Privacy at PicSmash
Your selected images are decoded, resized, and encoded in your browser. Their contents do not go to the PicSmash application server.
Network requests
The browser requests the PicSmash page, JavaScript, fonts, images, and API responses needed to run the site. It also sends small JSON product-event records to PicSmash's first-party analytics endpoint. Google Analytics loads automatically when a Google Analytics measurement ID is configured. Microsoft Clarity is disabled for this application.
What anonymous analytics contains
The current event schema records:
- the page template, event type, and schema version;
- coarse browser and device classes;
- input and output formats, settings preset, and safe failure category;
- bucketed batch count, byte size, and duration;
- conversion success/failure, preview, download, warning, retry, cancellation, and related-link actions;
- exact batch totals used only to increment daily aggregate counts and byte totals.
PicSmash does not collect image contents, filenames, folder names, full local paths, EXIF values, image hashes, or a persistent visitor identifier. Exact per-batch byte totals and durations are not retained in the event log.
Analytics, cookies, and retention
Product analytics is collected automatically and uses no cookies or persistent visitor identifier. Event-level records are retained for 90 days; daily aggregate totals are retained for trend reporting. Google Analytics may set or read its own cookies and processes data under Google's terms and privacy practices.
How to verify local processing
Open your browser's developer tools, select the Network panel, clear it, and convert an image. You can inspect the first-party analytics request body; it contains measurements and categories, never the selected file or its name.
Who operates PicSmash
PicSmash is built and operated by sadeq.dev. Use that site for current creator and contact information.