Privacy Policy
Last updated: 24 August 2026
Short version
- Your image files never leave your browser. We have no way to see, store, or transmit them.
- We use Google Analytics to count visits and measure which tools get used. No personal information is sent to Google, no image data is sent.
- If you buy MiniPx Pro, Paddle handles your payment. They see your name, email, and country (for VAT/tax). We see only that a payment occurred.
- The pricing page, in any language — and only that page — also loads Paddle Retain, a third-party subscription-analytics script from
public.profitwell.com. It is not covered by the analytics question in the cookie banner. Section 4. - We do keep a small amount of data on our own servers, and only for Pro: which devices a license is active on, and what you agreed to at checkout. Not your name, not your email, not your card. Section 5 sets out exactly what and Section 10 says how long.
- The AI tools download their model file from a third party (Hugging Face or Google) the first time you use them. That host sees your IP address. It never sees your image — the model comes to you, your file does not go to it. Section 7.
- We do not sell, share, or use your data for advertising. Ever.
1. Who we are
MiniPx (minipx.com) is operated by Gaurav Bhowmick, an individual sole proprietor based in India. For any privacy question, write to contact@minipx.com.
2. Your image files
This is the most important thing in the document. Your image files never leave your browser. When you drop an image into MiniPx, it is read, processed, and re-encoded entirely by JavaScript running on your device. The compressed output appears in your browser memory and is downloaded directly to your computer. At no point is the image data transmitted to our servers, to Netlify, to Google, to Paddle, or to anyone else.
You can verify this yourself: open browser DevTools, switch to the Network tab, drop in an image, watch the compression run. No image data is transmitted. The compression engine runs in your browser, so its code is delivered to your device and available for inspection there.
Two honest footnotes, because "never leaves your browser" should survive scrutiny rather than depend on you not looking. First, the AI-powered tools download a model file from a third party the first time you use them — that is a download to your device, never an upload of your image. Section 7 covers it. Second, the page analyzer at /analyzer/ is the one tool on this site that talks to our server: you give it a public website address, and our server fetches that page's HTML and the response headers of the images it references so we can estimate savings. It never downloads image bytes, and it has nothing to do with the files you compress. Neither footnote touches the images you process.
The same promise covers the MiniPx Chrome extension, which processes your images entirely on your own machine; its only network request is fetching an image you right-click and hand to it. Because an extension asks for browser permissions this site cannot, it has its own policy setting out each one: see the Chrome extension privacy policy.
3. What we do collect: anonymous analytics
We use Google Analytics 4 (property ID G-CPKR150KT7) to understand traffic patterns and feature usage. The data sent to Google is anonymous and aggregated. It includes:
- Page views, scroll depth, and time on page (bucketed: 10s / 30s / 60s / 3min / 10min).
- Approximate location at country and city level (derived from IP, which Google anonymizes before logging).
- Coarse device class (mobile / tablet / desktop), viewport size, network connection class (4G / wifi when the browser exposes it), and your top language preference.
- Traffic source attribution: the referring website’s hostname only (never the full URL or query string), plus any UTM campaign parameters present in the link you clicked.
- First-touch attribution: the first time we ever saw your device, we record the original referrer and UTM in your browser’s localStorage. We send this back with later events so we can answer questions like "where did this user originally come from?" without re-identifying you.
- A random per-tab session ID (regenerated whenever you open a new tab) so events from the same browsing session can be grouped. Not linked to any identity.
- Outbound link clicks: domain only (e.g. "github.com"), never the full destination URL.
- Compression-related event metadata: file extension, input and output sizes in KB, compression ratio, format chosen, mode used. We do not send filenames or file contents.
- Interactive tool events: slider changes, toggle changes, preset selections, Pro upgrade prompts, errors classified into safe categories. None include file content or personal data.
- Pro feature interaction (visible to us only as anonymous counts): which Pro features are explored (panel expanded), which controls are touched (watermark anchor, opacity, scale, codec settings, responsive sizes, multi-format selections, saved presets, platform presets, rename templates), which Pro tier prompts you see, and which upgrade nudges convert to a /pricing/ visit.
