Privacy and image processing
In short: you edit images in your browser and they are never uploaded – neither we nor anyone else can see them. We use no cookies, no ads and no tracking.
Where images are processed
Opening, compressing, resizing, converting and removing metadata all happen right in your browser (JavaScript and WebAssembly). Files are never sent to or stored on a server, and the server never processes them. Finished images stay only in the memory of the open page until you download them or close the page.
Only the tools themselves are downloaded from our server – scripts, fonts and programs for handling formats (for example for HEIC photos from iPhones). They are the same for every visitor, contain none of your data, and your browser caches them.
Metadata in your photos
Photos from phones and cameras often carry the exact GPS location, the date and time they were taken, the device model or a small thumbnail. By default we remove them during processing. If you choose Keep the capture date and camera, we keep only those two details – never the location.
Only your browser reads the metadata, so it can show the Location label on a photo. It is never sent anywhere.
Technical logs and abuse protection
Every request to the website passes through the Cloudflare network and our server. Both necessarily process technical data: IP address, time, page address and browser type. The web server keeps these logs for security and troubleshooting for at most 14 days, then they are deleted. We don’t use them for profiling or link them with anything.
To prevent overload, we count requests from each IP address. We don’t store the IP address in the database: we use only a one-way fingerprint (HMAC) whose secret salt changes every day. These records are deleted within 24 hours.
Statistics, cookies and third parties
This website uses no cookies at all. We use no third-party analytics, no ads and no tracking pixels. All website files (scripts, fonts, icons) load from our own server.
We keep only anonymous daily totals: how many images were processed and downloaded, and how often each tool or conversion was used (for example HEIC → JPG) – both also per language version of the website. Your browser sends only the feature name and counts – no identifiers, file names or anything from the images; the number of images and the processing time only rounded into groups.
If an unexpected error occurs, your browser sends us its description and location in our code, the website version and the browser and system type (e.g. “Chrome 140, Windows”). Addresses, email addresses, longer quotes and long numbers are removed from the report beforehand – it never contains anything from your images. We delete reports after 30 days. If your browser has Global Privacy Control or “Do Not Track” turned on, nothing is sent at all, not even the totals.
Who helps us run the website
- Cloudflare, Inc. – the network the website runs through (speed and attack protection). It processes the technical data of requests as described above. It may also process data outside the EU, protected by the EU standard contractual clauses.
- OVH GmbH – the server the website runs on (data center in Germany). Your images are never on it.
Locally in your browser
Your browser remembers the light or dark theme you chose and the last tool settings (such as format, quality or dimensions). It doesn’t remember the names or content of your files. You can delete this by clearing the website’s data in your browser.
Questions and contact
We keep nothing about you as a person – no accounts, names or email addresses, and we never have your images. The server’s technical logs are deleted after 14 days at the latest. That’s why there’s usually nothing for us to hand over, correct or delete.
Send privacy questions to hello@peekless.app. If you feel we’re not handling data properly, you can lodge a complaint with a data protection authority – for example the one in the country where you live.
Last updated: October 1, 2026. If we change this policy, we will update this page.