Skip to Main Content

Privacy Policy

How Image-to-Prompt.org collects, uses, stores, and shares data

2026/08/22

1. Who We Are

This Privacy Policy explains how Image-to-Prompt.org (the Service, we, us, or our) processes personal information when you visit the website, analyze an image, create an account, save Prompt History, make a purchase, or contact us.

  • Data controller / operator: XU ZHENYU
  • Registered business address: District 5, Nanri Community, Gaoqiao Street, Tongxiang City, Jiaxing City, Zhejiang Province 314500, People's Republic of China
  • Privacy contact: [email protected]

2. Information We Process

Depending on how you use the Service, we process the following categories.

Account and Authentication Data

Name, email address, email-verification status, profile image, password hash, Google account identifiers if you choose Google sign-in, linked-account data, role and account status, session tokens, session timestamps, IP address, and user-agent information.

Image Inputs and Prompt Content

Uploaded image bytes or a public image URL, filename, MIME type, visual-analysis fields, six generated Prompts, saved edits, visible text detected in the image, AI model and request identifiers, and token-usage totals.

Images may incidentally contain faces, location clues, documents, health information, or other sensitive details. We do not ask you to provide sensitive personal information. Do not upload such content unless you have the necessary rights and a lawful reason to do so.

Usage and Technical Data

One-time anonymous-trial usage, pending-History claim tokens, request timestamps, pages or features used, error and security events, approximate location derived from IP address where provided by infrastructure services, browser type, operating system, and device information. Google Analytics 4 also uses a pseudonymous browser Client ID, Session ID, and, after sign-in, an internal, non-public User-ID to connect product-funnel events without sending your name or email address.

Billing and Credit Data

Credit balance and transactions, purchased product or plan, payment and invoice identifiers, customer and subscription identifiers, payment status, billing period, cancellation status, and transaction timestamps. Full payment-card details are collected by Creem, not by the Service.

After a verified Creem Webhook completes local settlement, we report the product, currency, transaction identifier, and transaction-level revenue to Google Analytics 4. Initial purchases and subscription renewals are reported as different events. A browser checkout redirect alone is not counted as revenue.

Communications

Your name, email address, message, and related correspondence when you contact support or use an account-recovery or verification workflow.

3. How We Obtain Information

We receive information directly from you, automatically from your browser and device, from Google when you choose Google authentication, and from Creem when it reports checkout, subscription, refund, chargeback, or billing events.

When you submit a public image URL, our server retrieves the image from that address. The remote host may receive our server IP address and the Image-to-Prompt.org/1.0 user-agent string.

4. Why We Process Information

We process information for the following purposes and, where applicable, legal bases:

  • Provide the Service and perform our contract: authenticate users, analyze images, generate six Prompts, provide History, manage credits, support batch processing for eligible plans, and deliver purchased features.
  • Legitimate interests: secure the Service, prevent fraud and abuse, enforce credit and rate limits, troubleshoot failures, maintain records, improve reliability, understand completion of the image-analysis and purchase funnels, measure paid conversion and renewal performance, and establish or defend legal claims. We balance these interests against your rights.
  • Legal obligations: maintain appropriate financial and transaction records, respond to valid legal requests, and comply with tax, accounting, sanctions, consumer-protection, and data-protection requirements.
  • Consent: activate optional technologies or send optional marketing where consent is required. The current production configuration does not enable a marketing newsletter or advertising cookies.

5. Image Analysis and AI Processing

For each analysis, the image is sent to APIMart through its API and processed using gpt-5.6-luna. The same request performs safety classification, visual analysis, and generation of all six Prompt formats. APIMart receives the image, instructions, and technical request data needed to return the result.

APIMart states that it may process Content Data, including prompts, inputs, and generated outputs, and temporarily store generated outputs to provide its API. It states that it does not use API content to train AI models. See the APIMart Privacy Policy and APIMart Terms.

AI analysis is probabilistic. Safety filtering or generation may reject an image or produce an inaccurate description. These decisions are used only to operate the Service and do not produce legal or similarly significant effects.

Before a six-Prompt package is saved or returned, the Service sends the text of all six generated Prompts and a non-personal request identifier to the Creem Moderation API. Creem returns an allow, flag, or deny decision. We deliver the package only after an explicit allow; a flag, deny, timeout, provider error, or invalid response blocks delivery. Creem receives the generated Prompt text for this check, but does not receive the uploaded image through the Moderation API. Analysis-only requests do not generate Prompts and therefore do not use prompt moderation.

6. Image Storage and Public URLs

After a successful analysis, the Service uploads the submitted image to Cloudflare R2 so it can be shown in the result and History interface. The image is served through a permanent, publicly reachable URL. The URL is difficult to guess but is not access-controlled; anyone who obtains it may view or share the image. Do not upload confidential, private, or highly sensitive images.