- Pro funnel telemetry: pricing-page views, plan-card impressions, plan-CTA clicks, Paddle checkout open/close/complete/error (no card data ever seen by us — Paddle handles that), activation success/error, and a composite "Pro engagement score" (0–10) per session summarising how deep into the upgrade funnel a session reached.
- Account-page churn signals (Pro users only): manage-subscription / cancel-subscription / upgrade-to-annual / device-removal clicks. We use these to measure where Pro users get stuck or churn. We never see your billing email, card, or any Paddle PII through these events.
We use this data to understand which tools are popular, which need work, where users get stuck, and which traffic sources convert. We never tie this data to a person or attempt to re-identify visitors. Google’s own privacy policy and your control over Google’s tracking apply: see policies.google.com/privacy and Google’s opt-out browser add-on.
4. What we do collect: payments (Pro only)
If you purchase MiniPx Pro, the payment is processed by Paddle.com Market Ltd. Paddle is the merchant of record. They collect what is necessary to complete the transaction and handle tax compliance:
- Your name and billing email.
- Your billing country (for VAT, GST, or sales tax).
- Card details (which Paddle never shares with us).
- Your purchase amount and the product purchased.
Paddle stores this data under their own privacy policy: paddle.com/legal/privacy. From Paddle we receive only a webhook notification that the purchase occurred, with your customer ID hashed before we log it. We do not store your name, email, or card information on our servers.
Paddle Retain runs on the pricing page. Paddle’s checkout script loads a second script from public.profitwell.com (Paddle Retain, formerly ProfitWell) whenever you open /pricing/ or one of its translated versions (/de/pricing/, /fr/pricing/, /es/pricing/, /pt/pricing/, /hi/pricing/, /id/pricing/). It is Paddle’s subscription-analytics and failed-payment-recovery tool. It sends data about the page to retain-api.profitwell.com and api.profitwell-events.com, and it can display a payment-recovery message in a frame served from Paddle’s own domain. We do not control what it collects and we receive none of it directly — it reports to our Paddle account.
Two things worth saying plainly about it. It is a third-party script, so it is the one part of this site that is not covered by the analytics question in the cookie banner — that banner governs Google Analytics, not this. And it runs only on the pricing page: it is not present on the homepage, on any of the tools, or on the account and activation pages. It never sees your images, because your images never leave your browser on any page. If you would rather it did not run at all, a content blocker will stop it without affecting anything else on the site.
Your Pro license itself (the Paddle transaction or subscription ID) is stored in your browser's localStorage on the device where you activated it. You can clear it at any time from the account page.
5. What we store on our own servers (Pro licensing)
Earlier versions of this policy left this out, which was a real omission. We do run server-side storage. It exists to make Pro licenses work and to stop one license being shared across a hundred devices, and it holds five small record sets in Netlify Blobs:
- Activation records, keyed to your Paddle transaction or subscription ID. Each record holds the list of devices the license is active on — and a "device" here is only the random identifier your own browser generated (see "minipx_device_fp" below), never a hardware serial or anything issued by your operating system. Alongside each device we store when it was first seen and when it was last seen, plus your plan (monthly / annual / lifetime), the first activation time, and a short rolling list of recent validation attempts used to detect key sharing.
- Revocation records — if a subscription is cancelled or a purchase refunded, we store the transaction or subscription ID with the time, the reason, and the Paddle event that triggered it, so the license stops working immediately rather than on the next Paddle round trip.
- Consent records from checkout, keyed to the transaction ID. These hold a version identifier for the confirmation wording you were shown, a SHA-256 hash of that exact wording, the plan, the timestamp from your browser and our own server timestamp, and your Paddle customer ID. Deliberately not the wording as free text and deliberately not your email — the hash proves what you were shown without us holding a second copy of your identity.
