Privacy Policy

Last updated: 4 August 2026

This policy describes what happens to your data when you use magicremover.org. It is written to be specific rather than reassuring — where something is kept longer than you might assume, it says so.

Who we are

MagicRemover (magicremover.org) is an independently operated AI photo-cleanup service. We are the data controller for the information described in this policy.

Privacy questions and data requests: hello@magicremover.org.

What we collect

Images and video you upload

The file you upload, and the mask you paint, are transmitted to the AI provider that performs the edit. We do not use your uploads to train models, and we do not sell or share them with anyone outside the processors listed below.

To choose a better prompt for the model, the tool may also send your uploaded image together with a copy showing your mask to Google's Gemini API, which returns a short text description of what is inside the masked region. If that step is unavailable the tool falls back to a generic prompt and your image is not sent.

Account information

If you sign in with Google we receive your name, email address and profile picture URL from Google OAuth. We never see your Google password or anything else in your Google account. These records, along with your credit balance and credit transaction history, are stored in our managed database (Cradler).

Usage and anti-abuse data

We keep per-device and per-account counters so the free tier can be enforced, plus short-lived per-IP counters that stop scripted abuse. We record an activity log entry per removal (timestamp, tool, outcome, truncated IP) and aggregate anonymous statistics such as daily active users and total removals.

Cookies and local storage

A signed, HTTP-only device cookie holds a random identifier so an anonymous allowance survives a page reload — it contains no personal information. Auth.js sets an HTTP-only session cookie when you sign in. A counter is also mirrored in your browser's localStorage. We set no advertising or cross-site tracking cookies.

How we use it

  • To perform the removal you requested and return the result
  • To enforce free-tier limits and block automated abuse
  • To keep your credit balance correct and resolve billing disputes
  • To show your saved results in your gallery, if you are signed in
  • To reply when you contact us
  • To understand aggregate usage patterns (anonymised counts only)

We do not sell your data, we do not use it for advertising, and we do not profile you.

Who else receives your data

Each of these performs a specific job and receives only what that job needs. Each is bound by its own privacy policy.

RunningHub
Runs the inpainting model for the image tools. Receives your uploaded image and mask. Requests are served from infrastructure in China.
Replicate
Fallback inference provider for the image tools. Receives your uploaded image and mask when used.
Google Gemini API
Receives your uploaded image and a masked copy in order to describe the masked region, which improves the removal prompt. Not used if the step is unavailable.
apimodels.app
Powers the video subtitle and on-screen-text removal tool. Your video is uploaded directly from your browser to their storage and is deleted by them after 7 days.
Cradler
Managed Postgres and object storage. Holds user records, credit balances, the credit transaction log, and stored result images.
Cloudflare R2
Object storage for result images, with a one-day delete rule on the anonymous bucket. Cloudflare also provides DNS for the domain.
Google OAuth
Handles sign-in. We receive only your name, email address and profile picture URL.
Stripe
Processes credit purchases. Card details go directly to Stripe and never reach our servers; we receive only the confirmation and the amount.

The application itself runs on a dedicated server we operate, not on a third-party serverless platform. Usage counters and the task queue live in a self-hosted Redis instance on that same server.

How long we keep things

Original uploads
Held only for the duration of processing, then discarded. We do not retain your source file.
Results — not signed in
Deleted automatically within 24 hours by a scheduled cleanup job.
Results — signed in
Kept indefinitely so they remain available in your gallery. They are deleted when you delete them, or when you ask us to close your account.
Uploaded video
Deleted by apimodels.app after 7 days. The finished video is available for the same window.
Usage counters
Expire automatically at the end of the UTC day.
Activity log
Retained on a rolling short-term basis for abuse investigation, then expires automatically.
Account and credit records
Retained until you request deletion. Credit transaction entries may be kept longer where needed to meet financial record-keeping obligations.

Your rights

Depending on where you live you may have the right to access, correct, export, or delete the personal data we hold about you, to object to or restrict processing, and to lodge a complaint with your data protection authority.

To exercise any of these, email hello@magicremover.org from the address you signed in with, so we can confirm the request is really yours. We respond within 30 days, usually much sooner. Deleting your account removes your user record, credit balance and stored gallery images.

Security

All traffic is served over HTTPS. Session and device cookies are HTTP-only and signed. Payment card data never touches our infrastructure. Stored data sits with managed providers that encrypt at rest and in transit. No system is perfectly secure, and we will not pretend otherwise — but we do not hold card numbers or passwords, which removes the two things most worth stealing.

Children

MagicRemover is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

Changes to this policy

We may update this policy as the service changes. Material changes are reflected in the date at the top of this page. Continuing to use MagicRemover after a change means you accept the updated policy.

Powered by apimodels.app — a unified AI image generation API