Privacy Policy
Last reviewed: 15/09/2026
1. Overview
This Privacy Policy explains how Images Upscaler (imagesupscaler.ai) collects, uses, shares, and protects personal information when you visit our website, create an account, process images, purchase services, submit a review, or contact us. It also explains the choices and privacy rights available to you.
In brief: we use information to provide and secure the service, process purchases, support customers, maintain accurate credit and account records, and improve the product. We do not sell personal information for money.
2. Information we collect
We may collect account details such as name, email address, username, authentication identifiers, profile image, registration and last-active dates, account status, subscription or plan status, preferences, and records of the permissions or choices you provide; images and processing instructions you submit; support messages and reviews; and technical information such as IP address, browser and device details, timestamps, requested pages, referrer, security events, cookies or similar identifiers, and service logs. Browser-storage observation may also record first-seen and last-seen metadata for an observed technology.
Guest and free-credit identifiers: To provide guest credits, prevent duplicate welcome or monthly free-credit grants, and detect misuse, Images Upscaler assigns a guest identifier through a strictly necessary cookie. We may also create a privacy-protected matching value using network and general device information. We do not collect a hardware serial number, IMEI, MAC address, or another manufacturer-assigned device identifier for this purpose. The matching value can associate free-credit activity across browsers using a similar network and device environment. If a visitor signs in, the guest identifier and free-credit record may be associated with the account and email address. We use this information for free-credit administration, balance reconciliation, security, and abuse prevention—not for cross-site advertising.
How free-credit reconciliation works: We maintain guest and account credit balances so the same free allowance is not issued more than once. When you open the upscaler, request a balance, sign in or register, or start an upscale, the service may compare the remaining welcome and monthly credits attached to the guest cookie, account, and pseudonymous matching value. For records in the same free-credit lifecycle, the service normally applies the lowest valid remaining free balance so that changing browsers, clearing a cookie, or creating an account does not issue the same allowance again. A genuinely newer monthly grant may be carried to an older matching record. This synchronization affects welcome and monthly free credits only; it does not reduce paid subscription, add-on, or additional credits.
We collect and use your email address for account creation, email verification, account security, password resets, and essential service-related communications.
We collect information directly from you, automatically from your browser or use of the service, from administrators who manage credits or accounts, and from service providers involved in authentication, infrastructure, image processing, security, analytics, communications, or payments.
Google authentication: We use Nextend Social Login with Google to let you create an account, sign in, and manage the Google account connected to your Images Upscaler account. When you use Google authentication, the service may receive your first name, last name, email address, and Google profile picture or avatar, together with identifiers needed to authenticate and connect your account. We use information received from Google only to create, authenticate, and connect your Images Upscaler account. We do not use Google user data for advertising, sell Google user data, or disclose it for unrelated purposes.
Payment details are collected and processed by our authorised reseller and Merchant of Record, Paddle. We receive transaction and subscription identifiers, product or plan, price, status, dates, tax, refund, cancellation, chargeback, checkout email, and other limited customer information needed to provide and administer your purchase, but do not receive complete payment-card details.
3. Credits, plans, and billing history
We keep an itemised history of credit and plan activity. Each time credits are granted, purchased, renewed, added by an administrator, spent, returned, refunded, cancelled, charged back, or expired, a record may be added to the user credit ledger. This applies to welcome, free monthly, subscription, add-on, one-time, recurring, promotional, and manually awarded credits.
A ledger entry may include the date and time, event type and source, description, plan name, number of credits added or removed, balance and credit-category balances after the event, transaction, batch, subscription or other reference, checkout email, an administrative note, and related purchase or account status. We also keep current balances, allowances, grant and expiry dates, renewal or cancellation status, and the administrator change record, which may identify the acting administrator, affected user, before-and-after value, timing, scope, and reason or note.
This history is used to deliver credits and subscriptions, show and reconcile balances, investigate failed processing, prevent duplicate grants or deductions, administer refunds and chargebacks, detect fraud or misuse, answer support questions, resolve disputes, and meet financial, tax, accounting, and record-keeping obligations. Credit ledger entries are records of transactions and service delivery; they are not advertising profiles and are not sold. When an account is permanently deleted, its Individual User Credit Ledger is retained for 60 days and then permanently deleted.
