The short version
Most InstaFile tools can be used without an account. Supported basic JPG and PNG resize, crop, rotate, compression, and conversion work can run locally in your browser; those files are not uploaded to InstaFile. Other operations and browser-local fallbacks send files to our servers for processing. Server request uploads and working files are removed when processing finishes. Most processed results are normally available for up to 30 minutes; vector previews and their private clean SVGs are normally available for up to 24 hours so a user can decide whether to unlock the result. We do not sell personal information or use your files to train an InstaFile model.
Files, results, and URLs you submit
When a tool uses server processing, we receive the file contents, filename, type, size, and settings you select. Processing occurs on our infrastructure in readable form. Transfers use HTTPS in production, but the service is not end-to-end encrypted. When a tool confirms browser-local processing, the file stays in that browser tab and is not sent to InstaFile for the operation.
Synchronous request uploads and working copies are deleted after the request finishes. When the durable processing queue is enabled, encrypted transport and private object storage may hold queued or retrying inputs for up to two hours by default; inputs are deleted after successful processing, cancellation, or a final failure. Most processed results and previews expire after 30 minutes by default. Vector previews and the private clean SVGs behind them expire after 24 hours by default, whether or not the clean SVG is purchased. Remotely imported files and prepared video crop or trim sources may also be stored temporarily. Files may disappear sooner because of storage limits, cancellation, or an error.
Many processed-result URLs and anonymous queued-job access tokens act as temporary bearer links: anyone who obtains one may be able to check or download that result until it expires. The links use long random tokens, but you should still avoid sharing them with anyone who should not receive the file. Clean vector results are different: they require an active Pro subscription, an account-linked purchase, or the guest Stripe Checkout Session recorded for that exact result. The guest Checkout Session identifier acts as a temporary bearer credential for the paid file, so avoid sharing its return or download URL. Prepared video source files and shared-storage objects are private and are not directly exposed as public website files.
If you use remote import or webpage capture, we receive the URL you enter and fetch the public resource from our infrastructure. The destination website receives requests from our capture or import service and may process those requests under its own privacy policy. Do not submit URLs containing passwords, private access tokens, or information you are not authorized to retrieve.
Account information
An account is optional for many tools, including the published single-image clean raster vector preview and its one-time SVG purchase. An account is required to use Pro vectorization and larger vector batches or to start a subscription. If you create or use one, we process:
- Email address — used to create the account, deliver verification or login codes, and communicate about the account.
- Name — optional; it may be supplied by you or by Google if you choose Google sign-in.
- Account records — creation date, email-verification status, plan tier, subscription status and period end, recent job details, one-time vector-result purchase access, and, for Google sign-in, Google's account identifier. We do not receive or store your Google password.
- Billing records — Stripe customer, subscription, checkout, payment-intent, charge, refund, and dispute identifiers; the exact vector-result reference for one-time purchases; signed billing-event identifiers used to apply purchases once; reconciliation summaries; and manual-review flags or failure messages. Guest SVG purchases are recorded without creating an InstaFile account. InstaFile does not receive or store full payment-card details.
- Session and verification records — session tokens and email verification codes are stored as hashes. Email codes are valid for 10 minutes. The sign-in cookie and session are valid for up to 30 days unless you log out sooner.
Requesting a signup code does not immediately create a permanent account. Until you verify the code, the email address and optional name are kept in an expiring pending-signup record for up to 24 hours. Successful verification creates the account; an expired unverified record is removed by periodic cleanup.
Email codes are delivered through Resend. Resend also sends signed delivery-status events so InstaFile can detect delivery delays, failures, bounces, and complaints. InstaFile's event table stores only the opaque event identifier, event type, and event timestamps; it does not copy the recipient address, message subject, or message contents from those events. If Google sign-in is configured and you choose it, Google provides a verified email address, name, and account identifier through Google Identity Services.
Information collected automatically
- Request and security data — IP address, request headers, requested route, timing, queue wait, response size, and error or diagnostic details may be processed by our server, hosting provider, and network provider to deliver the service, measure capacity, enforce rate and resource limits, troubleshoot failures, and prevent abuse. Most application rate-limit counters are short-term records held in server memory. Login-throttle records use shortened cryptographic hashes derived from the normalized email address and visitor IP. For account quotas, the application stores period-based usage counts. Durable-job owner keys use shortened hashes derived from the visitor IP rather than storing the full IP in those records; durable jobs also store a hash of the bearer access ticket.
- Cloudflare Web Analytics — every page loads Cloudflare's analytics beacon for aggregate traffic and performance measurement. The beacon is cookieless and does not use browser storage to recognize you, but Cloudflare still receives the request and associated technical and performance data. See Cloudflare's Privacy Policy.
- Google Fonts — pages request fonts from Google. Those requests disclose your IP address, the requested font URL, referrer, and browser or operating-system headers to Google. Google says the Fonts API does not set cookies or use this information for targeted advertising. See Google Fonts privacy and data collection.
- Browser storage — if you save a workflow, its tool sequence is stored in your browser's local storage until you remove it or clear site data. Temporary workflow handoffs are stored in session storage and normally end with the browser session. When an anonymous queued vector result is sent to checkout, session storage temporarily keeps its bearer access ticket so the paid download can resume after Stripe returns you to InstaFile. For anonymous durable jobs, local storage also keeps the job ID, bearer access ticket, status path, tool route, timestamps, status, and limited filename/status details so the Jobs page can resume the work. The browser prunes those local entries after about 31 days, and the corresponding anonymous server record normally expires sooner. These records stay on your device unless you use them to submit files to a tool.
We use the essential pulpimg_session cookie only when you sign in. It is HttpOnly and
SameSite=Lax, and it is marked Secure on HTTPS deployments. InstaFile does not currently use advertising cookies.
