Privacy Policy
Last updated: September 5, 2026
This policy explains what happens to your files and your data when you use Pixpoo (“Pixpoo”, “we”, “us”). We have tried to write it as a description of how the site actually works rather than as a list of things we are permitted to do, because the first is more useful to you.
The short version
- Most of our tools never send your file anywhere. It is opened, processed and saved by your own browser.
- The image toolkit is the exception: it uploads your picture, processes it in memory and returns it immediately. Nothing is written to disk or kept afterwards.
- You do not need an account to use any tool.
- We never use your files to train anything, and we never sell personal data.
- The site runs Google Analytics, which sets cookies and processes data about your visit. Advertising, where it appears, is served by Google AdSense, which sets its own. Both are covered in detail below.
- If you tap the heart or leave a star rating on a tool, we record that rating against the tool, with a random id your browser makes up so one person is not counted twice.
What happens to your files
This is the question most people come to a privacy policy to answer, so it goes first and in full. The behaviour genuinely differs from tool to tool.
| Tool | Where your file is processed |
|---|---|
| PDF toolkit (all 21 tools) | Entirely in your browser. The file is never transmitted. |
| Whiteboard | In your browser. Boards are saved in your browser’s own storage. See the note on shared sessions below. |
| Passport photo maker | In your browser, including background removal. |
| Photo editor | In your browser, except when you export to AVIF, GIF, TIFF, JPEG 2000 or JPEG XL, which are encoded on our server. |
| Watermark Image | In your browser for PNG, JPEG and WebP output. Other output formats are encoded on our server. |
| Resize, Crop, Compress, Convert, Upscale | On our server. Your image is uploaded, processed and returned. |
When a file is uploaded
The image toolkit — resize, crop, compress, convert and upscale — works differently from the rest of the site. Your image is uploaded to our servers so it can be processed there, and the result is returned to you. The file is held in memory only for as long as the operation takes; it is never written to disk, never added to a database and never retained after the response is sent.
It is used for the single operation you asked for and nothing else, and it is not logged.
We do not use your files to train machine-learning models, we do not analyse their contents for any purpose beyond performing the requested operation, and we do not share them with anyone.
When a file is not uploaded
For everything else, your file is read from your disk by your browser, changed in memory on your own machine, and saved back by the browser. Nothing about it reaches us, which means there is nothing on our side to store, leak or hand over. This is why those tools keep working if your connection drops halfway through an operation.
Two clarifications that follow from this. First, some of these tools download software to your browser from a public code network in order to run — the PDF engine, the background-removal model, the recognition engine. That request tells the network which file it is serving and the IP address asking for it, but it carries none of your content. Second, because these tools keep nothing on our servers, we cannot recover your work if you lose it.
Shared whiteboard sessions
One deliberate exception is worth stating clearly. Your whiteboard stays on your device unless you choose to start a shared session. From that moment, board data is relayed through a public synchronisation server operated by the Yjs open-source project so that other participants can see your changes. That server is not run by us. A room is identified by a short random name and has no password, so anyone with the link can join. We would not use shared sessions for confidential material, and we would rather say so than let the word “private” elsewhere on the site imply otherwise.
Information we collect
Without an account
- Request data. When your browser contacts our server — for a page, or for one of the server-side image operations — it sends an IP address, a user-agent string and similar technical details. We use these to serve the request and to apply rate limits that keep automated abuse from crowding out people.
- Analytics. Google Analytics records which pages and tools are used, roughly where in the world visitors are, and how they arrived. It sets cookies and assigns an identifier to your browser.
- Advertising. Where advertising appears on the site, it is served by Google AdSense, which sets its own cookies and identifiers. Ad units are still being rolled out, so you may not see them on every page yet.
- Local storage. Some tools store things in your browser rather than on our servers — whiteboard boards, your theme choice, recently used colours. That content never leaves your device and we cannot read it. Two small exceptions are sent to us when they are used: your sign-in token, if you have an account, and the random feedback id described below.
- Ratings and love taps. Optional, and only when you tap them. Covered in full in the next section.
Ratings and the love button
When a tool finishes, it offers a heart to tap and five stars to rate the result. Both are optional, and nothing is recorded unless you actually tap.
