Legal
Privacy Policy
How ImageGrid handles personal information, retention, and requests.
Last updated: July 13, 2026
This Privacy Policy explains, in practical terms, how Ryan Rhode ("Ryan Rhode", "we", "us", or "our") handles personal information for the ImageGrid service. It is written for a service operated from Ontario, Canada and is intended to describe actual present-day practices, not broad legal guarantees beyond what the service currently does.
Operator and privacy contact
ImageGrid is operated from Ontario, Canada by Ryan Rhode.
For privacy-related questions, requests, or complaints:
- signed-in users should use the privacy area under
/app/privacywhere available - public privacy or legal inquiries can be sent through the contact page
Ryan Rhode is responsible for personal information handled through ImageGrid, including information processed on his behalf by service providers.
Scope
This policy applies to:
- the public website and documentation
- customer account creation and sign-in
- account management under
/app/* - API and billing workflows connected to customer accounts
Information ImageGrid collects
Ryan Rhode may collect, through ImageGrid:
- account identity information such as email address and display name
- authentication data such as password hashes, verification tokens, reset tokens, and session records
- billing-related identifiers returned from payment providers
- API key metadata, but not the full plaintext key after issuance
- operational metadata such as IP-adjacent security fingerprints, user-agent strings, form timing signals, and abuse-review records
- usage and audit records connected to uploads, jobs, artifact delivery, quota events, and internal administrative actions
ImageGrid is designed to process customer image content and derived outputs. Those files and their technical metadata are also part of the service data footprint.
Why the information is used
Ryan Rhode uses this information to operate ImageGrid and to:
- create and secure user accounts and sessions
- run customer accounts, API access, and billing
- enforce quotas, retention rules, and abuse controls
- investigate service misuse, fraud, or operational failures
- meet accounting, tax, contractual, security, and legal obligations
Cookies and local storage
ImageGrid currently uses:
- HTTP cookies for signed-in web sessions
- local browser storage for the saved theme preference
See the Cookie Policy for more detail.
Sharing
Ryan Rhode does not publish customer account data publicly. Data may be shared with service providers that are necessary to run ImageGrid, such as infrastructure, email, payment, and storage-related vendors, or where disclosure is required for security, legal, or operational reasons.
Service providers and disclosures
ImageGrid relies on third-party providers where reasonably necessary to operate the service. Depending on the workflow, this may currently include providers such as Stripe for payment and billing workflows, Fastmail and ZeptoMail for email-related workflows, Bunny.net for storage or delivery-related workflows, and other hosting or infrastructure providers.
Information may also be disclosed:
- where required by law, court order, or lawful process
- to investigate or respond to fraud, abuse, security incidents, or other misuse
- to protect the rights, property, or safety of Ryan Rhode, users, or others
- as part of a business transfer, reorganization, or asset sale, if one occurs
Cross-border processing
Some service providers used to operate ImageGrid may process or store information outside your province or country, including outside Canada. When that happens, the information may be subject to the laws of the jurisdiction where it is processed.
Ryan Rhode uses contractual and operational measures intended to require service providers to protect personal information in a manner appropriate to the sensitivity of the information and the role the provider performs.
Retention
Ryan Rhode keeps ImageGrid data only as long as reasonably needed for the purpose it serves, subject to operational, security, accounting, and legal requirements.
Examples:
- session and verification records are retained to support account security and traceability
- usage, audit, abuse, and billing records may be retained longer where needed for fraud review, support, accounting, or security
- uploaded and generated image data may be removed by retention policy, quota policy, account action, or manual support workflow
Retention behavior may evolve as the product matures, but public statements should track actual system behavior rather than optimistic future intent.
Access, correction, export, and deletion requests
Signed-in users can submit privacy-related requests from the account privacy area in the product. Current request types include:
- metadata export requests
- account-data deletion requests
Requests are tracked in-product, reviewed against the current account state, and evaluated against any data that must be retained for billing, fraud prevention, legal, accounting, or security reasons.
Current request boundaries are:
- privacy exports are metadata-first and do not currently bundle stored image binaries
- approved account-data deletion removes stored customer content, issued access, and account-specific quota overrides
- some reduced billing, audit, usage, and abuse-review history may still be retained after account-data deletion
For privacy or legal inquiries outside the signed-in product, use the public contact form.
International availability
ImageGrid may be accessed from outside Canada. This policy describes the service as currently operated and does not make blanket claims of compliance in every jurisdiction.
Questions, complaints, and verification
To protect account data, Ryan Rhode may ask for enough information to verify the identity and authority of the person making a privacy-related request before acting on it.
If you believe ImageGrid has handled your personal information improperly, use the contact page and identify the issue as a privacy complaint so it can be reviewed directly.
Updates
This policy may be updated as the product, vendors, workflows, or legal obligations change. Material updates will be reflected by changing the date at the top of this page.