Data Controller
The data controller for img.pro is:
Moshi Inc.
4023 Kennett Pike #50475
Wilmington, DE 19807
United States
Contact for privacy matters: privacy@img.pro.
Overview
img.pro is an image hosting and CDN service. This policy explains what data we collect, how we use it, the legal bases on which we rely, and your rights regarding your information.
- We collect minimal data necessary to provide the service
- We do not sell or share your personal information for cross-context behavioral advertising
- We do not use your images for advertising
- We do not track visitors to sites using our CDN
Information We Collect
Account Data
- Email address — Account identification, important notifications
- Name — Personalization, team collaboration
- Authentication state — Session tokens and one-time sign-in codes (we are passwordless; no passwords exist to store). API keys are stored hashed
- Consent records — Timestamp and country at signup, indicating which optional consents you granted (e.g., marketing email)
Usage Data
- Image upload counts and storage used — Quota tracking
- Upload origin — IP address, user agent and, where available, country recorded with each image upload, for abuse investigation and for reporting illegal content to the authorities (kept with the image record; see Retention below)
- API request logs — Debugging, abuse prevention (retained ~30 days)
- Product analytics — Sanitized page and interaction activity, device/performance data, session replay, browser errors, and a bounded set of categorical product outcomes. Signed-in custom events use opaque account, app, and workspace identifiers rather than names or email addresses. Replay may include ordinary visible UI text and non-password input values.
- Billing analytics — Subscription, invoice, payment, refund, product, price, and customer/billing fields made available by our Stripe account, including Stripe object identifiers, so we can connect product use to realized revenue and subscription health. Access is restricted to authorized operators.
What We Don't Collect
- We don't track individual visitors to websites using our CDN
- We don't store visitor IP addresses from CDN requests — viewing or downloading an image records nothing about who requested it (uploading one does; see Upload origin above)
- We don't profile or sell information derived from your images
Legal Bases for Processing (GDPR / UK GDPR)
Where the General Data Protection Regulation or the UK GDPR applies, we process personal data under the following bases:
- Performance of a contract (Art. 6(1)(b)) — for account creation, authentication, image hosting and delivery, billing, and customer support.
- Legitimate interests (Art. 6(1)(f)) — for security, abuse prevention, content-safety classification, fraud detection, and limited browser analytics where applicable law permits an opt-out model. We balance these against your rights and use data minimization, retention limits, Global Privacy Control, and preference controls to keep the impact proportionate.
- Consent (Art. 6(1)(a)) — for non-essential browser analytics and marketing trackers where prior consent is required, and for marketing email. You can withdraw consent at any time without affecting prior processing.
- Legal obligation (Art. 6(1)(c)) — for tax records, responding to lawful requests, and statutory reporting (including, where applicable, mandatory reporting of CSAM under 18 U.S.C. §2258A).
How We Use Your Information
- Service delivery: Storing and serving your images via our CDN
- Account management: Authentication, team invitations, email verification
- Security: Detecting abuse, preventing fraud, protecting infrastructure
- Content safety: Automated classification of uploaded images to detect violations of our Acceptable Use Policy. Classifications inform whether content is flagged, hidden behind a viewer-side warning, subject to a reduced retention window, or removed from public serving. A state-changing manual override records the authenticated operator, action, resulting decision, and any applicable structured category; merely opening or reviewing an item without changing its state creates no event. See the Retention section for how classifications interact with retention.
- Product and revenue analytics: Understanding acquisition, activation, retention, product quality, app/workspace performance, subscription conversion, realized revenue, and refunds; diagnosing errors and performance regressions; and deciding what to improve.
- Communications: Transactional notifications (verification, billing, security alerts) sent via Amazon SES; optional product updates sent via Flodesk only where you have given consent (or, in jurisdictions that permit it, on an opt-out basis).
Data Storage and Security
- Images: Stored on Cloudflare R2 (encrypted at rest)
- Databases: Cloudflare D1 with encryption at rest
- Transit: All connections use TLS/HTTPS encryption
- Authentication secrets: API keys are stored hashed. Session tokens and one-time sign-in codes are stored as issued, so that a session can be validated and revoked — both are short-lived and are deleted on expiry, sign-out, or account deletion
Retention
How long we retain personal data depends on its purpose, any image expiry you choose, deletion of an image or account, and applicable content-safety, recovery, billing and legal requirements. Your subscription tier does not determine ordinary image retention.
- Authenticated user uploads: retained until you delete the image or close your account, unless an earlier expiry was explicitly set for the image, or the image is blocked under the Acceptable Use Policy. Ordinary blocked content receives a maximum lifetime of 24 hours from upload, regardless of subscription tier; an earlier expiry you selected still wins. A sensitive-content flag by itself changes presentation through blur-and-reveal controls and does not shorten retention. CSAM is handled under a separate legally required preservation and reporting process rather than this ordinary blocked-content window.
