Data Controller
The data controller for img.pro is:
Moshi Inc.
4023 Kennett Pike #50475
Wilmington, DE 19807
United States
Contact for privacy matters: privacy@img.pro.
Overview
img.pro is an image hosting and CDN service. This policy explains what data we collect, how we use it, the legal bases on which we rely, and your rights regarding your information.
- We collect minimal data necessary to provide the service
- We do not sell or share your personal information for cross-context behavioral advertising
- We do not use your images for advertising
- We do not track visitors to sites using our CDN
Information We Collect
Account Data
- Email address — Account identification, important notifications
- Name — Personalization, team collaboration
- Authentication state — Session tokens and one-time sign-in codes (we are passwordless; no passwords exist to store). API keys are stored hashed
- Consent records — Timestamp and country at signup, indicating which optional consents you granted (e.g., marketing email)
Usage Data
- Image upload counts and storage used — Quota tracking
- Session metadata — IP address and user agent at sign-in (kept while the session is active; see Retention below)
- Upload origin — IP address, user agent and, where available, country recorded with each image upload, for abuse investigation and for reporting illegal content to the authorities (kept with the image record; see Retention below)
- API request logs — Debugging, abuse prevention (retained ~30 days)
- Product analytics — Sanitized page and interaction activity, device/performance data, masked replay, browser errors, and a bounded set of categorical product outcomes. Signed-in custom events use opaque account, app, and workspace identifiers rather than names or email addresses.
- Billing analytics — Subscription, invoice, payment, refund, product, price, and customer/billing fields made available by our Stripe account, including Stripe object identifiers, so we can connect product use to realized revenue and subscription health. Access is restricted to authorized operators.
What We Don't Collect
- We don't track individual visitors to websites using our CDN
- We don't store visitor IP addresses from CDN requests — viewing or downloading an image records nothing about who requested it (uploading one does; see Upload origin above)
- We don't profile or sell information derived from your images
Legal Bases for Processing (GDPR / UK GDPR)
Where the General Data Protection Regulation or the UK GDPR applies, we process personal data under the following bases:
- Performance of a contract (Art. 6(1)(b)) — for account creation, authentication, image hosting and delivery, billing, and customer support.
- Legitimate interests (Art. 6(1)(f)) — for security, abuse prevention, content-safety classification, fraud detection, and limited browser analytics where applicable law permits an opt-out model. We balance these against your rights and use data minimization, retention limits, Global Privacy Control, and preference controls to keep the impact proportionate.
- Consent (Art. 6(1)(a)) — for non-essential browser analytics and marketing trackers where prior consent is required, and for marketing email. You can withdraw consent at any time without affecting prior processing.
- Legal obligation (Art. 6(1)(c)) — for tax records, responding to lawful requests, and statutory reporting (including, where applicable, mandatory reporting of CSAM under 18 U.S.C. §2258A).
How We Use Your Information
- Service delivery: Storing and serving your images via our CDN
- Account management: Authentication, team invitations, email verification
- Security: Detecting abuse, preventing fraud, protecting infrastructure
- Content safety: Automated classification of uploaded images to detect violations of our Acceptable Use Policy. Classifications inform whether content is flagged, hidden behind a viewer-side warning, subject to a reduced retention window, or removed from public serving. Operator review of flagged content is logged. See the Retention section for how classifications interact with retention.
- Product and revenue analytics: Understanding acquisition, activation, retention, product quality, app/workspace performance, subscription conversion, realized revenue, and refunds; diagnosing errors and performance regressions; and deciding what to improve.
- Communications: Transactional notifications (verification, billing, security alerts) sent via Amazon SES; optional product updates sent via Flodesk only where you have given consent (or, in jurisdictions that permit it, on an opt-out basis).
Data Storage and Security
- Images: Stored on Cloudflare R2 (encrypted at rest)
- Databases: Cloudflare D1 with encryption at rest
- Transit: All connections use TLS/HTTPS encryption
- Authentication secrets: API keys are stored hashed. Session tokens and one-time sign-in codes are stored as issued, so that a session can be validated and revoked — both are short-lived and are deleted on expiry, sign-out, or account deletion
Retention
The factors that determine how long we retain a given piece of personal data are: (a) whether the upload was authenticated; (b) your subscription tier; (c) the upload surface (for example, a dashboard upload versus a transient image-processing tool); and (d) the content classification produced by automated and, where applicable, operator review. The blanket retention ceilings below are durable commitments; the operational windows that apply within them are disclosed at the moment of upload by the surface you are using (for example, a tool page indicates the retention window for the outputs of that tool) and may be tuned over time to balance user expectations, storage constraints, and safety.
