Legal
Privacy Policy
Effective date: September 16, 2026 · Version 2.2 · PhotoEditRocket is operated from the United States and is not offered for sale in the EU or UK. This policy explains what we collect and what we do with it, and the rights in section 7 are open to everyone regardless of where they live.
★ At a glance
- All editing happens in your browser. The editor has no upload step and no server-side processing, so your photos, PSDs, ORAs and templates stay on your computer.
- We do not sell or share personal information. No data broker relationships and no cross-context behavioural advertising.
- No third-party analytics. We use no Google Analytics and no analytics cookies — our visit count is a first-party tally on our own server.
- No advertising cookies and no ad-network scripts. We advertise on X, and we need to know whether those ads work — but we do that without putting anything on your device. When you arrive from one of our ads, X adds a click id to the link. If you then buy, our server tells X that that click converted. Nothing is stored in your browser, no script from X ever loads on this site, and no identifier is created that could follow you anywhere else. Close the tab and the click id is gone. See Cookies for the detail.
- License key stays on your device. The 16-character key is kept in four places on this machine — localStorage, a first-party
per_liccookie, the browser's IndexedDB database and its cache storage — so it survives any one of them being cleared, and in the file you download. The Cookies page lists them. The key is not transmitted by the app: a timed licence carries its own term, and the app works out when that term ends locally rather than asking us. - We aim to collect as little as we can. We do not ask for or collect images, biometric data, geolocation, health data, or government IDs.
1. Who we are
PhotoEditRocket is an independent app run by a solo developer in the United States, and we decide how your data is handled (the “data controller”). Questions? Email support@photoeditrocket.com. Use the subject line “Privacy request” and it reaches the right place faster; we reply within 30 days.
2. What we collect and why
Our aim is to collect as little as possible. This page describes how the software and this site are built and what we intend them to do. We work to minimise what is collected and to give you as much privacy as we practically can, rather than claiming a guarantee no software can honestly make. Where something is sent, it is named here. If you find behaviour that does not match this page, please tell us and we will correct one or the other.
We keep this to a minimum by design. We do not collect your images, PSDs, templates, biometrics, location, health data or IDs — the editing itself runs in your browser.
- Your email & payment info — only when you buy, to deliver your license and handle refunds. Payment goes through Stripe, so your full card number is handled by Stripe and is not exposed to us.
- Aggregate page views — a counter kept on our own server (page name only, no cookies, no IP, nothing that identifies you).
- Support messages — if you email us, we keep your message to reply and follow up.
- Basic security logs — our host may briefly log IP + browser type to keep the site safe.
- Your IP address, when you use a form — if you send us a message through the contact or free-licence form, your IP address is included in the email that reaches us, and a one-way hash of it is held briefly to stop the form being used for spam. We use it only to judge whether a message is genuine. It is not used to identify you, is not shared with anyone else, and lives only as long as the email does (see section 6).
- Your license key — kept on your device. The installed app contacts us once at launch to check for a new version. That request carries a version number and nothing else. It used to include your license key on a timed licence; it no longer does, and we are not aware of any remaining request in the app that carries it. A 30-day, 6-month, 1-year or 5-year licence now carries its own term inside the key, and the app works out when that term ends on your own machine, offline, without telling us anything.
3. Cookies
We use only the storage needed to run the site — no ads, no Google Analytics, no tracking, and no consent banner. Full details are on the Cookies page. Stripe sets its own security cookies on its checkout page.
4. Who we share data with
- Stripe — to take payment (stripe.com/privacy).
- Our web host — serves the site and keeps short security logs. Our page-view counter runs on this same server, so no third party receives it. Fonts and every script the editor uses are served from this same server too — nothing on this site loads from Google Fonts or a public CDN, so no request (and no IP address) goes to a third party just by visiting a page. The only third-party connections are ones you start yourself: pressing play on a video (YouTube, in its no-cookie mode) or choosing to pay (Stripe).
- X (formerly Twitter) — ad measurement only, and only if you reached us by clicking one of our ads. In that case our server tells X that the click it issued led to a purchase. What travels is the click id X created itself, plus which of four events happened (home page viewed, editor opened, review licence requested, purchase completed) — and nothing else: no email address, no name, no licence key, no order value, no IP address, no browser details. No X script is loaded by this site and nothing is written to your device for it. If your browser sends Global Privacy Control or Do Not Track we do not pick the click id up in the first place, so there is nothing left to report. (x.com/privacy)
We do not sell your personal information and we have no data-broker relationships. The only advertising-related disclosure we make is the conversion report to X described above: it carries a click id that X issued itself, it measures whether an ad worked rather than building a profile or following you to other sites, and it does not happen at all if your browser sends Global Privacy Control or Do Not Track — in that case we withhold the click id entirely, so no report is possible.
5. International transfers
We operate from the United States, so your data is processed there. Where EU, UK or Swiss personal data reaches a processor, we rely on that processor’s Standard Contractual Clauses or equivalent safeguards. We are not self-certified under the EU–US Data Privacy Framework and do not claim its protections.
6. How long we keep it
- Purchase records: 7 years (tax rules).
- Support emails: up to 24 months, then deleted.
- Visit counter: a running total per page only — no per-visit records.
- Server logs: up to 30 days.
- Ad-click de-duplication: a one-way hash of the click id, so one ad click is not counted twice — 45 days, then deleted. It cannot be turned back into the click id or anything about you.
- Form IP addresses: only inside the support email they arrived with, so they follow the support-email period above. The spam-prevention hash is discarded within the hour.
7. Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, delete it, send you a copy in a portable form, restrict what we do with it, or object to a particular use. Where we asked for your consent — the review-publication tick box on the free-licence page is the only place we do — you can withdraw it at any time, and withdrawing it does not undo anything done beforehand. You can also stop the ad-measurement report described in section 4: set your browser to send Global Privacy Control or Do Not Track and it will not happen at all, or just ask us. Email support@photoeditrocket.com. Your first request each year is free, we may verify your identity first, and we reply within 30 days. If you are unhappy with how we handled a request, you can raise it with your local data-protection or consumer authority.
8. Children
PhotoEditRocket isn’t for children under 16, and we don’t knowingly collect their data. If a child has sent us data, email us and we’ll delete it.
9. Security
We use HTTPS everywhere, a strict content-security policy, and tokenised payments through Stripe. If a data breach ever affects you, we’ll notify you promptly, as the law requires.
10. Changes
If we change this policy, we’ll update the date above and, for big changes, post a notice on the homepage for at least 14 days.
11. Contact
Email support@photoeditrocket.com for anything privacy-related. A postal address is available on request to people exercising legal rights.