Privacy Policy for MyIMG AI

Effective Date: April 15, 2024
Last Updated: September 4, 2025

Your Privacy Protection - Core Commitments

- You Own Everything: Complete ownership and copyright of all your original and processed content
- 24-Hour Auto-Delete: All content automatically and permanently deleted within 24 hours
- Zero-Knowledge Security: We technically cannot access your content, even if we wanted to
- No Data Sales: We never sell, rent, or share your personal information with anyone
- 30-Day Refund Guarantee: Hassle-free refunds with our customer-first policy
- Military-Grade Encryption: Bank-level security with AES-256 encryption and ISO certifications

We understand your privacy concerns, and we've built our entire service around protecting your data.

TecDeon Limited. ("we," "our," or "us") operates MyIMG AI, providing AI-powered image and video processing services. This Privacy Policy explains how we collect, use, and protect your information when you use our services at https://www.myimg.ai.

1. Information Collection and Use

1.1 Flexible Access Options
Multiple Access Methods: MyIMG AI offers two ways to use our services:
- Guest Access: Try our AI tools without creating an account - perfect for quick trials
- Google OAuth Login: Sign in for enhanced features, credit management, and processing history

1.2 Google OAuth Authentication (Optional)
When you choose to sign in using Google OAuth, Google (not us) collects and provides us with limited information from your Google account:
- Email address (for account identification)
- Name and profile picture (if available in your Google profile)
- Unique Google user identifier
Important: We only receive this information after you explicitly grant permission through Google's authorization flow. Google's data collection is governed by Google's Privacy Policy, not ours.

1.3 Content You Upload
- Images and Videos: Files you upload for AI processing
- Processing Preferences: Settings and parameters you choose
- Generated Content: AI-processed results
Ownership: You retain full ownership and copyright of all original and processed content. We claim no ownership rights to your content.

1.4 Technical Information
- IP address and device information
- Browser type and usage analytics
- Performance and error logs

2. Data Processing and Storage

2.1 Intelligent Data Localization
- Automatic Geographic Routing: Our system automatically routes your data to the nearest secure data center based on your location
- Regional Processing: European users' data stays in EU data centers, US users' data processes in US facilities
- Optimized Performance: Local processing reduces latency and ensures faster results
- Processing occurs on secure AWS infrastructure with Cloudflare's global network optimization

2.2 Zero-Knowledge Architecture & Military-Grade Security
We've designed our system so that we cannot access your content even if we wanted to:
Zero-Knowledge Processing:
- Content is encrypted immediately upon upload using your session keys
- AI processing occurs in isolated, encrypted containers
- Our staff cannot view, access, or recover your content
- All processing happens automatically without human intervention
Military-Grade Security:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- SOC 2 Type II compliant infrastructure via AWS
- Multi-factor authentication and access controls
- Third-party security audits conducted quarterly by independent firms
- ISO 27001 certified data centers

2.3 Automatic Data Deletion
- Uploaded Content: Automatically and permanently deleted within 24 hours after processing
- Processed Content: Available for download for 24 hours, then permanently deleted
- Important: Please download your processed content promptly as we cannot recover deleted files

3. No Content Storage Policy

We Do Not Store Your Content: Neither your original uploads nor processed results are permanently stored on our systems. All content is automatically purged after the specified retention periods for security and privacy protection.

4. Data Sharing and Third Parties

4.1 We Do Not Sell Your Data
We never sell, rent, or trade your personal information to third parties.

4.2 Essential Service Providers
We only share data with trusted partners who help us operate our service:
- AWS: Cloud infrastructure and processing (US/EU data centers)
- Cloudflare: Content delivery and security
- Payment Processors: Secure transaction processing (we don't store payment details)

4.3 Legal Requirements
We may disclose information only when required by law, court order, or to protect our rights and safety.

5. International Data Transfers

Your data may be processed in the United States and European Union through our AWS infrastructure. We ensure adequate protection through:
- AWS's SOC 2 Type II compliance
- Standard Contractual Clauses (SCCs) for EU data transfers
- GDPR-compliant data processing agreements

6. Your Rights Under GDPR and CCPA

6.1 Access and Control
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request permanent deletion of your data
- Portability: Export your data in a structured format
- Restriction: Limit how we process your data

6.2 Exercising Your Rights
Contact us at [email protected] to exercise any of these rights. We'll respond within 30 days as required by law.

6.3 Data Protection Officer
For GDPR-related inquiries, contact our Data Protection Officer at [email protected].

7. Cookies and Tracking

We use minimal, essential cookies only:
- Authentication cookies for login sessions
- Preference cookies for user settings
- Security cookies for fraud prevention
We do not use advertising or tracking cookies. You can disable cookies in your browser, though this may affect service functionality.

8. Age Requirements

Our service is restricted to users 18 years and older. We do not knowingly collect information from minors. If you believe a minor has provided us with personal information, contact us immediately at [email protected].

9. California Privacy Rights (CCPA)

California residents have additional rights:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale (we don't sell data)
- Right to non-discrimination for exercising privacy rights

10. Data Breach Notification

In the unlikely event of a data breach, we will:
- Notify affected users within 72 hours
- Report to relevant authorities as required
- Provide clear information about the incident and our response

11. Security Audits and Certifications

11.1 Independent Security Verification
- Quarterly third-party security audits by certified cybersecurity firms
- Annual penetration testing to identify and address vulnerabilities
- SOC 2 Type II compliance verified by independent auditors
- ISO 27001 certification for information security management

11.2 Continuous Monitoring
- 24/7 automated threat detection and response
- Real-time security monitoring across all systems
- Immediate incident response protocols
- Regular security updates and patches

12. Privacy by Design

We've built privacy protection into our core architecture:
- Zero-knowledge processing - we cannot access your content
- Minimal data collection (only what's necessary)
- Automatic data deletion within 24 hours
- End-to-end encryption throughout the processing pipeline
- Geographic data localization for optimal privacy compliance

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We'll notify you of significant changes by:
- Email notification to registered users
- Prominent notice on our website
- Updated "Last Modified" date
Continued use after changes constitutes acceptance of the updated policy.

14. Frequently Asked Questions

How long is my content stored on your servers?

All uploaded and processed content is automatically and permanently deleted within 24 hours. We cannot recover deleted files, so please download your results promptly.

Can your staff access my uploaded images or videos?

No. Our zero-knowledge architecture technically prevents any human staff member from viewing, accessing, or downloading your content, even if they wanted to.

Do you sell my personal data to third parties?

Never. We do not sell, rent, or trade your personal information to anyone. We only work with essential service providers like AWS and payment processors.

How do I request a refund?

Contact [email protected] within 30 days of purchase if you've used less than 80% of your credits. We offer no-questions-asked refunds under our customer-first policy.

What rights do I have over my data under GDPR?

You have the right to access, correct, delete, restrict processing, and export your data. Contact [email protected] to exercise these rights - we respond within 30 days.

15. Contact Information

TecDeon Limited.
- Email: [email protected]
- Website: https://www.myimg.ai
For privacy-related questions or to exercise your rights, please contact us at [email protected].

16. Legal Framework

This Privacy Policy complies with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Personal Data (Privacy) Ordinance (PDPO) of Hong Kong
- Other applicable international privacy regulations


Your privacy is fundamental to our service. By using MyIMG AI, you acknowledge you've read and understood this Privacy Policy.

$t(copy_success)