ImgOrigin

Privacy policy

Effective October 1, 2026. This policy covers the ImgOrigin API, MCP connector and website at https://api-bakeoff.up.railway.app (the "Service"), operated by Chirag Bachani ("we").

The short version

What we collect, why, and for how long

DataWhyKept for
Images you uploadTo run the search. Stored on our server under an unguessable link so the search provider can fetch it.Deleted when the search returns (usually seconds); at most 5 minutes
Images you send by link (including listing photos)Downloaded into memory to make a fingerprint for caching and, for listing checks, sent to the search providerNot stored
Listing-check photo links and the listing's website name, with the result countsMeasuring and improving result quality. Not linked to your account.30 days
Image fingerprints and search resultsTo answer repeat searches for free. A fingerprint is a 128-bit perceptual hash; the image can't be rebuilt from it. Results are public page titles and links. Not linked to your account.30 days
Email address (typed by you, or shared by Google when you choose "Continue with Google"; we ask Google for nothing else)Your account, sign-in codes, key delivery, billingUntil you delete your account
API keySign-in. We store only a one-way hash and the first 10 characters.Until you rotate it or delete your account
Connected-app sign-ins (OAuth)Letting apps you approve run searches for you. We store which app, one-way hashes of its access and refresh tokens, and when they expire.Access 1 hour, refresh 30 days, or until you disconnect or delete your account
"Remember this browser" cookie (a random token; we store only its hash)Skipping the sign-in step when you connect another app from the same browser30 days, or until you delete your account
Which apps you've allowedNot asking again each time an approved app reconnectsUntil you disconnect the app or delete your account
Plan, subscription status, monthly search countsEnforcing plan limitsUntil you delete your account
Sign-in codesConfirming your email (stored hashed)Expire after 10 minutes; erased within 1 day
IP address (and email) on sign-in, sign-up and recovery attemptsPreventing abuse1 day
Server request logs (address, page, status; never request contents or keys)Running and securing the ServiceUp to 30 days, per our hosting provider

We never see or store card numbers. Stripe handles payments.

Who we share data with

Only the service providers needed to run the Service, each for the purpose listed:

We may disclose data if the law requires it. We don't use advertising or analytics trackers on the website.

Your choices and rights

Security

Keys are stored only as hashes and removed from logs. Traffic uses HTTPS. Payment webhooks are signature-checked. Uploaded files are checked by content and deleted quickly.

Children

The Service is not directed to children under 13, and we don't knowingly collect their data.

Changes and contact

We'll post changes here and email account holders about material ones. Questions: support@imgorigin.com.