Your images are processed in your browser — Cloud HD (Pro, opt-in) is the only exception

Privacy Policy

Last updated: 7 October 2026

Short version

1. Who we are

MiniPx (minipx.com) is operated by Gaurav Bhowmick, an individual sole proprietor based in India. For any privacy question, write to contact@minipx.com.

2. Your image files

This is the most important thing in the document. Your image files never leave your browser. When you drop an image into MiniPx, it is read, processed, and re-encoded entirely by JavaScript running on your device. The compressed output appears in your browser memory and is downloaded directly to your computer. At no point is the image data transmitted to our servers, to Netlify, to Google, to Paddle, or to anyone else.

You can verify this yourself: open browser DevTools, switch to the Network tab, drop in an image, watch the compression run. No image data is transmitted. The compression engine runs in your browser, so its code is delivered to your device and available for inspection there.

Three honest footnotes, because "never leaves your browser" should survive scrutiny rather than depend on you not looking. First, the AI-powered tools download a model file from a third party the first time you use them — that is a download to your device, never an upload of your image. Section 7 covers it. Second, the page analyzer at /analyzer/ is the one tool on this site that talks to our server: you give it a public website address, and our server fetches that page's HTML and the response headers of the images it references so we can estimate savings. It never downloads image bytes, and it has nothing to do with the files you compress. Neither footnote touches the images you process.

Third, and this is the real one: if you are a Pro subscriber you can switch on Cloud HD — or use one of the four Cloud HD photo-repair tools — and when you do, that photo is uploaded to our server for that run. Cloud HD is the only part of MiniPx that ever does this, it is off until you turn it on, and you agreed to it — including the 14-day cancellation waiver for runs — when you bought Pro; the tools tell you before every run that the photo goes to our server and when it is deleted, and nothing is asked of you again. Section 2A sets out exactly what happens to the file, who sees it and how long it exists. If you never switch it on and never use those four tools, the sentence at the top of this section is unqualified: your images never leave your browser.

The same promise covers the MiniPx Chrome extension, which processes your images entirely on your own machine; its only network request is fetching an image you right-click and hand to it. Because an extension asks for browser permissions this site cannot, it has its own policy setting out each one: see the Chrome extension privacy policy.

2A. Cloud HD: the one time an image leaves your browser

Cloud HD is how a Pro account runs a bigger, better model than your device can manage, on a server we rent, and it is available only on a paid Pro account. On three tools — the background remover, the image upscaler and the passport photo maker — it is an option: they run on your device unless you switch Cloud HD on, per tool. Four more tools — restoring, colourising and enhancing old photos, and removing an object from one — are built on the same server and the same meter, and have no on-device mode. None of the seven asks you to confirm anything before a run: the cancellation waiver that covers Cloud HD runs is part of what you agreed to at checkout (section 9), and each tool states, in plain text beside its run control, that the photo goes to our server and when it is deleted. If you never switch Cloud HD on and never use those four tools, nothing in this section ever happens to you.

What is sent. One photo, the one you are working on, at the moment you press the button. Nothing else: not your other files, not your filename, not where the photo was taken, not what camera took it. Before the model sees your photo at all, our server re-encodes it into a plain image — pixels, the right way up, in a standard colour space — and throws the original file away. That step exists to defend the server against malicious image files, and it has the side effect of stripping the location and camera information your phone writes into a photo. For the object remover, the mask you paint travels with the photo and is deleted with it.

Where it goes. The upload goes to Cloudflare R2, object storage operated by Cloudflare, Inc. The model runs at Modal Labs, Inc. Both are in the United States, so your photo is processed in the United States. Section 12 covers what that means legally.

How long it exists. We delete your photo as soon as the run finishes, and in every case within 24 hours. Specifically: the file you uploaded is deleted before we even hand you the link to your result; the result itself is reachable for five minutes through a short-lived link and then expires; a sweeper runs every fifteen minutes over anything left behind; and a rule on the storage bucket deletes anything at all that survives a day. That is our promise and our machinery, not a policy of the companies above. For passport and ID photos we go further: both the photo you sent and the photo we made are deleted as soon as your browser confirms the download, rather than waiting out the five minutes.

