Privacy Policy
This policy explains how TinyImage handles your files and information. Our image and PDF tools use browser-based and server-assisted processing. Some conversion and compression workflows store files temporarily so you can download them.
Last updated and effective: August 14, 2026
Who We Are
TinyImage is operated by Glaxosoft LLC. If you have questions about this policy or want to make a privacy request, contact us at support@tinyimage.io.
Information We Collect
We collect information needed to provide TinyImage, including account details such as email address, display name, authentication provider, subscription status, API key metadata, quota usage, support messages, and billing-related identifiers. Payment card details are handled by Stripe and are not stored by TinyImage.
We also collect usage and technical data such as IP-based rate-limit identifiers, browser and device information, requested routes, file type, file size, processing status, error details, timestamps, and authentication status. This helps us operate the service, prevent abuse, debug issues, and improve reliability.
Temporary File Storage
When a tool creates a stored download link, uploaded and generated media may be kept temporarily in Firebase Storage. Those stored files are automatically deleted after 24 hours. A specific file may be retained beyond that period only when preservation is required by law or is necessary to investigate a documented security, fraud, or abuse incident. Any preserved copy is access-restricted and deleted when the legal hold ends or the investigation and any resulting claim are resolved. Uploaded and generated media is excluded from routine backups and is not retained merely for a billing dispute, chargeback, or support request.
When you submit image URLs or use server-powered tools, TinyImage may fetch, analyze, convert, optimize, or temporarily cache the files needed to complete your request. We do not use uploaded media content for advertising or model training.
Private Access and Signed URLs
Files placed in temporary storage are not publicly listed. Download access is provided through signed URLs that expire. Signed URLs may be generated for anonymous users and signed-in users, and storage paths are scoped to the request, user, or temporary visitor identifier.
Account and Anonymous Uploads
You can use many tools without an account. Anonymous requests may use temporary identifiers for quota and abuse prevention. Signed-in users may have files associated with their account identifier for the same temporary 24-hour processing window.
Ownership
You retain ownership of files you upload and files generated from them. Temporary storage does not transfer ownership to TinyImage.
Security Practices
For workflows that store files, we use Firebase Storage, private cache controls, signed download URLs, and automatic lifecycle cleanup. Access to operational systems is limited to authorized maintainers.
No method of transmission or electronic storage is completely secure, so we cannot guarantee absolute security. You should keep your account credentials and API keys confidential.
Analytics and Logs
Server logs may include request metadata such as route, timing, file type, file size, error details, IP-based rate-limit identifiers, and authentication status. Logs are used for security, debugging, abuse prevention, and service reliability. We do not use uploaded media content for advertising or model training.
Cookies and Local Storage
TinyImage may use cookies, local storage, and similar technologies to keep you signed in, remember interface preferences, support security features, measure usage, and prevent abuse. You can control cookies through your browser settings, but some account or security features may not work correctly if cookies are disabled.
How We Use Information
We use information to provide image and PDF tools, manage accounts and subscriptions, issue and protect API keys, process support requests, enforce quotas, detect and prevent abuse, monitor service performance, troubleshoot technical issues, comply with legal obligations, and communicate service or policy updates.
Service Providers
We use trusted providers to operate TinyImage, including Firebase and Google Cloud for authentication, database, storage, hosting, and infrastructure services, Stripe for subscription billing and payment processing, and Google Fonts for font delivery. These providers process information only as needed to provide services to us and are governed by their own privacy and security terms.
Retention
We use the following retention periods or deletion criteria:
- Uploaded and generated media placed in temporary file storage, meaning file content and cached copies rather than related account, billing, report, or log metadata, is retained for up to 24 hours, subject only to the limited hold described above.
- Account profile, authentication, quota, and API key metadata is retained while the account is active and deleted or anonymized within 30 days after a verified account-deletion request.
- Published analyzer reports are retained until you delete the report or your account. A deleted report is immediately unpublished; its residual record is retained for up to 90 days for restoration, abuse prevention, and dispute handling, then deleted or anonymized.
- Security, rate-limit, and operational logs are retained for up to 90 days, unless an entry is linked to an active security investigation or legal claim.
- Support communications are retained for up to three years after the request is closed so we can maintain context and resolve follow-up disputes.
- Billing, transaction, invoice, chargeback, and tax records are retained for seven years after the relevant transaction or the end of the customer relationship, whichever is later.
- Backup copies of non-media records are removed through the applicable provider's backup-rotation cycle, ordinarily within 90 days after deletion from active systems. Uploaded and generated media is excluded from routine backups.
If a record is subject to a legal hold, fraud or security investigation, chargeback, or active dispute, we retain only the information relevant to that matter until the obligation expires or the matter and any resulting claim are resolved. Access is restricted during the hold, and the record is then deleted or returned to its ordinary retention schedule. This rule applies to account, billing, support, report, and log records. A chargeback or active dispute does not extend media retention unless the specific media also meets the limited legal, security, fraud, or abuse hold criteria stated under Temporary File Storage.
Account Controls
Signed-in users can update profile details or request account deletion from account settings. Anonymous users, or anyone with a privacy request that account settings cannot handle, can contact us at support@tinyimage.io. Processed files placed in temporary storage remain covered by the 24-hour lifecycle cleanup.
Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, object to, or restrict the processing of your personal information. You may also have the right to withdraw consent where processing is based on consent. We may ask you to verify your identity before responding to a request.
For users in the European Economic Area, United Kingdom, or similar jurisdictions, our legal bases may include performance of our contract to provide requested tools, accounts, subscriptions, and payment-related services; compliance with legal obligations for tax, accounting, fraud, and lawful requests; our legitimate interests in securing, maintaining, and improving TinyImage where those interests are not overridden by your rights; and consent where we specifically request it. Payment processing is a processing purpose supported primarily by contract performance, with related records also processed where necessary to meet legal obligations.
EEA and UK users also have the right to lodge a complaint with a data protection supervisory authority. EEA users may contact the authority in the country where they live or work or where the alleged infringement occurred. UK users may contact the Information Commissioner's Office. You may contact us first at support@tinyimage.io, but you are not required to do so before contacting an authority.
Data Transfers
TinyImage is operated by Glaxosoft LLC and may process information in the United States and other locations where our service providers operate. Data protection laws in those locations may differ from the laws where you live. For transfers from the EEA or UK, we rely on an applicable adequacy decision or regulation where available. Otherwise, we use applicable contractual safeguards, including the European Commission's Standard Contractual Clauses for EEA transfers and the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses for UK transfers, together with required transfer assessments and supplementary measures. To request information about the mechanism that applies to a transfer or a copy of the relevant safeguards, contact support@tinyimage.io.
Legal Disclosures
We may disclose information if we believe it is necessary to comply with law, respond to legal requests, protect the rights, property, or safety of Glaxosoft LLC, TinyImage users, or the public, investigate misuse, enforce our terms, or protect against legal liability.
Links to Other Sites
TinyImage may link to third-party websites or services. We are not responsible for the privacy practices, content, or security of sites and services that we do not operate.
Children's Privacy
TinyImage is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to TinyImage, contact us so we can take appropriate action.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will post the updated policy on this page and update the date shown above. For material changes, we will provide advance notice through the email address associated with your account, an account notice, or a prominent in-product banner. The updated policy becomes effective on the date stated at the top of this page or on a later date identified in the notice.