PRIVACY POLICY
Privacy Policy
This policy describes what imagedit actually does with information. It is a notice. Acknowledging it at checkout is not consent to every processing activity, and it is not consent to marketing.
Who we are
imagedit is the website at https://imagedit.net. The operator of imagedit is responsible for the site records and billing records described here. Where a privacy law requires a controller to be named, that operator is the controller for those records.
Paddle is a separate business. Paddle.com is the Merchant of Record and online reseller for the checkout it shows, and it is responsible for the payment information it collects there. This policy does not make Paddle the controller for the whole site, and it does not make imagedit the controller for Paddle’s card handling.
Scope
This policy covers the public website, the browser editor, batch export, saved presets, checkout, and messages you send to the published contact address. It does not cover a third-party site you open from a link.
Information we collect
imagedit does not offer accounts. It does not ask you to create a password, and it does not collect a profile.
- If you pay, Paddle collects the billing details its checkout requires, including an email address. That email is not copied into the billing database.
- Restore purchase asks you to type that same email. The server sends it to Paddle to find the customer, then discards it. It is not written to the database or to the application log.
- The site stores a Paddle transaction id, a Paddle customer id, the price id, the time, the checkout id, and the policy versions accepted for that checkout, so it can tell a completed purchase from a refund or chargeback.
- A paid purchase can store up to 12 preset names and export settings, such as format and size limits. Those records do not contain images.
- If you email support, you decide what the message contains. The message is handled by your email provider and whoever reads the mailbox. It is not stored by the editor.
Image and file processing
You choose a JPEG or still PNG with the file picker, or by dropping it on the page. The editor decodes and prepares it in your browser, using browser image and canvas features, including a worker where the browser allows one. The prepared file is downloaded from the browser to your device.
The image is not sent to an imagedit upload API, form, or cloud store for editing. The public site does not provide the older server processing path. Batch export uses the same browser processing. Closing or reloading the tab drops the image from the page. The site has no image library, no temporary object store for images, and no image CDN.
The browser may apply an orientation flag while decoding. Saving a new JPEG or PNG can drop or change metadata, including EXIF. imagedit does not read that metadata out of the file in order to store it or send it anywhere.
Ordinary visits still produce request data, described below. Local image processing does not remove those ordinary web logs.
Payment information
The card form is Paddle’s. imagedit does not receive your full card number or card security code, and it does not put them in its database or logs.
What the site does keep, when a signed Paddle notice says the payment completed, is the transaction id, Paddle customer id, price id, completion time, and the checkout id that links the notice to the browser that started checkout. A later full refund or chargeback notice can mark that purchase revoked. The site does not store a card brand, billing address, or invoice copy of its own. Paddle can provide the buyer receipt from its own system.
Automatically collected information
A normal request to the site can include an IP address, user agent, the page address, and the time. The application writes a periodic count of requests and errors, and it writes whether a Paddle notice was accepted or rejected. It does not write the notice body or the payment secret. The host that serves the site may keep its own connection logs. This application does not set a retention period for those host logs.
There is no analytics product, no advertising tag, and no error-reporting service embedded in the pages.
Cookies and similar technologies
The editor does not use localStorage or sessionStorage to remember a purchase or a preference.
Two cookies are set only around a purchase. ir_checkout is an HttpOnly cookie for the checkout attempt. It lasts up to two hours. ir_session is an HttpOnly cookie set after the server has verified a completed payment or a restore. Both are SameSite=Lax, and they are marked Secure on the https site. They are not advertising cookies.
ir_session is an HttpOnly session credential for the browser that verified or restored the purchase. It is not the record of ownership. The server stores a hash of the cookie, not the cookie itself. Losing the cookie does not delete the purchase. Restore purchase sends the checkout email to this server long enough to ask Paddle, then drops it. The email is not written into the billing database.
When the Paddle payment form loads, Paddle can set cookies or similar storage inside its own frame. That storage belongs to Paddle’s checkout. imagedit does not read it.
There is no cookie banner because the site does not load an optional analytics or advertising tracker. If one is added later, it will not run before the policy and any required choice are updated.
How we use information
Records are used to run the site, open a purchase, confirm that a payment succeeded, restore a verified purchase onto a browser, apply a full refund or chargeback, store the preset settings tied to that purchase, answer a message you send, and protect the site from abuse. They are not used to send a marketing list. A transactional receipt comes from Paddle, not from an imagedit mailer. The site has no mailer.
