1.Overview
This Privacy Policy explains what information Magic Image ("we", "us") collects when you use the website, image pages and the developer API, how we use it, who we share it with, and the choices you have.
We designed Magic Image to work without an account. Most of what we hold is the images you choose to upload and the minimum technical data needed to serve them.
2.Information we collect
Images and image metadata. When you upload an image we store the file itself and information about it: a generated identifier, the original file name, content type, size, width and height, upload and update timestamps, safety flags such as whether the image is shown blurred, and a view counter. Image files can contain embedded metadata such as camera details or GPS location. We do not guarantee that this embedded data is removed, so strip it before uploading if you do not want it shared.
Account information. Sign-in is handled by G-Profile, a separate sign-in service, and Magic Image never sees your password or manages your G-Profile account. After you sign in we receive only what we need to know who you are: your G-Profile user identifier, together with your email address, display name and profile photo so we can show them in your account menu. We link your non-anonymous uploads to that identifier and email. How G-Profile itself handles your account is described in its own privacy policy.
Developer API data. When you create an API key we store the name you give it, a short prefix for display, a hashed version of the key, and the dates it was created, last used and revoked.
Technical and usage data. Our hosting and backend providers automatically log information such as IP address, browser type, device information, referring page, request time and the pages or images requested. Image pages also record an aggregate view count.
Information you send us. If you contact us, we keep the messages and contact details you provide so we can respond.
3.How we use information
We use the information described above to:
- store, resize, serve and display the images you upload and generate shareable links;
- attribute uploads to your account so you can manage them in My Gallery and through the API;
- authenticate you and keep you signed in;
- blur, hide or remove content in order to keep the Service safe and enforce our Terms and Conditions;
- detect, prevent and investigate abuse, spam, security incidents and misuse of API keys;
- notify our operators when a new image is uploaded (this internal notification contains the image identifier only);
- monitor performance, fix bugs and improve the Service;
- comply with legal obligations and respond to lawful requests.
We do not use your images to train machine-learning models, and we do not sell your personal information or your images.
4.Who can see your images
Uploaded images are not listed on the home page. Images can be viewed by anyone who has the link. Image links are long and random but they are not secret: sharing a link means anyone who receives it can view the image and forward the link, and a link posted publicly elsewhere may be picked up by search engines.
Image files are stored encrypted. Nobody, including us, can view or modify the content of your images outside of serving them to people who open a valid link.
Your email address and display name are never shown publicly alongside your images. They are only visible to you in your account menu.
5.How we share information
We share information only with the service providers we need to run Magic Image:
- G-Profile, a separate sign-in service that verifies who you are and passes back the basic identity information described above;
- Google Firebase (Authentication and Cloud Firestore), used to manage sign-in sessions and to store image and account records;
- Vercel, which hosts the website and processes standard server logs;
- our own image storage and API backend, which stores the image files;
- Slack, which receives internal operator notifications containing the identifier of newly uploaded images.
These providers process data on our behalf and are not permitted to use it for their own purposes. We may also disclose information when required by law, to protect the rights and safety of users and the public, or if the Service is transferred to a new operator, in which case this policy will continue to apply.
6.Cookies and local storage
We use a small number of strictly necessary cookies and browser storage entries:
- a language cookie that remembers the interface language you selected;
- Firebase Authentication storage that keeps you signed in between visits;
- a short-lived session entry used to protect the sign-in flow against forgery;
- local storage for interface preferences, such as whether you last uploaded anonymously.
We do not use advertising cookies, and we do not embed third-party advertising or social-media trackers. You can clear these entries at any time in your browser settings; doing so will sign you out.
7.Data retention and deletion
Images remain stored until you delete them or we remove them under our Terms and Conditions. Deleting an image immediately hides it from My Gallery, image pages and the API. The underlying file and its record may be kept for a limited period in backups and abuse-prevention records before being permanently removed.
Revoked API keys are kept as revoked records so that requests made with them can be traced. Server logs are retained for a short period by our hosting providers according to their own retention schedules.
If you want an image or your account data permanently erased sooner, or if you are the subject or rights holder of an image uploaded by someone else, contact us and we will act as quickly as we reasonably can.
8.Security
All traffic to Magic Image is encrypted with HTTPS, and image files are encrypted when stored so that nobody, including us, can view or alter their content. API keys are stored as hashes, and secrets used to talk to our backend never leave the server. Access to production systems is limited to the people who operate the Service.
No online service can be completely secure. Please choose carefully what you upload and who you share links with, and revoke any API key you suspect has been exposed.
9.Your rights and choices
Depending on where you live you may have the right to access, correct, export, restrict or delete personal information we hold about you, and to object to certain processing. You can exercise many of these rights directly:
- view and delete your uploads in My Gallery;
- create and revoke API keys from the Developer API page;
- sign out from your account menu;
- upload anonymously if you do not want an image linked to your account.
For anything else, including requests to delete your account data, contact us using the details below. We may need to verify your identity before acting on a request. If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
10.Children
Magic Image is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has uploaded images or created an account, contact us and we will remove the data.
11.International transfers
Our providers may store and process information on servers located outside the country where you live, including in the United States and Singapore. Where required, we rely on the providers' standard contractual safeguards for such transfers.
12.Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page shows when the latest version took effect. If we make material changes we will try to give reasonable notice on the website before they apply.
13.Contact us
Questions about this document, a takedown request, a complaint, or anything else related to Magic Image? Submit the contact form and we will respond as soon as we can.
Open contact form