Privacy

There's no server on the other end of this page — the correction happens inside the tab you already have open, so your picture isn't something we could look at even if we wanted to.

The short version

Choosing a photograph hands it to the browser, not to us. It is decoded into memory, measured, corrected and — if you press Save — written back out as a new file by the same tab. At no point does any of it travel over the network, because there is nowhere for it to travel to: this site is a set of static files with no server, no database and no address that would accept an image.

What happens to the file you open

The picture becomes a bitmap held in the tab’s memory and a second, smaller copy for the screen. Both are discarded when you open another picture, close the tab or navigate away. Nothing is written to the disk, to local storage or to a cache — there is no “recent files” list here and no way to build one. Your original file is never modified; saving produces a new file next to it, named after the old one.

The one thing fetched from the network on your behalf is a decoder for HEIC, and only if you open a HEIC. It is code, it comes down once, and your photograph is not part of the request.

What the site itself records

Nothing at all, as this page stands today. The measurement property that would tally visits has never been set up — the place its token goes still holds a placeholder, and the layout only puts the beacon on the page once a real one is pasted in. So no visit is tallied, and no third-party request of any kind leaves your browser on a page load. If that ever changes it will be a cookie-free service that reports visits by page and by country, setting no identifier and following nobody between sites, and this paragraph will be rewritten the day it does.

The half of this that is not a promise is the half about your picture. Nothing can report what you opened, what the correction decided or whether you saved anything, because the code that would send it does not exist and the build refuses to let anyone write it: a script reads the image source for any network or storage call and fails the publish if it finds one. Turning visit counting on later would not change that, because they are not the same mechanism.

Advertising

This site is built to be funded by Google advertising, and where each unit may sit is already decided: in the reading, below the working surface, never above it and never inside it. None of it is switched on. The domain has not been approved by AdSense, so the placement components render nothing — no band, no reserved gap, and no advertising script on any page you can load right now. You are reading a policy written for the arrangement that is coming rather than one describing something already there.

When it does come, an ad script will see the page it sits on, the address you arrived from, and the ordinary set of things any third-party script on any site can see — which is exactly why browser settings and extensions that limit that are worth having. It will not see your photograph. It is handed no access to the canvas and it sits nowhere near the tool, and the picture cannot reach it in any case, because the picture never leaves the tab.

Children, and everyone else

There is no account, no sign-in and no form on this site, so there is nothing here that collects a name, an address or an age from anybody of any age. If you would like something removed, there is nothing held to remove; if that surprises you, read the paragraph above about what a static export can and cannot do.

Changes

If this policy changes, the change will be visible in the page itself rather than announced — there is no mailing list to announce it to. The commitment that will not change is the first one: the correction happens where the picture already is.