Privacy policy
Effective October 1, 2026. This policy covers the ImgOrigin API, MCP connector and website at https://api-bakeoff.up.railway.app (the "Service"), operated by Chirag Bachani ("we").
The short version
- We delete uploaded images as soon as your search finishes, usually within seconds.
- We don't train AI models on your data, and we don't sell or rent it.
- We keep your email, a scrambled fingerprint (hash) of your API key, your plan and your monthly search count. We don't link the images you search to your account.
- You can delete your account yourself at any time.
What we collect, why, and for how long
| Data | Why | Kept for |
|---|---|---|
| Images you upload | To run the search. Stored on our server under an unguessable link so the search provider can fetch it. | Deleted when the search returns (usually seconds); at most 5 minutes |
| Images you send by link (including listing photos) | Downloaded into memory to make a fingerprint for caching and, for listing checks, sent to the search provider | Not stored |
| Listing-check photo links and the listing's website name, with the result counts | Measuring and improving result quality. Not linked to your account. | 30 days |
| Image fingerprints and search results | To answer repeat searches for free. A fingerprint is a 128-bit perceptual hash; the image can't be rebuilt from it. Results are public page titles and links. Not linked to your account. | 30 days |
| Email address (typed by you, or shared by Google when you choose "Continue with Google"; we ask Google for nothing else) | Your account, sign-in codes, key delivery, billing | Until you delete your account |
| API key | Sign-in. We store only a one-way hash and the first 10 characters. | Until you rotate it or delete your account |
| Connected-app sign-ins (OAuth) | Letting apps you approve run searches for you. We store which app, one-way hashes of its access and refresh tokens, and when they expire. | Access 1 hour, refresh 30 days, or until you disconnect or delete your account |
| "Remember this browser" cookie (a random token; we store only its hash) | Skipping the sign-in step when you connect another app from the same browser | 30 days, or until you delete your account |
| Which apps you've allowed | Not asking again each time an approved app reconnects | Until you disconnect the app or delete your account |
| Plan, subscription status, monthly search counts | Enforcing plan limits | Until you delete your account |
| Sign-in codes | Confirming your email (stored hashed) | Expire after 10 minutes; erased within 1 day |
| IP address (and email) on sign-in, sign-up and recovery attempts | Preventing abuse | 1 day |
| Server request logs (address, page, status; never request contents or keys) | Running and securing the Service | Up to 30 days, per our hosting provider |
We never see or store card numbers. Stripe handles payments.
Who we share data with
Only the service providers needed to run the Service, each for the purpose listed:
- Google (Cloud Vision): to check where a photo appears. It receives the photo itself.
- SerpApi and Scrapingdog (Google Lens): to perform image searches. They receive the image's link, and Google fetches the image.
- Google (Sign in with Google): only if you choose it, to confirm your email address.
- These providers' own terms and privacy policies govern their processing.
- Stripe: payments and subscriptions (your email, billing details).
- Resend: sending email (your email address, the message).
- Cloudflare: the human check on sign-up and recovery (Turnstile), and DNS.
- Railway: hosting and database.
We may disclose data if the law requires it. We don't use advertising or analytics trackers on the website.
Your choices and rights
- Delete your account: send
DELETE /v1/accountwith your key and{"confirm": "delete my account"}. This erases your email, key and usage history, and cancels any subscription (Stripe keeps payment records as the law requires). Or email support@imgorigin.com. - See your data:
GET /v1/account, or email us. - Rotate or recover your key at any time.
- Depending on where you live (for example under GDPR or CCPA), you may have further rights to access, correct, delete or port your data, or to object to processing. Email support@imgorigin.com to use them.
Security
Keys are stored only as hashes and removed from logs. Traffic uses HTTPS. Payment webhooks are signature-checked. Uploaded files are checked by content and deleted quickly.
Children
The Service is not directed to children under 13, and we don't knowingly collect their data.
Changes and contact
We'll post changes here and email account holders about material ones. Questions: support@imgorigin.com.