Privacy notice

Edit Image edits your images in your browser, not on a server. This notice says which personal data is processed when you use the site, by whom and why, and what rights you have under the General Data Protection Regulation (GDPR).

Who is responsible

The operator of Edit Image, a private individual in Sweden, is the controller under the GDPR for the data described here. Contact:

[email protected]

Visiting the site

The site is a set of static files, which Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) serves through its network (Cloudflare Pages). When your browser requests a page or a file, Cloudflare processes the request's data: your IP address and the approximate location Cloudflare derives from it, the date and time, the address requested, your browser's user agent (its name and version and the operating system), the page you came from (referrer) and technical details of the connection, such as the protocol and the response's status.

Cloudflare uses the data to deliver the site and to protect it from attacks and misuse, such as floods of requests. The legal basis is Art. 6(1)(f) GDPR. The operator's legitimate interest is to deliver the site you asked for, reliably and securely. The site has no server code and keeps no logs of its own.

Cloudflare acts on the operator's behalf, as a processor (Art. 28 GDPR), for the request logs it shows the operator. For the data it uses to secure and run its network, it is a controller of its own, as its privacy policy says.

Cloudflare documents no fixed period for how long it keeps the request data. For the data it processes on the operator's behalf, its data processing addendum limits it to as long as the processing is needed to provide the service, and to the end of the operator's contract at the latest, unless the law requires Cloudflare to keep it longer. In Cloudflare's dashboard, the operator can see a sample of the past 7 days' requests, with their IP addresses.

Cloudflare, Inc. is in the United States. A request is handled in the Cloudflare data centre nearest you, which can be outside the EU, and Cloudflare can store logs in its data centres elsewhere, including in the United States. Transfers to the United States rely on Cloudflare's certification under the EU-U.S. Data Privacy Framework (its entry), for which the European Commission has adopted an adequacy decision (Art. 45 GDPR). Other transfers, and those to the United States should the certification lapse, rely on the EU standard contractual clauses (Commission Implementing Decision (EU) 2021/914), which Cloudflare's data processing addendum includes (Art. 46(2)(c) GDPR).

Downloading the AI models

The Find sensitive info, Find faces, Highlight text lines and Remove background buttons, and the Read tool, need a model, which each downloads the first time you use it. A dialog first says what downloads and its size, and nothing is fetched until you press Download. Your browser then requests the files from this site, and Cloudflare serves them as it serves the pages. Cloudflare processes the same request data as for a page, for the same purposes, on the same legal basis and in the same roles. Each request names a model file and says nothing about your image.

What's stored on your device

The site keeps these in your browser's storage, on your device. What isn't deleted by itself, as described below, stays until you delete it. None of it is sent to the operator or anyone else.

To delete all of it, clear this site's data in your browser's settings.

What never leaves your device

Your images and your edits, the text the AI tools read from them and the faces they find are processed only in your browser. None of it is uploaded, and the operator never receives any of it. The models run in a worker that the site doesn't allow to connect anywhere. Saving writes the image to your device, Copy puts it on your clipboard, and Share hands it to the app you pick.

No analytics or ads

The site runs no analytics or tracking, shows no ads, and loads nothing from other sites, such as fonts, videos or social media buttons. The site itself sets no cookies. During an attack, Cloudflare can ask your browser to prove it isn't a bot, and then sets a cookie, cf_clearance, that records for 30 minutes that it passed, so that you aren't asked again on every page.

Emailing the operator

If you write to [email protected], the operator processes your email address, your message and anything else you include, to answer you. The legal basis is Art. 6(1)(f) GDPR, the interest in answering. The operator's email provider keeps the messages on the operator's behalf.

Your rights

Under the GDPR you have the right to:

To use them, email [email protected]. What the site stores on your device never reaches the operator, and you can see and delete it there yourself.

The operator's supervisory authority is the Swedish data protection authority, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden, imy.se.

Your right to object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your data based on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). The operator then stops processing it, unless there are compelling legitimate grounds for the processing that override your interests, rights and freedoms, or it serves the establishment, exercise or defence of legal claims. To object, email [email protected].

Do you have to provide data?

No law or contract requires you to. The site can't be delivered to your browser without the request data, your IP address in particular.

No automated decisions

No decisions are made about you by automated means, and no profile of you is built (Art. 22 GDPR). The AI tools run on your device and only suggest what they find, for you to confirm.

As of 25 September 2026.