Skip to content

Privacy policy

Last updated 2026-10-02

Who we are

ImageStep is operated by Jun Zhang, a sole proprietor trading as ImageStep, based in California, United States, the data controller for the personal data described here and the person you reach at support@imagestep.dev. There are no employees and no offices; questions about your data reach one person directly.

ImageStep is not offered in the European Economic Area, the United Kingdom or Switzerland, and a sign-in from there is refused (see the terms).

What we store

  • Account: email, name and avatar from the sign-in method you chose (email link, GitHub or Google), which sign-in methods are linked, and when the account was created.
  • API keys: a hash of each key you create, its name, its prefix and when it was last used. The key itself is shown once and never stored.
  • Assets: the images you upload or generate, their metadata (dimensions, EXIF, GPS if the file carries it, hashes) and the outputs of jobs. Kept for the retention period of your plan (30 days on Free, 180 days on Pro, 1 year on Max) unless you delete them earlier.
  • Presets and templates: the steps of presets you save, and the HTML and CSS of templates you save, each with every earlier version.
  • Jobs and billing: job records with their parameters and cost, credit transactions, billing periods and your Stripe customer id. Invoices and card details are held by Stripe.
  • Usage: for each synchronous call, which operation ran, with which key and when, and a daily count per operation and key.
  • Webhooks: the endpoint URLs you register, which events you subscribed to, and the last 14 days of delivery attempts with their payload and response status.
  • Feedback: reports your agents send to /api/v1/feedback — what ImageStep could not do, in their own words, with anything structured they attach. Free text, so treat it as you would any message to us: it is deleted with your account.
  • Server logs: what the service did on each request — the operation, its outcome and its timing — tagged with your account id, and on some lines your email address.
  • Audit log: which account performed which account-level action (a key, an asset, a preset or a template created, changed or deleted; a job submitted; a payment event), and every refused sign-in, each with the IP address and browser user agent it came from — those two for 90 days, like the server logs.
  • Visits: page views from cookieless analytics (below), with the country, browser, operating system, device type and referring page. The IP address is used to work out the country and is not stored; visits are grouped by a hashed identifier that changes every month, so they identify nobody.

Who processes it

  • Hetzner (servers in Falkenstein, Germany) runs the service, its database and its logs. Cloudflare is the CDN, DNS and the tunnel every request enters through, and stores your assets, in Cloudflare R2 in the United States (its Western North America location), and the encrypted backups of our database, in Cloudflare R2 in Europe (its Western Europe location).
  • AI operations send the image and, where one applies, the prompt to the provider that serves the model you chose. Which provider that is follows from the model id: OpenRouter routes generation and editing (and the model provider behind OpenRouter depends on the model and on failover, so it is not a fixed list); Fal.ai and Replicate serve the background-removal, upscaling and face-restoration models, fetching the image from a short-lived link to a temporary copy we delete within the hour. We tell OpenRouter data-collection: deny, which routes only to upstreams that do not store or train on the payload — and the payload is your image. What a provider keeps after it has answered is governed by its own terms, not by us.
  • Stripe handles payments; we never see card numbers. Amazon SES (us-east-1) delivers transactional email and therefore processes your address and the message body.
  • If you sign in with GitHub or Google, that provider tells us your email address, name and avatar URL, and learns that you signed in here. Signing in with an email link involves neither of them.
  • Cloudflare, Stripe, Amazon SES, GitHub, Google, OpenRouter, Fal.ai and Replicate are US companies; Hetzner, where the service and its database run, is in Germany. Backups of that database, encrypted at rest, are kept in Cloudflare R2 in Europe (its Western Europe location), each for at most 56 days.

The same companies are the sub-processors of the personal data inside the images you send, which you control and we process on your behalf under the data processing addendum. Customers are emailed 30 days before a new one receives it.

