Privacy Policy
Last updated: 2026-07-27
IMAGEDIT is operated by Lee, an individual doing business as 'IMAGEDIT', located in Shanghai, China. References in this policy to "IMAGEDIT", "we", "us", and "our" mean Lee doing business as IMAGEDIT. To contact us about privacy or data protection, write to support@imagedit.co.
This Privacy Policy explains what information we collect when you use IMAGEDIT (the website at imagedit.co and the image-editing services we provide through it), why we collect it, the legal bases we rely on, who processes it on our behalf, how long we keep it, and the rights you have over it. It applies globally; depending on where you live, the GDPR (European Union and United Kingdom), the CCPA (California), and the People's Republic of China Personal Information Protection Law (PIPL) may give you additional rights described below.
Who we are
IMAGEDIT is an image-editing service. You upload an image, we run machine-learning models on it to produce an edited result (for example removing the background, erasing an object, or upscaling the resolution), and we deliver that result back to you. The controller responsible for your personal data is Lee, an individual doing business as 'IMAGEDIT', located in Shanghai, China. You can reach us at support@imagedit.co for any privacy, data, or takedown question, including requests to access, correct, or delete your data.
Information we collect
We collect only the information we need to operate the service:
- Account information. When you sign up we collect the email address you use to sign in. We do not collect a password; sign-in is handled through a magic link or one-time passcode sent to your email.
- Images you upload. When you ask IMAGEDIT to edit an image, the image file you upload and the edited result we produce are processed and temporarily stored so we can deliver them to you. See "Data retention" below for how long they live.
- Usage information. We keep records of how the service is used — which editing tool was invoked, how many edits you have made, the number of credits you have purchased or consumed, and similar operational counts. This is necessary to operate the service, enforce rate limits and quotas, and detect abuse.
- Billing information. When you make a purchase we collect the information needed to process the payment. Payment processing is handled by our billing provider (see "Third-party processors"); we do not store your full card number.
- Cookies and similar technologies. We use a small number of cookies to keep you signed in, remember your preferences, and (if you opt in) measure usage. See the "Cookies" section below.
- Communication. If you write to us (for example at support@imagedit.co), we keep the correspondence so we can resolve your question.
We do not knowingly collect additional information beyond what is listed here, and we do not buy personal data from data brokers.
How we use your information
We use the information we collect to:
- operate the service — run edits on the images you upload and return the results;
- create and maintain your account, keep you signed in, and authenticate you by magic link or one-time passcode;
- allocate, track, and bill the credits and rate limits associated with your account or device;
- detect, prevent, and investigate abuse, fraud, and security incidents;
- maintain records required for accounting, tax, and legal compliance;
- respond to your requests and provide support; and
- understand, in aggregate, how the service is used so we can improve it.
We do not use your uploaded images to train machine-learning models, and we do not sell your personal data.
Legal basis for processing (GDPR)
For users in the European Union and the United Kingdom, the lawful bases we rely on under the GDPR are:
- Performance of a contract. Processing your account information, uploaded images, usage records, and billing data is necessary to provide the editing service you requested.
- Consent. Where you have opted in (for example to optional analytics cookies), we process on the basis of your consent. You can withdraw consent at any time without affecting processing that was carried out before withdrawal.
- Legitimate interests. Keeping logs to detect abuse, prevent fraud, maintain security, and comply with our record-keeping obligations is in our legitimate interest as the service operator, and these interests are not overridden by your rights and freedoms.
- Legal obligation. Some retention (for example of billing records) is required by law.
AI / ML processing
IMAGEDIT's core feature is that we run machine-learning models on the images you upload in order to produce edits (currently: background removal, object erasing, and image upscaling). When you request an edit, your uploaded image is sent to compute infrastructure that executes the relevant model and returns a result. The image is processed for the sole purpose of producing the edit you requested and is deleted in line with the retention schedule below; it is not used to train our models. Outputs of machine-learning models can be imperfect and should be reviewed before use; this is described further in our Terms of Service.