How we use information
- Provide the requested file operation, remote import, or webpage capture.
- Make temporary results available for preview, workflow handoff, and download.
- Create and secure accounts, deliver login codes, maintain plan entitlements, and authorize purchased vector results.
- Start and manage Stripe checkout, subscriptions, billing-portal sessions, one-time vector-result purchases, refunds, disputes, failed-payment status, and reconciliation with Stripe.
- Enforce limits, investigate errors or abuse, and maintain the service.
- Measure aggregate usage and performance and improve the tools.
- Comply with law and protect users, the service, and others.
Service providers and disclosures
We disclose data only as needed for the service or as required by law. Current categories include:
- Hosting and network infrastructure — receives requests and temporarily stores or processes uploads and results.
- Cloudflare — aggregate web analytics and related network or request processing; when shared processing is enabled, the browser may also upload queued inputs directly to a private Cloudflare R2 bucket using a short-lived, file-specific authorization. Cloudflare then temporarily stores those inputs and processed results under the retention rules below. When you use webpage capture, InstaFile sends the public URL, viewport and output settings to Cloudflare Browser Run, which loads the destination page and returns the rendered screenshot. InstaFile does not send your InstaFile session cookie or credentials for the destination site.
- Google — font delivery on page visits and optional Google sign-in.
- Resend — delivery of account verification and login emails.
- Stripe — hosted checkout, payment processing, subscription administration, fraud prevention, and the customer billing portal.
- Database and private object-storage providers — durable job records and temporary queued inputs or outputs when shared processing is enabled.
- Websites you ask us to contact — when you use remote import or webpage capture.
We may also disclose information when legally required, to protect rights or safety, or as part of a merger, acquisition, financing, or transfer of the service, subject to appropriate safeguards. We do not sell or rent personal information and do not disclose it for cross-context behavioral advertising.
Retention
- Synchronous request uploads and working files — removed when the request finishes.
- Queued inputs — removed after success, cancellation, or final failure and otherwise expire with the job after up to two hours by default.
- Job history — after media is deleted, signed-in accounts retain lightweight job details such as tool, filenames, status, attempts, timestamps, and error summaries for 30 days by default. Anonymous server job records are retained for seven days by default. The Jobs page removes an anonymous browser ticket after the server no longer recognizes it.
- Processed results and prepared media — most expire after 30 minutes by default. Vector previews and their private clean SVGs expire after 24 hours by default, including after a one-time purchase, and can be removed earlier as described above.
- Email codes — valid for 10 minutes and deleted or replaced after use, expiry handling, or a new request.
- Email delivery events — opaque signed-event identifiers, event types, and timestamps are retained for approximately 35 days to prevent duplicate processing and monitor delivery health. Recipient addresses, subjects, and message contents are not copied into this event table or monitoring metrics.
- Sessions — valid for up to 30 days; logging out invalidates the current session.
- Pending signup records — retained for up to 24 hours unless verification completes sooner.
- Login-throttle records — hashed email- and IP-derived counters expire after approximately 10 minutes.
- Account records — retained while the account exists and as needed for security, legal compliance, or dispute resolution.
- Billing records — Stripe retains payment records under its policies and legal obligations. InstaFile removes processed webhook-event identifiers, resolved webhook-failure records, and aggregate reconciliation-run summaries after approximately 400 days. Subscription, account-linked and guest one-time result purchase, refund, revocation, and dispute-review records may remain as needed for legal compliance, fraud prevention, accounting, or dispute resolution, even after the temporary file itself expires.
- Browser storage — retained on your device as described above until the browser or you removes it.
- Infrastructure and analytics records — Railway retains production application, HTTP, build, and deployment logs for 30 days on the current Pro plan. Grafana receives bounded operational metrics, not application logs, and its Free plan retains those metrics for 14 days after the trial. Cloudflare's current Free plan exposes sampled security events for up to 24 hours and security analytics for seven days. Cloudflare says Browser Run Quick Actions process webpage content and generated screenshots ephemerally and discard them after returning the response; InstaFile disables the optional Browser Run output cache. Resend retains provider-side email data for 30 days. These provider windows may change with the plan or provider policy; we do not copy them into a longer-lived general-purpose log archive.
Security
We use HTTPS/TLS in production, hashed session tokens and email codes, HttpOnly session cookies, upload limits, private object storage, and temporary retention. Anonymous processed-file and job links use long random tokens; signed-in job access can also be authorized through the account. Bearer links still grant access to anyone who has them. No service is perfectly secure, so keep your originals and do not upload material you cannot risk exposing.
Your choices and rights
- Use supported browser-local and other eligible free tools, including the published single-image clean raster vector preview, without creating an account. You can also purchase that exact SVG as a guest. Pro vectorization, larger vector batches, and subscriptions require an account.
- Do not choose Google sign-in if you prefer email-code sign-in.
- Clear saved workflows through your browser's site-data controls.
- While signed in, open the account menu in the site header and choose Delete account to cancel an active InstaFile subscription and permanently delete your InstaFile account, purchase-access records, and login sessions. Stripe may retain transaction records it must keep. You can also contact us to request access, correction, export, or deletion of account information.
Depending on where you live, privacy law may provide additional rights, including rights to know, correct, delete, restrict, object, or receive a portable copy of certain information. We may need to verify your identity before completing a request, and lawful exceptions may apply.
International processing
InstaFile and its providers may process information in countries other than your own. Those countries may have different data-protection laws. Where required, appropriate transfer safeguards should apply.
Children
InstaFile is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided account information, contact us so we can review and delete it where appropriate.
Changes to this policy
If we make material changes, we will update the date at the top of this page and, where appropriate, notify you.
Contact
Questions about privacy? Email us at [email protected].