When you do, we store one row containing:
- which tool it was — merge-pdf, compress-pdf and so on;
- whether it was a love tap or a rating, and for a rating, the number of stars;
- a random identifier your browser generates for itself and keeps in local storage;
- where in the flow you were, so we can tell a result screen apart from anywhere else;
- whether you were on a desktop, a phone or a tablet, and the country your connection appears to come from, where our network tells us. Nothing more precise than the country.
The random identifier exists for one reason: so that one person tapping twice is not counted twice. It is not linked to your account, it is never sent anywhere except to us, and it is not something we can trace to a person — it is a string of random characters and nothing else. Clearing your browser’s site data deletes it, and the next visit generates a fresh one.
We do not store your IP address or your browser’s user-agent string with this. Your rating and the file you were working on have nothing to do with each other: we know that somebody gave Merge PDF four stars, not who they are or what they merged.
If you contact us or create an account
- Messages. If you write to us through the contact page, we keep your email address and message so we can reply and so we can track a bug through to a fix.
- Account details. If you create an account, we store the email address and the details you provide. No tool requires one.
Advertising and analytics, in plain terms
Pixpoo is free and has no paid tier. Advertising is intended to pay for the servers, and we would rather describe that arrangement accurately than imply the site runs on goodwill.
Our advertising partner is Google AdSense. Ad units are still being rolled out across the site, so you may not see advertising everywhere yet — but the description below applies wherever it does appear, and we would rather you could read it in full than discover it later. Google Analytics is running site-wide already.
Google AdSense and Google Analytics are provided by Google, which acts as an independent controller of the data it collects through them. Google may use cookies and device identifiers to measure traffic and to select and measure advertising, and its use of that data is governed by Google’s own policies rather than by ours. You can read how Google handles data at policies.google.com/technologies/partner-sites and opt out of personalised advertising at adssettings.google.com.
Note that these services are entirely separate from your files. Advertising and analytics operate on your visit to the website. They have no access to the documents and images you process, whether those are handled in your browser or on our server.
Third parties involved
| Who | What they receive |
|---|---|
| Our hosting provider | Requests to the site, including images sent to the server-side image tools |
| Google Analytics | Page views, tool usage, approximate location, referrer, cookie identifiers |
| Google AdSense | Ad requests and the cookies and identifiers used to serve and measure them |
| Public code networks (jsDelivr, esm.sh and similar) | Your IP address when your browser downloads a library or model a tool needs. No file content. |
| Yjs public sync server | Whiteboard content, but only while you have a shared session running |
We do not sell personal data, and we do not share your files with any of them.
How long we keep things
- Files processed on our server — the length of the operation, then discarded. This covers the image tools.
- Files processed in your browser — never held by us at all.
- Messages you send us — kept while we deal with them and for a reasonable period afterwards.
- Account details — until you ask us to delete the account.
- Ratings and love taps — kept for as long as we run the tools, because their whole purpose is to compare how tools do over time. They contain nothing that identifies you.
- Analytics and advertising data — according to Google’s retention settings for those products.
Your choices and rights
You can block or delete cookies in your browser, opt out of personalised advertising through Google’s settings, and use browser or extension-level controls to block analytics entirely. Ratings and love taps only ever happen if you tap them, and clearing your site data removes the random id behind them. None of this stops the tools from working.
Depending on where you live, you may have rights to access, correct, delete or export the personal data we hold about you, to object to certain processing, or to complain to a data protection authority. Because we hold very little — no files, and nothing that identifies you unless you contacted us or created an account — most requests are quick to handle. Ask through our contact page.
Security
Traffic to the site is encrypted in transit. The most meaningful security measure here, though, is architectural rather than procedural: for most of the site there is no upload, so there is no transfer to intercept and nothing stored to be breached. Where files are processed on our server, they exist only in memory for the duration of the request. No system is completely secure, and we do not claim otherwise.
Children
Pixpoo is not directed at children under 13, or under the minimum age set by local law where that is higher, and we do not knowingly collect personal data from them.
Changes
We will update this policy when the way the site works changes, and revise the date at the top when we do. Where a change is significant — a new third party, a new category of data — we will describe it rather than quietly amending a sentence.
Contact
Questions about this policy, or about the data we hold, go to our contact page. See also our Cookie Policy and Terms of Service.