Third-party processors
We rely on a small number of third parties to operate the service. Each processes personal data only on our instructions and under a written contract, and only for the purpose of delivering the part of the service they provide:
- Creem — handles subscription and one-time billing on our behalf, and in doing so processes the billing identifiers and payment details needed to complete a transaction.
- Cloudflare R2 — provides the object storage where your uploaded images and edited results are held temporarily before they expire and are deleted.
- Neon — hosts the PostgreSQL database we use to store account, task, and usage records.
- Resend — delivers transactional email (sign-in magic links and one-time passcodes) on our behalf.
If we add or replace a material processor, we will update this section. We do not authorize any processor to use your personal data for its own purposes.
Data retention
We keep personal data only as long as we need it:
- Uploaded images and edited results: 7 days. Image files you upload and the results we produce are retained for seven days so you can return to them within the editor, after which they are deleted from storage.
- Account data: until you delete it. We keep your account information (such as your sign-in email) for as long as your account is active. You can request deletion at any time by writing to support@imagedit.co, and we will remove your account data in line with this policy and applicable law.
- Billing, accounting, and anti-fraud records: as required by law. Records we are required to keep for tax, accounting, or legal purposes — including records needed to detect and prevent fraud — are retained for the period mandated by the applicable requirement and then deleted.
When retention ends, data is either deleted or anonymized so it can no longer be associated with you.
Cookies
We use two kinds of cookies and similar storage:
- Strictly necessary cookies. These are required for sign-in, session integrity, and core editor features. They are always on; the service does not work without them.
- Optional analytics cookies. If you opt in through the consent banner, we may use cookies to anonymously measure usage so we can improve the service. You can accept or reject analytics cookies, and you can change your choice at any time from the consent panel.
We do not use cookies to build advertising profiles or to sell your data. The consent banner you see on first visit lets you choose which categories to allow, and your choice is remembered on this device.
Data sharing
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share personal data only:
- with our processors listed above, to the extent necessary for them to provide the service we have asked them to provide;
- when we believe disclosure is necessary to comply with a legal obligation, protect our rights or property, investigate fraud or security incidents, or protect the safety of our users or the public; and
- in connection with a sale, merger, or transfer of all or part of our business or assets, subject to the protections described in this policy.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- rectify personal data that is inaccurate or incomplete;
- erase your personal data ("right to be deleted");
- receive a copy of your personal data in a structured, machine-readable format, and to transmit it to another controller ("portability");
- object to processing based on legitimate interests or carried out for direct marketing; and
- restrict the processing of your personal data in certain circumstances.
These rights are recognized by the GDPR (EU and UK), the CCPA (California), and the PIPL (People's Republic of China), among other laws. To exercise any of them, write to support@imagedit.co from the email address associated with your account and tell us what you would like to do. We will respond within the time frame required by applicable law, and we may need to verify your identity before acting.
International data transfers
IMAGEDIT operates globally and our processors' infrastructure is distributed. As a result, your personal data may be processed in a country other than your own — for example, Cloudflare and Neon may process data in regions outside your residence. Where this occurs, we rely on standard contractual safeguards (such as the European Commission's Standard Contractual Clauses for transfers out of the EEA/UK, and equivalent measures under other regimes) to ensure your data is protected to a standard consistent with this policy and applicable law.
Children
IMAGEDIT is not directed to children and we do not knowingly collect personal data from anyone under 13. If you believe we have collected personal data from a child under 13, please contact us at support@imagedit.co and we will delete it. The service is intended for users who are 13 or older.
Security
We use reasonable technical and organizational measures to protect your personal data — for example, encrypting data in transit, restricting access to systems that hold personal data to authorized personnel, and limiting how long sensitive data (such as uploaded images) is retained. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to keep the risk as low as reasonably possible.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If we make a material change — one that substantially affects your rights or how we use your data — we will take reasonable steps to notify you (for example by displaying a notice in the service or, where appropriate, by email). We encourage you to review this page periodically.
Contact
If you have any question, concern, or request regarding this Privacy Policy or your personal data, contact us at support@imagedit.co. We will respond in accordance with applicable law.