Privacy Policy

Privacy Policy

Effective: October 8, 2026

This policy explains what Iminify collects when you use https://www.iminify.com, why, how long we keep it, who else sees it, and what you can do about it. It applies whether you use the tool as a guest or with an account.

The short version

  • Your images are compressed on our own servers in the European Union. No other company receives them to compress them.
  • AI alt text is on unless you switch it off: a small copy of each image (at most 768 pixels on its longest side) goes to Anthropic, whose model describes it. Anthropic deletes it within 30 days and doesn't train on it.
  • We keep an upload and its optimized copy until you delete it. Nothing removes them on a timer.
  • An account holds your name, your email address, and a password hash or the Google, GitHub, Microsoft or Apple account you sign in with. A phone number and a profile photo are optional.
  • Pro is billed by Lemon Squeezy. We keep the card brand and its last four digits, never the card number.
  • Google Ads and Google Analytics cookies are set only with your consent if you're in the EEA, the UK or Switzerland, and can be switched off from the footer anywhere else.
  • If you arrive through an affiliate's link, a Lemon Squeezy script records that visit so a Pro purchase can be credited to the affiliate. It doesn't wait for the cookie banner.
  • If you connect an AI app to Iminify, it receives what it asks for (your images' details and links, the pages you scan, your usage) under its own privacy policy. You can disconnect it at any time.
  • We don't sell personal data, and we don't use your images for anything except the compression you asked for.

Who is responsible for your data

Iminify is run by Mozex Labs, which is the data controller for everything described here. Write to [email protected] for anything about your data: questions, requests, complaints.

What we collect and why

When you visit the site

Every request to the site carries your IP address, your browser's identification string, the page you asked for and the time. We use these to serve the pages, to protect the site against abuse, and to apply the daily limits, which are counted per IP address for guests. Cloudflare, which sits in front of the site, derives your country from the IP address and passes it to us; we use it to decide whether to show you the cookie banner and to preselect your country in the phone number field in Settings, and we don't store it.

Cloudflare also measures page views and page load times for us through Cloudflare Web Analytics. It sets no cookie and builds no profile; the numbers are aggregated. Cloudflare doesn't run that measurement for visitors it serves from its data centres in the European Economic Area, the United Kingdom or Switzerland.

Legal basis: our legitimate interest in running and protecting the Service. Retention: application logs are kept for 14 days, the daily counters for 24 hours, and error reports for at most 90 days at our monitoring provider.

When you compress an image as a guest

We store the image you upload, its name, size, dimensions and format, the options you chose, the optimized copy, and a link between the result and your browser session so the results table can show it to you. If you rename a result, we store the new name next to the original one and use it for the download. If you compress a result again with different settings, we store a copy of the original as a new result, so deleting either result leaves the other in place. Your IP address is used to count your daily uploads and AI alt texts, and a result compressed again counts as one upload.

Legal basis: providing the service you asked for. Retention: see "Your images" below.

When AI writes your alt text

AI alt text is switched on in the settings beside the upload box, and you can switch it off before you upload. It's on for images sent through the API and through an AI app you've connected as well, unless the request sets alt_text to false. While it's on, each image you compress gets a short description for its alt attribute and a suggested file name. We make a small copy of the image for this: at most 768 pixels on its longest side, re-encoded, with its metadata removed. That copy, and the language you picked, go to Anthropic's API, where the Claude Haiku model writes the description and the name. We store both with the result, with the language, and with a fingerprint of the original file (a SHA-256 hash) so an image we've already described isn't sent again. The small copy is deleted from our server as soon as the answer arrives, or after a day if something goes wrong. A suggested name only renames your download if you turned on "Rename files", click "Use this name", or the request asked for it.

Anthropic processes the copy for us under its data processing agreement. It deletes what it receives and returns within 30 days, keeps it longer only if its safety systems flag it as a breach of its usage policy (then for up to 2 years) or when the law requires, and its commercial terms forbid it to train models on it. A page scan sends Anthropic a small copy only of the images the page shows without any alt text, for the alt text its report suggests, and none if you switch alt text off before you scan.

