Last updated 18 August 2026.
This says what we hold about you, why, who else sees it, and how to get rid of it. It describes what the site actually does today, and it was written by reading the code rather than by copying another site’s policy. If we change what the site does, this page changes with it.
Who we are
Aiimage is run by one person, not a company. The legal name and postal address that belong here will be added before the site opens to visitors. Requests about your data go through the contact page, and a person reads them.
What we hold
Your account. An email address, a user name, and a password we never see in readable form: WordPress stores a one-way hash of it. Nothing else. We do not ask for a real name, a postal address, a phone number or a date of birth, and there is no field to type one into.
What you asked for. Every generation is recorded: which tool, the description you typed, the settings, when it ran, and whether it worked. The description is kept with the job so a result can be traced back to the request that produced it.
What you made. Pictures and clips are stored in our own media library, on our own server, under your account.
Your credits. A running list of every credit added and spent, with the reason for each. Your balance is the sum of that list rather than a number we keep and edit.
What you write to us. If you use the form on the contact page we keep what you sent: the topic you chose, your email address, your name if you gave one, and the message itself. The name is optional and the form works without it. There is no support desk behind this: the site itself is where your message is read and where it stays until it is deleted. If you were signed in, the message is stored with your account number, so a report about a generation can be matched to the generation.
The form does not record the address you connect from. To stop one sender flooding it we keep a scrambled marker for an hour, which expires on its own and cannot be turned back into an address. That is separate from the server logs described below, which do hold addresses.
What the server records
This section exists because most policies leave it out, and because it is the one place where an address of yours is written down.
Our hosting company keeps an access log of every request that reaches the site: a page, a stylesheet, a picture, anything. Each line holds the time, the IP address the request came from, what was asked for, the browser and operating system your browser announces, the country that address is in, the size of the answer and how long it took.
This is how web servers work rather than a decision we made, and it is what makes it possible to see that a site is being attacked or that a page is failing. We do not join it to accounts, we do not use it to build a picture of you, and we do not send it anywhere. It is held for the hosting company’s own period and we do not control how long that is.
The hosting company also turns those logs into counts for us: requests, bandwidth, countries. Those are made from the log after the fact, on their server. Nothing in the page you load is watching you.
What we do not hold
The pictures you upload. When you upload a picture to restyle, animate, sharpen or clear the background from, PHP holds it as a temporary file for the length of that one request. We read it, re-encode it, send it on, and the temporary file is discarded when the request ends. Nothing of ours copies it into the media library or anywhere else. Only the result comes back and is stored.
Re-encoding has a side effect worth knowing about: the new file carries none of the original’s camera data. Anything your camera or phone wrote into the picture (the model, the time, the GPS position where it was taken) does not leave your computer.
Payment details. The site takes no money and has no payment form. There is nothing to store.
Third-party trackers. No analytics script, no advertising network, no social buttons, no fonts fetched from anybody else’s server. Nothing in the page you load reports to a third party, and nothing follows you from here to another site. The only figures anybody sees about visits are the ones the hosting company counts from its own logs, described above.
Who else sees your data
fal.ai. This is the one that matters, and it is not optional: the site cannot generate anything without it.
When you press the button we send fal.ai the description you typed and, if you uploaded a picture, that picture. We send it with our own key. Your email address, your user name and your account are not sent, and fal.ai does not know who you are. What comes back is the finished file, which we download and store here.
fal.ai is a company in the United States, so this is a transfer of data outside Europe. What they do with what we send is governed by their own policy. If you are not comfortable with that, the honest advice is not to use the site: there is no version of it that works without them.
Our hosting company. The site runs on Hostinger. They hold the server, the database, the daily backups and the access logs, as any hosting company does.
Nobody else. We sell nothing to anyone, and we share nothing for advertising, because there is no advertising.
How long we keep it
Until you delete it.
Your results are listed on your account and each has a Delete button that removes the file for good. Your account, your job history and your credit record stay until you ask us to delete the account, which is done by writing to us.
We want to be exact about this, because a lot of policies are not. Nothing on a timer deletes your pictures, your jobs or your messages. WordPress runs its own housekeeping on a schedule (checking for updates, clearing expired temporary values, emptying the wastebasket of things already deleted) and none of our own work is scheduled at all: a generation only moves forward while a browser is asking about it. If you want something gone, delete it, or write to us and we will.
What you can ask for
The server is in Europe and the GDPR applies. You have the right to see what we hold about you, to have it corrected, to have it deleted, to get a copy of it, and to object to what we do with it.
There is no form for this. Write to us through the contact page, choose “My data” as the topic, and say what you want. We answer within a month, which is the limit the law sets rather than the time we intend to take.
You can also complain to a data protection authority if you think we have handled your data badly.
Cookies
Only the ones that make signing in work. A visitor who has not signed in is given no cookies at all, and that was checked against the live site rather than assumed. The cookie page lists what appears once you do sign in.
Children
The site is not for anyone under 16, and there is nothing here for them. We do not knowingly hold data about a child. If you believe we do, write to us and it will be deleted.
When this changes
The date at the top changes with it. If a change is significant (a new company receiving your data, a new kind of data collected) we will say so on the site rather than quietly editing this page.