Skip to main content

Legal / Privacy

Privacy, without the fog.

A readable account of the information needed to host images, maintain accounts, and keep imgtree working safely.

01
Updated March 2026
02
Eight sections
03
Service data only

In brief

01
What we keep
Uploaded files, their technical details, and the account information needed for signed-in features.
02
Why we keep it
To deliver images, run your account, prevent abuse, and operate the service.
03
What we do not do
We do not sell personal information or build advertising profiles from it.

01

Introduction

This Privacy Policy explains how imgtree (“we”, “us”) collects, uses, and stores information when you use our image hosting service.

By uploading images or creating an account, you acknowledge this policy. If you do not agree, please do not use the service.

02

What we collect

Guest uploads: we store the image file, a generated thumbnail, technical metadata (dimensions, MIME type, byte size), and a public page URL. We may record approximate network information for abuse prevention and rate limiting.

Registered accounts: we store your email address, username, password hash, session identifiers, and content you create (images, albums, API key metadata). API secrets are hashed; the raw secret is shown only once at creation.

Logs: we may retain short-lived server logs (IP address, user agent, request path, timestamps) for security, debugging, and capacity planning.

03

How we use data

We use collected information to:

  • Deliver uploaded images and generate share links or embed codes you request
  • Authenticate accounts, enforce quotas, and protect the service from abuse
  • Operate backups, soft-delete workflows, and scheduled purge jobs
  • Improve reliability and understand aggregate usage patterns
We do not sell your personal information.

04

Storage and processors

Image bytes and thumbnails are stored in object storage (Cloudflare R2 or equivalent infrastructure). Database records and application hosting may run on third-party providers chosen by the operator of this deployment.

Public images are reachable at URLs recorded in our database. Do not upload content you are not authorized to share.

05

Cookies and authentication

We use cookies or similar mechanisms to maintain signed-in sessions and to protect forms against cross-site request forgery.

You can clear cookies in your browser; signed-in features will stop working until you log in again.

06

Analytics

We may use privacy-conscious analytics to understand traffic, performance, and errors. Analytics are aggregated where possible and are not used to build advertising profiles.

07

Retention, deletion, and your rights

Deleted or expired content is removed according to operational schedules, including soft-delete markers and background purge jobs. Backups may persist for a limited time.

Account holders may delete their uploads from the dashboard or via the API. For other data requests, contact the operator of this imgtree instance.

08

Changes to this policy

We may update this policy as the product evolves. The “Updated” date on this page changes when we do. Continued use after an update means you accept the revised policy.