Last updated: September 7, 2026
PrivaCanvas is designed so that the images you edit stay on your device. Image decoding, face detection, redaction, and export run inside your browser. PrivaCanvas does not upload your images to its application server.
Clearing or closing the page removes the current editing session from browser memory. Downloaded files remain wherever you save them on your device.
PrivaCanvas uses MediaPipe Tasks Vision and a BlazeFace model for automatic face detection. The runtime and model files are downloaded from the PrivaCanvas website, and inference runs on your device.
MediaPipe states that input images are processed on-device and are not sent to Google. Its web library contains code that can send performance and utilization metrics to Google. PrivaCanvas uses Content Security Policy to block that Google metrics endpoint. PrivaCanvas does not enable analytics that send image contents.
See the third-party licenses page for the runtime and model license records.
Like most websites, the hosting and security infrastructure may temporarily process ordinary request information such as IP address, browser type, requested URL, timestamps, and error logs. This information may be used to operate, secure, and troubleshoot the service.
The site may store essential preferences, such as language or appearance, in your browser. The current free editor and batch beta do not require an account or payment information. A future paid version will require a separate policy update before live payment or entitlement data is collected.
PrivaCanvas may use Cloudflare Web Analytics to measure visits and page performance. Its browser beacon reports page views, paths, referring sites, country, device type, browser, operating system, navigation type, page-load timing, and Core Web Vitals. Cloudflare states that this service does not collect or use visitors' personal data, does not track individual visitors across its customers' sites, and does not use cookies or local storage to collect these metrics.
The Web Analytics beacon does not receive images, filenames, face counts, redaction coordinates or modes, OCR text, exported files, or editor actions. Cloudflare Web Analytics does not currently support custom events or log URL query strings, so PrivaCanvas does not use it to reconstruct an individual editing session or advertising profile.
PrivaCanvas separately records aggregate product events with Cloudflare Workers Analytics Engine. The single editor counts whether an image was selected, automatic detection was requested, a redaction was created, and a redacted image was downloaded. The batch beta counts whether files were selected, batch processing was requested, at least one result completed, and a ZIP was downloaded. Each event is counted at most once per current editing or batch session. The event record contains only the event name and count. It does not contain the image, filename, number of files or faces, metadata result, redaction mode or coordinates, OCR text, downloaded file, account identifier, or a persistent visitor identifier. Cloudflare currently retains Workers Analytics Engine data for three months.
Cloudflare retains unsampled beacon data for seven days and then keeps sampled aggregate data; the dashboard currently exposes the previous six months. You may contact us to ask questions or exercise rights available under applicable law.
PrivaCanvas does not sell your personal information. Technical information may be processed by hosting, security, analytics, or infrastructure providers only as needed to operate and improve the website, or disclosed when required by law.
Automatic detection can miss faces or mark the wrong area. Review every result before sharing an image. Do not rely on PrivaCanvas as a guarantee of legal compliance or complete anonymization.
This policy may be updated as the product changes. The date at the top of this page will show the latest revision.
PrivaCanvas is currently operated by an independent developer. For privacy questions, requests, or support, email easton2090@gmail.com.