I InstaFile Fast image tools

Legal

Privacy Policy

Last updated: September 2, 2026. This policy explains how InstaFile handles files, accounts, billing, and usage data.

The short version

Most InstaFile tools can be used without an account. Supported basic JPG and PNG resize, crop, rotate, compression, and conversion work can run locally in your browser; those files are not uploaded to InstaFile. Other operations and browser-local fallbacks send files to our servers for processing. Server request uploads and working files are removed when processing finishes. Most processed results are normally available for up to 30 minutes; vector previews and their private clean SVGs are normally available for up to 24 hours so a user can decide whether to unlock the result. We do not sell personal information or use your files to train an InstaFile model.

Files, results, and URLs you submit

When a tool uses server processing, we receive the file contents, filename, type, size, and settings you select. Processing occurs on our infrastructure in readable form. Transfers use HTTPS in production, but the service is not end-to-end encrypted. When a tool confirms browser-local processing, the file stays in that browser tab and is not sent to InstaFile for the operation.

Synchronous request uploads and working copies are deleted after the request finishes. When the durable processing queue is enabled, encrypted transport and private object storage may hold queued or retrying inputs for up to two hours by default; inputs are deleted after successful processing, cancellation, or a final failure. Most processed results and previews expire after 30 minutes by default. Vector previews and the private clean SVGs behind them expire after 24 hours by default, whether or not the clean SVG is purchased. Remotely imported files and prepared video crop or trim sources may also be stored temporarily. Files may disappear sooner because of storage limits, cancellation, or an error.

Many processed-result URLs and anonymous queued-job access tokens act as temporary bearer links: anyone who obtains one may be able to check or download that result until it expires. The links use long random tokens, but you should still avoid sharing them with anyone who should not receive the file. Clean vector results are different: they require an active Pro subscription, an account-linked purchase, or the guest Stripe Checkout Session recorded for that exact result. The guest Checkout Session identifier acts as a temporary bearer credential for the paid file, so avoid sharing its return or download URL. Prepared video source files and shared-storage objects are private and are not directly exposed as public website files.

If you use remote import or webpage capture, we receive the URL you enter and fetch the public resource from our infrastructure. The destination website receives requests from our capture or import service and may process those requests under its own privacy policy. Do not submit URLs containing passwords, private access tokens, or information you are not authorized to retrieve.

Account information

An account is optional for many tools, including the published single-image clean raster vector preview and its one-time SVG purchase. An account is required to use Pro vectorization and larger vector batches or to start a subscription. If you create or use one, we process:

Requesting a signup code does not immediately create a permanent account. Until you verify the code, the email address and optional name are kept in an expiring pending-signup record for up to 24 hours. Successful verification creates the account; an expired unverified record is removed by periodic cleanup.

Email codes are delivered through Resend. Resend also sends signed delivery-status events so InstaFile can detect delivery delays, failures, bounces, and complaints. InstaFile's event table stores only the opaque event identifier, event type, and event timestamps; it does not copy the recipient address, message subject, or message contents from those events. If Google sign-in is configured and you choose it, Google provides a verified email address, name, and account identifier through Google Identity Services.

Information collected automatically

We use the essential pulpimg_session cookie only when you sign in. It is HttpOnly and SameSite=Lax, and it is marked Secure on HTTPS deployments. InstaFile does not currently use advertising cookies.

How we use information

Service providers and disclosures

We disclose data only as needed for the service or as required by law. Current categories include:

We may also disclose information when legally required, to protect rights or safety, or as part of a merger, acquisition, financing, or transfer of the service, subject to appropriate safeguards. We do not sell or rent personal information and do not disclose it for cross-context behavioral advertising.

Retention

Security

We use HTTPS/TLS in production, hashed session tokens and email codes, HttpOnly session cookies, upload limits, private object storage, and temporary retention. Anonymous processed-file and job links use long random tokens; signed-in job access can also be authorized through the account. Bearer links still grant access to anyone who has them. No service is perfectly secure, so keep your originals and do not upload material you cannot risk exposing.

Your choices and rights

Depending on where you live, privacy law may provide additional rights, including rights to know, correct, delete, restrict, object, or receive a portable copy of certain information. We may need to verify your identity before completing a request, and lawful exceptions may apply.

International processing

InstaFile and its providers may process information in countries other than your own. Those countries may have different data-protection laws. Where required, appropriate transfer safeguards should apply.

Children

InstaFile is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided account information, contact us so we can review and delete it where appropriate.

Changes to this policy

If we make material changes, we will update the date at the top of this page and, where appropriate, notify you.

Contact

Questions about privacy? Email us at [email protected].