- Legacy uploads created without an account: new anonymous uploads are no longer accepted. Existing rows remain in their current bucket; any expiration already recorded on them continues through the normal cleanup lifecycle, and no ownership-transfer or claim process remains.
- Image bytes after deletion or retention expiry: moved to a private operator-recovery store to allow recovery from accidental or contested removals. Ordinary deleted images have a 90-day recovery window; images removed after their chosen expiry have a 30-day recovery window. Each window starts when the recovery copy is stored, which can be later than the deletion or expiry. After the window, that copy becomes eligible for automatic removal. Content in operator-recovery is no longer served from our public-facing CDN. Legal preservation follows the separate process described above.
- Account data: We retain account data while your account is active. You can request deletion from Profile and reverse it during the grace period using the recovery link we email you. After that period, your account and owned App and bucket data become eligible for automated erasure. Completion may be delayed while required billing, preservation or recovery steps finish. Some records remain for the recovery, billing, analytics, abuse-prevention and legal purposes described in this policy.
- Sessions: a sliding expiry of approximately three months, with a hard maximum of approximately twelve months from sign-in — after that a fresh login is required. Session records contain the token, account reference, and lifecycle timestamps; we do not retain a sign-in IP address or browser identifier on them. Expired sessions are purged automatically on a recurring sweep and hard-deleted at submit when you delete your account.
- Image records and upload origin: captions, custom metadata, and the upload IP address, browser identifier and country remain with the image record during recovery. After ordinary deletion or expiry, the record becomes eligible for automatic erasure when its recovery window has ended and the original and derivative bytes have been removed. Existing eligible records follow the same cleanup. Unresolved abuse cases, account holds and legal preservation prevent ordinary erasure; operational failures can delay completion. App, bucket or account deletion may erase ordinary records earlier through its separate cleanup process. Uploads into another owner's storage follow that storage's lifecycle. Historical image counts can shrink as records are erased. Billing, report and compliance records follow their separate policies.
- Worker / API request logs: approximately one month.
- Stripe billing records: retained on Stripe's side for approximately ten years for tax and accounting reasons (legal-obligation exception under GDPR Art. 17(3)(b)). For Stripe Customers attached to buckets your account owns, account deletion makes a best-effort attempt to clear the PostHog person-attribution key from each non-terminal Subscription before canceling it, then scrubs the Customer record's identifying fields (name, email, phone, address). Billing details you entered as an admin of somebody else's bucket remain records of that bucket and are not canceled or scrubbed by deleting your membership account; email privacy@img.pro for access or deletion requests concerning those payer details. Stripe may refuse a metadata change on an already-terminal historical Subscription, or a transient Stripe failure may prevent the pre-cancel cleanup; opaque app/workspace attribution and the historical invoice ledger remain for aggregate revenue, tax, and accounting records. Any surviving PostHog person join is covered by the vendor-side access and erasure process below.
- PostHog product and revenue analytics: browser-storage lifetime and controls are listed at /cookies. Rejecting analytics or deleting your account clears PostHog persistence in that browser and stops future browser collection and browser-to-server journey linkage. A bounded set of pseudonymous server outcomes remains separate from that browser preference because it uses no browser storage: media processing, account verification, App API outcomes, billing handoffs, and subscription changes. Stripe billing-source records used for revenue analysis are also separate from browser storage and may include Stripe identifiers and customer/billing fields. Browser opt-out does not unwind a transaction or a revenue join already received. Previously received analytics may remain until the configured project-retention period expires; request access, object to server analytics, or request vendor-side erasure by emailing privacy@img.pro.
- Abuse and DMCA records: retained for the rolling 12-month repeat-infringer policy and any pending counter-notification window. If you filed the report, your email address on it is replaced with a placeholder at deletion. Other details submitted with a report — the reporter's name, IP address and browser identifier — are kept, because the record has to stay defensible as filed.
Subprocessors and Third-Party Services
To deliver the Service we share limited data with the following processors under their applicable contractual and data-protection terms. The current list is also maintained at /subprocessors.
- Cloudflare — image hosting, CDN, databases, edge compute (R2, D1, Workers, KV), and background bot protection on sign-in, signup, and public marketing pages (Turnstile — evaluates request signals such as IP address, TLS fingerprint, and user agent; see Cloudflare's Turnstile Privacy Addendum).
- Amazon Web Services — transactional email delivery (SES) and automated content-safety classification (Rekognition) on uploaded images. Image data is transmitted only for the duration of the classification request; we do not authorize this processor to retain images for model training.
- Stripe — payment processing for paid subscriptions; collects payment-method data directly from your browser.
