This Privacy Policy explains how InpaintingAI (“we,” “us,” or “the service”) handles information when you visit inpaintingai.com or use the browser-based photo editor. Two daily image edits may be used without an account. We process a protected device identifier and limited network signals to enforce that allowance; an account is required to purchase or spend permanent credits.
1. Data we may collect
We may receive information you choose to provide, such as your name, email address, account identifier, authentication provider, preferred language, support topic, and message when you create an account or submit the contact form. When the editing service is configured, it receives the image you upload, the painted selection mask, and the description you enter so the requested edit can be produced. A content report or appeal may also include a policy category, job or decision reference, reporter contact details, and the explanation you submit.
Like most websites, hosting, security, analytics, and advertising systems may process technical data such as IP address, browser type, device type, referring page, approximate location derived from IP, timestamps, pages viewed, and interaction or error events. A pseudonymous device identifier and IP-derived abuse signals may be retained to prevent resetting the daily allowance by clearing browser data. We do not intentionally collect sensitive personal information and ask that you do not upload it.
2. How we use data
We use information to deliver requested edits, respond to support and privacy requests, prevent misuse, diagnose failures, measure aggregate product usage, improve performance, understand which pages are useful, and comply with legal obligations. We also use prompts, generated results, safety decisions, and limited audit metadata to detect prohibited content, prevent abuse, review reports, enforce the Acceptable Use Policy, and handle appeals. If advertising is enabled, data may also be used to measure and personalize advertising where local law and your consent allow it.
3. Uploaded images and AI processing
You retain ownership of images you upload. We do not claim ownership of your photos or generated outputs. Image, mask, and prompt data may be transmitted to the configured AI processing provider solely to produce the requested edit. AI edits are processed by fal.ai or Replicate. We send the current image, the mask for that mark, and its instruction. No-login removal edits may use the allenhooo/LaMa model through Replicate. Purchased-credit edits and edits that need instruction-following generation use quality-focused fal.ai routes, which may include Finegrain Eraser, FLUX.1 Fill Pro, Google Nano Banana 2, or OpenAI GPT Image 2. When several marks are used, they are sent as separate, sequential requests rather than one merged instruction, and different marks may use different models. fal.ai and Replicate have their own processing, infrastructure, and retention rules.
Before generation, the text prompt is sent to Waffo Prompt Sift for a content-safety decision. The configured provider may apply its own safety controls, and a reduced-size copy of the final edited image is sent to a separate fal.ai image-safety classifier before the result is released. Safety audit records store the decision, reason, matched category, provider reference, and a cryptographic hash; they do not store a second copy of the prompt or image in the moderation-event record.
The browser may temporarily hold image data in memory while you edit. Closing or refreshing the page clears that working session unless your browser retains data for its own recovery features. Do not upload an image unless you have the right to use and edit it.
4. PDF editing and conversion
Opening, previewing, and editing a PDF in the online PDF editor happens in your browser. The PDF is not sent to our server for those editing actions. If you choose Export to Word, the uploaded source PDF is sent to the conversion service because server-side document processing is required.
PDF-to-Word conversion uses a temporary working directory for the source PDF and generated DOCX. The temporary directory is deleted when the conversion request finishes, whether it succeeds or fails. We do not intentionally place PDF conversion files in account storage, a database, or permanent object storage. Hosting and security systems may still process limited request metadata such as timestamps, technical errors, IP address, and file size; response files are served with no-store cache instructions.
5. Third-party services
Depending on production configuration, the service may use Vercel for hosting, Supabase for authentication, database records, and private image storage; fal.ai for AI image processing, including endpoints based on models supplied by Black Forest Labs, Google, or OpenAI; Waffo Pancake for one-time checkout, legacy subscription, refund requests, and prompt safety checks; Google Analytics for aggregate usage measurement; and Google AdSense for advertising. An email or contact-form provider may process fields you submit. These companies act under their own privacy policies and may process data in countries outside your own.
Integrations are enabled only when their corresponding environment settings are configured. Their mention here does not mean every integration is active in every build.
7. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal data; receive a portable copy; or withdraw consent. You may also complain to your local data protection authority. We may need to verify your identity before completing a request. We do not discriminate against people for exercising privacy rights.
8. Retention and security
Contact messages are kept only as long as needed to respond, maintain reasonable support records, and meet legal obligations, normally no longer than 24 months. For each account, private storage keeps only the latest original image, combined mask preview, and final result. Starting a newer generation replaces the prior retained media set. Intermediate per-mark inputs, masks, and results are temporary and are deleted after they are no longer needed. Generation, credit-ledger, device-allowance, legacy subscription, payment, refund, security, and audit metadata may be kept longer to operate the account, reconcile provider charges, prevent fraud, and meet legal or accounting obligations. Content-safety reports, appeals, and moderation-event metadata are normally retained for up to 24 months, and longer only when needed for an active investigation, legal obligation, or defense of rights. fal.ai and other providers apply their own retention rules to data processed on their systems; we request reduced provider-side request I/O retention where supported.
We use reasonable technical and organizational safeguards, but no internet transfer or storage system is perfectly secure. Avoid uploading confidential, biometric, financial, medical, or other highly sensitive images.
9. Children and changes
The service is not directed to children under 13, and we do not knowingly collect their personal data. We may update this policy as the product or legal requirements change. The updated date at the top will identify the current version.
10. Contact
Send privacy questions or rights requests through the contact form and choose “Privacy request,” or write to support@inpaintingai.com. The service is operated by an independent remote product studio in the Asia/Shanghai time zone.
Reports of prohibited content and appeals should use the content report form. Do not send illegal image files through ordinary email.