4. Service, image, and activity records
When an image-upscaling request is made, we may record the account or guest identifier, batch identifier, start and end time, selected scale, processing status and detailed technical log lines, number attempted, completed, failed, or downloaded, credits charged or returned, and input file size and dimensions. Logs may also contain an IP address, user agent, referrer, request or security context, and error information. These records support processing, credit reconciliation, security, abuse and fraud prevention, support, refund review, troubleshooting, and service analytics.
Submitted images and processing instructions are handled to perform the requested service. Technical analytics may include image dimensions and file size, but we do not use the content of submitted images to create advertising profiles. Please do not upload images you are not entitled to use or unnecessary sensitive information.
5. Administrative pages and authorised access
Authorised administrators can use restricted tools to operate and protect the service. The names below describe administrative functions; they are not separate disclosures of information to the public.
- User Logs: displays searchable account identity, batch and processing records, technical request context, error and credit details for support, security, abuse, fraud, and refund review.
- Additional CSS: stores site presentation code entered by administrators. It ordinarily does not store customer personal information, although normal administrator access and security logs may still be generated.
- Contact Us Admin: displays the user ID, name, email, category, subject, message, date, status, and administrator response associated with a support request.
- Upscaler Analytics: reports totals and trends for batches, attempts, successes, failures, downloads, scale, file size, dimensions, credit availability, use, and expiry. Filters can distinguish guests, registered users, and administrators. Reports should be used in aggregated form where individual identification is not necessary.
- User Credit Management: permits authorised staff to view and adjust a user balance and credit categories and records the change, timing, affected account, acting administrator, before-and-after values, and any note.
- User Credit Records: displays scheduled and completed bulk or individual credit changes, including type, amount, target, administrator, timing, status, and notes.
- User Plans and Consent: displays account email, registration and activity dates, plan and price information, account status, and the user's recorded product-update or offer preference. A marketing preference is used only in accordance with that choice and can be changed.
- Reviews Analytics: displays the reviewer's account identity and email to administrators, submitted ratings, quality, ease, speed, recommendation score, use case, comment, display name choice, publication permission, approval status, and submission or update date. Email addresses are not published.
Access to these pages is limited to personnel with an operational need and protected by account permissions and, for certain functions, additional access controls. Administrative actions and ordinary hosting or security access may be logged. Staff must use this information only for the purposes described in this Policy.
6. How we use information
We use information to create and authenticate accounts; process and deliver image-upscaling requests; administer and document credits, purchases, refunds, chargebacks, plans, and subscriptions; respond to support messages; operate reviews and honour publication choices; provide service notices; prevent fraud, abuse, and security incidents; enforce applicable terms; troubleshoot and improve reliability; generate service analytics; comply with law; establish, exercise, or defend legal claims; and, where permitted, measure usage or send marketing communications.
We do not use sensitive personal information to infer characteristics about you, and we do not make decisions producing legal or similarly significant effects based solely on automated profiling. Automated checks may protect login, detect bots or abuse, validate eligibility, reconcile credits, or flag activity for review; an authorised person can investigate support, restriction, refund, and account issues.
7. Marketing communications
We may send you product updates, special offers, promotions, and other marketing communications only where you have chosen to receive them.
You may provide this consent when creating or registering an account on Images Upscaler or, where available, during checkout through Paddle.
You can unsubscribe from marketing emails at any time by using the unsubscribe link included in our emails. Unsubscribing from marketing communications does not affect essential service emails, such as account, security, password reset, billing, or transaction-related messages.
8. Why processing is permitted
Where applicable law requires a legal basis, we rely on performance of a contract or steps requested before a contract to provide the service and administer purchases; legitimate interests in operating, improving, documenting, and securing the service, preventing fraud, supporting customers, and protecting legal rights; compliance with legal, tax, accounting, and regulatory obligations; and consent for optional analytics, marketing, public review display, or communications.
Where we ask for consent, you may refuse or withdraw it at any time without affecting earlier lawful processing. Where we rely on legitimate interests, we consider the need for the processing, its effect on individuals, and appropriate safeguards. You may object as described below.