- Rate-limit counters, keyed to your IP address (per minute and per day) and to the license key (per hour). Plain integers in short-lived buckets, used to stop abuse of the license endpoint.
- Paddle webhook event IDs, held for ten minutes so a retried delivery is not processed twice. No customer data in them.
What is genuinely not there: your name, your email address, and your card details. Paddle holds those as merchant of record and does not pass them to us. The Paddle customer ID we do hold is an opaque reference, and in our server logs it is hashed before being written. If you would like your activation record cleared, remove the device from the account page or write to us.
6. Cookies and local storage
We use a small number of cookies and localStorage / sessionStorage items. Every one of them is first-party (set by your browser, scoped to minipx.com only). Separately, the AI tools cache downloaded model files on your device, and those files come from a third party — Section 7 covers that.
Set by Google Analytics:
- Google Analytics cookies (_ga, _gid, _ga_…) for traffic analysis.
localStorage (persists until you clear it):
- "minipx_consent" — whether you accepted or declined analytics on the consent banner. Shown to visitors in the EEA and UK. Without this we would have to ask you on every page.
- "minipx_pro_license" — your Pro license (transaction/subscription ID, plan, expiry, last validation timestamp). Only set if you purchase Pro.
- "minipx_ec_era" — a single timestamp marking when your current license entitlement began. Used to work out whether an offline grace period still applies. Only set if you purchase Pro.
- "minipx_device_fp" — a random UUID used to bind your Pro license to this device (anti-piracy). Not used for analytics or tracking. Created on every visit, Pro or not. This is the identifier that appears in the activation records described in Section 5.
- "minipx_saved_presets" — your saved tool settings if you use the Pro Saved Presets feature. Plain JSON, sits only on your device.
- "minipx_theme" — your dark/light mode preference.
- "minipx_ai_quota" — a count of how many free AI-tool runs you have used and, if you have used them all, when the tools unlock again. Four numbers on your device. No image data, nothing about what you processed, and it is never sent to us.
- "minipx_pro_preview_used" — a record of which Pro features you have already spent your one free preview on, so a preview cannot be replayed indefinitely.
- "minipx_passport_stats" — a local counter of passport photos you have generated, used to show your own running total on the passport tool. Counts only, no images.
- "minipx_first_touch" — your first-ever traffic source (referrer, UTM campaign, landing page, timestamp). Used to answer "where did this user originally come from?" in our analytics, without ever identifying you personally.
- "minipx_pro_first_use_pending" — a one-shot flag marking that you have just activated Pro but not yet used a Pro feature, so the "first use" event fires once and only once. Previous versions of this policy listed this as sessionStorage. That was wrong: it is localStorage, and it survives closing the tab.
sessionStorage (cleared when you close the tab):
- "minipx_pending_consent" — set only when you buy Pro. Holds the confirmation wording you agreed to at checkout so the activation page can offer you a copy to download. Cleared once you download it, or when you close the tab.
- "minipx_session" — a random per-tab session ID + last-touch attribution.
- "minipx_pro_score" / "minipx_pro_score_meta" / "minipx_pro_score_emitted" — composite Pro engagement score (0–10) and metadata for this tab session only. Lets us emit one summary event per session rather than dozens of individual events.
- "minipx_session_start_fired" — a one-shot flag that gates the "session started" event.
- "minipx_purchase_fired_txn" — the transaction ID of a purchase whose conversion event has already been sent, so a page refresh on the activation screen does not count your purchase twice.
- "mpx_first_upload_ts", "mpx_first_value_fired" and "mpx_churn_…" flags — funnel timing markers. They record when you first added a file this session and which funnel milestones have already reported, so each fires once rather than repeatedly. Timestamps and one-shot flags, nothing about the file.
- "mpx_chunk_reload_at" — the time of the last automatic page reload after a failed script download, so a broken deploy cannot put your browser into a reload loop.
