Privacy Policy

Editing happens on your machine. This page is about the exceptions, and there are only a few of them.

Last updated .

The short version

Image Horse opens your photos in your browser and edits them there. The image engine is Rust compiled to WebAssembly and it runs on your own processor, so the pictures you open are not uploaded to edit them, resize them, compress them or annotate them. You do not need an account to use it.

Four things do leave your device, and each one is listed below: anonymous usage analytics, your account details if you make an account, the cloud features that only run when you are signed in, and the AI tools, which are off until you switch them on.

What stays on your device

Your photos, your edits, your layers and your gallery are stored in your browser’s own database (IndexedDB) on the machine you are using. We do not receive them and we cannot read them. They are not backed up anywhere. If you clear your browser’s site data for Image Horse, that copy is gone and we have no way to restore it, so export anything you want to keep.

Because this storage belongs to the browser and the address, a gallery saved on one browser or one device does not appear on another.

Analytics

Both the website and the editor run Google Analytics 4, and it runs for everyone — there is no switch for it and we do not ask first. It sets cookies and it contacts Google on every page load. It records pages viewed, rough location derived from the network address, and general device and browser details. It does not receive your photos or anything you type into the editor. The website and the editor are separate properties.

The editor also runs Vercel Web Analytics, which counts page views without cookies and without identifying you.

Accounts

Accounts are optional and the editor works fully without one. If you do make an account, it is handled by Clerk, which stores your email address, your name and picture if you provide them, and the identity from whichever provider you signed in with. If you sign in with Google or GitHub we receive your email address, name and avatar from them, and nothing else — we never see your password with either.

Cloud features, when you are signed in

Signing in enables features that need a server: share links, syncing preferences across devices, and keeping edit history off-device. These run on Convex. What is stored there is the material those features need — the document you chose to share or sync, and the account it belongs to. Signed out, none of it runs.

The AI tools

These are off by default and they are the only part of the editor that sends a picture to a server. The New dialog has a switch for online features; while it is off, the AI tools are not offered. When you turn it on and use one, the prompt you wrote and the image or mask you are working on are sent to our server and processed by Replicate, which runs the model. They are used to produce your result and are not used to train anything by us.

Payment

The paid tier is billed by Stripe. Stripe handles the card details and we never see them. We keep the subscription status Stripe reports so the app knows which tier your account is on.

What you can switch off

  • Use the editor signed out. Everything except the cloud and AI features works, and nothing is tied to a person.
  • Leave online features off. That is the shipped default, and it keeps every picture in the tab.
  • Strip metadata on export. Settings › Security removes EXIF, GPS, XMP and IPTC from what you save, or removes only the location and keeps the camera details.
  • Clear your site data to delete the local gallery, or block cookies for this site to stop the analytics cookies.

Children

Image Horse is not directed at children under 13 and we do not knowingly collect their information.

Changes

When this policy changes the date at the top of the page changes with it. The page is in the same public repository as the software, so its whole history is readable there.

Contact

Questions about any of this, or a request to delete an account and what is stored with it, can go to chrislanejones@gmail.com or to the issue tracker.

The editor is free and needs no account.

It runs on your own machine. Nothing you open is uploaded to edit it.