1. Who we are
PictureMatters ("we", "the service") is a free online image metadata and forensics analysis tool operated at picturematters.in. Contact for all privacy matters: hello@picturematters.in.
2. Information we collect
- Uploaded images (temporary) — images you submit for analysis. They are stored in a server-side temporary directory only for the duration of processing and expire automatically within 15 minutes. The assembled original is deleted immediately after the report is created; a small thumbnail remains until expiry so the report page can display it.
- Report data (temporary) — the analysis results are stored as a JSON report alongside the thumbnail and expire on the same 15-minute cycle. Nothing about your image is retained after expiry: no archives, no backups, no database.
- Rate-limit data (ephemeral) — to prevent abuse, a truncated hash prefix of an uploaded file may be kept for up to 60 seconds to throttle repeated identical submissions. It contains nothing that identifies you or reconstructs the image.
- Server logs — like virtually all web servers, the hosting environment may keep standard access logs (URLs requested, timestamps, IP addresses, user agent) for operational and security purposes. We do not add image content, GPS data or report contents to logs; log retention is determined by our hosting/logging configuration.
- Local browser storage — your recent-scan list and theme preference are stored in your browser's localStorage only. This data never leaves your device and is not transmitted to us. Clearing it (history drawer → Clear, or your browser settings) removes it entirely.
3. What we do not collect
- No names, email addresses or account data — there are no accounts.
- No payment information — the service is free.
- No permanent record of uploaded images or generated reports.
- No selling or sharing of personal data with data brokers. Ever.
4. Cookies
The site sets no tracking cookies. Your theme choice and scan history use browser localStorage, which is not a cookie and is not transmitted to the server. If third-party services described in section 6 are enabled in the future, their cookie behavior will be disclosed here.
5. Analytics & advertising
Currently none. The site runs no analytics scripts and displays no advertisements. If measurement or advertising is introduced later, this policy will be updated first — including the specific providers involved, what they collect, and your choices — before any such code is activated.
6. Third-party services
- Google Fonts — typography is loaded from Google's CDN, which means your browser communicates with Google when fetching fonts. If you prefer to avoid this, block the request; the site falls back to system fonts.
- heic2any (CDN) — when a HEIC/HEIF file is analyzed from a non-Safari browser, a decoder library is fetched from a public CDN to convert it in your browser. The image itself is not sent to that CDN.
- OpenStreetMap Nominatim — for images with GPS data, the server may query this free geocoding service to display an approximate place name. The query contains only the coordinates, not the image or any identifier of you. Queries are rounded and cached to keep request volume minimal, per Nominatim's usage policy. Place data © OpenStreetMap contributors.
7. Uploaded images: processing & storage policy
- Uploads travel in encrypted transit (HTTPS) and are processed on the server solely to generate your report.
- Storage is access-restricted (randomized names, owner-only permissions, no direct web access, PHP execution disabled).
- Report URLs are unlisted, unpredictable, noindexed, and expire with the report.
- We do not view, use, publish or share your images. There is no human review pipeline.
8. Data retention summary
Deleted immediately after report generation (seconds).
Auto-expire within 15 minutes.
Up to 60 seconds.
Stored only in your browser until you clear it.
Per hosting provider defaults (typically days to weeks); contain URLs/IPs, not image data.
9. Security
The technical measures protecting uploads — token randomization, permissions, directory protection, output escaping — are documented in detail on the Security page.
10. Your rights & choices
- Access & deletion — since we retain no personal data and your uploads self-delete within minutes, there is ordinarily nothing to request. If you believe data about you exists beyond that (e.g., in logs), email us and we will address it.
- Browser data — clear your scan history from the history drawer, or via your browser's site-data settings.
- Minimize exposure — remove sensitive metadata before sharing files anywhere; see our guide to removing EXIF.
- If a privacy authority's rules apply to your use of the site and you have questions, contact us at the address above.
11. Children
The service is not directed at children under 13, and we do not knowingly collect personal information from them. There is no registration pathway that would allow it.
12. Changes to this policy
If this policy changes materially — in particular before any analytics or advertising is introduced — the updated version will be posted on this page with a new "last updated" date. Significant changes will be highlighted on the homepage for a reasonable period.