Image Analyze is operated by Enterprise Hare LLC (“we,” “us”). We collect the minimum data needed to operate the Service, process payments, and improve the experience. This policy explains what we collect, why, and how you can exercise your rights.
1. Data We Collect
- Account information: Email address and user ID provided through Clerk (our authentication provider) when you create an account.
- Payment data: Processed and stored by Stripe. We store only transaction references (Stripe customer ID, payment status); we never see or store your full card number.
- Image inputs: Photos you upload or URLs you submit for analysis. Stored temporarily in Microsoft Azure Blob Storage for processing.
- Anonymous session data: For visitors who have not signed in, we generate a server-side fingerprint (a salted hash of request headers) to track free-check usage. No cookies or client-side tracking are used for this purpose.
- Usage and log data: Request metadata, timestamps, IP addresses, and error logs to operate, secure, and improve the Service.
- Contact form submissions: Name, email, and message content when you reach out through the contact form.
2. How We Use Your Data
- To authenticate you and manage your check balance.
- To process images and deliver analysis results.
- To process payments and maintain billing records.
- To prevent abuse, enforce rate limits, and secure the Service.
- To respond to your support requests.
- To comply with legal obligations.
3. Legal Basis for Processing
We process data to perform the service you request (delivering analysis results), under legitimate interest (maintaining security, preventing fraud, managing abuse), and when required by law (billing records, legal requests). Where consent is required (e.g., marketing communications), we ask before collecting that data.
4. Third-Party Services & Data Sharing
We share data only with processors necessary to run the Service:
- Clerk — authentication and user management.
- Stripe — payment processing.
- Microsoft Azure — image storage, queue processing, and compute infrastructure.
- SightEngine — AI-generated image detection analysis.
- SerpAPI / Google — reverse image search (when included in analysis).
- Mailgun — contact form email delivery.
- Vercel — web application hosting, edge functions, and analytics.
We do not sell your personal data. Ever.
When required by law, we may share limited data with law enforcement, regulators, or courts that present valid legal process.
5. Data Retention
- Uploaded images: Retained while results are available, then deleted during routine cleanup.
- Analysis results: Retained as long as your account is active or until you request deletion.
- Billing records: Retained for up to seven years or the applicable legal minimum for tax and accounting compliance.
- Security and access logs: Retained for up to six months to aid incident investigations.
- Contact form messages: Retained for up to one year, then deleted.
You may request deletion of your data at any time through our contact form. Full account deletions remove all personal data except minimal billing records required by law.
6. Your Rights
- Access or update your profile via your account settings in Clerk.
- Request a copy of your data or request deletion through our contact form.
- Control cookies via your browser settings (see our Cookies Policy).
- Withdraw consent for optional processing at any time.
If you are in the EU/EEA, you may also lodge a complaint with your local data protection authority.
7. Security
We use industry-standard controls including encryption in transit (TLS), least-privilege access, structured logging, and request-ID correlation for incident response. No system is perfectly secure; please use strong credentials and protect your account.
8. Incident Response
If we detect a security incident affecting your data, we will investigate promptly, contain the scope, and notify you and the appropriate authorities as required by applicable law.
9. International Data Transfers
Data may be processed in the United States and other regions where our processors operate. By using the Service you consent to these transfers as permitted by applicable law.
10. Children's Privacy
The Service is not directed at anyone under 18. We do not knowingly collect personal data from minors. If we learn that we have collected data from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be posted here with an updated date. Continued use of the Service after changes take effect constitutes acceptance.
12. Contact
Questions or data requests? Use the contact form at the bottom of any page.
Enterprise Hare LLC · Illinois, U.S.A.