Privacy notice · Product preview
Image processing, private image storage, accounts and browser storage.
Last updated: 2026-09-07
Scope
This notice describes the free preview and the optional credits mode. It is a product testing notice, not a completed commercial privacy policy or a statement identifying a launched operator. Default processing remains free. The payment integration has not been verified with a merchant account or real payment collection.
Credits-based charging is not publicly open in this preview. A complete cloud image-processing deployment and real merchant payments still require live validation; these notes describe the implemented behavior when the relevant configuration is enabled.
Image processing and retention
Images are sent to our processing service; processing is not entirely inside your browser. Uploads are not used for model training.
When private cloud object storage (Cloudflare R2) is configured, both free and credits modes send the original through our server into that storage. The processing service reads it and saves the result and a comparison preview there. We attempt to delete the original after successful processing. Results can be recovered for 24 hours from task creation. Original files, previews, results and temporary task records are covered by a 24-hour storage lifecycle rule as a cleanup fallback. Lifecycle deletion is asynchronous, so this is not a promise of physical deletion at exactly 24 hours.
Images are private. Recovery requests require task ownership and expire 24 hours after task creation. Our server returns image data to the owner; the browser does not receive permanent storage links or storage credentials.
Without object storage configured, free processing instead sends the image through the service, holds it in memory and returns the result to the page. There is no server result-recovery library in this mode. Credits processing requires object storage and remains unavailable when it is not configured.
Replacing an image, resetting the workspace, or closing the page does not itself delete a server result. After a result is downloaded into the browser, color changes, export and repeated downloads use the local image without uploading it again. Keep your originals and save results to your device; this is not permanent image storage.
Cookies and browser storage
Free processing uses signed anonymous cookies for usage controls. Object-storage tasks also use the necessary HttpOnly cookie cutout_visitor, limited to /api/cutout, to identify the anonymous owner for recovery. It lasts up to 24 hours; clearing it prevents recovery of that anonymous owner's tasks. Authentication uses necessary session cookies, and language or appearance preferences may be stored locally.
For recovery, sessionStorage keeps the current request identifier and up to 10 recent task identifiers, their times and the storage-transport indicator. It does not store image binaries or signed image URLs there. Resetting the workspace preserves these recovery entries. Clearing site storage removes browser entries, not server records.
Accounts, payments and operational records
Free mode does not require an account. Credits mode requires authentication. Account, session, task, order and credit records are stored by the configured service database. Closing the browser does not remove them. Checkout, when enabled and configured, sends the information needed for payment to the selected payment provider; the provider handles its own payment interface.
This version has no established self-service account deletion or data-export flow. Operational request and error records may exist. Analytics, payment providers and other third-party integrations depend on the deployment configuration; this notice does not certify that they have been enabled or audited.
New object-storage tasks keep status and image-location identifiers in the service database when credits mode is used; image binaries are not stored in that database. Older temporary database results, if any, remain subject to their original expiry and cleanup policy. Database backups and change logs follow the database retention policy.
When configured, product analytics records fixed action names such as upload, processing outcome, download and checkout. These events do not include images, filenames, task identifiers, storage keys or account details. Checkout retries store a random request identifier in sessionStorage to avoid duplicate orders. Analytics providers and their deployment settings still require disclosure before public release.
Questions and release review
Use the channel through which this preview was shared for questions. No dedicated public privacy contact is established here. Before a public paid launch, operator identity, contact details, provider disclosures, cleanup scheduling, backup retention and the final privacy notice must be established and reviewed.