What we process, why, and for how long. Last updated 2026-09-05.
We run no analytics, no advertising and no tracking. Normal page and file requests are not written to an access log with IP addresses. Uploaded files are encrypted and we do not hold the key.
This is a translation for convenience. The German version is the legally binding one, and it prevails if the two ever disagree.
The controller within the meaning of the GDPR is:
imageserver.pw – Leon Schmidt
c/o Online-Impressum.de #1158
Europaring 90
53757 Sankt Augustin
Germany
Email: [email protected]. Further details are in the Impressum.
No data protection officer has been appointed, because the conditions in section 38 BDSG are not met. Please send privacy enquiries to the address above.
As a data subject you have the right
While signed in you can exercise the rights of access and portability yourself at any time, see section 19.
Starting with what does not happen, because it puts the rest of this document in context:
To send you a page at all, we process the connection data your browser transmits, in particular your IP address. That happens transiently, to answer the request.
We also limit how many requests are allowed in a given period, to prevent abuse. A counter is kept in memory for that, tied to your user key or, where there is none, to your shortened IP address. This counter is not stored permanently and expires after a minute.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the service.
There are two ways to create an account, and they can be linked afterwards.
Through Discord. We request the
identify and
guilds
scopes, which gives us your Discord ID, your username, your avatar and the list of your
servers. We use the server list solely to check whether you are a member of our Discord
server and to determine your boost status. We do not store the list. We do keep a refresh
token so that this check remains possible without signing in again. The provider is Discord
Netherlands B.V., Amsterdam.
With email and password. In that case we store your email address and a hash of your password. The password itself is not stored and is not readable by us.
In both cases we additionally create a display name, your personal API key, your settings, your plan, and timestamps for creation and modification.
The legal basis is Art. 6(1)(b) GDPR, since the processing is necessary to perform the user agreement.
You may secure your account further, at your option. For an authenticator app we store the corresponding secret in encrypted form, for a passkey the public credential identifier, a counter and a name you choose. Recovery codes are stored as hashes only.
The legal basis is Art. 6(1)(b) GDPR together with Art. 32 GDPR, which is the obligation to take appropriate security measures.
Every uploaded file is encrypted with AES-256 before it is written to disk. The key generated for it is not stored on our side, it sits in the link you receive. The stored files are therefore unreadable to us, and we cannot restore them either.
Alongside the encrypted file we store, for each upload:
Uploads made without an account are deleted automatically once they are seven days old. Uploads made with an account remain until you delete them or your account.
The legal basis is Art. 6(1)(b) GDPR. If you upload files showing other people, you are the controller for that.
For a short link we store the destination, the code, the domain used, the deletion key, the link to your account and the creation date.
When it is opened we increment a counter and note the time of the last visit. No record is
created per visitor, and no IP address or referrer is stored. On redirect we also set
Referrer-Policy: no-referrer,
so the destination does not learn where the visitor came from.
The legal basis is Art. 6(1)(b) GDPR.
If you create a BioLink page, we store the content you enter, such as display name, description, links, images and styling settings.
That page is explicitly public and can be opened by anyone who has its address. Everything you put there, you publish yourself. The legal basis is Art. 6(1)(b) GDPR.
If you connect a domain of your own, we store the domain name, its validation status and the link to your account. For setup and the certificate we transmit the domain name to Cloudflare, see section 16.
The legal basis is Art. 6(1)(b) GDPR.
We only send messages that the service requires: confirming your email address and resetting your password. There is no newsletter and no promotional mail.
Sending runs over a mail server we operate ourselves. No external provider is involved. The tokens belonging to a confirmation or a reset are stored as hashes only and expire quickly.
The legal basis is Art. 6(1)(b) GDPR.
Paid plans are handled through Tebex. Tebex acts as the merchant of record for the purchase and processes your payment data under its own responsibility, so its privacy policy applies to that part.
Payment details such as card or account data never reach us. When a checkout starts we transmit your account identifier, the chosen plan and your IP address to Tebex, the latter for fraud prevention and to determine tax. What we receive back and store is a reference to the subscription, its status and the end of the current period.
The legal basis is Art. 6(1)(b) GDPR, and for retaining records additionally Art. 6(1)(c) GDPR together with the commercial and tax retention periods.
A bot runs on our Discord server which assigns a role to signed-in members and determines how many boosts you contribute. We store the number of boosts together with the time of the last check, because it translates into extra storage and a higher upload limit.
The legal basis is Art. 6(1)(b) GDPR. If you use our Discord server, Discord's own privacy policy applies to that as well.
Reports. If you report a file through the report button, we store the reason given and the reference to the file. No details about the reporting person are recorded. The report is additionally forwarded into an internal Discord channel. If you report by email, we process what your message contains, as far as it is needed to deal with it.
Aborted uploads. If a transfer breaks off, our operational log keeps a warning containing the IP address, so that repeated failures can be narrowed down.
The legal basis is Art. 6(1)(f) GDPR, and for legal notices additionally Art. 6(1)(c) GDPR. Our legitimate interest is the prevention of abuse.
To protect against attacks and to speed up delivery we use Cloudflare, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA.
Every request to our site passes through Cloudflare. In doing so Cloudflare processes in particular the IP address, information about the browser and device, the address requested and the time of access, and it may set a cookie to detect malicious traffic. Suspicious requests can be blocked or challenged. We also transmit domain names when you connect a custom domain.
The legal basis is Art. 6(1)(f) GDPR, our legitimate interest being secure and available operation. The transfer to the USA is based on the European Commission's standard contractual clauses; Cloudflare is additionally certified under the EU-US Data Privacy Framework.
More at cloudflare.com/privacypolicy.
Our servers are located in Germany and operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen. Hetzner processes the data arising there as a processor on our behalf, under a contract pursuant to Art. 28 GDPR.
For troubleshooting we keep an operational log of the application, which we send to a log database we run ourselves. It contains events such as completed uploads and errors that occurred, in individual cases with an account identifier. We do not keep a per-request access log with IP addresses.
We take daily backups of the system. Deleted data may still be contained in them until the backup in question is overwritten. The legal basis is Art. 6(1)(f) GDPR.
| Data | Duration |
|---|---|
| Uploads made without an account | Deleted automatically once they are seven days old |
| Uploads with an account, short links, BioLink page | Until you delete them or your account |
| Account data | Until the account is deleted |
| Confirmation and reset tokens | Until they expire, then deleted |
| Billing records | For the statutory retention periods, up to ten years |
| Backups | Until the backup in question is overwritten |
While signed in you can trigger a full export of the data we hold about you. That serves your right of access under Art. 15 GDPR and your right to data portability under Art. 20 GDPR directly.
Individual uploads and short links you delete yourself, in the dashboard or through the deletion link that came with them. To have your entire account and everything belonging to it deleted, an informal message to [email protected] is enough.
Excluded is data we are required to retain by law, and copies in backups until those are overwritten.
Last updated: 2026-09-05. Translation for convenience, the German version prevails.