Privacy policy
Plain language, because vagueness here is how other people hide things.
Your files
The image you upload and the icon package made from it are stored privately in object storage. They are never placed in a public bucket and are never served from a public URL. The only way to reach a stored file is through a signed link that this site generates for you, and which stops working after 15 minutes.
They are deleted automatically on this schedule:
| What | Deleted after |
|---|---|
| Icon packages made with the browser tool | 1 hour |
| Icon packages made through the API | 24 hours |
A scheduled job runs every 15 minutes and removes anything past its window. Deletion is permanent. We cannot recover a file for you afterwards, and neither can anyone else.
What we do not do
- We do not look at your files.
- We do not train any model on your files, or let anyone else.
- We do not sell or share your files or your data.
- We run no advertising and no third-party advertising trackers.
Accounts
The browser tool needs no account at all. If you do create one for API access we store your email address, a bcrypt hash of your password, your plan, and a per-month count of how many icon packages you have generated. We never store your password. API keys are stored only as a SHA-256 hash, which is why a key is shown to you exactly once and cannot be recovered afterwards.
Payments
Payments are processed by Stripe. Card details are entered on a page Stripe hosts and never touch our servers. We store the Stripe customer and subscription identifiers, your plan, and your renewal date. Stripe has its own privacy policy covering what it holds.
Errors
When something breaks we record the error, the page it happened on, and a stack trace, so it can be fixed. Error reports do not contain your files. If you are signed in they may contain your account id, which is how a report gets connected to a bug you told us about.
Anonymous use
You can use the browser tool without an account. Doing so creates no user record. The files are stored under a random identifier and deleted on the schedule above.
Getting your data, or removing it
Deleting your account removes your user record, your API keys, your usage history, and your job history. Your files are already gone, on the schedule above. To ask for a copy of what we hold, or for deletion, write to the address below.
Contact
Questions about this policy, and requests to see or delete what we hold, can go to support@faviconize.com. Who operates Faviconize is set out on the about page.
See also the terms of service.