Version 1.0 · Effective date: · Last updated:
1. Optional feedback and follow-up
Every feedback question is optional. You can submit a single answer without signing in. Only after you select Submit feedback do we receive the answers you chose to provide, a feedback reference, the survey version, a coarse page path and the invitation type. We also record the submission time. Images, filenames, raw image metadata, URL query strings and account details are not attached. Please do not paste sensitive information into the form.
We store submitted feedback in Cloudflare D1 and use Resend to send notification emails to the site operator when email delivery is configured. We use these answers to understand needs and improve the product. An email address is optional; we only use it to contact you about your feedback if you select the permission-to-reply option. This does not subscribe you to marketing. Resend handles email contents and recipient details; see the Resend Privacy Policy.
Local browser storage remembers whether you dismissed or submitted this survey version. Session storage remembers foreground time and whether an invitation was shown, so navigation does not repeatedly trigger it. Draft answers stay in page memory and are not sent while you type. Clearing site data resets these preferences. Blocking storage does not stop the image tools, but preferences may not survive a reload.
To limit spam, the server derives a daily rotating, secret-protected key from the request IP address. The feedback record stores this key, not the raw IP address. Hosting infrastructure still processes normal network requests. The scheduled maintenance process removes database feedback after 90 days. Notification copies in the operator’s mailbox are managed separately and may be retained while a feedback conversation is active. You may request deletion using support@aimetadataremover.pro; include your feedback reference so we can locate a response even if you did not provide an email address.
2. Scope and data controller
This policy describes the current AI Metadata Remover website and browser-based metadata tools at aimetadataremover.pro. It covers site access, optional Google sign-in, local file processing and session diagnostics.
The operator and data controller responsible for the personal information described in this policy is Hu Xiaocheng (胡晓成), an individual based in Shenzhen, Guangdong, China. AI Metadata Remover is the service name, not a separate incorporated company. This policy applies from the effective date shown above. For privacy questions, data requests or account closure, email support@aimetadataremover.pro.
3. Google sign-in
Signing in shares your Google profile name, email address and account identifier with this application. Authentication and session records are stored in Cloudflare D1. Session cookies last up to seven days and are invalidated when you sign out.
No image, filename, prompt or image metadata is sent as part of signing in. You can inspect supported metadata without an account. Sign-in links your daily allowance and any Pro subscription to your account.
4. Your images and metadata
When you select a file, the tool reads its bytes in your browser to inspect supported metadata, prepare a cleaned copy and check the result. Image data, filenames, thumbnails, prompts, GPS coordinates and raw metadata values are not uploaded by these tools.
Original files remain on your device. Preview URLs and processing copies are temporary browser resources. Removing a file from the workspace releases its preview resources; leaving the page ends the workspace session. Downloads remain on your device until you delete them yourself.
5. Website requests and analytics
Loading a website sends network information, such as your IP address, the requested URL and browser request headers, to the infrastructure serving it. This is separate from selecting an image: local image processing does not mean that visiting the website makes no network requests.
The workspace holds up to 200 coarse diagnostic events in page memory. These describe selection, scanning, cleaning, verification and downloading using approved categories: page path, file format, sample-or-file source, size/count/time ranges, mode, outcome and error code. These events exclude filenames, image bytes, thumbnails, hashes, prompts, coordinates and raw metadata, and are not uploaded by the workspace.
Google Analytics 4 and Microsoft Clarity are loaded when you visit the site to measure site visits and page interactions, such as pages viewed, browser/device details, and interaction or session-replay data. Those providers may receive your IP address and set or read browser identifiers/cookies. Do not enter sensitive information into the website.
6. Why information is processed
Local file access is used only to carry out the inspection, cleaning and export actions you request. Optional sign-in information is used to identify your account and maintain your login session. Website request information is needed to deliver the site and may be used by hosting infrastructure for reliability and security.
Where applicable law requires a legal basis, providing a requested service is based on performing that service; necessary security and reliability processing is based on legitimate interests; legally required disclosures are based on legal obligations. Processing that requires consent must have that consent before it begins.
7. Cookies, storage and tracking
Optional Google sign-in uses session cookies lasting up to seven days; signing out invalidates the session. Google Analytics and Microsoft Clarity may use browser identifiers or cookies when you visit the site. Blocking necessary sign-in cookies may prevent login, but the local image tools remain available without an account. Workspace state and diagnostic events are held in memory rather than saved as a cloud history.
