← Back to SaveImage

Privacy Policy

SaveImage website, tools and Save image as… extension
Last updated: July 11, 2026

1. The Short Version

Save image as… ("SaveImage", "the Extension") is a privacy-first, open-source browser extension. Image conversion happens entirely on your own device. In one narrow case — when a website actively blocks your browser from converting its image — the Extension can, as an optional last resort, ask our server to fetch that single image so it can be converted (see Section 5); you can switch this off. Apart from that, the images you save never leave your computer, and the Extension requests no host permissions to read the pages you browse.

We do not ask for a profile or track you across websites. We process a small amount of pseudonymous technical and usage data to run credits, payments, abuse protection and product analytics. The categories, purposes and controls are described below.

2. What We Do NOT Collect

  • The images you convert, crop, or download — these are processed locally and are never uploaded to us. Two narrow exceptions, both described in Section 5: the optional AI features, which you must explicitly trigger, and the optional conversion fallback, which sends a single image to our server only when a website blocks your browser from converting it locally and only while that setting is left on.
  • The URL, address, or domain of the pages you visit, the filenames you save, or the contents of any image. (One narrow exception: when a conversion fails, the Extension can optionally report just the domain of the image that failed — never the page, the full link, the filename, or the image — so we can fix it. This has its own on/off switch; see Section 3.)
  • A public user profile or password-based account. Purchases are linked to a random browser identifier; Paddle holds the billing email, and we process that email only when you request purchase restoration.
  • Browsing history. The Extension uses no host permissions and does not read or monitor the pages you browse.

3. Product Analytics

To understand how the Extension and website tools are used, we send a small set of pseudonymous product events to PostHog. We do not send image bytes, filenames, prompts, full page URLs or billing identifiers in analytics.

What an event contains

  • The action taken — for example, that an image was converted, that the crop editor was opened, or that the Extension was installed.
  • The chosen output format (e.g. JPG, PNG, WebP), the Extension version, and your browser's UI language.
  • A random identifier generated on install, stored locally on your device. It is not tied to your identity and is used only to estimate how many people use the Extension. It is never synced and never combined with other data.
  • On saveimage.app, a separate random browser identifier stored in localStorage, the page path, a referrer stripped of its query string, and aggregate tool states such as opened, completed or failed. The analytics identifier is deliberately separate from the credit and billing identifier.

We explicitly do not send image contents, page URLs, page addresses, or filenames in any analytics event. The single, narrow exception is the image domain on a failed conversion, described under "Diagnosing failed conversions" below. PostHog receives your IP address as a normal part of any internet request; we use it only for coarse country-level aggregation and do not store it against your events as an identifier.

Diagnosing failed conversions

Some websites and image CDNs serve images in ways that block in-browser conversion. When a conversion fails, the Extension sends a short, anonymous error event that — to help us reproduce and fix the problem for that site — includes the domain of the image that failed (for example, pbs.twimg.com). It never includes the address of the page you were on, the full image link or query string, the filename, or the image itself.

This is controlled by a separate option, "Help fix failed conversions,"in the Extension's Privacy options. It is on by default and independent of the main analytics switch; turn it off and a failed conversion reports only an anonymous error code with no domain. It has no effect at all when usage analytics above is turned off — in that case nothing is sent.

Turning it off

You can disable Extension analytics at any time: open the Extension's Options page and turn off "Share anonymous usage stats." For the website, use the control below. We also honor Do Not Track and Global Privacy Control in browsers that expose those signals.

4. Settings & Local Storage

Your preferences (default format, quality, and other options) are stored using the browser's extension storage. If you are signed in to your browser, the browser may sync these settings across your own devices via your browser account — this is handled by your browser, not by us, and the settings are not sent to our servers. Images passed to the crop editor are stored in the Extension's local IndexedDB so the editor can continue working after a save or tab reopen. They remain on your device until Extension data is cleared or the Extension is uninstalled.

5. When Images Are Sent to Our Server

Converting images a website blocks

Some websites and image CDNs deliver their images in a way that prevents your browser from converting them on your device (technically, they omit the cross-origin header a browser needs to read the image into a canvas). When that happens, and only after every on-device attempt has failed, the Extension can fall back to our server: it sends the address (URL) of that single image to our processing server, which fetches that one image and returns it so the Extension can finish converting it to your chosen format. This runs only for images that would otherwise fail — never for images that convert normally — and the image is not stored or logged beyond the moment it is fetched and passed back.

