Privacy policy
BlurMyPhoto has no accounts and sets no cookies, the only thing it counts is that a page was opened, and there is no server anywhere that could receive one of your photographs. That leaves very little to write a policy about, so this one describes what actually happens and nothing more.
1. The short version
Last updated 17 August 2026.
- There is no account to create and nothing to sign up for.
- No cookies are set, of any kind, first-party or third-party.
- One cookieless page-view counter, described in full in section 8. No tracking pixel, no session recording, no profile, no identifier that outlives the request.
- Your images are opened, edited and saved by your own browser. They are never uploaded, to us or to anyone else.
- The only personal data we could ever hold about you is an email you decide to send us.
Everything below is the long version of those five lines. If any of them stops being true, the date above changes on the same day.
2. What we collect
Essentially nothing, and that is structural rather than a promise. The site is a set of static files on Cloudflare Pages. There is no application server, no database and no account system, which means there is no endpoint an image or a form submission could be sent to.
There is no contact form anywhere on the site. The contact page gives an email address instead, which is deliberate: a form needs a handler, and a handler is a server holding your message.
No first-party cookie is set. Nothing is written to localStorage, sessionStorage or IndexedDB. Nothing about your visit survives the tab closing.
That leaves email. If you write to hello@blurmyphoto.com we hold your address, your message and anything you attach to it, in an ordinary mailbox, for as long as the exchange is useful and no longer than 24 months after our last reply, after which it is deleted. The lawful basis for handling correspondence someone chose to start is our legitimate interest in answering it — Article 6(1)(f) of the General Data Protection Regulation. Where you send more than an answer requires, such as a photograph attached to a bug report, the basis is your consent under Article 6(1)(a), and you can withdraw it by asking us to delete the message. Nobody who writes to us is added to a mailing list, because there is no mailing list.
3. Your images
When you open a file, the browser's File API reads it into a canvas on the page in front of you. Everything after that — face detection, the boxes you draw, the pixelation, the blur, the exported file — happens in your device's own memory. There is no upload, because there is no upload endpoint.
This is enforced by your browser rather than trusted to us. Every page is served with a Content-Security-Policy header whose connect-src directive names four origins and no others: this site, the jsDelivr CDN, Google's model storage and Cloudflare's page-view beacon. Any other outbound connection the page attempted would be refused by the browser before it left your device, and not one of those four is an address a photograph could be sent to. You can verify that two ways. Open the network panel in your browser's developer tools and watch what the page requests. Or load the page, put the device into aeroplane mode (airplane mode), and confirm that blurring a face still works with the network switched off.
Face detection does not change this. Choosing a file causes your browser to download Google's MediaPipe Tasks Vision runtime, version 1.0.1, from jsDelivr, and the blaze_face_short_range model from Google's model storage. The detection then runs on your own device. Traffic goes one way: code comes down, no image goes up. Neither file is fetched at page load, so if you never open a photo, neither is ever requested. HEIC and TIFF files each pull one further small library, again only when a file of that type is opened, and on Safari not even that, because Safari decodes HEIC itself.
One useful side effect of working in a canvas: re-encoding an image discards its EXIF block, so every file this site produces has already lost its camera data and GPS coordinates. That is also all the metadata stripper does, without the redaction step.
4. Advertising and Google AdSense
Accuracy matters here more than brevity. Advertising is not live. There is currently no AdSense code on any page of this site, no advertising script of any kind, and no advertising cookie. The reserved rectangles you may notice on other pages are empty placeholders holding their final height so the page does not jump when a unit is eventually placed in one.
When advertising is switched on, the following will apply, and this section will be rewritten on the day it happens rather than afterwards.
- Google and its partners will use cookies to serve advertisements based on your prior visits to this site and to other sites.
- You can opt out of personalised advertising at Google Ads Settings.
- Google's own explanation of how it uses data from sites that use its services is at How Google uses information from sites or apps that use our services.
Advertisements will sit beside the tool, not inside it. No advertising network will receive your image, for the same reason nobody else does: the image is never transmitted anywhere at all.
