Privacy Policy
Effective: 2026-08-22 · Last amended: 2026-09-01
By default, your images never leave your browser
Every editing and conversion feature in editpot runs entirely in your browser.
- Files you open (images, PSD, AI, GIF, etc.) are never uploaded to our servers. We cannot receive, store, or view your files, their names, or their metadata.
- We are preparing an optional paid cloud save feature that keeps only the files you press save on, so you can continue on another device. It is not available yet — we will update this policy and tell you before it launches.
- The personal data described below relates only to your account. The files you edit are never collected in the first place.
1. What we collect and how
| Category | Data | How |
|---|---|---|
| Sign-up (email) | Email address, password (stored as a one-way hash) | Entered by you |
| Sign-up / login (Google) | Email address, name, profile picture, Google account identifier (sub) | Received from Google OAuth with your consent |
| Automatically | IP address, country, browser type/version, language setting, access time, visit count and time spent, usage records (how the editor was opened, how many times each tool was used, export format and image dimensions), cookies | Generated while you use the service |
| Cloud save (paid, optional — planned) | The work files you save (images included), file name, save time | When you run the save feature |
| Paid plans (planned) | Payment details are collected and processed directly by our Merchant of Record; we never store card numbers | Payment provider |
If you use the tools without creating an account, we collect nothing beyond the "Automatically" row above.
The usage records in that row are counts and statistics — such as how many times a tool was used. They never include the names or contents of the files you edit (§0); by default your images are not sent to our servers at all.
2. Why we process it
- Account identification, login sessions, account management
- Providing paid features and purchase history (when introduced)
- Service announcements and support
- Keeping the service secure and preventing abuse
- Complying with legal obligations
3. How long we keep it
| Data | Retention |
|---|---|
| Account data (email, name) | Until you delete your account, then erased without delay |
| Abuse records | 90 days after account deletion |
| Access and usage logs (IP, visitor cookie identifier, usage statistics) | Kept while needed to operate and improve the service and to prevent abuse; erased without delay once that purpose is fulfilled |
| Cloud save work files (planned) | Until you delete them or delete your account. If a subscription ends, we keep them for a grace period so you can download them and then erase them; the exact period will be stated in this table and announced before the feature launches |
| Commerce records (when payments launch) | 5 years for contract and payment records, 3 years for dispute records (Korean E-Commerce Act) |
When you delete your account, your account data is erased immediately and any remaining access or usage logs are detached from your account, leaving only statistics that can no longer identify you.
4. Sharing with third parties
We do not share your personal data with third parties, except:
- with your prior consent, or
- where required by law or a lawful request from authorities.
5. Processors and international transfers
The servers and database that run the service are equipment the operator owns and runs directly; no domestic processor handles your data. We do use the following overseas providers, which involves transferring data outside Korea (disclosed under Article 28-8(1)(3) of the Korean Personal Information Protection Act):
| Processor | Country | Data | When | Purpose / retention |
|---|---|---|---|---|
| Cloudflare, Inc. ([email protected]) | USA and global edge network | IP address, connection logs | On each connection | CDN, security, DNS. For the duration of our contract |
| Google LLC (if you use Google sign-in) | USA | OAuth identification data | On login | Authentication |
If you do not wish your data to be transferred abroad, you may refrain from creating an account or delete it; the in-browser editing tools remain fully usable without an account.
6. Deletion
When the retention period ends or the purpose is fulfilled, data is erased without delay using irreversible methods. Data we must keep by law is stored separately and erased when the statutory period expires.
7. Your rights
You may at any time request access to, correction of, deletion of, or suspension of processing of your personal data. You can delete your account yourself from the "Delete account" item in the account menu. For access, correction, or suspension requests, email us (§10). We respond within 10 days. You may act through a legal representative or an authorized agent.
If you are in the EU/EEA or UK, you additionally have the rights under the GDPR (including data portability and the right to lodge a complaint with your supervisory authority). Our legal bases are contract performance (Art. 6(1)(b)) for account features and legitimate interests (Art. 6(1)(f)) for security logging.
8. Cookies
- An essential session cookie (
si_session) keeps you logged in. It is issued as httpOnly, so page scripts cannot read it, and it is cleared when you log out. - A visitor cookie (
si_vid, stored for 400 days) lets us count visits without double-counting. It is a random value that does not identify you on its own; if you log in, it is linked to your account. - We do not use Google Analytics, any other third-party analytics, or advertising trackers. Visit and usage statistics are recorded on our own servers and are not shared with anyone.
- You can block or delete cookies and site data in your browser settings; login-based features may then be unavailable.
- Work-in-progress state may be saved in your browser's local storage only; it is not sent to our servers unless you use cloud save (planned).
9. Security
- Passwords are stored only as one-way hashes (scrypt) with a random per-account salt; we never keep the original
- All traffic is encrypted with TLS (HTTPS), with HSTS enabled
- Session tokens are issued as httpOnly cookies that page scripts cannot read
- Least-privilege access — statistics and account data can only be read by requests that pass a server-side administrator check
- Access logs are retained and reviewed for signs of abnormal access
- Password reset links expire after 30 minutes and can be used once
- Password reset responses do not reveal whether an account exists (no account enumeration)
- Not sending your files to a server in the first place removes the largest source of exposure (§0)
10. Contact
| Privacy officer | Choe Seunggyu (최승규) |
| [email protected] |
11. Changes to this policy
We announce changes on this page at least 7 days before they take effect (30 days for changes that reduce your rights).
- Published / effective: 2026-08-22
- Amended 2026-09-01 — advance notice of the planned cloud save feature (paid, optional). Nothing we collect today has changed; we will announce again before the feature actually launches