- Authenticated user uploads: retained until you delete the image or close your account, with two exceptions. Content identified by our classification or review processes as falling within categories prohibited by the Acceptable Use Policy is removed after a limited recovery window, regardless of subscription tier. Content identified as restricted but not prohibited (for example, nudity that does not fall within the prohibited categories) may be subject to a limited retention window on free accounts; paid accounts retain such content until you delete it.
- Anonymous uploads: retained for a limited window that depends on the upload surface and the content classification. The specific window is disclosed by the upload surface at the moment of upload. As a blanket ceiling, we will not retain an anonymous upload for more than two years from the date of upload regardless of any longer window advertised by an upload surface; in practice operational windows are much shorter. To extend retention beyond the operational window, sign in for a free account before uploading.
- Image bytes after deletion or retention expiry: moved to an operator-recovery store and retained there for a limited window to allow recovery from accidental or contested removals, then automatically reaped. The recovery window does not extend the public visibility of the content — content moved to operator-recovery is no longer served from our public-facing CDN.
- Account data: retained while your account is active. You can delete your account at any time from Settings. Deletion is reversible for a grace period via the email link we send at submit; after the grace period, all account data, owned-collection content, API keys, and marketing-list membership are permanently erased on the next sweep run. The full window between submit and erasure is well inside the GDPR Art. 12(3) one-month maximum response window.
- Sessions: a sliding expiry of approximately three months, with a hard maximum of approximately twelve months from sign-in — after that a fresh login is required. Expired session records (which include the sign-in IP address and browser identifier) are purged automatically on a recurring sweep. Hard-deleted at submit when you delete your account.
- Upload origin records: the IP address, browser identifier and country captured when an image is uploaded are stored on that image's record and have no expiry of their own — we keep them for as long as the record exists. They can outlive the image itself: when an anonymous upload's retention window ends, or when you delete an image, the record behind it remains. Records attached to images in collections you own are erased when your account is deleted; uploads you made before signing in and never saved to your account, and uploads into a collection someone else owns, stay with those images. Where content is preserved for a legal investigation or a report to the authorities, the record is kept for at least the preservation period that applies and for as long as the matter remains open.
- Worker / API request logs: approximately one month.
- Stripe billing records: retained on Stripe's side for approximately ten years for tax and accounting reasons (legal-obligation exception under GDPR Art. 17(3)(b)). At account deletion we make a best-effort attempt to clear the PostHog person-attribution key from each non-terminal Subscription before canceling it, then scrub the Stripe Customer record's identifying fields (name, email, phone, address). Stripe may refuse a metadata change on an already-terminal historical Subscription, or a transient Stripe failure may prevent the pre-cancel cleanup; opaque app/workspace attribution and the historical invoice ledger remain for aggregate revenue, tax, and accounting records. Any surviving PostHog person join is covered by the vendor-side access and erasure process below.
- PostHog product and revenue analytics: browser-storage lifetime and controls are listed at /cookies. Rejecting analytics or deleting your account clears PostHog persistence in that browser and stops future browser collection and browser-to-server journey linkage. A bounded set of pseudonymous server outcomes remains separate from that browser preference because it uses no browser storage: media processing, anonymous-to-account claims, account verification, App API outcomes, billing handoffs, and subscription changes. Stripe billing-source records used for revenue analysis are also separate from browser storage and may include Stripe identifiers and customer/billing fields. Browser opt-out does not unwind a transaction or a revenue join already received. Previously received analytics may remain until the configured project-retention period expires; request access, object to server analytics, or request vendor-side erasure by emailing privacy@img.pro.
- Abuse and DMCA records: retained for the rolling 12-month repeat-infringer policy and any pending counter-notification window. If you filed the report, your email address on it is replaced with a placeholder at deletion. Other details submitted with a report — the reporter's name, IP address and browser identifier — are kept, because the record has to stay defensible as filed.
Subprocessors and Third-Party Services
To deliver the Service we share limited data with the following processors under their applicable contractual and data-protection terms. The current list is also maintained at /subprocessors.
- Cloudflare — image hosting, CDN, databases, edge compute (R2, D1, Workers, KV), and background bot protection on sign-in, signup, and public marketing pages (Turnstile — evaluates request signals such as IP address, TLS fingerprint, and user agent; see Cloudflare's Turnstile Privacy Addendum).
