DRAFT, pending legal review. Not yet in effect. Bracketed items are placeholders.
Privacy policy
Effective [EFFECTIVE DATE]. This policy covers the Reverse Image Search API, MCP connector and website at https://imgorigin.com (the "Service"), operated by [OPERATOR NAME] ("we").
The short version
- We delete uploaded images as soon as your search finishes, usually within seconds.
- We don't train AI models on your data, and we don't sell or rent it.
- We keep your email, a scrambled fingerprint (hash) of your API key, your plan and your monthly search count. We don't keep a record of which images you searched.
- You can delete your account yourself at any time.
What we collect, why, and for how long
| Data | Why | Kept for |
|---|---|---|
| Images you upload | To run the search. Stored on our server under an unguessable link so the search provider can fetch it. | Deleted when the search returns (usually seconds); at most 5 minutes |
| Images you send by link | Downloaded into memory to make a fingerprint for caching | Not stored |
| Image fingerprints and search results | To answer repeat searches for free. A fingerprint is a 128-bit perceptual hash; the image can't be rebuilt from it. Results are public page titles and links. Not linked to your account. | 30 days |
| Email address | Your account, sign-in codes, key delivery, billing | Until you delete your account |
| API key | Sign-in. We store only a one-way hash and the first 10 characters. | Until you rotate it or delete your account |
| Connected-app sign-ins (OAuth) | Letting apps you approve run searches for you. We store which app, one-way hashes of its access and refresh tokens, and when they expire. | Access 1 hour, refresh 30 days, or until you disconnect or delete your account |
| Plan, subscription status, monthly search counts | Enforcing plan limits | Until you delete your account |
| Sign-in codes | Confirming your email (stored hashed) | Expire after 10 minutes; erased within 1 day |
| IP address (and email) on sign-up and recovery attempts | Preventing abuse | 1 day |
| Server request logs (address, page, status; never request contents or keys) | Running and securing the Service | [LOG RETENTION, per hosting plan] |
We never see or store card numbers. Stripe handles payments.
Who we share data with
Only the service providers needed to run the Service, each for the purpose listed:
- SerpApi and Google: to perform the image search. They receive the image's link, and Google fetches the image. Their own terms and privacy policies govern that processing.
- Stripe: payments and subscriptions (your email, billing details).
- Resend: sending email (your email address, the message).
- Cloudflare: the human check on sign-up and recovery (Turnstile), and DNS.
- Railway: hosting and database.
We may disclose data if the law requires it. We don't use advertising or analytics trackers on the website.
Your choices and rights
- Delete your account: send
DELETE /v1/accountwith your key and{"confirm": "delete my account"}. This erases your email, key and usage history, and cancels any subscription (Stripe keeps payment records as the law requires). Or email support@imgorigin.com. - See your data:
GET /v1/account, or email us. - Rotate or recover your key at any time.
- Depending on where you live (for example under GDPR or CCPA), you may have further rights to access, correct, delete or port your data, or to object to processing. Email support@imgorigin.com to use them. [ADD REGION-SPECIFIC DETAILS / LEGAL BASES AFTER LEGAL REVIEW]
Security
Keys are stored only as hashes and removed from logs. Traffic uses HTTPS. Payment webhooks are signature-checked. Uploaded files are checked by content and deleted quickly.
Children
The Service is not directed to children under [13/16], and we don't knowingly collect their data.
Changes and contact
We'll post changes here and email account holders about material ones. Questions: support@imgorigin.com.