What it is never used for. Your photo is used to produce your result and for nothing else. We do not use it to train, tune, evaluate or improve any model, and our contract with the company that runs the model for us does not permit them to use it for that either. Nobody here looks at it — there is no screen anywhere in MiniPx that could show it to us, and by the time you could ask, it is gone.

What we keep afterwards. A record of the run, with no image in it: which tool, which model and which version of it, whether it worked, how big the file was going in and coming out, how long it took, and when. Section 5 lists the fields. You can see this list yourself on your account page, which is also where we show you which model processed your photo.

What it costs you. Each run uses one unit of your monthly cloud allowance, and the meter is shown before every run. A few high-cost runs — the tools mark them as HD runs — also draw a separate monthly HD counter, shown the same way before the run. A run that fails on our side is not charged.

If you would rather not. Leave the switch off. The background remover, the upscaler and the passport photo maker still work on your own device exactly as they did before; the four photo-repair tools are server-only, so not using them is the whole choice; and everything else on MiniPx — compression, conversion, resizing, the PDF tools, the favicon generator — never had a server option in the first place and still does not.

3. What we do collect: anonymous analytics

We use Google Analytics 4 (property ID G-CPKR150KT7) to understand traffic patterns and feature usage. The data sent to Google is anonymous and aggregated. It includes:

We use this data to understand which tools are popular, which need work, where users get stuck, and which traffic sources convert. We never tie this data to a person or attempt to re-identify visitors. Google’s own privacy policy and your control over Google’s tracking apply: see policies.google.com/privacy and Google’s opt-out browser add-on.

If you decline analytics, nothing is sent. Once you have declined — on our own consent banner, which asks in the EEA, the UK and Switzerland (between 8 September and 4 October 2026 Google's consent message asked there instead) — your browser sends Google Analytics nothing at all: no page views, no events, and not the cookieless signal Google's Consent Mode would otherwise still send. That holds from the moment you decline, on every page after it, for as long as your browser keeps the choice (section 6). The analytics script file may still be fetched as part of the page, but it is switched off and transmits nothing. Before you have answered, and after you accept, analytics works as described above.

4. What we do collect: payments (Pro only)

If you purchase MiniPx Pro, the payment is processed by Paddle.com Market Ltd. Paddle is the merchant of record. They collect what is necessary to complete the transaction and handle tax compliance:

Paddle stores this data under their own privacy policy: paddle.com/legal/privacy. From Paddle we receive only a webhook notification that the purchase occurred, with your customer ID hashed before we log it. We do not store your name, email, or card information on our servers.

Paddle Retain runs on the pricing page. Paddle’s checkout script loads a second script from public.profitwell.com (Paddle Retain, formerly ProfitWell) whenever you open /pricing/ or one of its translated versions (/de/pricing/, /fr/pricing/, /es/pricing/, /pt/pricing/, /hi/pricing/, /id/pricing/). It is Paddle’s subscription-analytics and failed-payment-recovery tool. It sends data about the page to retain-api.profitwell.com and api.profitwell-events.com, and it can display a payment-recovery message in a frame served from Paddle’s own domain. We do not control what it collects and we receive none of it directly — it reports to our Paddle account.

Two things worth saying plainly about it. It is a third-party script, so it is the one part of this site that is not covered by the analytics question in the cookie banner — that banner governs Google Analytics, not this. And it runs only on the pricing page: it is not present on the homepage, on any of the tools, or on the account and activation pages. It never sees your images: the free tools never send an image anywhere, and a Cloud HD run (§2A) goes to our own server, never to Paddle. If you would rather it did not run at all, a content blocker will stop it without affecting anything else on the site.

Your Pro license itself (the Paddle transaction or subscription ID) is stored in your browser's localStorage on the device where you activated it. You can clear it at any time from the account page.

