Legal
Privacy Policy
Last updated: July 30, 2026
This policy explains what OpusImg processes, which image tools stay on your device, when files are sent to our service, and the choices available to you.
1. Scope and who is responsible
OpusImg (“OpusImg”, “we”, “us”) is the controller of personal information processed through the OpusImg website, web app, accounts, and APIs, except where we process customer content solely on a Business or Business customer’s instructions. Questions and privacy requests can be sent to privacy@opusimg.com.
2. Local and server-side image processing
- Local tools. When a tool is labelled “Processed on your device”, the selected file is decoded and processed in your browser. OpusImg does not receive the file contents for that operation. Normal website requests, consent settings, and diagnostics described below still apply.
- Server and AI tools. When a tool is labelled as using secure servers, its input is uploaded to private object storage and made available to our processing service for the requested operation. The tool identifies this before intake. AI processing may use RunPod or Replicate.
- No model training. We do not use customer files or AI outputs to train our models.
- User control. You can remove stored assets from the dashboard. Deleted assets are soft-deleted first so they can be restored for up to 24 hours; storage deletion follows the configured lifecycle after that window.
3. Information we collect
3.1 You provide
- Account information such as name, email address, password hash, verification status, and sign-in-provider identifiers.
- Customer content and related metadata when you use storage, projects, server-side tools, or AI features.
- Billing identifiers, subscription state, plan, and transaction status. Lemon Squeezy processes payment-card details; OpusImg does not store full card numbers.
- Support, legal, sales, waitlist, and other messages you choose to send.
3.2 Collected automatically
- Request and security data such as IP address, user agent, timestamps, route, authentication state, and abuse-prevention results.
- Operational records needed to meter credits and quotas, process jobs, deliver webhooks and email, investigate errors, and maintain security.
- Error and performance diagnostics through Sentry. We configure analytics events to avoid raw filenames and file contents.
- Optional browser product analytics through PostHog and aggregate website analytics through Plausible, only after the relevant consent choice.
4. Why we process information
- Provide accounts, local and server-side tools, storage, projects, and APIs.
- Authenticate users and send verification, security, and service messages.
- Process requested jobs and return their results.
- Administer plans, payments, credits, quotas, refunds, and cancellations.
- Prevent fraud and abuse, protect users, and diagnose service failures.
- Improve the product using analytics where you have consented.
- Comply with law, resolve disputes, and enforce our Terms.
5. Legal bases (GDPR)
Where the GDPR or UK GDPR applies, we rely on contract to create and administer an account and deliver requested services; legitimate interests to secure, operate, meter, and improve the service in ways that do not override your rights; consent for optional browser analytics and marketing technologies; and legal obligation for records we must retain or disclosures we must make. You can withdraw consent at any time without affecting earlier processing.
6. Cookies & tracking
We classify cookies and similar technologies into three groups. You control the non-essential ones via the banner, or any time through .
| Category | Examples | Default |
|---|---|---|
| Strictly necessary | Authentication, consent preferences, security, and error monitoring | Always on |
| Product analytics | PostHog usage events | Off until you consent |
| Aggregate analytics & attribution | Plausible page views and campaign attribution | Off until you consent |
PostHog and Plausible do not load in the browser until you opt in to their categories. PostHog is configured to respect Do Not Track. You can change or withdraw a choice at any time using Cookie preferences; withdrawing a choice stops future optional capture and clears the active PostHog identity.
7. Service providers and disclosures
We disclose information only as needed to operate the service, honor your choices, complete a transaction, comply with law, or protect rights and safety. Depending on the feature and configuration, providers include:
| Provider or category | Purpose |
|---|---|
| Cloudflare | Object storage, content delivery, and optional Turnstile abuse prevention |
| RunPod and Replicate | GPU processing for requested AI features |
| Lemon Squeezy | Merchant of record: checkout, payment processing, tax handling, invoicing, and subscription administration |
| Resend | Transactional email and delivery events |
| Sentry | Error, crash, and performance diagnostics |
| PostHog and Plausible | Optional product and website analytics after consent |
| Optional Google sign-in and on-demand Google Fonts in the editor |
We do not exchange personal information for money. We do not use customer content for cross-context behavioural advertising.
8. International transfers
Providers may process information outside your country. Where transfer safeguards are required, we rely on an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism made available by the relevant provider.
9. Data retention
- Files used only by a labelled local tool remain in your browser and are released when the relevant in-browser session or handoff expires.
- An incomplete server upload is marked to expire after 24 hours. Completed assets and projects remain until you delete them or the service applies a disclosed feature-specific retention rule.
- A deleted stored asset is recoverable for up to 24 hours before storage deletion. Backup, provider, and security logs may take longer to age out.
- Project version history depends on plan: Free keeps only the current project state, Pro exposes 30 days of versions, and higher plans may retain version history while the project exists.
- Account, subscription, transaction, tax, security, and dispute records are kept while needed for the purpose collected and any legal retention period.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; restrict or object to processing; withdraw consent; or appeal a refused request. California residents may also request the categories, sources, purposes, and recipients of covered personal information and may exercise applicable opt-out and non-discrimination rights.
Cookie choices can be changed using . Stored assets can be deleted from the dashboard. Self-service account export and deletion are not yet available; to make either request, or exercise another privacy right, email privacy@opusimg.com. We may verify your identity before fulfilling a request. You may also complain to your local data-protection authority.
11. Security
We use TLS in transit, private storage keys, scoped access controls, signed upload and download URLs, upload scanning, hashed passwords and one-time tokens, and monitoring. No system is perfectly secure. We investigate incidents and provide legally required notices.
12. Children’s privacy
OpusImg is not directed to children under 16. We do not knowingly collect personal information from a child who cannot lawfully consent to the processing. Contact us if you believe a child has provided information without required permission.
13. Changes
We may update this policy as the product or law changes. We will update the date above and provide additional notice when a change materially affects how we use personal information.
14. Contact
Email privacy@opusimg.com. See also our Terms of Service. Business customers can request a data-processing agreement from legal@opusimg.com.