Skip to main content
PicForge

Privacy Policy

PicForge is built so your images stay on your device. This page explains exactly what the tools process, what the optional analytics measure, how sharing an image into the app works, and the choices you have.

The short version

Every deterministic tool — resize, compress, crop, rotate, convert, social sizes, favicon, ID photo, EXIF, filters, watermark, editor, viewer, blur/censor, color picker, GIF frames and merge PDF — runs entirely in your browser. Your image bytes never leave your device.

There are no accounts and no cookies, and no image or setting is stored on a server. Image data leaves your device only when you start it: a cloud AI feature you explicitly opt into (a downscaled copy, after consent), or sending a file to PicForge from your phone’s share sheet — a memory-only hand-off that is never stored or logged (see “Sharing an image into PicForge” below).

What we process

When you open an image, it is read and processed in your browser using Canvas, WebAssembly and background workers. Nothing is uploaded. Tool settings are stored in your browser’s localStorage (keys such as pf:tool:<id>) and can be removed by clearing site data.

We do not ask for an account, an email address, or any other identifier, and we do not sell or share data.

Analytics: what we measure

Analytics answer questions like “which tools are used?” and “where do errors happen?”. They are cookieless and aggregate: no cookies, no fingerprinting and no per-user profiles.

When analytics are enabled, the app may send these events: page_view, tool_open, file_selected, input_rejected, process_start, process_success, process_error, download, ai_opt_in, ai_opt_out, ai_result, offline_used, setting_changed, web_vital and js_error.

Sizes and dimensions are rounded into buckets before leaving the device. File size: under 100 KB, 100–500 KB, 500 KB–2 MB, 2–10 MB or over 10 MB. Image size: under 1 MP, 1–5 MP, 5–12 MP, 12–25 MP or over 25 MP. Batch size: 1, 2–5, 6–20 or 21–50.

Settings are reported only as the setting key when it changes from its default value — never the value itself. Filenames, EXIF, GPS, pixel data, clipboard contents and user identifiers are never collected, and a unit test enforces that the payload builder only emits allowlisted keys.

The transport is same-origin and disabled by default: unless this deployment has configured a collector endpoint, no telemetry request is made at all. You can turn analytics off at any time with the toggle in the footer. The preference is stored locally as pf:analytics and takes effect immediately. Do Not Track and Global Privacy Control force analytics off, with no override.

Optional AI features

Remove Background and Blur/Censor can optionally use an AI service for higher-quality results. AI is off by default and requires your explicit consent for each browser session.

Only after you consent, a downscaled copy (up to 1536 px on the long edge) of the selected image is sent to the AI service configured for this deployment, solely to compute the result. The service is stateless: the result returns to your browser, and image data is not retained.

If you decline, the local on-device alternatives remain fully available: manual background removal, manual censor regions and on-device models that load from this site. Consent is revocable at any time and ends when the session ends. While offline, cloud AI is unavailable.

Sharing an image into PicForge

If you have the app installed and use your device’s share sheet to send an image to PicForge, the file is relayed to your browser through our edge in memory only. It is never stored, logged, or processed on a server; the relay is limited to one image of up to 15 MB and is rate-limited.

As soon as the image reaches your browser it is held in memory for this tab only — exactly like a file you picked yourself — so you can choose a tool without selecting it again. It is never written to storage and is removed by “Remove image”, “clear all”, or closing the tab. Everything the tools do after that happens on your device.

Your controls

  • Analytics: turn them off in the footer; the change applies immediately.
  • AI consent: granted and revoked per session from the consent panel.
  • Sharing into the app: only when you start it from your device’s share sheet; the file is relayed in memory and never stored or logged.
  • Local settings: stored on your device; clearing site data removes them.
  • No data sale, no ads, no tracking pixels and no third-party scripts.

Changes to this policy

If this policy changes, the “last updated” date changes with it. Material changes will be summarized on this page.

Last updated: 2026-09-15