9. How information is shared
We disclose information only as reasonably necessary to hosting, database, infrastructure, authentication, security, analytics, customer-support, communications, image-processing, and payment providers; professional advisers such as legal, accounting, audit, or insurance providers; authorities or other parties where required to comply with law or protect rights and safety; and a successor in a merger, financing, reorganisation, or sale of business assets. Providers are permitted to process information only for the relevant service and subject to appropriate confidentiality, security, and data-protection obligations.
Cloudflare Turnstile: We use this strictly necessary security and bot-protection service on login, registration, and other protected functions. Cloudflare may process technical browser, device, network, and security information needed to perform the verification.
A review is made public only when you permit public display and an administrator approves the relevant placement. Depending on your choice, the public review may show your chosen display name or “Anonymous,” rating, comment, use case, and date; it will not show your email address. You can change permission or remove your review through your account.
We do not sell personal information for money. We also do not share personal information for cross-context behavioural advertising or use it for targeted advertising as those concepts may be defined in applicable rules. If our practices change, we will update this Policy and provide any required choice before doing so.
10. International processing
We and our providers may process information in countries other than the country where you live. Those countries may have different privacy rules. Where required, we use recognised transfer safeguards, such as an adequacy decision, approved contractual protections, or another lawful transfer mechanism, and apply supplementary security measures where appropriate. You may contact us for more information about safeguards relevant to your information.
11. Retention and security
We retain personal information only for as long as reasonably necessary to provide and secure the service, administer accounts and purchases, reconcile credits, respond to support requests, prevent fraud and abuse, resolve disputes, and comply with financial, tax, accounting, legal, and regulatory obligations. The periods below describe our ordinary retention practices; a shorter or longer period may apply where required or permitted by law.
- Images and associated information — 48 hours. Uploaded images, upscaled images, processing instructions, and associated metadata stored with those images are automatically deleted after 48 hours. Logged-in users can delete images sooner from their dashboard. When they do, the selected files and associated image metadata are deleted immediately. This does not delete separate account, billing, credit, or service records. You are responsible for downloading results you wish to keep before they are deleted.
- Upscale processing logs — 60 days from batch creation. We store the activity log submitted for each single or batch upscale together with the final processing record. These records are deleted 60 days after the batch was created. They may include an account or guest identifier, request and batch identifiers, timestamps, processing status, technical errors, image dimensions and file size, credit usage, IP address, browser or device information, and referrer information. This log archive is separate from the temporary image folder: deleting a batch, expiry of its images under the 48-hour lifecycle, or deletion of the user account does not delete the log early. The restricted User Logs page reads these retained records from the authoritative service log store.
- Limited exceptions. A particular log may be retained for longer where reasonably necessary to investigate a security incident, fraud or abuse, handle a support request, refund or dispute, comply with a legal or regulatory obligation, or establish, exercise, or defend a legal claim. Access is restricted, and the record is deleted or de-identified when the extended-retention reason ends.
- Account deletion. When an account is permanently deleted, its account profile and cloud image files are deleted and any active subscription is cancelled. The separate upscale processing log remains until its ordinary 60-day expiry. A temporary deleted-account record containing limited account and contact details may be retained for up to 60 days to complete deletion processing and address support or account issues. The Individual User Credit Ledger is permanently deleted 60 days after account deletion. Other transaction, billing, and pseudonymous free-credit matching records are not necessarily deleted at the same time: they may remain after account closure where needed to reconcile credits, document service or payment activity, prevent a person from receiving the same free allowance again, prevent fraud or abuse, resolve disputes, or comply with financial or legal obligations.
- De-identification after account deletion. After the 60-day account-deletion period, direct identifiers are removed from any related processing records that must remain. Depending on the record, this can include the account identifier, username, email address, guest or device identifiers, IP address, referrer, and browser or device information. Remaining de-identified or pseudonymised information may be retained only where necessary for security, fraud prevention, accounting, dispute resolution, legal compliance, statistics, or service improvement.
- Credit administration records. Email addresses in individual account credit-change records are removed 60 days after permanent account deletion. Remaining information may be retained where necessary to document credit changes, transactions, refunds, chargebacks, service delivery, accounting, fraud prevention, or authorised administrative activity.
- Guest cookie and guest record — up to one year after last use. The guest cookie expires after up to one year and may be refreshed when the guest record is used. The corresponding guest record and matching association are ordinarily removed after one year without use. Clearing the cookie removes it from that browser but does not itself delete other credit, log, or matching records.