Legal basis: providing the service you asked for. Retention: the description and the suggested name stay with the result until you delete it; Anthropic's copy at most 30 days in the normal course.

When you create an account

We store your name, your email address, a hash of your password if you set one (never the password itself), the time you verified your email, and, if you fill them in, a phone number and a profile photo. If you turn on two-factor authentication, we store its secret and your recovery codes, encrypted. If you tick "remember me", or sign in through one of the companies below, we store a token that keeps you signed in. Your history, every compression and page scan with its settings and outcome, is attached to the account.

For security we also keep a record of each signed-in session: its IP address, browser and last activity. You can see them all on the Sessions page in your settings and sign the other ones out. API tokens you create are stored hashed, with the name you gave each one and the time it was last used, which the API Tokens page shows you.

If we ever suspend the account, we record why. If Pro is granted to the account, we record the plan and the date it ends.

Signing in with Google, GitHub, Microsoft or Apple. You can sign up or sign in with an account you already have at one of these companies instead of a password. We send you to its page, and if you agree there, it sends us an identifier for your account with it, your name, your email address, whether it has verified that address, and the basic profile details it shares with every sign-in, such as the address of a profile picture. We keep the identifier and the email address it sent, to recognise you the next time, and use the name and email address for your Iminify account; nothing else it sends is kept. It never sends us your password there. If the address belongs to an Iminify account you already have and the company has verified it, you're signed into that account and the two are connected. If that account's address had never been verified, we treat the account as yours: we verify the address and remove the password, two-factor setup, other connected sign-ins, API tokens and connected apps anyone set up on it before. You can connect and disconnect these accounts in Settings, Sign-in methods, and choose a password in Settings, Password.

Legal basis: providing the account you asked for, and our legitimate interest in keeping accounts secure. Retention: until you delete the account.

When you buy Pro

The checkout belongs to Lemon Squeezy, our merchant of record. Lemon Squeezy collects your name, email address, billing address, payment details and any tax information the checkout asks for, and it emails you the receipt. It sends us a customer reference, the subscription's status, interval and renewal date, the card brand and its last four digits, the amount of each order and a link to its receipt. We store those to know which plan your account is on and when it ends, to answer billing questions, and to handle refunds and payment disputes.

Legal basis: performing the subscription contract; Lemon Squeezy has its own tax and accounting obligations for the invoices it issues. Retention: with your account; Lemon Squeezy keeps invoices for as long as tax law requires it to.

When you share a result

Each finished result has a Share action in its menu. Nothing happens until you confirm it. When you do, we give the result a random link of its own, record when you made it public, and from then on anyone who has the link can open a page showing the optimized copy, the original and a comparison of the two where a browser can draw the original (a HEIC or TIFF original is offered as a download only), their sizes, dimensions, format, the settings you chose and the date, and can download both files. They can also compress the original with settings of their own, which stores a copy of it as a result of theirs, under their session or account, exactly as if they had uploaded it; that copy is theirs to keep or delete and doesn't end when you stop sharing. No sign-in is needed for any of this. The link isn't listed anywhere on the site, the page tells search engines not to index it, and its images carry the same instruction, but anyone you or a later visitor pass the link to can open it. Stop sharing from the same menu at any time; the page and its images answer "not found" from then on. Deleting the result ends the share too. If you shared as a guest, you can stop sharing only while your session lasts; after that, email us the link and we'll switch it off.

Legal basis: providing the service you asked for. Retention: until you stop sharing or delete the result.

When you scan a page

We store the address you entered, the addresses of the images found on it with what the scan measured about each (its size, its format and how the page shows it), the images themselves as compressions, and any note about why a scan or an image failed. Our servers fetch the page and its images, so the site you scan sees our address, a browser signature, and the page address as the referring page. It never sees you.

