Last updated 4 September 2026
Privacy Policy
Family photos are sensitive data, and so are a client's unreleased products. This page says plainly where your uploads go and how to get rid of them.
The short version
Your uploads are stored so your merge history works. They are not sold, not licensed to anyone, and not used to train any model. Delete a merge and its source images are deleted with it. That is the whole policy in four sentences; the rest is detail.
What we collect
Your account details. Email address, and optionally your name and company. Your password is stored as a salted hash — we cannot read it, and neither can anyone who obtains the database.
Your images. The files you upload as sources, and the images the service produces from them.
Your instructions. The prompts you write and the presets you choose, kept alongside each merge so you can reuse what worked.
Basic usage records. Sign-in times, IP address at sign-in, merge counts and credit changes. We use these to run the service, detect abuse and answer your billing questions.
We do not use advertising trackers, we do not run ad retargeting, and we do not buy data about you from anyone.
Analytics. We use Google Analytics 4 to see which pages people actually use — visit counts, which browser and country, which pages lead somewhere. GA4 truncates IP addresses before storing them and we have not enabled Google Signals, ad personalisation or data sharing for advertising. It never sees your uploaded images, your prompts or your merge results, because those never leave the parts of the app behind your login. If you would rather not be counted, any browser-level blocker or the Do Not Track setting stops it, and nothing about the product breaks.
Who else touches your images
One processor: Google, via the Gemini image API. (Google also receives page-level analytics as described above, but that is separate and never includes your images.) Your source images and instruction are sent there to produce the result. Google states that content submitted through the paid API is not used to train its models. If that arrangement is not acceptable for your material, this service is not suitable for it — and we would rather tell you here than in a footnote.
Payments, when you subscribe, are handled by a payment processor that receives your billing details directly. We never see or store a full card number.
How long we keep things
- Free plan merges: 30 days, then deleted automatically along with their sources.
- Paid plan merges: kept until you delete them.
- Account records: kept while your account exists, and removed within 30 days of deletion.
- Billing records: retained as long as tax law requires, typically seven years.
Your controls
You can delete any merge from the workspace at any time, which removes the result and every source image behind it. You can export your results by downloading them. You can request full account deletion by emailing us, and we handle it by email specifically so that a single click can never wipe someone's account.
If you are in the EU or UK, you have the right to access, correct, port and erase your data, and to object to processing. Email us and we will action it within 30 days — usually the same week.
Children
This service is not intended for anyone under 16, and we do not knowingly hold accounts for them.
Security
Passwords are hashed. Session tokens are stored in httpOnly cookies, which means a script running on a page cannot read them. Transport is encrypted. No system is perfect, and we would rather describe what we do than claim invulnerability.
Changes
If we change this policy in a way that affects how your images are handled, we will email registered users before it takes effect rather than quietly updating the date at the top.
Contact
Email hello@bestimagecombiner.com with any privacy question, including the awkward ones.