
Privacy & data handling
How ImageTrace handles your photos
ImageTrace is built for photographers who care about where their work goes, so we are deliberate about what happens to the images you upload. Everything below is how the product actually works today.
Where your data lives
ImageTrace is hosted in the European Union and operates under the GDPR. Your account data and images are processed and stored on EU-based infrastructure.
Your account
You can sign in with an email address and password, or continue with Google, Microsoft or Apple. Either way you can add a second step: an authenticator app, or a passkey using your fingerprint, face or a security key. You get one-time recovery codes in case you lose the device.
What happens to a photo you scan
When you start a scan, your photo is uploaded over an encrypted (HTTPS) connection to our EU servers, where it is processed so we can search the web for copies. For a one-off scan, nothing disappears behind your back. If you leave a search untouched for 30 days, it moves to your Archive, where everything stays restorable with one click. 30 days after that, the uploaded image itself is permanently deleted from our servers, unless you keep it in your Library or monitor it. You always keep the list of URLs where it was found, and you can delete the image yourself at any time. Images you monitor are the exception (see below).
Images you monitor or keep as evidence
If you turn a photo into a recurring monitor, or save a match as evidence for a report, that image is stored encrypted at rest for as long as you keep it, and removed when you delete the monitor or the case. You stay in control of what we retain.
Content Credentials
If your files carry Content Credentials, ImageTrace reads the manifest and shows whether the signature is valid and who signed it. You can publish a public certificate page for any image, private by default and revocable in one click. Content Credentials do not help us find copies: they are trivially stripped from anything reposted on the web.
Your rights under the GDPR
You can request access to, export of, or deletion of your personal data at any time. Deleting your account removes your images and personal data, subject to any legal retention we are required to keep (e.g. invoicing records). To exercise any right, email [email protected].
Deleting your account
In the ImageTrace app, open Account and choose Delete account. Your account stays for 30 days after you ask us to delete it. During that time you cannot use ImageTrace, but you can cancel by signing in. After 30 days we remove your sign-in details, your profile, your uploaded images, your scans and your monitors. Invoices are kept for 7 years because the law requires it, and letters you already sent stay available to the people who received them. You can also email [email protected] to request deletion, or to have individual scans, monitors or cases removed without closing your account.
Notifications
For every kind of message we send, you choose: email, in the app, both, or nothing at all. Billing notices about a renewal or a lapsed plan always arrive by email, because missing one costs you money.
Payments
Payments are handled by a PCI-DSS compliant payment provider. ImageTrace never sees or stores your full card details.
Questions
Anything unclear about how we treat your images or data? Email [email protected]. The full terms are in our Terms & Conditions.