1. Who we are and what this policy covers
PicFitly (“we”, “us” or “our”) operates the image tools and contact service at picfitly.com. This policy explains how information is handled when you visit the website, use its tools or contact the operator. It covers the current service, including its www address.
For privacy questions or requests, use our contact form and choose Privacy request. PicFitly is the public service name used to contact the operator responsible for this website.
This policy describes our practices; it does not mean that merely visiting the website gives consent to optional tracking. Links to other websites are governed by those websites’ policies.
2. Your images and local processing
When you choose, drop or paste an image, our tools read its contents, filename, format and dimensions in your browser to perform the operation you requested. Image files, previews and converted results are not uploaded to PicFitly, Cloudflare or Google by the image tools.
Working files and results are held in the page’s memory. Clearing the queue releases the application’s references to them. The browser manages memory and may restore page state according to its own settings; we cannot promise a forensic erasure of data from your device. Downloaded results are files you control and remain on your device until you delete them.
We do not maintain a server-side image library, account history or image recovery service. We cannot retrieve an original or converted image that you have only processed locally. Pasting uses the image data you explicitly paste; the site does not continuously monitor your clipboard. Images are not sent to an AI service or used by these tools for model training.
3. Information that reaches us or our providers
| Information | When and why |
|---|---|
| Contact details and message | Your name, email address, selected topic and message are transmitted when you submit the contact form, so we can handle your request. |
| Submission records | A random message reference, submission and update times, notification status and email message identifier help us save messages, avoid duplicates and diagnose delivery problems. |
| Abuse-prevention identifier | The contact service uses your IP address and the current date to calculate a daily hash for submission limits. The contact database stores the hash, not the raw IP address. This is pseudonymous information, not a guarantee of anonymity. |
| Support correspondence | If you reply to correspondence about a request, we receive your reply address, message, email headers and any information you choose to include. Mailbox replies are separate from the contact form database. Start a new request with the contact form. |
| Website connection and security data | Cloudflare processes network requests to deliver and protect the website. This may include IP address, request URL, time, browser information, referring information when supplied, and security or error details. Operational information may be available to the operator through Cloudflare. |
| Browser security and reliability information | Cloudflare may use security cookies and supported browsers may send network failure reports. See the Cookie Policy for the distinction between these features and optional tracking. |
The contact form accepts text only. Please avoid sending passwords, payment details, government identifiers, medical records or other sensitive information. If you include information about another person in a message, share only what is necessary and what you are entitled to share.
4. Why we use information
- Deliver the requested website and local image tools.
- Receive and respond to questions, bug reports, feature suggestions and privacy requests.
- Prevent automated abuse, excessive submissions and duplicate notifications.
- Investigate faults, maintain reliability and understand reported problems.
- Meet applicable legal requirements and establish or defend legal claims where necessary.
Where a law requires a lawful basis, our operation of the website, handling of ordinary support requests and protection against abuse rely on legitimate interests in providing a useful, reliable service, subject to your rights. Processing required by law relies on that legal obligation. Where consent is required for an optional future feature, we will request it before the relevant processing; you may withdraw that consent without affecting earlier lawful processing.
We do not sell personal information or share it for cross-context behavioral advertising. The current website has no advertising, remarketing or visitor analytics scripts, marketing mailing list, account system or payment collection. Provider security logs and service metrics are separate from advertising analytics. We do not use contact data to make automated decisions that have legal or similarly significant effects; automated submission limits can temporarily prevent a form submission. Please wait and retry the contact form if a limit is reached.
5. Providers and other disclosures
Cloudflare hosts and delivers the website, protects network requests, processes contact submissions, stores the contact database and provides email routing and notification delivery. See Cloudflare’s Privacy Policy.
Google Gmail hosts the operator’s receiving mailbox. Contact form notifications and subsequent support correspondence are handled there. Google processes those messages under its applicable terms and Privacy Policy. Visiting or using the image tools does not itself send your images to Gmail or load an embedded Google widget.