This fallback is controlled by the "Convert blocked images via our server"option in the Extension's Privacy settings. It is on by default; turn it off to keep every conversion fully on your device — blocked images are then simply saved in their original format instead.

Subscriptions

Premium is a subscription — there is no license key. Payments and billing are handled by Paddle.com Market Limited, which acts as merchant of record; when you purchase, your payment and contact details are handled by Paddle under its own privacy policy. To link a purchase to your install we generate a random, anonymous account identifier stored locally on your device (never synced); we do not store your name or email — only Paddle does. Restoring a subscription on another device sends the email you paid with to our server solely to look it up with Paddle and email you a code.

AI image tools

Optional AI tools are available through free credits, one-time credit packs or a subscription (remove background, enhance/upscale, object erase and prompt-based edits). These features — and only these features — send the image you are editing to our processing server, which checks your subscription or free-credit balance and forwards the image to our AI provider (Replicate) to perform the requested operation. The result is returned to your editor. We do not use your images to train models, and images are not retained beyond what is needed to perform the operation. These tools run only when you explicitly invoke them.

Credits, rate limits and abuse prevention

The website and Extension use a random account identifier to track free, purchased and subscription credits. Our server receives the IP address that accompanies a network request and uses keyed hashes and short-lived counters to enforce per-account and per-network rate limits, protect the free tier and prevent automated abuse. We do not use those controls to build an advertising profile.

6. What We Never Do

  • We do not sell your data.
  • We do not serve ads or use advertising trackers.
  • We do not build advertising or marketing profiles about you.
  • We do not share your data with third parties except the service providers strictly needed to operate the features described above (PostHog for anonymous analytics; Paddle and Replicate only for premium/AI features you choose to use).

7. Data Retention

Pseudonymous analytics events are retained by our analytics provider for as long as needed for product analysis. Credit, rate-limit and purchase-linking records are kept for as long as needed to provide the service, prevent repeated free-tier abuse and meet payment or legal obligations. Local settings and random identifiers remain in Extension storage or website localStorage until you clear that data or uninstall the Extension.

8. Children

The Extension is a general-purpose utility and is not directed at children under 13. We do not knowingly collect personal information from children.

9. Your Rights

We do not maintain a public profile, but privacy laws may give you rights to access, correct, object to, restrict or delete personal data. You can disable analytics using the controls above. For a request about billing, restore data or server records, contact us and include enough information to locate the relevant purchase or browser identifier.

10. Legal Basis for Processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: our legitimate interest in understanding and improving the Service and preventing abuse (for the pseudonymous product events and security controls described above, with analytics controls available); the performance of a contract with you (to provide premium features you purchase); and your consent where required. You may withdraw consent or object to processing based on legitimate interest at any time, including by disabling analytics or uninstalling the Extension.

11. International Data Transfers

Our analytics provider (PostHog) and certain other service providers may process data on servers located in the United States or other countries that may not provide the same level of data protection as your jurisdiction. Where such transfers involve personal data, we and our providers rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law. By using the Extension, you acknowledge that the limited, anonymous data described in this Policy may be processed in those locations.

12. Third-Party Services

The Extension relies on a small number of third-party services described above — PostHog (anonymous analytics), and, for premium features you choose to use, our payment provider (payments and licensing) and Replicate (AI image processing). These services are operated by independent companies under their own privacy policies and terms, over which we have no control and for which we are not responsible. We encourage you to review their policies. We are not affiliated with, and do not endorse, any website on which you use the Extension.

13. Disclaimer of Warranties and Limitation of Liability

The Extension is provided on an "as is" and "as available" basis, without warranties of any kind, whether express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, accuracy, and non-infringement. We do not warrant that the Extension will be uninterrupted, error-free, or that any image conversion or AI operation will meet your requirements.

To the maximum extent permitted by applicable law, in no event will the developer be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, profits, or goodwill, arising out of or in connection with your use of (or inability to use) the Extension, even if advised of the possibility of such damages. Nothing in this Policy excludes or limits liability that cannot be excluded or limited under applicable law. Some jurisdictions do not allow certain limitations, so some of the above may not apply to you.

14. Changes to This Policy

We may update this Privacy Policy as the Extension evolves. Material changes will be reflected here with an updated "Last updated" date. Continued use of the Extension after changes take effect constitutes acceptance of the revised policy.

15. Contact

SaveImage is operated by Northpine Labs LLC. For privacy-related questions or requests, email us at [email protected].