Legal

Privacy Policy

Last updated: July 30, 2026

This policy explains what OpusImg processes, which image tools stay on your device, when files are sent to our service, and the choices available to you.

1. Scope and who is responsible

OpusImg (“OpusImg”, “we”, “us”) is the controller of personal information processed through the OpusImg website, web app, accounts, and APIs, except where we process customer content solely on a Business or Business customer’s instructions. Questions and privacy requests can be sent to privacy@opusimg.com.

2. Local and server-side image processing

  • Local tools. When a tool is labelled “Processed on your device”, the selected file is decoded and processed in your browser. OpusImg does not receive the file contents for that operation. Normal website requests, consent settings, and diagnostics described below still apply.
  • Server and AI tools. When a tool is labelled as using secure servers, its input is uploaded to private object storage and made available to our processing service for the requested operation. The tool identifies this before intake. AI processing may use RunPod or Replicate.
  • No model training. We do not use customer files or AI outputs to train our models.
  • User control. You can remove stored assets from the dashboard. Deleted assets are soft-deleted first so they can be restored for up to 24 hours; storage deletion follows the configured lifecycle after that window.

3. Information we collect

3.1 You provide

  • Account information such as name, email address, password hash, verification status, and sign-in-provider identifiers.
  • Customer content and related metadata when you use storage, projects, server-side tools, or AI features.
  • Billing identifiers, subscription state, plan, and transaction status. Lemon Squeezy processes payment-card details; OpusImg does not store full card numbers.
  • Support, legal, sales, waitlist, and other messages you choose to send.

3.2 Collected automatically

  • Request and security data such as IP address, user agent, timestamps, route, authentication state, and abuse-prevention results.
  • Operational records needed to meter credits and quotas, process jobs, deliver webhooks and email, investigate errors, and maintain security.
  • Error and performance diagnostics through Sentry. We configure analytics events to avoid raw filenames and file contents.
  • Optional browser product analytics through PostHog and aggregate website analytics through Plausible, only after the relevant consent choice.

4. Why we process information

  • Provide accounts, local and server-side tools, storage, projects, and APIs.
  • Authenticate users and send verification, security, and service messages.
  • Process requested jobs and return their results.
  • Administer plans, payments, credits, quotas, refunds, and cancellations.
  • Prevent fraud and abuse, protect users, and diagnose service failures.
  • Improve the product using analytics where you have consented.
  • Comply with law, resolve disputes, and enforce our Terms.

5. Legal bases (GDPR)

Where the GDPR or UK GDPR applies, we rely on contract to create and administer an account and deliver requested services; legitimate interests to secure, operate, meter, and improve the service in ways that do not override your rights; consent for optional browser analytics and marketing technologies; and legal obligation for records we must retain or disclosures we must make. You can withdraw consent at any time without affecting earlier processing.

6. Cookies & tracking

We classify cookies and similar technologies into three groups. You control the non-essential ones via the banner, or any time through .

CategoryExamplesDefault
Strictly necessaryAuthentication, consent preferences, security, and error monitoringAlways on
Product analyticsPostHog usage eventsOff until you consent
Aggregate analytics & attributionPlausible page views and campaign attributionOff until you consent

PostHog and Plausible do not load in the browser until you opt in to their categories. PostHog is configured to respect Do Not Track. You can change or withdraw a choice at any time using Cookie preferences; withdrawing a choice stops future optional capture and clears the active PostHog identity.

7. Service providers and disclosures

We disclose information only as needed to operate the service, honor your choices, complete a transaction, comply with law, or protect rights and safety. Depending on the feature and configuration, providers include:

Provider or categoryPurpose
CloudflareObject storage, content delivery, and optional Turnstile abuse prevention
RunPod and ReplicateGPU processing for requested AI features
Lemon SqueezyMerchant of record: checkout, payment processing, tax handling, invoicing, and subscription administration
ResendTransactional email and delivery events
SentryError, crash, and performance diagnostics
PostHog and PlausibleOptional product and website analytics after consent
GoogleOptional Google sign-in and on-demand Google Fonts in the editor

We do not exchange personal information for money. We do not use customer content for cross-context behavioural advertising.

8. International transfers

Providers may process information outside your country. Where transfer safeguards are required, we rely on an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism made available by the relevant provider.

9. Data retention

  • Files used only by a labelled local tool remain in your browser and are released when the relevant in-browser session or handoff expires.
  • An incomplete server upload is marked to expire after 24 hours. Completed assets and projects remain until you delete them or the service applies a disclosed feature-specific retention rule.
  • A deleted stored asset is recoverable for up to 24 hours before storage deletion. Backup, provider, and security logs may take longer to age out.
  • Project version history depends on plan: Free keeps only the current project state, Pro exposes 30 days of versions, and higher plans may retain version history while the project exists.
  • Account, subscription, transaction, tax, security, and dispute records are kept while needed for the purpose collected and any legal retention period.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; restrict or object to processing; withdraw consent; or appeal a refused request. California residents may also request the categories, sources, purposes, and recipients of covered personal information and may exercise applicable opt-out and non-discrimination rights.

Cookie choices can be changed using . Stored assets can be deleted from the dashboard. Self-service account export and deletion are not yet available; to make either request, or exercise another privacy right, email privacy@opusimg.com. We may verify your identity before fulfilling a request. You may also complain to your local data-protection authority.

11. Security

We use TLS in transit, private storage keys, scoped access controls, signed upload and download URLs, upload scanning, hashed passwords and one-time tokens, and monitoring. No system is perfectly secure. We investigate incidents and provide legally required notices.

12. Children’s privacy

OpusImg is not directed to children under 16. We do not knowingly collect personal information from a child who cannot lawfully consent to the processing. Contact us if you believe a child has provided information without required permission.

13. Changes

We may update this policy as the product or law changes. We will update the date above and provide additional notice when a change materially affects how we use personal information.

14. Contact

Email privacy@opusimg.com. See also our Terms of Service. Business customers can request a data-processing agreement from legal@opusimg.com.