editpot.

Privacy Policy

Effective: 2026-08-22 · Last amended: 2026-09-01

This policy explains what information editpot ("we", "the service") collects, why, and what your rights are.

By default, your images never leave your browser

Every editing and conversion feature in editpot runs entirely in your browser.

1. What we collect and how

Category Data How
Sign-up (email) Email address, password (stored as a one-way hash) Entered by you
Sign-up / login (Google) Email address, name, profile picture, Google account identifier (sub) Received from Google OAuth with your consent
Automatically IP address, country, browser type/version, language setting, access time, visit count and time spent, usage records (how the editor was opened, how many times each tool was used, export format and image dimensions), cookies Generated while you use the service
Cloud save (paid, optional — planned) The work files you save (images included), file name, save time When you run the save feature
Paid plans (planned) Payment details are collected and processed directly by our Merchant of Record; we never store card numbers Payment provider

If you use the tools without creating an account, we collect nothing beyond the "Automatically" row above.

The usage records in that row are counts and statistics — such as how many times a tool was used. They never include the names or contents of the files you edit (§0); by default your images are not sent to our servers at all.

2. Why we process it

  1. Account identification, login sessions, account management
  2. Providing paid features and purchase history (when introduced)
  3. Service announcements and support
  4. Keeping the service secure and preventing abuse
  5. Complying with legal obligations

3. How long we keep it

Data Retention
Account data (email, name) Until you delete your account, then erased without delay
Abuse records 90 days after account deletion
Access and usage logs (IP, visitor cookie identifier, usage statistics) Kept while needed to operate and improve the service and to prevent abuse; erased without delay once that purpose is fulfilled
Cloud save work files (planned) Until you delete them or delete your account. If a subscription ends, we keep them for a grace period so you can download them and then erase them; the exact period will be stated in this table and announced before the feature launches
Commerce records (when payments launch) 5 years for contract and payment records, 3 years for dispute records (Korean E-Commerce Act)

When you delete your account, your account data is erased immediately and any remaining access or usage logs are detached from your account, leaving only statistics that can no longer identify you.

4. Sharing with third parties

We do not share your personal data with third parties, except:

  1. with your prior consent, or
  2. where required by law or a lawful request from authorities.

5. Processors and international transfers

The servers and database that run the service are equipment the operator owns and runs directly; no domestic processor handles your data. We do use the following overseas providers, which involves transferring data outside Korea (disclosed under Article 28-8(1)(3) of the Korean Personal Information Protection Act):

Processor Country Data When Purpose / retention
Cloudflare, Inc. ([email protected]) USA and global edge network IP address, connection logs On each connection CDN, security, DNS. For the duration of our contract
Google LLC (if you use Google sign-in) USA OAuth identification data On login Authentication

If you do not wish your data to be transferred abroad, you may refrain from creating an account or delete it; the in-browser editing tools remain fully usable without an account.

6. Deletion

When the retention period ends or the purpose is fulfilled, data is erased without delay using irreversible methods. Data we must keep by law is stored separately and erased when the statutory period expires.

7. Your rights

You may at any time request access to, correction of, deletion of, or suspension of processing of your personal data. You can delete your account yourself from the "Delete account" item in the account menu. For access, correction, or suspension requests, email us (§10). We respond within 10 days. You may act through a legal representative or an authorized agent.

If you are in the EU/EEA or UK, you additionally have the rights under the GDPR (including data portability and the right to lodge a complaint with your supervisory authority). Our legal bases are contract performance (Art. 6(1)(b)) for account features and legitimate interests (Art. 6(1)(f)) for security logging.

8. Cookies

9. Security

  1. Passwords are stored only as one-way hashes (scrypt) with a random per-account salt; we never keep the original
  2. All traffic is encrypted with TLS (HTTPS), with HSTS enabled
  3. Session tokens are issued as httpOnly cookies that page scripts cannot read
  4. Least-privilege access — statistics and account data can only be read by requests that pass a server-side administrator check
  5. Access logs are retained and reviewed for signs of abnormal access
  6. Password reset links expire after 30 minutes and can be used once
  7. Password reset responses do not reveal whether an account exists (no account enumeration)
  8. Not sending your files to a server in the first place removes the largest source of exposure (§0)

10. Contact

Privacy officer Choe Seunggyu (최승규)
Email [email protected]

11. Changes to this policy

We announce changes on this page at least 7 days before they take effect (30 days for changes that reduce your rights).