Privacy Policy

1. Who we are

MiniPic operates the online image compression service at minipic.ai. For the purposes of the GDPR, we are the controller of the personal data described in this policy. You can reach us about any privacy matter at [email protected].

2. What data we collect

We practise data minimisation and collect only what is necessary to provide and protect the Service:

3. How we handle your images

To meet our legal obligations we run automated safety screening on uploads. Content detected as unlawful is blocked and deleted immediately; the related screening record (not the image content itself) may be retained as required by law.

4. Why we process your data (lawful bases)

Under Article 6 GDPR we rely on the following lawful bases:

5. Service providers and sharing

We use carefully selected processors to deliver parts of the Service, acting on our instructions under a data processing agreement that requires them to process data only for the agreed purpose and to keep it secure. These include:

We do not sell your personal data, and we do not share it with other third parties except as required by law or with your consent.

6. International transfers

We host the international service on infrastructure that may be located outside your country. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, and apply additional measures where needed. You may contact us for more information about the safeguards in place.

7. Data retention

We use cookies and browser local storage that are strictly necessary to keep you signed in, remember your preferences (such as theme and output format) and protect security. We do not use cookies for cross-site advertising tracking. You can manage or clear this data through your browser settings, though some features may then stop working.

9. Your rights

Subject to applicable law, you have the following rights over your personal data:

To exercise these rights, use your account settings or email [email protected]; we will respond within the period required by law. You also have the right to lodge a complaint with your local data protection supervisory authority.

10. Security and breach response

We maintain technical and organisational measures — including encryption in transit and at rest, access controls and least-privilege access — together with an incident response plan. In the event of a personal data breach, we will notify the competent supervisory authority and, where required, affected individuals, in line with Articles 33 and 34 GDPR.

11. Children

The Service is intended for adults and is not directed at children. We do not knowingly collect personal data from children below the age of digital consent. If we learn that we have collected such data without the required consent, we will delete it promptly.

12. Changes to this policy

We may update this policy from time to time. We will notify you through an on-site notice or other appropriate means and update the version number and effective date at the top of this page. For changes that materially affect your rights, we will give more prominent notice. Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy.

13. Contact us

For any question, request or complaint about this policy or our handling of your personal data, email us at [email protected]. We will respond as soon as possible.