Privacy Policy
How Imagelier collects, uses and protects your images, account data, payments and analytics data, which processors we use, and your privacy rights.
2026/09/30
Overview
Imagelier is an AI image text editor for replacing text inside images. This Privacy Policy explains what data we collect, why we use it, which processors help us run the service, and how long image task data is retained.
Imagelier is built for legitimate image updates such as menu changes, product visuals, posters, UI documentation, and localization drafts. Do not upload content you do not have the right to process.
Data We Collect
We collect the minimum data needed to provide the service:
- Account data: name, email address, login provider identifiers, session data, and account settings.
- Image task data: uploaded image URLs or storage keys, detected OCR regions, submitted replacement text, output image URLs or storage keys, task status, timestamps, error codes, and usage metadata.
- Payment data: Stripe customer id, subscription id, checkout session id, invoice id, price id, subscription status, and billing-cycle timestamps. Full card details are processed by Stripe and are not stored by Imagelier.
- Usage and device data: IP-derived anonymous identifiers, browser details, page events, editor events, checkout events, and coarse diagnostic logs.
- Acquisition source: when you arrive from another website or from a link
tagged with
utm_source, the domain of that website (for examplebing.com), the tag, and the page you landed on. This visit record is kept for 24 hours under a one-way hash of your IP address and browser, and is linked to your account only if you sign up within that time. - Support data: messages you send through contact or support channels.
How We Use Data
We use data to:
- provide upload, OCR, AI inpainting, rendering, and download features;
- operate Free and Pro access, quotas, watermarks, and billing;
- detect abuse, rate-limit anonymous usage, and enforce the Terms of Service;
- send account, verification, billing, and support emails;
- understand product reliability and conversion funnels;
- understand which websites and campaigns bring new users;
- respond to privacy, deletion, export, refund, and support requests.
Image Processing and Retention
Imagelier stores image task data only for product operation, debugging, abuse prevention, and the retention promises below.
- Anonymous and Free task objects: cleaned after 24 hours where the task tier is known or cannot be safely identified.
- Pro task objects: retained for up to 30 days so users can recover recent work and so support can investigate failed paid tasks.
- Expired task records: associated object references are deleted or marked stale when cleanup runs.
- Acquisition source: the temporary visit record is deleted after 24 hours. The source saved with an account (domain, tag, and landing page only) is kept for the life of the account and deleted with it.
If the system cannot determine whether a task is Pro, it uses the shorter retention window. Backups, provider logs, and security logs may retain limited metadata for longer where required for security, accounting, or legal obligations.
OCR Provider Disclosure
Image OCR is processed by Microsoft Azure AI Vision (Read) by default. Image
data is sent to Microsoft's servers for text recognition. If Azure is
unavailable, Imagelier falls back to Alibaba Cloud OCR (RecognizeAdvanced),
hosted in China, and then to Baidu AI Studio hosted PP-OCRv5, also located in
China. Imagelier does not create a separate long-lived OCR copy beyond the
retention periods described in this policy. Processing and retention by these
providers are governed by their data processing terms, including Alibaba
Cloud's Data Processing Agreement
(https://www.alibabacloud.com/help/en/legal/latest/data-processing-agreement).
If self-hosted OCR is activated later, image OCR may instead be processed on infrastructure operated for Imagelier.
UK/EU user data may cross borders, including to China when a fallback OCR provider is used, under UK/EU GDPR Standard Contractual Clauses (SCC) or equivalent transfer safeguards. The processor list below identifies the OCR, storage, payment, email, and analytics providers currently used by the service.
Third-Party Processors
Imagelier uses these processors:
- Cloudflare: Workers, D1, R2, KV, CDN, and related infrastructure.
- Microsoft Azure AI Vision: default hosted OCR for text detection and coordinates.
- Alibaba Cloud OCR: hosted OCR when fallback OCR is active.
- Baidu AI Studio: hosted PP-OCRv5 OCR as a last-resort OCR fallback.
- Replicate: AI inference for inpainting, image restoration, typeface suggestions, and AI style (Pro), including third-party models served through Replicate (for example models from OpenAI and Alibaba Qwen).
- Stripe: checkout, subscriptions, invoices, customer portal, and payment processing.
- Resend: transactional email and newsletter/contact management.
- PostHog: product analytics and funnel diagnostics when analytics is configured.
- Feishu or Discord webhooks: operational notifications when configured.
We may update this list as the product changes. Material changes will be reflected in this policy.
International Transfers
Imagelier is operated from Cloudflare and SaaS infrastructure that may process data across regions, including the United States. UK/EU user data may be transferred outside the UK/EU. Where required, transfers rely on contractual and technical safeguards such as Standard Contractual Clauses and processor terms.
Using self-hosted OCR can reduce opaque third-party OCR processing, but it does not remove all cross-border processing constraints.
Cookies and Analytics
Imagelier uses essential cookies for authentication, security, locale preferences, and checkout continuity. Product analytics are used only when the configured analytics provider is enabled. Recording the acquisition source does not set cookies or store anything on your device. See the Cookie Policy for details.
Your Rights
Depending on your location, you may request:
- access to personal data we hold about you;
- correction of inaccurate data;
- deletion of your account and related task data;
- export of account-related data;
- restriction or objection to certain processing.
To make a request, contact us through the contact page. We may need to verify your identity before acting on the request.
Security
We use access controls, provider secrets, signed sessions, rate limits, and processor-level safeguards to protect the service. No internet service can guarantee perfect security, but we design Imagelier so image processing and task data are bounded and auditable.
Changes
We may update this Privacy Policy as Imagelier evolves. The date above shows the latest published update.
Contact
For privacy questions, deletion requests, or processor questions, contact us at contact.