5. What we store on our own servers (Pro licensing)

We do run server-side storage. It exists to make Pro accounts work — to sign you in, to know what you have paid for, and to stop one purchase being shared across a hundred devices. Since August 2026 it is a Postgres database hosted by Supabase in the United States (us-east-1), and it holds these record sets:

What is genuinely not there: your name, your card details, and any image you have ever processed. That last one still holds even with Cloud HD switched on — a Cloud HD photo passes through storage we rent and is deleted, and it is never written into the database described in this section. Paddle holds your card as merchant of record and does not pass it to us. Sign-in codes are emailed to you by Resend on our behalf; Resend sees your email address and the code, nothing else. Until 9 September 2026 a copy of the older licence records also remains in Netlify Blobs while the previous licence system is retired, and it is deleted after that date. It is not dormant in the meantime: as purchases and refunds come in, the payment webhook still mirrors the checkout consent record (keyed to the Paddle transaction ID, and carrying your Paddle customer ID) and any revocation into that older store as well as into Postgres. If you would like a device or session removed, do it from the account page or write to us.

6. Cookies and local storage

We use a small number of cookies and localStorage / sessionStorage items. Every one of them is first-party (set by your browser, scoped to minipx.com only). Separately, the AI tools cache downloaded model files on your device, and those files come from a third party — Section 7 covers that.

Set by MiniPx when you sign in to a Pro account (and only then):

Set by Google Analytics (not loaded on the account or activation pages):

localStorage (persists until you clear it):

sessionStorage (cleared when you close the tab):

Cache Storage and IndexedDB (AI tools only):

No session replay tools. No fingerprinting. No advertising cookies — MiniPx shows no ads (section 6A).

6A. No advertising

MiniPx shows no advertising, on the free tools or on Pro. Since 4 October 2026 no page loads an ad script, sets an advertising cookie, or sends anything to an ad network, and the browser extension never carried ads.

Until 4 October 2026 the free tools showed ads served by Google AdSense, and in the EEA, the UK and Switzerland Google's consent message asked before any were shown. An advertising cookie Google set during a visit before that date belongs to Google and expires on Google's own schedule; you can remove it by clearing your browser's site data, and Google's Ads Settings still control how Google uses it.

Your image files never reached an ad vendor at any time: no ad vendor ever received a file, a filename, or a pixel.

7. AI model downloads (third-party)

The AI-powered tools (background removal, upscaling, face detection) run the model on your device, but the model file has to get there first. We do not host these files. The first time you use one of those tools your browser downloads it directly from huggingface.co (Hugging Face, Inc.) or storage.googleapis.com (Google Cloud Storage, serving Google's MediaPipe models).

Be clear about what that means, in both directions. Those hosts see what any web server sees when your browser requests a file from it: your IP address, your user agent, and which model file you asked for. That is a third-party disclosure and, because those hosts are outside the EEA and UK, an international transfer. It is covered in Section 12.

What they do not see is your image. The request goes one way — the model comes to your device, your file never goes to theirs. Nothing about the image, its name, its size, or its contents is part of that request, and once the model is cached (see Section 6) no further request is made at all. If you never open an AI tool, this download never happens.

Their handling of the request is governed by their own policies: huggingface.co/privacy and policies.google.com/privacy.

8. Server logs

The site is hosted on Netlify. Netlify keeps standard server logs of HTTP requests (IP address, user agent, requested path, response code, timestamp) for security and abuse prevention. These logs are not sold or shared and are rotated regularly. See netlify.com/privacy for their data handling.

9. Lawful basis for processing

Under the GDPR and UK GDPR we have to name the legal ground for each thing we process, not just describe it. Here they are, one per purpose:

Under India's Digital Personal Data Protection Act 2023 the equivalents are: analytics runs on your consent under section 6, and license validation, fraud prevention and security fall under the legitimate-uses provisions in section 7 for data you voluntarily provided for that purpose. Where the DPDP Act requires consent, the notice you are reading is the notice required by section 5.

10. How long we keep things

Previous versions of this policy did not state retention periods at all. They should have. These are ours:

11. Your rights under GDPR, UK GDPR and the India DPDP Act

You have the right to:

Automated decision-making. We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you. The one automated rule worth naming so you can judge it yourself: if a Pro license is presented from more devices than the plan allows, the extra device is refused, and repeated attempts from many different devices within an hour can cause the license to be revoked. That is a license-enforcement rule applied to a key, not a judgement about a person, and a human will review it if you ask — write to us and we will restore access if the pattern was innocent.