Cloudflare encrypts R2 objects in transit and at rest. Storage location depends on the configured bucket location and jurisdiction. See Cloudflare's Privacy Policy and R2 data-security information.

7. Retention

Our current retention practices are:

  • Anonymous result records: stored for approximately 24 hours so the result can be claimed after sign-in. Expired records are removed during subsequent cleanup operations and may not disappear at the exact expiration second.
  • Anonymous trial counters: the random browser identifier's hash and used trial count are retained separately from images and results to prevent daily refills. Removing an expired result or claiming it after sign-in does not reset the trial counter.
  • Signed-in History: stored until you delete an individual entry, delete the account, or request deletion, subject to required legal retention.
  • R2 image objects: retained while the corresponding anonymous result or signed-in History entry exists. When you delete a History entry, the Service deletes its R2 object before removing the database record. When you delete your account, the Service first deletes the R2 objects associated with your History and then deletes the account and associated History records. When an anonymous result expires, its R2 object is deleted before the expired record is removed during a subsequent cleanup operation.
  • Authentication sessions: ordinarily expire after 7 days, although security records and revoked-session information may be retained longer where needed.
  • Payment and credit records: retained for the period reasonably necessary for accounting, tax, fraud prevention, disputes, chargebacks, and legal compliance.
  • Support communications and logs: retained only as long as reasonably necessary to respond, secure the Service, and resolve disputes.

Backups and caches may retain deleted information for a limited period before being overwritten. A previously accessed public image may also remain in an intermediary or browser cache briefly after its R2 object is deleted. If an R2 deletion attempt fails, the corresponding History, account, or anonymous result record is retained so the deletion can be retried instead of leaving an untracked image object. We may preserve information longer when required by law or necessary to establish, exercise, or defend legal claims.

8. Service Providers and Disclosures

We disclose only the information reasonably necessary for these functions:

  • APIMart: AI safety review, visual analysis, and Prompt generation.
  • Cloudflare R2: image object storage and public delivery.
  • Creem: Prompt content moderation, merchant of record, hosted checkout, payment processing, tax, invoicing, fraud prevention, refunds, chargebacks, and subscription administration.
  • Resend: transactional email, including verification, password reset, and support messages.
  • Google: optional Google sign-in and One Tap identity services.
  • Google Analytics 4: pseudonymous product-funnel measurement and verified purchase and subscription-renewal reporting. We do not send images, image URLs, filenames, generated Prompts, names, email addresses, or payment-card details to Google Analytics.
  • Hosting, database, security, and professional providers: infrastructure, backups, monitoring, legal, accounting, and security support as needed.

We may also disclose information when required by law, to protect rights or safety, in connection with a merger or sale, or with your direction or consent.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not knowingly use image or Prompt content for advertising profiles.

GA4 receives only the limited event parameters needed for aggregate product and revenue measurement. Specifically, we do not send images, image URLs, filenames, generated Prompts, names, email addresses, or payment-card details to Google Analytics. We also do not send cookies, authentication tokens, payment signatures, or server API secrets as event parameters.

9. International Transfers

Our providers operate in multiple countries. APIMart is operated from Hong Kong, Creem from Estonia, Resend from the United States, and Cloudflare uses a global network with R2 storage controlled by bucket configuration. Information may therefore be processed outside your country.

Where required, we will rely on an adequacy decision, contractual safeguards, or another lawful transfer mechanism. You may contact us for information about the safeguards applicable to your data.

10. Your Rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or a copy of your information; object to certain processing; withdraw consent; and appeal or complain to a data protection authority. California residents may also have rights to know, correct, delete, and receive equal service when exercising privacy rights.

We do not sell or share personal information as those terms are used for California cross-context behavioral advertising. We do not knowingly collect or use sensitive personal information for purposes requiring a right to limit.

You can delete individual History entries in the Service and can delete your account from security settings. Those actions also request deletion of the R2 objects associated with the affected History. If an operation reports that the stored image could not be deleted, the related entry or account is kept so you can retry or contact us for assistance.

Send requests to [email protected]. We may need to verify your identity and may retain information where an exception applies. Authorized agents should provide evidence of authority.

11. Security

We use measures designed to protect information, including HTTPS, HTTP-only and signed cookies where appropriate, server-side API credentials, access controls, input validation, and encryption provided by our infrastructure. No system is completely secure, and we cannot guarantee absolute security or prevent a recipient of a public image URL from redistributing it.

12. Children

The Service is not directed to children under 13 or the minimum digital-consent age in their jurisdiction. Users under the age of legal majority may use the Service only with permission from a parent or guardian and may not purchase a paid plan themselves. Do not submit an image of a child unless you are legally authorized to do so.

13. Changes and Contact

We may update this Policy when our practices, providers, or legal requirements change. We will update the date above and provide additional notice when a change materially affects your rights.

Questions, complaints, and privacy requests may be sent to [email protected].