Updated August 26, 2026
Privacy Policy
This policy explains how ChangeTextImage handles uploads, account data, credits, payments, analytics, and AI image processing.
Developer and contact
ChangeTextImage is operated by an independent developer providing AI-powered image text editing services. For privacy requests, legal inquiries, support requests, billing, refund, abuse, or other questions, please contact us at support@changetextimage.com.
Information we collect
We may collect website and device information, analytics events and pseudonymous analytics identifiers, uploaded image files, optional masks, private queued edit instructions, generated output metadata, account email and Google profile identifiers, credit balances, credit transactions, generation history metadata, Creem or PayPal checkout metadata, support messages, and security or abuse logs. Normal generation history does not store or display the original text, replacement text, or internal AI prompt. A separate encrypted failure-audit copy is described below.
Uploaded images and AI processing
Images, masks, requested text changes, and server-generated edit instructions are used to process the requested edit and may be sent to KIE AI, fal, or OpenAI image editing endpoints. The active provider and its temporary processing storage may change as the service evolves. Do not upload sensitive official records, private conversations, financial documents, or materials you do not own or have permission to modify.
Chrome extension privacy
The optional Chrome extension has a separate privacy notice at /chrome-extension-privacy. That notice explains the right-click image URL shortcut, extension permissions, and image URL import flow.
Account, credits, and history
Google login may provide the account email, name, profile picture, and Google account identifier needed to create an account session. The D1 credit ledger stores account identifiers, email, credit balances, first-login grant status, transactions, login timestamps, generation status, input/output metadata, output retention timestamps, purchase attempts, Creem checkout or order references, PayPal order or capture references, a pseudonymous GA browser identifier when available, and related timestamps for account, billing, support, fraud-prevention, abuse-prevention, and purchase attribution purposes.
Analytics and session replay
The measurement stack can include Google Search Console, GA4, Ahrefs Analytics, Microsoft Clarity, and Plausible when configured. Production browser analytics scripts are delayed until after the page load event so they do not block the first page render. After a payment provider confirms a credit purchase, the server may send GA4 the purchase value, currency, credit pack, payment provider, internal purchase identifier, and the pseudonymous GA browser identifier used for attribution; it does not send account emails or PayPal or Creem payment identifiers. Upload previews, generated results, text fields, account details, dashboard history, checkout status, and pricing checkout areas are marked for replay masking.
Payments
Checkout options may include Creem or PayPal, depending on which payment option is shown and selected before purchase. Creem may act as the merchant of record for Creem checkout, handling payment processing, tax calculation, receipts, buyer-facing payment records, refunds, disputes, and related compliance workflows. PayPal may receive checkout details for PayPal checkout, including the selected plan, amount, currency, order reference, capture reference, and return or cancel status. We do not store full payment card numbers, payment card security codes, or PayPal credentials on this application server.
Retention
Raw uploaded images, masks, and private queued edit instructions may be temporarily stored for processing and recovery for up to 24 hours; queued instructions are cleared when a job reaches a terminal state. A separate encrypted audit copy of edit parameters, including the original text, replacement text, and whether a mask was supplied, may be retained to investigate failures: it is deleted on success and kept for up to 7 days after a failed, refunded, or expired terminal state. Generated output images may be stored in private R2 for up to 7 days for Dashboard downloads, then they expire. Ordinary generation metadata is retained for up to 30 days. Operational logs are retained for up to 30 days; payment, credit, security, and abuse audit logs for up to 180 days; and daily aggregated event statistics for up to 180 days. Payment and accounting records may be retained as legally required, typically at least 7 years. Abuse, fraud, dispute, or legal-request records may be retained longer where necessary.
Your rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. To make a privacy request, contact support@changetextimage.com. Some billing, security, fraud-prevention, abuse-prevention, or legal records may be retained when an exception applies.
Children
This service is not intended for children under 13. Do not use the service if you are not old enough to consent to the processing of your information in your location.
Changes
We may update this Privacy Policy when the service, providers, legal requirements, or data practices change.