Legal bases where applicable
Some laws, including the GDPR, require a legal basis. Where that applies, the fitting bases are: doing what you ask by using the editor and completing a purchase; keeping payment, refund, and chargeback records where the contract or the law requires it; and the operator’s legitimate interest in securing and operating the site. Sending an email is a request for a reply. Checkout does not bundle those activities into one consent, and there is no separate marketing consent because there is no marketing list.
How we share information
Information is shared with the providers that perform a specific job: the host that serves the site, and Paddle for checkout and buyer support. A message you send by email is shared with the email path you use. Professional advisers or a public authority can receive information when the law requires it. imagedit does not give information to an advertising network.
Service providers
- Paddle provides checkout, acts as merchant of record, calculates the tax it must collect, and handles the buyer receipt. It receives the payment data you enter in its form and the checkout id the site passes through.
- The hosting provider serves https://imagedit.net and can see ordinary request data. Image files are not part of that traffic for the editing tools.
No analytics, advertising, authentication, cloud-storage, or support-desk vendor is connected to the product.
Sale and sharing
imagedit does not sell personal information. It does not share personal information for cross-context behavioral advertising. There is no “Do Not Sell or Share” control because that kind of sale or sharing is not in the product. If advertising is added, this section and the loading of those tools will be changed first.
Data retention
Image files are not retained, because they are not uploaded. A checkout attempt cookie expires after two hours. The email typed into Restore purchase is not retained.
The billing database keeps the Paddle transaction id, customer id, price id, status, the policy versions accepted at checkout, and preset settings so a refund or a later restore can be matched. It does not keep the buyer email. The purchase row remains until a full refund or chargeback revokes it. The browser session can end without ending the purchase.
Host logs follow the host’s own retention, which is not defined in this application. Email you send to support is retained according to the mailbox you contacted, not by an in-product deletion job.
Security
The public site is served over HTTPS. Purchase cookies are HttpOnly. Card data is collected by Paddle rather than in an imagedit form. These are ordinary safeguards. They are not a promise that the service cannot be compromised.
International transfers
The site is offered to people in more than one country. The host that serves it, and Paddle, may process information outside the country where you are. This policy does not claim that a particular transfer tool, such as standard contractual clauses, is in place for every provider. It also does not claim that all processing stays in one country.
Your privacy rights
Depending on where you live, and subject to the law that applies, you may have a right to access, correct, or delete information, to restrict or object to some uses, to receive a portable copy, to withdraw a consent you actually gave, or to complain to a regulator. imagedit does not treat every visitor as holding every right under every statute.
To ask, email contact@imagedit.net. Include the transaction id from your Paddle receipt if the request is about a purchase. Do not send a card number, card security code, or password. There is no in-product account page that can export or delete a profile, because there is no profile. Image files are already only on your device.
Regional rights
EEA and the United Kingdom
Where the GDPR or UK GDPR applies, you can ask for access, correction, deletion, restriction, objection, and portability where those rights fit, and you can complain to a supervisory authority. Providing card data to Paddle is required to complete a purchase. The other site features do not require an account. No EU or UK representative is named here, because none has been appointed. Automated decisions that produce legal or similarly significant effects are not part of this product.
Israel
Where Israeli privacy law applies, you can ask the operator to tell you whether it holds information about you and to correct or delete it where that law requires. Use the contact address above.
California and other U.S. state laws
Those laws apply only if their own thresholds are met. If one applies to you and to this service, you may have rights to know, delete, and correct personal information, and to opt out of sale or sharing. As described above, imagedit does not sell or share personal information in that sense. Appeal a refusal by replying to the same contact.
Children
The service is not directed at children, and it is not a children’s product. It does not knowingly collect personal information from children. A parent who believes a child has sent personal information can write to the privacy contact and ask for it to be deleted where the site has it.
Changes to this policy
This policy is version 1.2, effective September 29, 2026. A change replaces this page and updates the version and date. The date is not the day you happen to open the page. A material change will be posted on this page before it is meant to apply, unless a law requires something sooner.
Contact
Support: contact@imagedit.net
ImageEdit Support: +972 58-288-8204
Privacy requests go to the same address.
The contact page explains what to include. Do not send a card number, card security code, password, or image file.