Privacy Policy

Last updated: October 7, 2026

In short: most of gimgs.net works without an account and without tracking. Image requests are served from an edge cache and leave only short-lived technical logs. If you choose to sign in, we store the minimum needed to run your account (your email address, name and username). If you connect Google Drive, we only touch files that you create with gimgs.net. We do not sell personal data, and we do not use advertising or analytics cookies of our own.

1. Who we are and what this policy covers

This policy explains how gimgs.net (“we”, “us”, the “Service”) collects and uses personal data. It covers the website gimgs.net, its sub-domains (including the sign-in service at auth.gimgs.net), its public APIs, the MCP endpoint, and the images delivered from these domains. The Service is operated by the owner of gimgs.net; you can reach us at support@gimgs.net. Our Terms of Service describe what the Service does.

2. Data we collect

2.1 Visiting the site and requesting images

When your browser or application requests a page or an image, our hosting provider (Cloudflare) processes the technical data of that request: the user agent, the requested URL, the referring page, the approximate country, and timing information. We use this data to deliver the content you asked for, to cache it at the edge, to detect and limit abuse, and to keep aggregate statistics (for example the total number of requests per day). We do not build per-user profiles from it.

  • Request logs are kept by Cloudflare for a short period according to its own policy; we only store aggregate counts.
  • The URL you request may itself contain information, such as a ticker symbol, a hostname, or an image URL passed to the thumbnail endpoints. We treat it as the content of the request and cache the resulting image, not the identity of who requested it.
  • When an image is not yet cached, our servers fetch it from its public source (for example favicon providers, logo collections, or stock-media sites). Those requests are made by our servers, not by your browser, so the source sees our server, not you.

2.2 Account (optional)

Signing in is optional and is handled by our sign-in service at auth.gimgs.net. You can sign in with Google or with a username and password.

  • Sign in with Google: we request the basic openid, email and profile scopes and receive your Google account ID, email address, name and, if available, profile picture. We use these to create or find your account and to show your name in the interface. We do not receive your Google password.
  • Username and password: we store your username, email address and a salted hash of your password. We never store the password itself.
  • Session data: when you are signed in we set a session cookie (see section 3) and record sign-in timestamps and roles (such as administrator).

2.3 Profile information you provide

On your profile page you may optionally add a display name, website, short bio, preferred language, newsletter preference, and billing details for invoices (company name, tax ID, address). This information is stored with your account and used only for the purpose you entered it for. You can edit or clear it at any time.

2.4 Google Drive connection (optional)

If you connect Google Drive from your profile, we ask Google for the drive.file permission. This permission only covers files that you create or open with gimgs.net; we cannot see, list, or modify any other file in your Drive. We store the email address of the connected Google account and an encrypted refresh token so that we can save and reopen your files without asking you to sign in again. You can disconnect at any time from your profile page, or from your Google account permissions; disconnecting revokes the token and deletes it from our systems.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not share it with third parties except as needed to provide the feature you requested or as required by law. No human reads your Google data except with your explicit permission, for security purposes, or to comply with the law.

2.5 Icons you contribute

When you submit an icon through the Contribute form or the API, we store the image, the site and identifier it is meant for, the time of submission, and your username if you are signed in. Submissions are rate-limited per visitor to prevent abuse. Approved icons become part of the public catalogue; rejected submissions are deleted.

2.6 Photosoft editor

Images you open, drop, or paste into the Photosoft editor are processed locally in your browser and are not uploaded to our servers, unless you explicitly save a file to a connected Google Drive. Editor preferences are kept in your browser (see section 3). Fonts used in the editor are loaded from Google Fonts, so your browser contacts Google when a font is previewed or used.

2.7 Support messages

If you email us, we keep the message and your email address for as long as needed to handle your request and for a reasonable period afterwards for reference.

3. Cookies and browser storage

We only set cookies that are necessary for the Service to work. We do not use third-party analytics or tracking cookies.

