Privacy
The short version: your images are traced in your own browser and never sent to us. Everything below is the detail behind that sentence.
Your images
Images you convert on this site are decoded by your browser and traced by a WebAssembly module running in a Web Worker in the same tab. They are not uploaded, not stored, not logged and not used to train anything, because they never leave your machine. This is a property of how the product is built rather than a promise about how we behave: there is no upload request to inspect and no bucket to audit.
The public API
The one exception is the public HTTP API at /api/v1/vectorize, which by definition receives the image you send it. Requests there are processed in memory to produce the response and the image is not written to disk or retained afterwards. If that is not acceptable for your material, use the in-browser converter, which sends nothing.
What we store when you buy
Buying Pro creates a licence record holding your email address, the Stripe customer and subscription identifiers, the plan and its status, and the timestamps. There is no user table and no password: the licence is the account. Sign-in works by emailing a single-use link, and those links are stored until they are used or expire.
Payments
Payments are handled by Stripe. Card details are entered on Stripe's own checkout and never touch our servers or this page. Stripe is the processor for that data and its own privacy policy applies to it; we receive the customer and subscription identifiers, the plan, the status and — where tax rules require it — the country and any tax identifier you supply.
Transactional email — sign-in links and billing notices — is sent through Amazon SES. We send no marketing email and there is no mailing list to be added to.
Analytics and consent
Product analytics uses PostHog on its EU cloud, and it is off until you opt in. Nothing is initialised during server rendering, nothing runs if your browser sends a Do-Not-Track signal, and nothing runs before you have granted consent — the three states are 'not asked', 'granted' and 'denied', and only the first shows a banner. Your decision is remembered in this browser's local storage under vt_analytics_consent. If no PostHog key is configured for a deployment, the whole analytics path is a no-op.
Cookies and local storage
A signed session cookie is set when you sign in; it is strictly necessary for the account area and carries no tracking. Your theme choice and your analytics decision are kept in local storage rather than in cookies. PostHog sets its own first-party cookie, and only after you have granted consent.
Hosting and logs
The site runs on a single server in the EU. The web server keeps ordinary access logs — IP address, timestamp, path, status, user agent — for operational and security purposes, on a short rotation. There is no third-party CDN in front of it.
Your rights
You can ask for a copy of the data held about you, ask for it to be corrected, or ask for it to be deleted. Deleting a licence ends the subscription. Write to hello@vectortrace.app and say what you want; we will answer within the statutory period. You also have the right to complain to a supervisory authority — ours is the Data State Inspectorate of the Republic of Latvia (Datu valsts inspekcija), and you may complain to the authority where you live instead.
Who is responsible
The controller for this processing is SIA DEVINTRY, Lacplesa iela 23-14, Jelgava, LV-3002, Latvia, reachable at hello@vectortrace.app. VAT identification number LV43603092074.