Privacy Policy
PicForge is built so your images stay on your device. This page explains exactly what the tools process, what the optional analytics measure, how sharing an image into the app works, and the choices you have.
The short version
Every deterministic tool — resize, compress, crop, rotate, convert, social sizes, favicon, ID photo, EXIF, filters, watermark, editor, viewer, blur/censor, color picker, GIF frames and merge PDF — runs entirely in your browser. Your image bytes never leave your device.
There are no accounts and no cookies, and no image or setting is stored on a server. Image data leaves your device only when you start it: a cloud AI feature you explicitly opt into (a downscaled copy, after consent), or sending a file to PicForge from your phone’s share sheet — a memory-only hand-off that is never stored or logged (see “Sharing an image into PicForge” below).
What we process
When you open an image, it is read and processed in your browser using Canvas, WebAssembly and background workers. Nothing is uploaded. Tool settings are stored in your browser’s localStorage (keys such as pf:tool:<id>) and can be removed by clearing site data.
We do not ask for an account, an email address, or any other identifier, and we do not sell or share data.
Analytics: what we measure
Analytics answer questions like “which tools are used?” and “where do errors happen?”. They are cookieless and aggregate: no cookies, no fingerprinting and no per-user profiles.
When analytics are enabled, the app may send these events: page_view, tool_open, file_selected, input_rejected, process_start, process_success, process_error, download, ai_opt_in, ai_opt_out, ai_result, offline_used, setting_changed, web_vital and js_error.
Sizes and dimensions are rounded into buckets before leaving the device. File size: under 100 KB, 100–500 KB, 500 KB–2 MB, 2–10 MB or over 10 MB. Image size: under 1 MP, 1–5 MP, 5–12 MP, 12–25 MP or over 25 MP. Batch size: 1, 2–5, 6–20 or 21–50.
Settings are reported only as the setting key when it changes from its default value — never the value itself. Filenames, EXIF, GPS, pixel data, clipboard contents and user identifiers are never collected, and a unit test enforces that the payload builder only emits allowlisted keys.
The transport is same-origin and disabled by default: unless this deployment has configured a collector endpoint, no telemetry request is made at all. You can turn analytics off at any time with the toggle in the footer. The preference is stored locally as pf:analytics and takes effect immediately. Do Not Track and Global Privacy Control force analytics off, with no override.
Optional AI features
Remove Background and Blur/Censor can optionally use an AI service for higher-quality results. AI is off by default and requires your explicit consent for each browser session.
Only after you consent, a downscaled copy (up to 1536 px on the long edge) of the selected image is sent to the AI service configured for this deployment, solely to compute the result. The service is stateless: the result returns to your browser, and image data is not retained.
If you decline, the local on-device alternatives remain fully available: manual background removal, manual censor regions and on-device models that load from this site. Consent is revocable at any time and ends when the session ends. While offline, cloud AI is unavailable.
Your controls
- Analytics: turn them off in the footer; the change applies immediately.
- AI consent: granted and revoked per session from the consent panel.
- Sharing into the app: only when you start it from your device’s share sheet; the file is relayed in memory and never stored or logged.
- Local settings: stored on your device; clearing site data removes them.
- No data sale, no ads, no tracking pixels and no third-party scripts.
Changes to this policy
If this policy changes, the “last updated” date changes with it. Material changes will be summarized on this page.
Last updated: 2026-09-15