Our legal bases

Each use of your data rests on one of three grounds:

  • Performance of a contract — your account, your API keys, running the operations you ask for, storing the assets and job records that result, and processing a subscription or a credit purchase. This is the service you asked for; without this data there is no service to give you.
  • Legitimate interests — server logs, audit entries, the visit counts, enforcing plan limits and rate limits, and preventing abuse. Our interest is keeping a small service running, secure and affordable; we have weighed it against your privacy, kept the data narrow, and keep each kind only as long as the next section says. You may object at any time.
  • Legal obligation — retaining what tax and accounting law requires us to keep about a payment, and responding to a lawful request.

How long we keep it

  • Assets, and the job and usage records of the work that made them: your plan's retention period, stamped when each is created and never shortened afterwards — a downgrade does not delete what you already paid to store.
  • Daily usage counts: 367 days, the longest window the Usage page shows.
  • Webhook delivery attempts: 14 days.
  • A stored response to a write, kept to answer a retry of the same request: 24 hours.
  • Server logs: 90 days, then deleted automatically.
  • Audit log: 1095 days after each entry, then deleted automatically; the IP address and user agent on an entry are cleared after 90 days, so an address is kept no longer here than in the server logs. Deleting your account anonymises your entries instead of deleting them (see Your rights).
  • Account, keys, presets, templates, webhook endpoints and feedback: until you delete them, or the account.
  • Database backups: a copy of the database is taken every few hours and kept, encrypted at rest, in Cloudflare R2 in Europe; each copy ages out within 56 days. We never restore a deleted account from one: a restore erases again every account deleted after the copy was taken.
  • Addresses mail cannot reach: when mail to an address bounces or is reported as spam, our email service stops mailing it for good, and Amazon SES puts it on its own do-not-send list. Deleting the account turns our entry into a one-way fingerprint that still stops the mail; SES keeps its entry until we remove it.
  • Invoices and payment records: Stripe keeps them as long as tax and accounting law requires, which is longer than the account itself.

Analytics and cookies

The site uses self-hosted, cookieless Umami analytics served from our own domain — no third-party trackers, no advertising. The cookies are the session cookie after you sign in; the short-lived ones set while you sign in (the CSRF token that protects the form, the page to return you to, and for GitHub and Google the sign-in state); and imagestep.rail, which remembers whether you collapsed the console's sidebar. None is used for tracking, so there is no consent banner to click.

Fonts

IBM Plex Sans, IBM Plex Mono and Literata ship with the site and are served from our own origin; no request goes to Google Fonts.

Your rights

Three of them are self-serve — access, portability and erasure — and the rest reach a person:

  • Access and portability — download what we hold about your account as one JSON file from Privacy & data. The image files themselves are not in it: each asset in the file names the path it downloads from, and the asset library downloads them too.
  • Erasure — delete the account from the same page. It removes your account, keys, assets, job and usage records, templates, presets, webhook endpoints and agent feedback, and cancels any subscription first. In the database what stays is the account's random identifier and the time it was deleted — no name, no address — so that a signed-in tab that outlived the account cannot bring it back; if it received the one-time welcome credit, a one-way fingerprint of the inbox it went to, so that credit is not granted to the same inbox again; and the two audit entries recording the erasure, with the IP address and browser it was requested from until those are cleared 90 days later. Your other audit entries are anonymised. Our email service keeps one thing: if mail to your address ever bounced or was reported as spam, a one-way fingerprint of it, so a new sign-up with that address is not mailed again. What the erasure does not reach — logs, backups, Amazon SES's do-not-send list and Stripe's records — is listed under How long we keep it.
  • Rectification — your display name is editable on the Profile page. To change the email address on an account, write to support@imagestep.dev and we will move it.
  • Restriction and objection — write to support@imagestep.dev. There is no form for these because each one is a conversation, not a button. Nothing here runs on your consent, so there is none to withdraw.
  • Complaint — you may lodge one with the privacy supervisory authority where you live, whether or not you raise it with us first.

Children

ImageStep is not directed at children, and an account requires you to be at least 16. We do not knowingly collect data from anyone younger; if you believe a child has an account here, write to support@imagestep.dev and we will delete it.

Changes to this policy

When this policy changes, the date at the top changes with it. A change that materially affects what we do with data you have already given us is announced by email to the address on your account before it takes effect, not only by editing this page.