- Amazon Web Services — transactional email delivery (SES) and automated content-safety classification (Rekognition) on uploaded images. Image data is transmitted only for the duration of the classification request; we do not authorize this processor to retain images for model training.
- Stripe — payment processing for paid subscriptions; collects payment-method data directly from your browser.
- PostHog Cloud EU — browser product analytics, funnels and retention, heatmaps, error and performance diagnostics, privacy-masked session replay, bounded server-side product outcomes, and Stripe-backed revenue analysis. The custom browser/server event stream uses sanitized route templates and referrer origins, bounded campaign dimensions, and opaque account/app/workspace identifiers; it excludes image content, filenames, captions, request bodies, account names and emails, IP properties, credentials, authorization codes, Stripe identifiers, internal numeric IDs, and exception text. Separately, the native Stripe source synchronizes selected subscription, invoice, payment, refund, product, price, and customer/billing fields—including Stripe object identifiers and contact fields present in those tables—under restricted operator access. PostHog may use a browser request IP for coarse GeoIP enrichment, after which our project setting discards the source IP.
- Flodesk — lifecycle and product-update email (only to recipients who have given the appropriate consent).
- Reddit — server-side conversion measurement for paid acquisition. We send a hashed (never plaintext) email together with standard request data (IP address, browser user agent) and Reddit's own ad-click identifier, used solely to attribute conversions to ads.
We do not sell personal data and we do not authorize subprocessors to use your data for purposes outside the Service.
International Data Transfers
Moshi Inc. is incorporated in the United States and most of our subprocessors are also U.S.-based. Where we transfer personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland to a country outside that region, we rely on one or both of the following safeguards:
- The EU–U.S. Data Privacy Framework (and the UK Extension / Swiss Addendum) where the recipient is certified.
- The European Commission's Standard Contractual Clauses (Module 2 controller-to-processor) supplemented by appropriate technical and organizational measures.
PostHog analytics and Stripe-source data are sent to its EU Cloud region. Browser analytics reaches that service through PostHog's managed d.img.pro proxy using credentialless requests, so img.pro session cookies are not sent with analytics traffic. We do not enable that processing for covered transfers until the applicable PostHog DPA, Standard Contractual Clauses, and UK terms have been accepted and archived. In strict or unknown jurisdictions the browser SDK is not loaded until you opt in; the bounded server outcomes and Stripe billing source do not read or write browser storage.
You may request a copy of the transfer mechanism that applies to a specific subprocessor by emailing privacy@img.pro.
Your Rights
Depending on where you live, you may have some or all of the following rights. We will respond to verifiable requests within the time frame required by applicable law (generally 30 days under GDPR; 45 days under CCPA/CPRA).
European rights (GDPR / UK GDPR)
- Access — Receive a copy of your personal data
- Rectification — Correct inaccurate or incomplete data
- Erasure - Delete your account and associated data. Self-serve at Settings → Danger Zone; reversible for 7 days via the email link we send.
- Portability — Export your data in a machine-readable format
- Restriction — Limit how we process your data while a question is being resolved
- Objection — Object to processing based on legitimate interests, including profiling
- Withdraw consent — At any time, without affecting prior processing
- Lodge a complaint — With your local data-protection authority (in the EU, you can find the list at edpb.europa.eu)
California rights (CCPA / CPRA)
- Right to know — Categories and specific pieces of personal information collected, sources, business purposes, and third parties to whom it is disclosed
- Right to delete — Subject to legal retention exceptions
- Right to correct — Inaccurate personal information
- Right to opt out of sale or sharing — We do not sell or share your personal information for cross-context behavioral advertising; we honor the Global Privacy Control signal
- Right to limit use of sensitive personal information — We do not use sensitive personal information beyond what is necessary to provide the Service
- Right to non-discrimination — We will not deny service, charge a different price, or provide a different quality of service for exercising any of these rights
To exercise any of these rights, email privacy@img.pro from the address on file with your account, or use the in-app data-export and account-deletion tools when available. If you are an authorized agent acting on behalf of a California resident, include written authorization with your request.
Children
img.pro is not intended for children under 16 years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@img.pro and we will delete it.
Changes to this Policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated through in-app notice or email to the address on file.
Contact
For privacy questions, requests, or complaints: privacy@img.pro. Mailing address: Moshi Inc., 4023 Kennett Pike #50475, Wilmington, DE 19807, United States.