- Free-credit and matching records. We separately retain the remaining welcome or monthly balance, applicable grant period, next grant date, guest or account credit identifier, and privacy-protected matching value. These records do not have the one-year browser-cookie expiry and may be retained for longer while reasonably necessary to prevent duplicate welcome or monthly grants, preserve an accurate credit lifecycle, investigate misuse, and maintain credit, transaction, dispute, security, accounting, or legal records. We minimise, de-identify, or delete them when they are no longer needed for those purposes. Routine upscale logs and direct identity-match evidence remain subject to the shorter periods stated above.
- Credit, transaction, and billing history. The Individual User Credit Ledger is deleted 60 days after account closure. Separate payment, tax, accounting, refund, chargeback, and billing entries may be retained after credits are used or expire and after account closure where necessary to document transactions and service delivery, administer refunds or chargebacks, maintain tax or accounting records, prevent fraud, resolve disputes, or comply with law. We remove or minimise direct identifiers when they are no longer necessary and delete or de-identify records when the applicable retention reason ends.
- Reviews and support. A review is retained until it is removed, the associated account is deleted, or it is no longer needed; removing it also removes it from future public display. Support communications are retained for the time needed to resolve and document the request and any related complaint, refund, dispute, security issue, or legal claim.
- Cookies and browser storage. Cookies and similar browser technologies are retained for the periods shown in our Cookie Policy. You can manage optional categories through our privacy preference centre and can clear stored data through your browser settings.
When personal information is no longer required, we delete it, aggregate it, de-identify it, or otherwise minimise it as appropriate. Information that can no longer reasonably identify a person may be retained for statistics, security, and service improvement.
We use reasonable technical and organisational safeguards, including access restrictions, authentication, limited administrative permissions, secure transport, logging, and service-provider controls. No internet service can guarantee absolute security. You are responsible for protecting your login credentials and should contact us if you believe your account has been compromised.
12. Your rights and choices
Depending on where you live and subject to lawful exceptions, you may have rights to confirm whether we process your information; access or know the categories, sources, purposes, recipients, and specific information involved; correct inaccurate or incomplete information; delete information; restrict or object to processing; withdraw consent; receive a portable copy; opt out of sale, sharing, targeted advertising, or certain profiling; and appeal a refused request. You may also complain to the privacy or data-protection authority where you live or work. Exercising a privacy right will not result in unlawful discrimination or retaliation.
A request to delete information may not require deletion of records we must or are permitted to keep, for example to complete a transaction, maintain security, document credit or payment activity, meet financial or legal duties, resolve disputes, or establish legal claims. In those cases, we limit retained information to the relevant purpose and delete or anonymise it when that reason ends.
You may submit a request for yourself or, where permitted, through an authorised agent. We may ask for information reasonably necessary to verify identity, account ownership, authority, and the scope of the request. We will respond within the period required where you live and explain any applicable extension or refusal. There is ordinarily no charge, but a permitted fee or refusal may apply to manifestly unfounded, excessive, or repetitive requests.
You can link or unlink a social account through Account & Security → Connected accounts. To unlink Google, choose Google → Disconnect. Disconnecting Google stops using that Google account to sign in to Images Upscaler; it does not delete your Google account or automatically delete your Images Upscaler account or information.
Manage optional browser technologies through our Cookie Policy and privacy preference centre. Account, review-publication, and marketing choices may also be available in your account or in messages we send. You may request account deletion and associated personal information by contacting [email protected].
13. Children
The service is not directed to children who are not old enough to consent to online data processing in their location, and we do not knowingly collect their personal information without the authorisation required from a parent or guardian. If you believe a child has provided personal information improperly, contact us so we can investigate and take appropriate action.
14. Contact and updates
Images Upscaler is responsible for the processing described in this Policy. To ask a privacy question, request the applicable contact or representative details, exercise a privacy right, or appeal our response, email support@imagesupscaler.ai. Please describe your request and the account email concerned; do not send passwords or complete payment-card details.
We may update this Policy as our service, providers, or legal obligations change. Material changes will be identified by the review date above and, where appropriate, communicated through the service or directly to account holders. If a change requires consent, we will request it before the relevant processing.