Cache Storage and IndexedDB (AI tools only):
- Cache Storage "minipx-ai-models-v1", with IndexedDB database "minipx-models" as a fallback where Cache Storage is unavailable. These hold the AI model files themselves so a model is downloaded once rather than on every use. Depending on which AI tools you use this can reach roughly 160 MB on your device. They contain model weights only — no images, and nothing about what you processed. Clearing site data removes them, and the tools will simply download again next time.
No advertising cookies. No cross-site tracking pixels. No session replay tools. No fingerprinting.
7. AI model downloads (third-party)
The AI-powered tools (background removal, upscaling, face detection) run the model on your device, but the model file has to get there first. We do not host these files. The first time you use one of those tools your browser downloads it directly from huggingface.co (Hugging Face, Inc.) or storage.googleapis.com (Google Cloud Storage, serving Google's MediaPipe models).
Be clear about what that means, in both directions. Those hosts see what any web server sees when your browser requests a file from it: your IP address, your user agent, and which model file you asked for. That is a third-party disclosure and, because those hosts are outside the EEA and UK, an international transfer. It is covered in Section 12.
What they do not see is your image. The request goes one way — the model comes to your device, your file never goes to theirs. Nothing about the image, its name, its size, or its contents is part of that request, and once the model is cached (see Section 6) no further request is made at all. If you never open an AI tool, this download never happens.
Their handling of the request is governed by their own policies: huggingface.co/privacy and policies.google.com/privacy.
8. Server logs
The site is hosted on Netlify. Netlify keeps standard server logs of HTTP requests (IP address, user agent, requested path, response code, timestamp) for security and abuse prevention. These logs are not sold or shared and are rotated regularly. See netlify.com/privacy for their data handling.
9. Lawful basis for processing
Under the GDPR and UK GDPR we have to name the legal ground for each thing we process, not just describe it. Here they are, one per purpose:
- Analytics — consent, Article 6(1)(a). In the EEA and UK, Google Analytics does not set an analytics cookie or store any analytics identifier on your device until you accept it on the consent banner, and your choice is recorded in "minipx_consent". Before that, your browser can still send Google a single cookieless signal that carries no identifier and is not stored against you — this is Google Consent Mode v2, the standard way sites ask before tracking without going dark for every visitor in between. You can withdraw consent at any time by clearing that key from site data or by writing to us, and withdrawal is as easy as giving it. Withdrawing does not undo processing that already happened lawfully.
- License validation and device binding — performance of a contract, Article 6(1)(b). If you have bought Pro, checking that your license is valid is simply how we deliver what you paid for. The device cap has an additional ground: our legitimate interest in preventing one license being shared across unlimited devices, Article 6(1)(f). We think that is a fair balance because the identifier is random, generated by your own browser, tied to nothing else about you, and the alternative — requiring an account — would mean holding more of your data, not less.
- Checkout consent records — legal obligation, Article 6(1)(c), together with legitimate interest, Article 6(1)(f). Consumer law requires us to be able to show what you were told about your cancellation rights before you paid, and the same record is what we would rely on in a payment dispute.
- Server logs and rate limiting — legitimate interest, Article 6(1)(f), in keeping the site available and the license endpoint from being abused. Security logging is expressly recognised as a legitimate interest in Recital 49.
Under India's Digital Personal Data Protection Act 2023 the equivalents are: analytics runs on your consent under section 6, and license validation, fraud prevention and security fall under the legitimate-uses provisions in section 7 for data you voluntarily provided for that purpose. Where the DPDP Act requires consent, the notice you are reading is the notice required by section 5.
10. How long we keep things
Previous versions of this policy did not state retention periods at all. They should have. These are ours:
- Activation and revocation records — kept while the license is active, then for 12 months after it ends. The tail exists because refunds, chargebacks and reactivations arrive after the fact, and because deleting a revocation record would quietly resurrect a cancelled license.
- Checkout consent records — 6 years. This is the one long period in the list, and it is not for our convenience: card networks and payment providers allow disputes to be raised long after purchase, and a consent record we have already deleted is a record we cannot use to defend you or ourselves.