Your browser may cache website assets and retain downloaded files. You can manage cached site data using browser settings.
8. Service providers and disclosure
We do not send selected images or raw image metadata to Google Analytics or Microsoft Clarity. These providers receive website usage information when you visit the site. We do not sell the image content you process locally or use it to train models.
Google provides authentication and Google Analytics, Microsoft provides Clarity, Cloudflare D1 stores account and usage records, and Waffo processes subscription checkout and payment events. We retain the plan, order reference, subscription status, billing period and daily usage records needed to provide access; we do not need your image bytes, filenames or raw metadata for billing. Payment details entered at checkout are handled by the payment provider rather than stored in our workspace. Hosting and network providers also handle requests used to deliver the website. Information held by the operator may be disclosed when legally required.
These providers operate international infrastructure, so account, payment, analytics and website request information may be processed outside your country. Local image processing does not mean that account data and website requests remain in your country. Where a transfer requires additional legal safeguards, we must put those requirements in place before that transfer.
9. Retention and deletion
- Selected images and output copies: kept in the active workspace session, with no server-side image history.
- Session diagnostics: limited to the latest 200 events in page memory; cleared when the page session ends.
- Downloaded files: controlled by you and your device, outside the workspace’s deletion controls.
- Account and billing records: account details are retained while your account is active; order, subscription and payment status records may be retained where needed for billing, disputes or legal obligations.
- Infrastructure logs: where Cloudflare Workers Logs are collected, see Cloudflare’s logging documentation for its retention schedule.
Signing out invalidates your session but does not delete stored account or billing records. To request deletion or account closure, use the process below under data rights. We will explain any records we must retain and why.
10. Security and your device
Keeping image processing inside the browser reduces the need to transmit private file content. Supported file checks and output verification help detect processing problems, but cannot guarantee that every metadata field is removed.
Keep your browser updated, use a trusted device and review the exported copy. Browser extensions and other software on your device are outside the tool’s control. Any legally required incident notifications remain subject to applicable law.
11. Access your data, request deletion or close your account
You may request access to, a copy of, correction of, or deletion of personal information held about you. Depending on applicable law, you may also restrict or object to processing, request a portable copy, withdraw consent, or complain to your data protection authority.
Images and local workspace data
Open the inspection panel to review the supported metadata in a selected image. Remove individual files or use Clear queue to remove them from the workspace. Close the page to end the in-memory session. Delete downloaded copies from your device separately. These actions do not change the original file or delete account records held by the service.
Request your account data or a correction
- Use the support email listed in the footer, preferably writing from the email address used for Google sign-in.
- Use the subject “Data access request” or “Data correction request”. Specify whether you want to review, receive a copy of, or correct your account information.
- We will verify your identity using only information reasonably needed to match the account, then provide the relevant data or explain any lawful restriction.
Delete personal data or close your account
Request data deletion · Request account closure
- Email the same support address with the subject “Delete my personal data” or “Close my account”. Include your sign-in email and whether you want specific data deleted or your entire AI Metadata Remover account closed.
- After verifying the request, we will delete the relevant data. Account closure includes deletion of the account profile and linked authentication records and invalidation of active sessions, except records we must retain for legal obligations or the establishment, exercise or defence of legal claims.
- We will confirm completion by email. If any data must be retained, we will explain the reason and applicable retention period. Closing your AI Metadata Remover account does not delete your Google account or files on your device.
Signing out is not account deletion. Requests are handled by email; there is no self-service account deletion button in the current interface. Do not send passwords, verification codes or private images with a request.
Response time
We will respond within 30 calendar days of receiving your request, or sooner where applicable law requires it. We will complete the request within that period where possible. If identity verification or an extension permitted by law is needed, we will explain what is required, the reason for any delay and the revised deadline within the initial response period.
12. Children
This service is not directed at children under 18. Do not send children’s personal information to the operator. Any report of such information being held by the operator should be handled by emailing support@aimetadataremover.pro.
13. Policy updates
We use account and subscription status, plus task references and daily usage counts, to provide plan allowances. Image contents, filenames, prompts and raw metadata are not needed for usage accounting. Any new upload flow must clearly explain what leaves your device and obtain any required consent.
Updates will be identified by the version and date on this page. Material changes require appropriate notice and, where required, fresh consent. Read the Terms of Service for billing, permitted uses and technical limits.