On Pro you can share a scan's report. Nothing happens until you confirm it. When you do, we give the report a random link of its own and record when you made it public, and from then on anyone who has the link can open a page showing the report: the scanned page's address, the addresses and names of its images, what the scan measured about each, the AI alt text suggested for an image shown without one, and thumbnails of the compressed copies. No sign-in is needed, and nothing on the page can be downloaded or changed. The link isn't listed anywhere on the site, and the page and its thumbnails tell search engines not to index them. It answers "not found" while your account isn't on Pro, and for good once you stop sharing, on any plan, or delete the scan. A report's CSV and PDF are made when you download them; we don't keep a copy.

Legal basis: providing the service you asked for. Retention: until you delete the scan; a report's public link until you stop sharing or delete the scan.

When you use the API

The API does what the website does, with the token you send standing in for your signed-in browser, so everything above applies to it in the same way: an image you send is stored and kept like an upload and gets an AI alt text unless the request switches it off, a scan is kept like a scan, both are attached to your account, and both count against its daily limits. Each request carries your IP address and your token; the limits on requests per minute are counted per account.

When you give the API the address of an image instead of the file, our servers download it from that address, so the site that hosts it sees our address, and its own address as the referring page, never yours. The file is stored like any upload and named after the address, and the address is kept with it, so the result can say where it came from.

Legal basis: providing the service you asked for. Retention: as for uploads and page scans above; a token until you delete it or the account.

When you connect an AI app

Apps like Claude, ChatGPT and Cursor can use Iminify for you through our MCP server, which is another way into the API. Connecting one starts with the app registering itself with us, which stores the name it gives and the addresses it asks us to send you back to. You then approve it on a page of ours while signed in. The app gets an access token that works for an hour, and a refresh token that it trades for a new pair and that lasts 30 days. We store both, the app they belong to, and when the app last called, which Settings > Connected apps shows you. Disconnecting an app there stops its tokens at once. An app can also be set up with one of your API tokens instead, and then it's covered by the section above.

What the app does with your images is stored and counted exactly as for the API. When it sends one of your files to an upload link, we keep the file until the app compresses it, and delete it about a day after it arrived if it never does. The download links the app gets for your images work without signing in for an hour, so anyone who has one can download that image until it expires.

What the app asks us for, we send to it: your images' names, sizes, settings and links, their AI alt text and suggested file names, the addresses they were fetched from, the addresses of the pages you scan, and your plan and today's usage. Your name and email address aren't among them. The app, and the company that makes it, handle what they receive under their own terms and privacy policy, not ours, and they aren't our processors: you choose to connect them.

Legal basis: providing the service you asked for. Retention: tokens until they expire or you disconnect the app, then removed within a day (an expired one 31 days after it expired); files sent to an upload link about a day.

When you email us

We keep your address and what you wrote for as long as it takes to deal with it, and for a reasonable time afterwards in case the matter comes back.

Your images

Compression is automated. Software decodes the image, re-encodes it, and measures the result; nobody looks at what an image shows, and no outside service is ever sent an image to compress it. Every encoder we use runs on the machines that also store your files. The one copy that leaves is the small one AI alt text sends to Anthropic, described in "When AI writes your alt text", and only while that setting is on.

Your images are private unless you share one. A guest reaches them through the browser session that uploaded them; an account holder reaches them by signing in. A result you've shared is the exception you chose: anyone with its link can open it until you stop sharing (see "When you share a result"), and so is a page report you've shared, whose thumbnails show the scan's compressed copies (see "When you scan a page"). The other exception is us: the admin tools we use to run the Service show a thumbnail of every stored image and let us open the full-size file, and they let us sign in as an account to reproduce a problem the account holder has reported. We use that access to support you, to investigate abuse or a report about content, and when the law requires it. Files you download pass through Cloudflare on the way to you, over an encrypted connection.

By default the optimized copy has its EXIF metadata removed: camera details, location, dates. If you choose to keep it, the copy keeps it. The original file you uploaded keeps its metadata in storage either way.