- PostHog Cloud EU — browser product analytics, funnels and retention, heatmaps, error and performance diagnostics, session replay, bounded server-side product outcomes, and Stripe-backed revenue analysis. The custom browser/server event stream uses sanitized route templates and referrer origins, bounded campaign dimensions, and opaque account/app/workspace identifiers; it excludes image content, filenames, captions, request bodies, account names and emails, IP properties, credentials, authorization codes, Stripe identifiers, internal numeric IDs, and exception text. Autocapture text is separately suppressed before event delivery. Session replay follows our PostHog project’s text/input masking setting and may include ordinary visible UI text and non-password input values. Matched media elements, hidden inputs, selected token/identifier-bearing elements, and designated private regions remain blocked client-side. Page, replay-timeline, network, and performance URLs handled by our sanitizer are reduced to query-free route templates or external origins; network request/response headers and bodies are removed in-browser before replay upload; session-replay console and canvas capture are disabled. Separately, the native Stripe source synchronizes selected subscription, invoice, payment, refund, product, price, and customer/billing fields—including Stripe object identifiers and contact fields present in those tables—under restricted operator access. PostHog may use a browser request IP for coarse GeoIP enrichment, after which our project setting discards the source IP.
- Flodesk — lifecycle and product-update email (only to recipients who have given the appropriate consent).
- Reddit — consent-controlled browser PageVisit measurement and server-side conversion measurement for paid acquisition. Browser measurement sends page-visit and standard request data when the Reddit pixel is enabled. Server conversions send a hashed (never plaintext) email together with IP address, browser user agent, event metadata, and, when marketing consent permits, Reddit's ad-click identifier if one is present. These signals are used solely to measure and attribute advertising.
We do not sell personal data and we do not authorize subprocessors to use your data for purposes outside the Service.
International Data Transfers
Moshi Inc. is incorporated in the United States and most of our subprocessors are also U.S.-based. Where we transfer personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland to a country outside that region, we rely on one or both of the following safeguards:
- The EU–U.S. Data Privacy Framework (and the UK Extension / Swiss Addendum) where the recipient is certified.
- The European Commission's Standard Contractual Clauses (Module 2 controller-to-processor) supplemented by appropriate technical and organizational measures.
PostHog analytics and Stripe-source data are sent to its EU Cloud region. Browser analytics reaches that service through PostHog's managed d.img.pro proxy using credentialless requests, so img.pro session cookies are not sent with analytics traffic. The applicable PostHog Data Processing Agreement, Standard Contractual Clauses, and UK terms have been accepted and archived with our compliance records. In strict or unknown jurisdictions the browser SDK is not loaded until you opt in; the bounded server outcomes and Stripe billing source do not read or write browser storage.
You may request a copy of the transfer mechanism that applies to a specific subprocessor by emailing privacy@img.pro.
Your Rights
Depending on where you live, you may have some or all of the following rights. We will respond to verifiable requests within the time frame required by applicable law (generally 30 days under GDPR; 45 days under CCPA/CPRA).
European rights (GDPR / UK GDPR)
- Access — Receive a copy of your personal data
- Rectification — Correct inaccurate or incomplete data
- Erasure - Delete your account and associated data. Self-serve at Settings → Danger Zone; reversible for 7 days via the email link we send.
- Portability — Export your data in a machine-readable format
- Restriction — Limit how we process your data while a question is being resolved
- Objection — Object to processing based on legitimate interests, including profiling
- Withdraw consent — At any time, without affecting prior processing
- Lodge a complaint — With your local data-protection authority (in the EU, you can find the list at edpb.europa.eu)
California rights (CCPA / CPRA)
- Right to know — Categories and specific pieces of personal information collected, sources, business purposes, and third parties to whom it is disclosed
- Right to delete — Subject to legal retention exceptions
- Right to correct — Inaccurate personal information
- Right to opt out of sale or sharing — We do not sell or share your personal information for cross-context behavioral advertising; we honor the Global Privacy Control signal
- Right to limit use of sensitive personal information — We do not use sensitive personal information beyond what is necessary to provide the Service
- Right to non-discrimination — We will not deny service, charge a different price, or provide a different quality of service for exercising any of these rights
To exercise any of these rights, email privacy@img.pro from the address on file with your account, or use the in-app data-export and account-deletion tools when available. If you are an authorized agent acting on behalf of a California resident, include written authorization with your request.
Children
img.pro is not intended for children under 16 years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@img.pro and we will delete it.
Changes to this Policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated through in-app notice or email to the address on file.
Contact
For privacy questions, requests, or complaints: privacy@img.pro. Mailing address: Moshi Inc., 4023 Kennett Pike #50475, Wilmington, DE 19807, United States.