Cloud HD is automated, and it decides nothing about you. A photo goes to a server, a model transforms it, a photo comes back. There is no scoring, no classification of you or of anyone in the picture, no face recognition, no comparison against any other photo, and no record derived from your face — the models measure pixels, not people. Nobody reviews the image, and no result of a cloud run changes what you pay, what you can access, or how we treat you. One check deserves naming precisely because this paragraph exists: the photo-restoration tool measures whether the restored face still matches the face in the photo you sent — a similarity check between our output and your input, on that run alone. It never compares your face against anyone else’s or against any database, and the run record keeps no measurement of your face — at most a code saying the check refused the result, in which case you are not charged. Beyond that, the rules that can refuse a run are usage limits and security checks — the monthly allowance, an hourly ceiling, a daily cap on failed runs, and a fresh sign-in check — and none of them judges you or your photo: when your allowance is used up, the tools say so until the month resets, and your device keeps working as before.

India DPDP Act 2023 — additional rights. Section 13(3) requires us to publish the contact details of a person who can answer your questions about processing. Section 14 gives you the right to nominate another individual to exercise your rights on your behalf if you die or become incapacitated. To nominate someone, write to us with their name and contact details and we will record it against your license.

Grievance Officer: Gaurav Bhowmick, the sole proprietor who operates MiniPx and is named in Section 1. For a sole proprietorship the proprietor is the responsible individual under section 13(3). Grievances under the DPDP Act should be sent to contact@minipx.com, which is monitored by the operator named in Section 1. We aim to respond within 7 days and will not exceed the statutory response periods.

To exercise any of these rights, email contact@minipx.com. For Pro purchases, you can also exercise these rights through Paddle directly.

12. International transfers

Google Analytics processes data in the United States. Paddle processes payment data in the United Kingdom, the United States, and the European Union. Supabase, Inc. hosts the account database described in Section 5 in the United States (AWS us-east-1). Resend, Inc. sends sign-in emails from the United States. Netlify hosts the site and runs our account endpoints from a global infrastructure footprint. All five are covered by standard contractual clauses or equivalent transfer mechanisms.

Cloud HD adds two more, and they are the only ones that ever handle an image. Cloudflare, Inc. stores the photo for the seconds or minutes it exists, and Modal Labs, Inc. runs the model on it. Both process it in the United States, which is why we say your photo is processed in the United States rather than something vaguer. The transfer runs on the European Commission’s standard contractual clauses, Module 2, the module for a controller sending data to a processor, and we have a data processing agreement with Modal that includes audit rights and requires them to tell us about a security breach without undue delay. We do not rely on the EU-US Data Privacy Framework as our main mechanism: the clauses stand on their own and do not depend on an adequacy decision surviving a court challenge. Separately from Cloud HD, the sign-in pages (/account/ and /activate/) and the re-authentication prompt on the Cloud HD tools load Cloudflare Turnstile, a bot check run by Cloudflare, Inc.: as soon as one of them opens, it receives your IP address and information about your browser and device, which Cloudflare uses to tell a person from an automated script, under Cloudflare’s own privacy policy: cloudflare.com/privacypolicy.

The AI model hosts described in Section 7 are a fourth transfer, and it is worth naming separately because it is the one that happens without any account or purchase. Hugging Face, Inc. is based in the United States, and storage.googleapis.com is operated by Google. When your browser downloads a model file, your IP address and user agent reach a server outside the EEA and UK. We do not have a data processing agreement with Hugging Face covering this, because we are not sending them your data — your browser is requesting a public file, in the same way it would from any public CDN. If that transfer is not acceptable to you, do not use the AI tools; every other tool on MiniPx works without it.

13. Children

MiniPx is a general-purpose utility, not a service targeted at children. We do not knowingly collect data from anyone under 13 (or under 16 in the EU). If you believe a child has provided us with data, write to contact@minipx.com and we will delete it.

14. Changes to this policy

We update this policy when our practices change. When we do, we update the "Last updated" date at the top and, for material changes, we email every account holder at the address on their account.

15. Contact

For any privacy question, write to contact@minipx.com. We aim to respond within 7 days.