An image may show other people. We don't know who they are, so we can't tell them their picture passed through Iminify. If you process images for a business or another organisation and they contain other people's personal data, that organisation is responsible for the data and we act as its processor; a data processing agreement is available on request.

Retention and deletion. Originals and optimized copies stay in storage until they're deleted. We don't delete them on a timer. Each image and each page scan in your results has a delete button; using it removes the record, the original and every optimized copy at once, and deleting a scan removes every image it found. Deleting your account removes all of them. Deletion is permanent: once a file has left storage, neither you nor we can get it back.

If you compressed images as a guest, your access to them ends with your browser session, about two hours after your last request or when you clear your cookies. The files stay in storage after that, unreachable by anyone but us, until we remove them. Email us the file name and roughly when you uploaded it and we'll delete it.

Cookies and similar technologies

Cookies are small files a website stores in your browser. These are the ones Iminify uses:

Cookie Set by What it does Lasts Needs consent
iminify_session Iminify Keeps you signed in, and holds a guest's results and your AI alt text settings from one page to the next 2 hours after your last request No
XSRF-TOKEN Iminify Protects forms against cross-site request forgery 2 hours No
remember_web_… Iminify Keeps you signed in when you tick "remember me" or sign in with Google, GitHub, Microsoft or Apple Until you sign out, at most 400 days No
iminify_consent Iminify Remembers the choice you made in the cookie banner 180 days No
theme (browser storage, not a cookie) Iminify Your light or dark mode choice Until you clear it No
iminify:docs-language (browser storage, not a cookie) Iminify The programming language you picked for the code samples in the API docs Until you clear it No
iminify_theme Iminify Tells our server whether you're in light or dark mode, so every page arrives already drawn in it 1 year No
cf_clearance Cloudflare Records that you passed a security check, so you aren't asked again 30 minutes No
ls_aff_ref Lemon Squeezy Set only when you arrive through an affiliate's link: remembers that visit so a Pro purchase is credited to the affiliate The referral period Lemon Squeezy sets Not asked
_gcl_au and other _gcl_ cookies Google Ads Link a click on one of our ads to what you then do on the site 90 days Yes
_ga, _ga_… Google Analytics Tell one visitor from another and count visits 2 years Yes
IDE, test_cookie and others on doubleclick.net and google.com Google Remarketing: showing our ads to people who have visited Up to 13 months Yes

The cookies that need consent come from Google's tags, which Google Tag Manager loads for us: the Google Ads tag measures our advertising, and Google Analytics shows how the site is used. Through them we report the pages you open and these moments:

  • you create an account, and whether you used a password or Google, GitHub, Microsoft or Apple, or verify its email address;
  • an image is queued for compression, with its file type, the compression level, the output format, whether it's resized, and the language of its AI alt text or that alt text is off;
  • you copy an AI alt text, or use the file name it suggests;
  • a page scan is queued;
  • you download a result, and how many images the download holds, or someone downloads a file from a shared page;
  • you make a result public, and each time its link is copied, handed to your device's own share sheet, or sent to a social network or by email from the site, with which one;
  • you reach the daily image, scan or AI alt text limit, or an upload is too large for your plan;
  • you open the Pro checkout, with the billing interval and its price;
  • you buy Pro, with the order number, the amount before tax, the currency and the interval.

Each page view also says which plan you're on: guest, free or Pro. Your images, file names, name and email address are never sent, and neither is the address of a page you scan. We don't load Tag Manager at all on the password reset page, because its address carries your reset link.

How consent works. If you're in the European Economic Area, the United Kingdom or Switzerland, Tag Manager and Google's tags don't load until you press Accept in the cookie banner. Reject is right next to it and does what it says; nothing about the site changes either way. Anywhere else they load unless you've said no. You can change your mind at any time from "Cookie settings" in the footer of every page, which turns them off and removes the Google cookies we can reach. If your browser sends the Global Privacy Control signal, we treat it as a no and don't ask.