5. Visitors in the EEA and the UK
Google does not permit personalised advertising to visitors in the European Economic Area or the United Kingdom unless the publisher uses a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework. Google's AdSense documentation on consent management requirements dates that requirement from 16 January 2024 for the EEA and the UK, and from 31 July 2024 for Switzerland. That platform is what asks you for consent and passes your answer to Google through Consent Mode v2.
One will be in place before a single advertisement is served to a visitor in those regions. Until then the question does not arise, because no advertising cookie is set at all — there is no advertising code on the site that could set one. When a consent platform is added, this policy will name it and say what it stores.
6. Cookies
At present, none. Not one, first-party or third-party. There is no cookie banner either, which is the honest consequence of having no cookies rather than a corner cut.
When advertising begins, third-party advertising cookies from Google and its partners may be set, subject to the consent process in section 5 for visitors in the EEA and the UK. Nothing else changes. No first-party cookie of our own is planned, and no cookie is or will ever be required for the tool to work. Refusing every cookie your browser allows you to refuse will not stop you redacting a photograph here.
7. Third parties that see your IP address
Requesting any file reveals your IP address to whoever serves it. That is how a response gets back to you, not a decision anyone made about you. Three organisations are in that position on this site. None of them receives your image, because your image is never sent anywhere.
Google Fonts used to be a fourth. The typefaces are now served from this domain, which means Google is no longer handed your IP address on every page load simply because a page has words on it.
- Cloudflare
- Hosts the site and serves every page and file on this domain. Cloudflare privacy policy.
- jsDelivr
- Serves the face-detection runtime and the HEIC and TIFF decoders from cdn.jsdelivr.net. Contacted only after you open a file. jsDelivr privacy policy.
- Google model storage
- Serves the face-detection model file from storage.googleapis.com. Contacted only after you open a file. Google privacy policy.
The last two are never contacted at all if you read a page without opening a photo.
8. Analytics
One page-view counter, and it is the least invasive one we could find: Cloudflare Web Analytics. It records that a page was requested, which page, roughly how quickly it rendered, and the country the request came from. It does not set a cookie, does not write to localStorage, does not build a fingerprint, and has no identifier that could follow you to another site or back to this one tomorrow. There is nothing in it that could be tied to you, which is also why we cannot tie it to you.
No tag manager, no heatmap, no session recorder, no split-testing script, and no Google Analytics. Cloudflare already serves every file on this domain, so the beacon reveals nothing to a party that was not already handling the request.
We would rather have counted nothing. But a site funded by advertising has to know which of its pages people actually read, or it ends up guessing — and guessing tends to end in more advertising rather than less. Counting pages without identifying readers is the version of that we can defend.
9. Children's privacy
The site is not directed at children under 13. There are no accounts, no first-party tracking and no way to build a profile of anyone, so there is nothing here that could knowingly collect a child's data. If you believe a child has sent us an email and you would like it removed, write to hello@blurmyphoto.com and we will delete it.
10. Your rights under the GDPR and the UK GDPR
You have the right of access to your personal data, and the rights to rectification, erasure, restriction of processing, objection, and data portability, along with the right to complain to a supervisory authority.
The honest position is that those rights attach to personal data a controller holds, and we hold almost none. If you have never emailed us, there is nothing here to access, correct, erase or port. If you have, write to hello@blurmyphoto.com and we will act within one month; ask for the exchange to be deleted and it is deleted. The controller for that correspondence is the BlurMyPhoto team, at the same address.
Once advertising begins, the only meaningful processing on this site will be Google's, and requests about that data go to Google rather than to us. Google Ads Settings controls personalised advertising, and the Google privacy policy sets out how to reach Google about the rest.
To complain about us or about Google, you can go to a supervisory authority without asking us first. In the United Kingdom that is the Information Commissioner's Office. In the EEA it is your national authority; the European Data Protection Board publishes the list of national supervisory authorities.
11. Changes to this policy, and how to reach us
Changes are made to this page directly, and the date in section 1 changes on the same day. Two are already scheduled: sections 4 and 6 will be rewritten when advertising goes live, and section 5 will name the consent platform once it is in place.
Questions, corrections and data requests all go to hello@blurmyphoto.com. If you would rather see what the tool does before deciding what you think of this policy, how it works covers the same ground from the technical side.