Privacy Policy
Last updated: October 2, 2026
SiPhotoEditor is an SI photo editor at siphotoeditor.com. SI means super intelligence, the name for what was formerly called AI. This privacy policy sets out how we treat personal data when you browse, sign in, upload a photo, ask for an edit or buy credits. Because the pictures people bring here often show real faces, most of this privacy policy is about photos: where they travel, who can open them and how long they stay.
Who this privacy policy applies to
This privacy policy covers every page of the site, the photo editor workspace, the gift center and any email we send you. Outside services you reach through us, such as Google sign-in or Stripe checkout, follow their own privacy policy.
Data we hold about you
- Account. Your email address. With Google sign-in, Google also passes along your name, your profile photo and your Google ID.
- Photos you upload. JPG, PNG and WebP files of up to 10 MB are accepted. Your browser redraws every photo on a canvas before uploading it, capped at 2048 pixels on the longest side, and the copy it sends no longer carries EXIF metadata such as GPS position, camera model or capture time. PNG and WebP stay in their format; other images are converted to JPEG.
- Instructions and results. The change you type or the quick edit you choose, the model, the credit cost, and the edited picture the model returns.
- Credits and orders. Each balance movement (purchases, gifts, edit charges, automatic refunds) and, per order, the pack, price, time, status and whatever Stripe confirms about the payment, possibly your checkout name, email and billing country. Card numbers never leave Stripe.
- Gift center. The stars and comment you leave under “Rate us”, your invite code and the list of accounts that joined with it.
- Technical data. For each login session, its IP address and browser; also your sign-up country as Cloudflare reports it, and when you were last active.
Photos of people
Many uploads show faces, some of them belonging to people other than you, and this privacy policy protects everyone pictured, not only account holders. We do not run face recognition, build face templates or try to identify anyone; the photo simply travels, as an image, to the editing model you picked, which processes the whole picture, faces included, to make the edit. Before you upload a picture of someone else, get their permission, as our Terms of Service require. If you appear in a photo edited here and want it removed, write to us and we will review the request.
The path of a photo edit
- Upload. The prepared photo goes into our Cloudflare R2 bucket and receives its own address under /media/ on siphotoeditor.com.
- Screening. When you press Apply edit, a Llama Guard moderation model on Cloudflare reads your instruction text, never the photo, and refuses flagged requests (sexual content, sexual violence, child safety, hate or self-harm) before any credits move. If that service is down, the edit continues and the provider’s own filters still apply.
- Editing. fal.ai fetches your photo from its /media address together with your instruction and runs the model you chose, made by Google, ByteDance, Alibaba, OpenAI, Black Forest Labs or xAI. fal.ai and the model’s maker may apply their own safety filters and handle the data under their own terms.
- Saving. We copy the edited picture into R2 at its own /media address, so Recent edits can still show it once fal.ai’s short-lived link has lapsed.
- Record. We keep a job record with the instruction, model, settings, credit cost, timing and, for a failed edit, the error, so we can refund failures and answer support questions.
Who can open your photos
Uploads and results are served from long, randomly generated addresses under siphotoeditor.com/media/. They are unlisted and practically impossible to guess, but they carry no password: anyone holding the exact link can open the file, so share a result only with people who should see it. A browser that has already opened a file may keep its own cached copy for a while, even after we delete ours.
Why we use this data
This privacy policy allows the following uses and no others:
- running and protecting your account;
- storing your photos, applying the edits you request and showing you the results;
- processing purchases, crediting your balance, returning credits for failed edits and answering support mail;
- preventing fraud and abuse and enforcing our rules;
- measuring which features get used.
Personal data is never sold, never used for ads and never used to train any model, and nothing you upload or create is published on the site or shown to other users.
Service providers
- Cloudflare: hosting, database, R2 storage, sign-in email delivery and the moderation model.
- fal.ai and the maker of the model you choose: they receive your photo and instruction to produce the edit.
- Stripe: card payments, reached via our payment hub.
- Google: verifies your identity for Continue with Google.
Several of these companies operate in the US and other countries beyond your own and rely on their own safeguards for international transfers. Apart from the sharing this privacy policy describes, or where a law compels us, we pass personal data to no one.
Cookies and browser storage
Only one cookie comes from us: sid, the login cookie, valid for at most 60 days and deleted at sign-out. We use no advertising or tracking cookies, although Google’s sign-in window and Stripe’s checkout page place cookies of their own. Opening a friend’s invite link stores its code in local storage for 30 days at most, which lets the invite count if you join later. Session storage remembers a dismissed offer banner and briefly holds any edit instruction passed in a link, so it leaves the address bar before analytics loads.
Analytics
For statistics we run our own copy of Umami, an open-source tool. It logs page visits and a small set of events, for example photo uploads, applied edits and checkout visits, along with the referring page, browser, device type, language and an approximate location based on your IP address. It uses no cookies, keeps no readable IP address, never sees your photos and serves no advertising.
How long data is kept
This privacy policy sets these limits, enforced by an hourly cleanup job where a deadline applies:
- Account details: while the account exists.
- Uploaded photos: erased automatically 30 days after upload. “Keep editing this result” turns a result into a fresh upload, which expires on the same 30-day clock. Once an original is gone, Recent edits can no longer show the before side of that edit.
- Edited results: until you delete the edit or your account. Deleting an edit erases its result file from our storage; the job record (instruction, model and cost) remains for billing.
- Login sessions: 60 days at most. Sign-in links work for 20 minutes, and we wipe their record the following day.
- Orders and credit history: for the retention period tax and accounting rules set, which can outlast the account.
Removing photos or closing your account
To have a photo removed sooner, or to close your account, email support@siphotoeditor.com from your registered address. Within 30 days, closing an account deletes your uploads and edited results, ends every session, clears the instructions saved with your edits, replaces your email address with a meaningless placeholder, and removes your name, profile picture, Google ID and country. Orders and credit history are kept for accounting.
Security
Connections are encrypted with HTTPS. We store session tokens and sign-in links only in hashed form, so even a leaked database copy would be useless for signing in to your account, and only a handful of admins can reach the back office.
Emails
Under this privacy policy we only email sign-in links you ask for, answers to your messages and rare service notices. Stripe may send a receipt after a purchase. We never send newsletters or promotions.
Your privacy rights
Wherever you are, this privacy policy lets you request access to your data, have mistakes corrected or have your account erased. Depending on where you live (for example the EEA, the UK or California), you may also have the right to object to or limit processing, to data portability and to complain to your data protection regulator. We neither sell nor share personal information in the sense of California law. To exercise any right under this privacy policy, write to support@siphotoeditor.com from your registered email.
Legal bases under the GDPR and UK GDPR: performing our contract with you (account, edits, purchases), legitimate interests (security and statistics), legal duties (tax records) and consent where it is required.
Children
SiPhotoEditor is for adults aged 18 or older, and we never knowingly collect data from minors. This privacy policy expects photos of children to be uploaded only by a parent or legal guardian. If you believe a minor has an account, tell us and we will delete it.
Updates to this privacy policy
If our data practices change, this privacy policy is revised and the date above updated; larger changes are also announced by email. Pricing and refunds are explained on the SI photo editor pricing page and in the Refund Policy. Send questions about this privacy policy to support@siphotoeditor.com, and see the home page for what the editor can do.
