Privacy Policy | ImageToURL
How ImageToURL handles public images, technical data, account information, deletion requests, and abuse prevention.
Last updated: 2026-07-28
Scope
This policy explains how ImageToURL handles information when you browse the site or upload an image. Account features and report intake are not enabled in the current development build.
Public Images
ImageToURL creates public image links. Anyone who has a direct URL can open the image. Do not upload confidential images or files you do not have the right to share.
Uploaded images are not intended to appear in a public gallery by default, but that does not make a direct link private. A link can be forwarded, embedded, or included on a page that search engines can crawl.
Information We Process
Depending on the feature you use, ImageToURL may process:
- Uploaded file data — the image bytes, file type, file size, image dimensions, storage key, and upload time.
- Technical and security data — IP address, request headers, browser type, rate-limit events, error logs, and abuse signals.
- Account data — name, email address, authentication identifiers, and upload history if account features are enabled later.
- Report data — the reported URL, reason, description, contact email, and resolution notes if report intake is enabled later.
- Analytics data — aggregated page and feature usage if analytics is enabled.
We use this information to provide image links, enforce upload limits, prevent abuse, investigate reports, maintain reliability, and improve the product.
IP Addresses and Rate Limits
Public upload requires abuse controls. ImageToURL may process the connection IP supplied by the hosting platform to apply rate limits, investigate harmful activity, and protect storage. Where practical, long-lived application records use a one-way hash rather than a raw IP address.
Security and operational logs are retained only as long as needed for reliability, abuse review, dispute handling, and legal obligations. Exact retention periods will be published when the production logging configuration is finalized.
Storage and Service Providers
The upload service uses Cloudflare R2 for object storage and a Cloudflare-managed public delivery domain. Authentication, email, analytics, and other optional providers will be listed here before they are enabled.
Service providers process data only to operate the product, secure it, or meet legal obligations. ImageToURL does not sell personal information.
Retention and Deletion
Valid images may remain stored until the uploader deletes them, the content violates the Terms, a rights or privacy request is accepted, or storage must be removed for security or legal reasons.
Guest uploads receive a signed deletion credential. Deleting an image removes the object or blocks its public URL, subject to short-lived caches, backups, fraud records, and legal retention duties.
Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data. You may also object to certain processing or withdraw consent where processing is based on consent.
Report intake and a general privacy contact are not enabled in this development build. They must be published before the service is promoted for production use.
Security
ImageToURL uses HTTPS, access controls, secret separation, and platform security features appropriate to the service. No Internet service can guarantee absolute security or uninterrupted availability.
Children
ImageToURL is not directed to children and must not be used to upload child sexual abuse material, sexual exploitation content, or private information about a child. Suspected illegal content may be preserved and reported as required by law.
Changes
We may update this policy when the product, providers, legal requirements, or data practices change. The updated date at the top identifies the current version.
