Privacy Policy

Last updated: 2026-08-05

This policy explains what SVGized collects, why, and what happens to it. The service is operated by AKIO LLC, 2800 E. Enterprise Ave, Ste 333, Appleton, WI 54913, United States, which is the data controller. You can reach us at info@svgized.com.

The short version: we do not store the images you upload, we do not run analytics, and we do not track you across the web.

1. Your uploaded images are not stored

This is the most important thing on this page, so it comes first. When you convert an image, the file is received, held in memory, processed, and returned as vector output. It is never written to disk and never kept after the request finishes.

There is no history feature and no archive. We cannot look at your files, and we cannot recover them for you later. If you upload a customer's logo, that logo does not persist anywhere on our side.

2. We do not train anything on your images

We do not use your uploaded images, or the vector output produced from them, to train, fine-tune, evaluate or benchmark any machine learning model. We do not sell them, license them, or pass them to anyone else for that purpose.

This is not only a promise. It is a consequence of how the service is built: the images are never stored, so there is no dataset to train on, and the conversion engine is a deterministic tracing algorithm rather than a learned model. There is nothing for your artwork to teach it.

3. What we do collect

  • Email address — only if you create an account. It is how you sign in and how we contact you about your account.
  • Account identifier and sign-in timestamps, held by our authentication provider.
  • Subscription status — which plan you are on, whether it is active, and when the current period ends. Card details never reach us; see “Payments” below.
  • Usage counters — the number of distinct images converted, so quotas and rate limits can be applied.
  • A hashed form of your IP address — see “IP addresses are hashed, not stored” below.
  • Server logs kept by our hosting provider, which include IP address and request metadata.

4. IP addresses are hashed, not stored

Anonymous visitors need some identifier so that quotas and abuse protection can work at all. We do not keep the raw IP address for this. It is combined with a secret server-side value and hashed; only the hash is stored, and it cannot be reversed back into an address.

Your hosting provider's request logs are separate from this and do contain IP addresses for a limited period; that is standard operational logging and is used for security and debugging, not for profiling.

5. Cookies

We use one kind of cookie: the session cookie that keeps you signed in. It is strictly necessary for the service to work and is not used for advertising or measurement.

There is no analytics, no tag manager, no advertising pixel and no third-party tracking script anywhere on this site. That is why you are not seeing a cookie banner — there is nothing optional to consent to. If that ever changes, this page changes with it and consent will be asked for properly.

6. Payments

Paddle.com Market Ltd handles all payments as merchant of record. Your card details go to them, not to us; we never see or store a card number.

They provide us with what we need to give you access: an identifier for your subscription, its status and its renewal date. Their own privacy policy covers the billing data they hold, including the billing address and tax information they need in order to invoice you correctly.

7. Who else processes your data

We use a small number of providers to run the service. Each one only receives what it needs:

  • Google Cloud (Cloud Run) — hosting and application logs. Servers are located in the United States.
  • Supabase — authentication and the application database: your email address, account identifier and subscription status.
  • Resend — delivery of sign-in emails. Receives your email address and the contents of that email.
  • Google — only if you choose to sign in with a Google account.
  • Paddle.com Market Ltd — payments and invoicing, as described above.

8. International transfers

The service is hosted in the United States, so if you are in the European Union, the United Kingdom or elsewhere outside the US, your account data is transferred there. Where required, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent mechanism agreed with each provider.

9. Legal basis for processing

If the GDPR or UK GDPR applies to you, we rely on the following bases:

  • Performance of a contract — running your account, applying your plan, and delivering conversions you request.
  • Legitimate interests — keeping the service available and preventing abuse, which is why usage counters and hashed IP addresses exist.
  • Legal obligation — retaining records related to payments where the law requires it.

10. How long we keep things

  • Uploaded images: not kept at all.
  • Account data: until you close your account.
  • Usage counters and hashed IP addresses: 12 months, then deleted.
  • Hosting logs: for the retention period set by our hosting provider, typically a matter of weeks.
  • Payment records: kept by Paddle.com Market Ltd for as long as tax and accounting law requires.

11. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, object to processing, or receive a copy in a portable format. Residents of the European Union and the United Kingdom have these rights under the GDPR and UK GDPR; residents of California have comparable rights under the CCPA and CPRA.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

To exercise any of these rights, write to info@svgized.com. Deletion means actual deletion of your account and its associated records, not deactivation. Some information may survive briefly in backups and in payment records that the merchant of record must retain by law.

If you are in the European Union or the United Kingdom and you believe we have handled your data improperly, you may complain to your national data protection authority.

12. Children

The service is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us at info@svgized.com and we will remove it.

13. Security

Traffic to and from the service is encrypted in transit. Access credentials are held in a managed secret store, not in our source code. We do not use passwords: sign-in is by one-time code or by Google, so there is no password of yours for us to lose.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority within the timeframes the law requires.

14. Changes to this policy

The date at the top of this page shows when this policy last changed. If a change materially affects how we handle your data, we will notify account holders by email before it takes effect.

15. Contact

Privacy questions and data requests: info@svgized.com, or AKIO LLC, 2800 E. Enterprise Ave, Ste 333, Appleton, WI 54913, United States.

← Back to the converterTerms of ServiceRefunds and Cancellation