Reverse Image Search API

DRAFT, pending legal review. Not yet in effect. Bracketed items are placeholders.

Privacy policy

Effective [EFFECTIVE DATE]. This policy covers the Reverse Image Search API, MCP connector and website at https://imgorigin.com (the "Service"), operated by [OPERATOR NAME] ("we").

The short version

What we collect, why, and for how long

DataWhyKept for
Images you uploadTo run the search. Stored on our server under an unguessable link so the search provider can fetch it.Deleted when the search returns (usually seconds); at most 5 minutes
Images you send by linkDownloaded into memory to make a fingerprint for cachingNot stored
Image fingerprints and search resultsTo answer repeat searches for free. A fingerprint is a 128-bit perceptual hash; the image can't be rebuilt from it. Results are public page titles and links. Not linked to your account.30 days
Email addressYour account, sign-in codes, key delivery, billingUntil you delete your account
API keySign-in. We store only a one-way hash and the first 10 characters.Until you rotate it or delete your account
Connected-app sign-ins (OAuth)Letting apps you approve run searches for you. We store which app, one-way hashes of its access and refresh tokens, and when they expire.Access 1 hour, refresh 30 days, or until you disconnect or delete your account
Plan, subscription status, monthly search countsEnforcing plan limitsUntil you delete your account
Sign-in codesConfirming your email (stored hashed)Expire after 10 minutes; erased within 1 day
IP address (and email) on sign-up and recovery attemptsPreventing abuse1 day
Server request logs (address, page, status; never request contents or keys)Running and securing the Service[LOG RETENTION, per hosting plan]

We never see or store card numbers. Stripe handles payments.

Who we share data with

Only the service providers needed to run the Service, each for the purpose listed:

We may disclose data if the law requires it. We don't use advertising or analytics trackers on the website.

Your choices and rights

Security

Keys are stored only as hashes and removed from logs. Traffic uses HTTPS. Payment webhooks are signature-checked. Uploaded files are checked by content and deleted quickly.

Children

The Service is not directed to children under [13/16], and we don't knowingly collect their data.

Changes and contact

We'll post changes here and email account holders about material ones. Questions: support@imgorigin.com.