
Optional analytics — consent
Loading optional analytics tools and linking consented visitor activity with your account to understand use and purchase outcomes. You can withdraw consent through Cookie Settings.
Legal and financial records — legal obligations and legitimate interests
Keeping records required by applicable law and handling payment disputes or legal claims. The basis depends on the record and purpose.

Account creation, credit transactions, generation status, orders, and refunds produce necessary business records even when you reject optional visitor analytics. These records support service delivery, reconciliation, security, and dispute handling.

4. Images, AI Processing, and Training

When you submit a generation or editing request, we send your prompt, relevant settings, and reference images or image links to Kie, the external service through which we access the selected image models. For follow-up edits, this can include a previous generated image and your editing instructions or annotations.

We also send prompt text to Creem and Waffo for content-safety checks. Creem requests include an account identifier; Waffo requests include the prompt and its language. Automated checks can reject or delay a request. If you believe a request was blocked incorrectly, contact support.

We store inputs, generation records, and results to deliver your request, show your work history, and support further edits. Work history and download interfaces check account access. Reference images may be delivered through public image links, which can be accessed by anyone who obtains them. Account access controls are not a promise that every underlying image link is private.

Our current service does not train its own AI models on your uploads or prompts. External generation and safety providers have their own processing, retention, and model-improvement practices. We do not promise that all external providers offer no-training or zero-retention processing. A model name shown in the editor does not mean you are using that model company’s API directly.

Upload only images you have permission to use. Avoid identity documents, financial or medical records, intimate images, and confidential business material. If your use requires specific confidentiality, deletion, or training assurances, contact us before uploading; do not assume those assurances are included.

5. Service Providers and Sharing

We do not sell your personal information. We disclose information to providers as needed for the functions below. A provider may use additional infrastructure or model services to fulfill its role.

  • Kie: Prompts, reference images or links, and generation settings for AI processing. See Kie’s Privacy Policy.
  • Waffo: Account identifier, email, selected product, and transaction information for checkout, payments, refunds, and reconciliation; prompt text for safety checks.
  • Creem: Prompt text and an account identifier for safety checks, plus customer and transaction information needed to handle historical Creem purchases or after-sales requests.
  • Neon: Database storage for account, authentication, credit, generation, purchase, and service records.
  • Cloudflare: Image and temporary-file storage through R2, and security verification through Turnstile. Verification can include a token, IP address, and browser or device signals.
  • Google: Sign-in and identity verification when you choose Google login; optional website analytics through Google Analytics when configured and consented.
  • Brevo: Support messages, recipient addresses, and service-email content for email delivery.
  • Vercel and Microsoft: Website analytics through Vercel Analytics and, when configured, interaction analytics through Microsoft Clarity, subject to your analytics choice.
  • Hosting and operational providers: Requests, technical information, and logs needed to deliver the website and maintain its reliability.

We may also disclose information when required by law, to investigate misuse or protect rights and safety, or as part of a business transfer with applicable protections. Other disclosures require an appropriate legal basis, including your consent where required.

6. Cookies, Local Storage, and Analytics

Necessary storage. Cookies and browser storage support sign-in, security checks, image transfers, draft recovery, saved settings, and active generation state. We use local storage, session storage, and browser databases as well as cookies. Clearing site data can remove local drafts or preferences and sign you out; it does not delete server-side account data.

Optional analytics. Google Analytics, Vercel Analytics, and Microsoft Clarity, where configured, load after you accept analytics. These tools can process page visits, device and browser information, referring information, and interactions. Clarity provides interaction analysis and session replay, which can capture how you navigate and interact with pages.

Our first-party visitor analytics use a random identifier, session and landing-page information, limited traffic-source fields, and events such as tool use and purchase outcomes. With consent, we may associate these identifiers with your account identifier; Google Analytics can also receive an account identifier and purchase or refund events. These identifiers are pseudonymous, not necessarily anonymous.

We do not include prompt text, uploaded images, generated images, image URLs, email addresses, or complete page query strings in our first-party product analytics event payloads. This statement describes those event payloads, not all data processed by external analytics tools or stored in necessary business records.

Choose Accept analytics or Reject optional in the banner. To change or withdraw your choice, use Cookie Settings in the footer and select Reject optional. This applies to this browser; repeat your choice on other browsers or devices. Reload the page after withdrawing to apply the choice to third-party scripts already loaded in that page.

