Privacy Policy

Last updated: 24 August 2026

Short version

1. Who we are

MiniPx (minipx.com) is operated by Gaurav Bhowmick, an individual sole proprietor based in India. For any privacy question, write to contact@minipx.com.

2. Your image files

This is the most important thing in the document. Your image files never leave your browser. When you drop an image into MiniPx, it is read, processed, and re-encoded entirely by JavaScript running on your device. The compressed output appears in your browser memory and is downloaded directly to your computer. At no point is the image data transmitted to our servers, to Netlify, to Google, to Paddle, or to anyone else.

You can verify this yourself: open browser DevTools, switch to the Network tab, drop in an image, watch the compression run. No image data is transmitted. The compression engine runs in your browser, so its code is delivered to your device and available for inspection there.

Two honest footnotes, because "never leaves your browser" should survive scrutiny rather than depend on you not looking. First, the AI-powered tools download a model file from a third party the first time you use them — that is a download to your device, never an upload of your image. Section 7 covers it. Second, the page analyzer at /analyzer/ is the one tool on this site that talks to our server: you give it a public website address, and our server fetches that page's HTML and the response headers of the images it references so we can estimate savings. It never downloads image bytes, and it has nothing to do with the files you compress. Neither footnote touches the images you process.

The same promise covers the MiniPx Chrome extension, which processes your images entirely on your own machine; its only network request is fetching an image you right-click and hand to it. Because an extension asks for browser permissions this site cannot, it has its own policy setting out each one: see the Chrome extension privacy policy.

3. What we do collect: anonymous analytics

We use Google Analytics 4 (property ID G-CPKR150KT7) to understand traffic patterns and feature usage. The data sent to Google is anonymous and aggregated. It includes:

We use this data to understand which tools are popular, which need work, where users get stuck, and which traffic sources convert. We never tie this data to a person or attempt to re-identify visitors. Google’s own privacy policy and your control over Google’s tracking apply: see policies.google.com/privacy and Google’s opt-out browser add-on.

4. What we do collect: payments (Pro only)

If you purchase MiniPx Pro, the payment is processed by Paddle.com Market Ltd. Paddle is the merchant of record. They collect what is necessary to complete the transaction and handle tax compliance:

Paddle stores this data under their own privacy policy: paddle.com/legal/privacy. From Paddle we receive only a webhook notification that the purchase occurred, with your customer ID hashed before we log it. We do not store your name, email, or card information on our servers.

Paddle Retain runs on the pricing page. Paddle’s checkout script loads a second script from public.profitwell.com (Paddle Retain, formerly ProfitWell) whenever you open /pricing/ or one of its translated versions (/de/pricing/, /fr/pricing/, /es/pricing/, /pt/pricing/, /hi/pricing/, /id/pricing/). It is Paddle’s subscription-analytics and failed-payment-recovery tool. It sends data about the page to retain-api.profitwell.com and api.profitwell-events.com, and it can display a payment-recovery message in a frame served from Paddle’s own domain. We do not control what it collects and we receive none of it directly — it reports to our Paddle account.

Two things worth saying plainly about it. It is a third-party script, so it is the one part of this site that is not covered by the analytics question in the cookie banner — that banner governs Google Analytics, not this. And it runs only on the pricing page: it is not present on the homepage, on any of the tools, or on the account and activation pages. It never sees your images, because your images never leave your browser on any page. If you would rather it did not run at all, a content blocker will stop it without affecting anything else on the site.

Your Pro license itself (the Paddle transaction or subscription ID) is stored in your browser's localStorage on the device where you activated it. You can clear it at any time from the account page.

5. What we store on our own servers (Pro licensing)

Earlier versions of this policy left this out, which was a real omission. We do run server-side storage. It exists to make Pro licenses work and to stop one license being shared across a hundred devices, and it holds five small record sets in Netlify Blobs:

What is genuinely not there: your name, your email address, and your card details. Paddle holds those as merchant of record and does not pass them to us. The Paddle customer ID we do hold is an opaque reference, and in our server logs it is hashed before being written. If you would like your activation record cleared, remove the device from the account page or write to us.

6. Cookies and local storage

We use a small number of cookies and localStorage / sessionStorage items. Every one of them is first-party (set by your browser, scoped to minipx.com only). Separately, the AI tools cache downloaded model files on your device, and those files come from a third party — Section 7 covers that.