Affiliate links. Some people recommend Iminify through Lemon Squeezy's affiliate programme, with links that carry ?aff= and a code. When you arrive through one, a Lemon Squeezy script on our pages works out an identifier from your browser's characteristics, sends it to Lemon Squeezy with the address of the page and the page you came from, and sets the ls_aff_ref cookie. If you then buy Pro, we pass that reference on to the checkout so the affiliate is credited. The script itself is downloaded from Lemon Squeezy on every page, which hands them your IP address and your browser's identification string the way any download does; on a visit that didn't come through an affiliate link and has no such cookie, it records nothing more. It runs whatever you chose in the cookie banner, but never on the password reset page or the email verification link, because their addresses carry a secret.

Third-party vendors, including Google, use cookies to show ads based on someone's earlier visits to our site. Google explains what it does with the data it collects on sites like ours at How Google uses information from sites or apps that use our services. You can switch off personalised ads from Google in Google's ad settings, and from other vendors on the Network Advertising Initiative's opt-out page.

Who we share data with

We share personal data only with the companies that help us run the Service, listed below, each of which is bound by a data processing agreement, and with authorities when the law requires it. If Iminify is ever sold, its data would go to the new owner under this policy, and we'd tell you first.

Provider What it does for us What it receives Where
Hetzner Online GmbH Runs our servers and object storage Everything the Service stores, including your images Germany
Cloudflare, Inc. Sits in front of the site: DNS, TLS, protection against attacks, page load measurement IP address and request data, page timings measured in your browser United States, with a global network; certified under the EU-U.S. Data Privacy Framework
Google LLC Google Tag Manager, advertising measurement and Google Analytics Pages opened, the events listed under cookies above, cookie identifiers, IP address, device details; only with your consent where it's required United States; certified under the EU-U.S. Data Privacy Framework
Lemon Squeezy (Sold through Link, LLC) Sells Pro as merchant of record, takes the payment and runs our affiliate programme Your name, email address, billing address, payment details and tax information; on every page, the IP address and browser identification string of the affiliate script's download; if you arrive through an affiliate's link, an identifier worked out from your browser, the page address and the page you came from United States; standard contractual clauses
Mailgun Technologies, Inc., a Sinch company Delivers the emails we send: verification, password resets, notices Your email address and the contents of those emails Processed in Mailgun's EU region; certified under the EU-U.S. Data Privacy Framework
Anthropic, PBC Writes the AI alt text and suggested file names A small copy of each image you compress while AI alt text is on (at most 768 pixels on its longest side, without metadata) and the language you picked United States; standard contractual clauses
Laravel Nightwatch (Laravel Holdings Inc.) Tells us when something breaks Error reports: the address and route that failed, the account that was signed in, the request's details, and the surrounding lines of our own code United States or European Union; standard contractual clauses

Each of them publishes its own privacy policy: Hetzner, Cloudflare, Google, Lemon Squeezy, Mailgun, Anthropic and Laravel.

When you sign in with Google, GitHub, Microsoft or Apple, that company isn't our processor: it runs the sign-in for you under its own privacy policy and records it there (Google, GitHub, Microsoft, Apple). We send it nothing about you beyond the request to sign you in.

We don't sell personal data, and we don't share it for advertising beyond the Google tags described above.

Where your data is processed

Our servers and our image storage are in the European Union, in Germany. Email is sent through Mailgun's EU region. Cloudflare handles requests at the network location nearest to you. The small copies AI alt text sends to Anthropic are processed in the United States.

Iminify is operated from outside the European Union, from a country that isn't covered by an EU adequacy decision, so the admin tools are read from there. That access is limited to what running the Service needs, happens over encrypted connections, and is covered by the commitments in this policy; it's necessary to provide the service you asked for (Article 49(1)(b) GDPR).

The providers based in the United States receive data under the EU-U.S. Data Privacy Framework where they're certified, and under the European Commission's standard contractual clauses otherwise, as listed in the table above.