NamePurposeLifetime
langRemembers the language you chose (English, Vietnamese, Portuguese).1 year
gimgs_sessSigned-in session (signed token, HttpOnly, only sent over HTTPS).30 days
gimgs_uFlag telling the page that a session may exist, so it can show your username.30 days
gimgs_rtPage to return to after signing in.10 minutes
lcnet_sessAdministrator session (staff only).Session

The sign-in service at auth.gimgs.net sets its own session cookies during sign-in. Some pages also use your browser's local storage for preferences that never leave your device: the Photosoft workspace layout and recent tools, and the view and filter settings of the crypto card comparison page.

If we display advertising through Google AdSense, Google and its partners may use cookies to show ads based on your visits to this and other sites. You can opt out of personalised advertising in Google Ads Settings and learn more at How Google uses information from sites that use its services. Where required by law, we will ask for your consent before loading such ads.

4. How we use data and on what legal basis

  • Providing the Service (delivering pages and images, running your account, saving your profile, connecting Google Drive): performance of our contract with you.
  • Security, abuse prevention and rate limiting (submission limits, blocking abusive traffic, reviewing contributions): our legitimate interest in keeping the Service safe and available.
  • Aggregate statistics (request counts, popular icons): our legitimate interest in understanding and improving the Service, using data that does not identify you.
  • Newsletter and other optional features: your consent, which you can withdraw at any time.
  • Legal obligations, such as responding to lawful requests or keeping invoice records.

We do not use personal data for automated decision-making with legal effects, and we do not sell or rent it.

5. Who we share data with

  • Cloudflare, Inc. hosts the Service on its global edge network and processes request data and cached images on our behalf.
  • Google LLC provides Sign in with Google, Google Drive, Google Fonts, and possibly Google AdSense. Google acts under its own privacy policy for the services you use directly, such as signing in or granting Drive access.
  • Public image sources (favicon providers, logo collections, stock-media sites) receive requests from our servers when an image is fetched for the first time; the request comes from our server, not from your browser.
  • Affiliate partners: Discover pages contain referral links. If you follow one, the partner's site receives the referral information in the link (such as a campaign tag) and applies its own privacy policy. We receive aggregate referral statistics, not your identity.
  • Authorities, when required by law or to protect our rights, users, or the public.

6. International transfers

The Service runs on Cloudflare's edge network, so your requests are handled at the data centre closest to you. Our databases, including account data, are stored on the cloud infrastructure of our hosting partners, which may be located outside your country. These partners offer standard contractual safeguards for international transfers.

7. How long we keep data

  • Technical request logs: short-term, according to Cloudflare's retention; aggregate counts without personal data may be kept indefinitely.
  • Cached images: until their cache lifetime expires or they are removed on request.
  • Account and profile data: for as long as your account exists. When you delete your account it is deactivated immediately and removed from our systems afterwards, except for records we must keep by law (such as invoices).
  • Google Drive tokens: until you disconnect Drive or delete your account.
  • Contributions: approved icons remain in the catalogue; rejected files are deleted; submission records are kept for abuse prevention and removed on request.

8. Your rights

Depending on where you live (for example under the GDPR in the European Economic Area and the United Kingdom, or the CCPA in California), you may have the right to access, correct, export, or delete your personal data, to restrict or object to its processing, and to withdraw consent. You can:

  • edit or clear your profile information on your profile page;
  • disconnect Google Drive from your profile page or your Google account permissions;
  • delete your account from your profile page, or by emailing us;
  • email support@gimgs.net for any other request. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority. We will not discriminate against you for exercising your rights.

9. Security

All traffic to the Service is encrypted with HTTPS. Session cookies are signed, HttpOnly, and only sent over secure connections. Passwords are stored as salted hashes, and Google Drive refresh tokens are encrypted at rest. Access to account data is limited to the operator and to the automated systems that need it. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; if we become aware of a breach affecting your data we will notify you as required by law.

10. Children

The Service is not directed at children under 13 (or under 16 where a higher age applies), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. The current version is always available at gimgs.net/privacy, with the date of the last update shown at the top. For significant changes we will give notice on the site or by email if you have an account.

This policy is published in English, Vietnamese, and Portuguese. Translations are provided for convenience only; if there is any inconsistency, the English version prevails.

12. Contact

Questions or requests about privacy: support@gimgs.net.