Set by Google Analytics:

localStorage (persists until you clear it):

sessionStorage (cleared when you close the tab):

Cache Storage and IndexedDB (AI tools only):

No advertising cookies. No cross-site tracking pixels. No session replay tools. No fingerprinting.

7. AI model downloads (third-party)

The AI-powered tools (background removal, upscaling, face detection) run the model on your device, but the model file has to get there first. We do not host these files. The first time you use one of those tools your browser downloads it directly from huggingface.co (Hugging Face, Inc.) or storage.googleapis.com (Google Cloud Storage, serving Google's MediaPipe models).

Be clear about what that means, in both directions. Those hosts see what any web server sees when your browser requests a file from it: your IP address, your user agent, and which model file you asked for. That is a third-party disclosure and, because those hosts are outside the EEA and UK, an international transfer. It is covered in Section 12.

What they do not see is your image. The request goes one way — the model comes to your device, your file never goes to theirs. Nothing about the image, its name, its size, or its contents is part of that request, and once the model is cached (see Section 6) no further request is made at all. If you never open an AI tool, this download never happens.

Their handling of the request is governed by their own policies: huggingface.co/privacy and policies.google.com/privacy.

8. Server logs

The site is hosted on Netlify. Netlify keeps standard server logs of HTTP requests (IP address, user agent, requested path, response code, timestamp) for security and abuse prevention. These logs are not sold or shared and are rotated regularly. See netlify.com/privacy for their data handling.

9. Lawful basis for processing

Under the GDPR and UK GDPR we have to name the legal ground for each thing we process, not just describe it. Here they are, one per purpose:

Under India's Digital Personal Data Protection Act 2023 the equivalents are: analytics runs on your consent under section 6, and license validation, fraud prevention and security fall under the legitimate-uses provisions in section 7 for data you voluntarily provided for that purpose. Where the DPDP Act requires consent, the notice you are reading is the notice required by section 5.

10. How long we keep things

Previous versions of this policy did not state retention periods at all. They should have. These are ours:

11. Your rights under GDPR, UK GDPR and the India DPDP Act

You have the right to:

Automated decision-making. We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you. The one automated rule worth naming so you can judge it yourself: if a Pro license is presented from more devices than the plan allows, the extra device is refused, and repeated attempts from many different devices within an hour can cause the license to be revoked. That is a license-enforcement rule applied to a key, not a judgement about a person, and a human will review it if you ask — write to us and we will restore access if the pattern was innocent.

India DPDP Act 2023 — additional rights. Section 13(3) requires us to publish the contact details of a person who can answer your questions about processing. Section 14 gives you the right to nominate another individual to exercise your rights on your behalf if you die or become incapacitated. To nominate someone, write to us with their name and contact details and we will record it against your license.

Grievance Officer: Gaurav Bhowmick, the sole proprietor who operates MiniPx and is named in Section 1. For a sole proprietorship the proprietor is the responsible individual under section 13(3). Grievances under the DPDP Act should be sent to contact@minipx.com, which is monitored by the operator named in Section 1. We aim to respond within 7 days and will not exceed the statutory response periods.

To exercise any of these rights, email contact@minipx.com. For Pro purchases, you can also exercise these rights through Paddle directly.

12. International transfers

Google Analytics processes data in the United States. Paddle processes payment data in the United Kingdom, the United States, and the European Union. Netlify hosts the site and stores our license records from a global infrastructure footprint. All three are covered by standard contractual clauses or equivalent transfer mechanisms.

The AI model hosts described in Section 7 are a fourth transfer, and it is worth naming separately because it is the one that happens without any account or purchase. Hugging Face, Inc. is based in the United States, and storage.googleapis.com is operated by Google. When your browser downloads a model file, your IP address and user agent reach a server outside the EEA and UK. We do not have a data processing agreement with Hugging Face covering this, because we are not sending them your data — your browser is requesting a public file, in the same way it would from any public CDN. If that transfer is not acceptable to you, do not use the AI tools; every other tool on MiniPx works without it.

13. Children

MiniPx is a general-purpose utility, not a service targeted at children. We do not knowingly collect data from anyone under 13 (or under 16 in the EU). If you believe a child has provided us with data, write to contact@minipx.com and we will delete it.

14. Changes to this policy

We update this policy when our practices change. When we do, we update the "Last updated" date at the top. For material changes, we will surface a site-wide notice for two weeks.

15. Contact

For any privacy question, write to contact@minipx.com. We aim to respond within 7 days.