The operator accesses messages to handle support and privacy requests. Information may also be disclosed where required by applicable law or a valid legal process, or where necessary to investigate abuse or protect rights and safety. We do not publish contact messages as website content automatically.
6. How long information is kept
- Images and results: no server-side retention by the image tools. Browser working state and your downloaded files are managed on your device.
- Contact database: submissions, the daily IP hash and delivery metadata are scheduled for deletion after 30 days. Cleanup runs every five minutes under normal operation, so removal occurs on the next successful cleanup after the threshold; a service interruption can delay it.
- Database recovery copies: deleted records may remain temporarily in provider recovery history. Cloudflare D1 documents a 7-day recovery window on its free plan and 30 days on its paid plan. This recovery history is separate from the live database. See Cloudflare D1 recovery documentation.
- Email copies and support correspondence: the database cleanup does not delete messages from Gmail or your mailbox. There is currently no fixed automatic deletion schedule for the operator’s email copies; they may be retained beyond 30 days to handle the request, follow-up correspondence or legal obligations. Contact us to request deletion of correspondence we control.
- Provider logs, security records and backups: these follow the provider’s applicable service settings and retention arrangements, rather than the form’s 30-day schedule. We cannot promise a single deletion period for every provider system.
We may retain relevant information longer if required by law or necessary for a specific dispute. A deletion request is assessed against applicable obligations and technical limits; we will explain any applicable limitation.
7. Processing locations and international transfers
Cloudflare and Google operate international infrastructure. Contact messages and technical information may be processed outside your country, including in the United States. The service does not promise storage exclusively in your country or region.
Where restrictions on international transfers apply, the relevant transfer must have an applicable legal mechanism and safeguards. Provider privacy notices explain their transfer arrangements. Contact us for information about the arrangements applicable to your request; this policy does not claim that every country offers the same legal protections.
8. Security and your choices
The public website uses HTTPS. The contact service validates input, limits submissions, restricts notification destinations and saves messages before attempting an email notification. These measures reduce risks but do not make internet transmission, email or storage risk-free.
You can use the image tools without contacting us. Use the contact form with a working reply address and the required fields to send a request. Save results before leaving the tool, and avoid including private image contents in a bug report unless you choose to disclose them in support correspondence.
Browser storage and cookie controls are described in the Cookie Policy. Deleting browser data does not delete a contact submission or an email that has already been sent.
9. Privacy requests and complaints
Depending on your location and the law that applies, you may have rights to access or obtain a copy of personal information, correct it, request deletion or restriction, object to certain processing, or receive portable data where applicable. Where processing depends on consent, you may withdraw it. Rights can be subject to exceptions and do not all apply to every activity.
Send a request through the contact form and choose Privacy request. Describe the request and, if available, include your message reference or the email address used to contact us. Please do not send an identity document unless it is necessary and we specifically request an appropriate verification method. We may ask for proportionate verification to avoid disclosing someone else’s data.
We will handle requests within the time required by applicable law and explain a refusal or limitation where required. We cannot provide or erase images that never left your browser. You may also complain to your relevant data protection authority. Contacting us first is welcome but does not remove a legal right to complain.
We do not sell or share information for targeted advertising, regardless of browser Do Not Track or Global Privacy Control signals. These signals do not disable essential security processing or delete messages already submitted.
10. Children
PicFitly is a general-purpose image tool and is not designed to collect personal information from children. The image tools do not require an account or a contact submission. Children should avoid submitting personal details and seek help from a parent or guardian when appropriate. If you believe a child has sent us information that should not have been collected, contact us so we can review it and take appropriate action.
11. Policy updates and contact
We will update this page when our practices change and revise the date above. Material changes will be highlighted where appropriate, and any consent required for new processing will be sought before it begins. A change to this policy does not itself authorize optional tracking.
Privacy requests: contact form. Related information: Cookie Policy and Contact.