- Rate-limit counters — minutes to a day. They live in time buckets that stop being read once the window passes.
- Paddle webhook event IDs — 10 minutes.
- Google Analytics — held by Google for the retention window configured on the GA4 property. GA4 caps user-level and event-level retention at 14 months; aggregated reports persist at Google beyond that, but cannot be resolved back to a session.
- Netlify server logs — rotated on Netlify’s own schedule, which we do not control. See their policy linked in Section 8.
- Everything in your browser (Section 6) — until you clear it. We cannot delete it for you, and we cannot read it either.
11. Your rights under GDPR, UK GDPR and the India DPDP Act
You have the right to:
- Know what data we hold about you and get access to it (Article 15). In practice: very little, see above.
- Have inaccurate data corrected (Article 16).
- Have your data erased (Article 17). For anything in your browser you can do this yourself in one step by clearing site data.
- Restrict processing (Article 18) — ask us to keep the data but stop using it, for example while a dispute over accuracy is being sorted out.
- Data portability (Article 20) — receive the data you gave us, or that we hold on the basis of consent or contract, in a structured, commonly used, machine-readable format. For MiniPx this means your activation record and your checkout consent record; we will send them as JSON.
- Object to processing based on legitimate interest (Article 21), including our device-binding and security processing. Tell us why and we will stop unless we can show compelling grounds that override your interests.
- Withdraw consent for analytics at any time, with no effect on the lawfulness of what happened before you withdrew.
- Lodge a complaint with your local data protection authority — in the UK the ICO, in the EEA your national authority, in India the Data Protection Board.
Automated decision-making. We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you. The one automated rule worth naming so you can judge it yourself: if a Pro license is presented from more devices than the plan allows, the extra device is refused, and repeated attempts from many different devices within an hour can cause the license to be revoked. That is a license-enforcement rule applied to a key, not a judgement about a person, and a human will review it if you ask — write to us and we will restore access if the pattern was innocent.
India DPDP Act 2023 — additional rights. Section 13(3) requires us to publish the contact details of a person who can answer your questions about processing. Section 14 gives you the right to nominate another individual to exercise your rights on your behalf if you die or become incapacitated. To nominate someone, write to us with their name and contact details and we will record it against your license.
Grievance Officer: Gaurav Bhowmick, the sole proprietor who operates MiniPx and is named in Section 1. For a sole proprietorship the proprietor is the responsible individual under section 13(3). Grievances under the DPDP Act should be sent to contact@minipx.com, which is monitored by the operator named in Section 1. We aim to respond within 7 days and will not exceed the statutory response periods.
To exercise any of these rights, email contact@minipx.com. For Pro purchases, you can also exercise these rights through Paddle directly.
12. International transfers
Google Analytics processes data in the United States. Paddle processes payment data in the United Kingdom, the United States, and the European Union. Netlify hosts the site and stores our license records from a global infrastructure footprint. All three are covered by standard contractual clauses or equivalent transfer mechanisms.
The AI model hosts described in Section 7 are a fourth transfer, and it is worth naming separately because it is the one that happens without any account or purchase. Hugging Face, Inc. is based in the United States, and storage.googleapis.com is operated by Google. When your browser downloads a model file, your IP address and user agent reach a server outside the EEA and UK. We do not have a data processing agreement with Hugging Face covering this, because we are not sending them your data — your browser is requesting a public file, in the same way it would from any public CDN. If that transfer is not acceptable to you, do not use the AI tools; every other tool on MiniPx works without it.
13. Children
MiniPx is a general-purpose utility, not a service targeted at children. We do not knowingly collect data from anyone under 13 (or under 16 in the EU). If you believe a child has provided us with data, write to contact@minipx.com and we will delete it.
14. Changes to this policy
We update this policy when our practices change. When we do, we update the "Last updated" date at the top. For material changes, we will surface a site-wide notice for two weeks.
15. Contact
For any privacy question, write to contact@minipx.com. We aim to respond within 7 days.