How long we keep things

Data Kept for
Uploaded images, optimized copies, page scans Until you delete them, or until the account is deleted
AI alt text and suggested file names With the result they describe, until it's deleted
The small copy made for AI alt text On our server until the answer arrives, at most a day; at Anthropic at most 30 days, longer only if its safety systems flag it
Guest results Files until deleted; your access ends about 2 hours after your last request
Public links to shared results Until you stop sharing or delete the result
Public links to shared page reports Until you stop sharing or delete the scan; paused while the account isn't on Pro
Account details and history Until you delete the account
Connected sign-in accounts (the identifier and email address a company sent) Until you disconnect them, or until the account is deleted
API tokens Until you delete them, or until the account is deleted
Connected AI apps' tokens An hour (access) and 30 days (refresh) of use; removed within a day of disconnecting the app, 31 days after expiring, or with the account
Files an AI app sent to an upload link Until the app compresses them, or about a day
An AI app's registration (the name and callback addresses it gave, the same for everyone who connects that app) Until a day after the last token issued to it is removed
Signed-in sessions 2 hours after the last request; expired ones are cleared
Password reset links 1 hour
Daily usage counters 24 hours
Application logs 14 days
Records of failed background jobs, which carry a file name 7 days
Error reports at Laravel Nightwatch At most 90 days
Billing records from Lemon Squeezy With the account; Lemon Squeezy keeps its invoices as long as tax law requires
Google Analytics data As set in our Google Analytics account, at most 14 months

Security

Every connection to the site is encrypted, and Cloudflare filters attacks before they reach our servers. Passwords are hashed with bcrypt and never stored in the clear. Two-factor authentication is available in your settings, and its secrets are encrypted at rest. Access to the servers, the storage and the admin tools is limited to those who run the Service. Our software dependencies are checked against published security advisories, and the Service is monitored around the clock.

If a breach ever puts your data at risk, we'll tell the supervisory authority within 72 hours where the law requires it, and we'll tell you without undue delay when the risk to you is high.

Your rights

You can do most things yourself: change your name, email address, phone number and photo in Settings; connect or disconnect the accounts you sign in with; delete any image or scan from your results; delete your account from Settings, Profile, Delete Account; and change your cookie choice from the footer.

You also have the right to ask us to:

  • confirm what personal data we hold about you and give you a copy of it;
  • correct anything that's wrong;
  • delete your data;
  • restrict or object to how we use it;
  • give you your data in a portable format;
  • withdraw a consent you gave, without affecting what was done before.

Email [email protected] from the address on your account, or, as a guest, tell us what you uploaded and when. We answer within a month; if a request is unusually complex we may take up to two more months and will say so. We'll ask you to prove who you are only where we need to.

Nothing here is required by law. Without an image there's nothing to compress, without an email address there's no account, and without a payment there's no Pro; everything else, the phone number, the photo, the advertising cookies, is optional. We make no decisions about you by automated means that have legal or similarly significant effects.

You can also complain to us directly at [email protected]. We acknowledge a complaint within 30 days and answer it without undue delay.

If you think we've handled your data unlawfully, you can complain to a supervisory authority: in the EU, the authority of the country where you live or work; in the United Kingdom, the Information Commissioner's Office. We'd appreciate the chance to sort it out first.

If you're in California or another US state with a privacy law, we don't sell personal information and we don't share it for cross-context behavioural advertising except through Google's tags, which you can switch off from the footer or with the Global Privacy Control signal. The rights above are available to you in the same way.

Children

Iminify isn't directed at children. You have to be at least 16 to use it, we don't knowingly collect data from anyone younger, and if we learn that we have, we delete it and close the account. If you think a child has given us their data, email us.

Changes to this policy

The date at the top is the date this version took effect. For a change that affects what we collect or how we use it, we'll email account holders before it takes effect and post a notice on the site. Earlier versions are available on request.

Contact

Email: [email protected]

Website: https://www.iminify.com