On withdrawal, our first-party optional collection stops and pending Google Analytics purchase events are skipped after the server confirms the change. If confirmation fails, the banner shows a pending state and retries. Withdrawal does not undo earlier processing or automatically erase historical records. You can separately request deletion.

We currently do not load Google AdSense advertising on this website. If advertising is introduced, we will update this policy and provide the choices required for that processing.

7. Retention and Deletion

Retention depends on the data, the feature, and the reason it is needed. We do not offer automatic deletion of all uploaded or generated content immediately after processing.

Accounts and saved work
Account details, inputs, generated images, thumbnails, and editing history are stored to maintain your account and work history. They do not currently have a fixed automatic deletion period. You can request deletion through support.
Temporary transfers and recovery records
Temporary image transfers and saved checkout tasks generally have a 24-hour validity window. Expiry prevents further use of the transfer or task; it does not mean every stored file or database record is erased at that moment. Temporary image-transfer files are eligible for cleanup after expiry.
First-party analytics
Our scheduled cleanup removes first-party events older than 14 months and related inactive visitor and session records when they are no longer referenced by retained records. Active records can remain longer. External analytics providers have separate retention settings and policies.
Purchases, credits, and refunds
We retain records needed to maintain balances, fulfill purchased credits, reconcile payments, handle refunds and disputes, and meet applicable accounting or legal requirements. Some records may need to remain after an account deletion request.
Support and operational records
Messages and logs are kept as needed to resolve requests, diagnose issues, investigate abuse, or meet legal obligations. The relevant criteria include whether a request or dispute is open and whether the record remains needed for security or legal purposes.

A deletion request may require separate handling of account records, stored files, and provider-held information. Copies in backups, logs, or records needed for legal claims may remain until their applicable retention period ends. Where we must retain information, we will explain the reason when responding to your request. Deleting browser storage or signing out does not delete these records.

8. Security and International Processing

We use account authentication, access checks on work-history and download interfaces, secure connections on the production website, and verification of payment and security requests. We also rely on our hosting, database, and storage providers’ infrastructure safeguards. No internet service can guarantee absolute security. Protect your sign-in account and avoid sharing image links containing personal information.

Our external providers may store or process information in countries outside your country of residence. We do not offer a promise of storage solely in the EU, UK, or any other single region. Applicable data-transfer requirements depend on the countries and providers involved. Contact us for information about the processing locations and transfer safeguards applicable to your use before submitting data that requires a particular location or contractual protection.

9. Your Rights and Choices

Depending on your location and applicable law, you may have rights to access your personal information, correct it, request deletion, obtain a portable copy, restrict processing, or object to processing based on legitimate interests. You may withdraw consent where processing relies on consent, without affecting the lawfulness of earlier processing.

To request access, correction, deletion, or an export, email support@imgtoimg.co from your account email where possible. Describe your request and identify the affected work if relevant. We may ask for information reasonably necessary to verify your identity; do not email a password, card security code, or identity document unless a secure, necessary verification method has been agreed.

Account deletion and full personal-data export are handled through support; downloading an image from My Work is not a full personal-data export. Rights are subject to applicable exceptions, including records needed for legal obligations, payment disputes, fraud prevention, or legal claims. We respond within the period required by applicable law; for GDPR and UK GDPR requests, this is generally one month, with permitted extensions explained to you.

Right to object. Where applicable, you can object to processing based on legitimate interests by contacting us and explaining your circumstances. You can reject optional analytics through Cookie Settings without making a support request.

You may complain to your local data-protection authority. UK users can contact the Information Commissioner’s Office. EEA users can contact the authority in the country where they live or work. Where applicable, we will not discriminate against you for exercising privacy rights.

10. Children’s Privacy

ImgtoImg is not directed to children under 13 or below the minimum age required to consent to data processing in their location. If you believe a child has provided personal information without the authorization required by applicable law, contact support@imgtoimg.co so we can investigate and address the information and account as required.

11. Changes and Contact

We update this policy when our services or data practices change. The date at the top identifies the current version. For material changes, we will provide additional notice where required and obtain fresh consent when the changed processing requires it.

For privacy questions, provider-processing questions, or a rights request, email support@imgtoimg.co. You can also use our contact form.