Privacy for your images
Your image files are processed on your device.
Local image processing
Selected image files are processed with browser APIs. We do not upload, store or inspect image content. Downloads are created locally. Public pages use StatInside (counter 51) for traffic analytics: visited tool, browser and network information, and analytics cookies. The counter runs in a separate empty frame; editor contents, filenames and image previews are not included. It is not loaded on account pages. Browser privacy tools may block analytics. Tools can be used without an account. Optional image.uk.app accounts are independent of uk.app accounts. We store your email, display name and password hash when you set a password. If you choose Google sign-in, we receive your verified email, display name and Google account identifier under the shared uk.app brand. We do not request Gmail or Drive access. Google sign-in connects only to this independent account; essential session and form-protection cookies keep you signed in securely. A local browser flag remembers that you use an account. While signed in, we store the tool used, number of generated files and processing date for your statistics. We do not store filenames, image contents or PDF contents. Account emails are sent through our mail provider from image@uk.app. Security rate limits and ordinary server logs help prevent abuse. For session management we store browser information, IP address, sign-in method and activity times until the session expires or is revoked (normally up to 14 days). Security emails notify you about new sign-ins and 2FA changes. If you enable 2FA, its setup secret is encrypted at rest and recovery codes are stored only as keyed hashes. Verification and setup codes are never sent to analytics services.
Account data and closure
In your account, Data & privacy lets you download account records as JSON and request closure. Closure requires your email confirmation, a seven-day cancellation period and administrator review. You may cancel before execution. Deletion removes the live account and linked usage, sign-in identities, 2FA data, sessions and queued account emails. Restricted backups and separate infrastructure logs are not instantly erased; historical backup cleanup and safe restoration require operator handling. Contact support for requests concerning those records.
Website requests
Loading this website sends ordinary HTTP requests to our hosting and proxy servers. Access logs may contain your IP address, requested path, time, response code and browser information. Do not put personal information in page URLs.
For operator details, privacy requests and general service policies, see the uk.app privacy policy or contact support.