Privacy Policy
Last updated: July 18, 2026
1. Overview
everyimg Studio (“we”, “us”, “our”) operates the website everyimg.studio — a browser-based image editor and a set of free image tools. This Privacy Policy explains what data is (and is not) processed when you use them.
2. Your images stay on your device
All editing runs locally in your browser. Opening, editing, applying filters, AI background removal, object removal, upscaling and exporting are performed on-device (WebAssembly/WebGPU). Your images are not uploaded to, stored on, or processed by our servers. Autosave, versions and recipes are stored locally in your browser’s private storage (OPFS/localStorage) and never leave your device.
3. Optional server AI (“Restore photo”)
One action is explicitly marked as running on a server: Restore photo. Only when you trigger it, the current image is transmitted over an encrypted connection and passed through — transient processing, we never write it to disk:
- Our API (hosted by Vercel) forwards the image in memory to the AI provider and streams the result back to you. No copy is retained on our side.
- The AI inference is performed by Replicate, Inc. (San Francisco, USA) as our processor under a data processing agreement with EU Standard Contractual Clauses. Replicate automatically deletes API prediction data — inputs, outputs and files — after at most one hour (Replicate data retention).
- If you don’t use “Restore photo”, no image data is ever transmitted anywhere.
4. Free daily budget & device cookie
The free daily budget for server AI is tracked with a signed, essential cookie (“eis_device”): a random device ID, the current day and a usage counter. It contains no personal data, is not used for tracking or advertising, and is strictly necessary to provide the free tier — therefore no consent banner is required (and we don’t show one).
5. Purchases (credits)
If you buy credits, payment is handled entirely by Stripe:
- Payment processing: Stripe Technology Company Ltd. (Dublin, Ireland) and its affiliates. Your payment details (card number etc.) are entered on Stripe’s hosted checkout page and never touch our servers. Stripe is certified under the EU-U.S. Data Privacy Framework; see the Stripe Privacy Policy.
- After a purchase we store your credit balance linked to your device ID, and the e-mail address from checkout as a recovery anchor (so you can restore credits on a new device). This data is stored in a managed database (Upstash, Inc., certified under the EU-U.S. Data Privacy Framework, processing under a DPA with Standard Contractual Clauses) for as long as your balance exists.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
6. Analytics — cookieless
We use Plausible Analytics — a privacy-friendly, EU-based service that works without cookies and without persistent identifiers. It gives us aggregate statistics (page views, tool usage) and cannot identify you.
7. Hosting
The website and API are hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA), which processes technical access data (such as IP addresses in server logs) for operation and security, as described in the Vercel Privacy Policy. Vercel participates in the EU-U.S. Data Privacy Framework.
8. Your rights (GDPR)
Under the General Data Protection Regulation you have the right to:
- Access your personal data
- Rectification of inaccurate data
- Erasure of your data (“right to be forgotten”)
- Restriction of processing
- Data portability
- Object to processing
To exercise any of these rights, contact us at info@everyimg.studio. You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali.
9. Data controller
Christian Lechner
Allitzstraße 25, 39023 Laas (BZ), Italy
Email:
info@everyimg.studio