Sevio

Privacy Policy

Last updated: June 27, 2026

This Privacy Policy explains how Sevio ("we", "us") collects, uses, and shares information when you use sevio.tech and our image processing services (the "Service").

1.1 Account information

When you register or sign in, we store:

  • Email address
  • Password — stored only in a secure hashed form using modern industry security practices; we never store it in plaintext. (Accounts created via Google may have no password at all.)
  • First name (required) and last name (optional)
  • Email verification status
  • Account role and account timestamps (created / updated)
  • Pending email address temporarily, while you are changing your email

1.2 Sign in with Google

If you choose "Sign in with Google", the Google Identity Services script is loaded in your browser directly from Google, and Google may set its own cookies in that context under Google's privacy policy. We then validate the resulting Google ID token on our server and read only the following fields from your Google profile:

  • Google account identifier (`sub`)
  • Email address and its verification status
  • First name and last name

We do not request access to any other Google data (Drive, Gmail, Calendar, contacts, etc.). We do not post anything to your Google account.

1.3 Sessions, devices, and security data

For each active session we store:

  • IP address
  • Browser / device user agent
  • A human-readable device label (e.g. "Chrome 119 on macOS") derived from the user agent
  • Session activity timestamps (created, last active, revoked)
  • Hashed authentication tokens (refresh and verification tokens are stored only as hashes)

You can review your active sessions and devices, and you may be notified by email when we detect a sign-in from a new or unfamiliar device. For that security alert we also read the two-letter country code of the sign-in from our network provider; this country is used only in the notification and is not stored.

1.4 Files you upload

To use the image tools, you provide images (JPEG, PNG, WebP, AVIF, GIF, HEIC) to be compressed, converted, or resized.

  • Some optimizations run entirely in your browser. For smaller JPEG and WebP files, the compression is performed locally on your device and the file is never uploaded to our servers.
  • When in-browser processing is not possible (e.g. PNG, AVIF, strict size targets, or large files), the image is uploaded to our servers for processing.

For files we process server-side, we read only the technical metadata needed for processing (format, dimensions, EXIF orientation). We do not use your uploaded images for advertising profiling or to train models, and we do not manually review their contents except where necessary to operate the Service, ensure security, or comply with law.

1.5 Usage analytics

We record technical events about the Service to monitor reliability and performance, including:

  • Event type (registration completed, Google sign-in, job started / completed / failed)
  • Operation type (compress / convert / resize)
  • Input and output file sizes and formats, and processing duration
  • Error category and a truncated error message when a job fails

These events are linked to your account. When you are signed in, each event is stored with your user identifier. Activity metrics such as daily/monthly active users (DAU/MAU) are computed directly from these per-user event records — they are not derived from anonymized or pre-aggregated data. Events generated by guests are not linked to an account identifier.

If you delete your account, your existing event records are dissociated from your account (the user identifier is removed), but the event records themselves are retained.

The events above are first-party and stored in our own database. In addition, our website uses Google Analytics 4 (provided by Google) to understand aggregate usage and improve the Service. Google Analytics runs under Consent Mode: it sets analytics cookies and collects data only after you opt in via the cookie banner. Until you accept — and if you decline — analytics storage stays disabled and no analytics cookies are set. You can withdraw your consent at any time from the “Cookies” link in the footer. Google acts as our processor for this data (see Google's privacy policy).

With your separate consent, we also use Google Ads to measure the effectiveness of our advertising (conversion tracking) — for example, to attribute a credit purchase to an ad. This runs under the same Consent Mode: advertising cookies and identifiers are used only after you opt in to the *Advertising* category in the cookie banner, and you can withdraw consent at any time. We do not use session-replay scripts.

1.6 Guests (anonymous use)

If you use the Service without an account, we may use technical identifiers to enforce usage limits and prevent abuse. We do not store your raw IP address for this purpose.

1.7 Cookies and local storage

We use the following first-party cookies:

CookiePurposeReadable by JavaScript
accessTokenAuthentication (access token)No (HttpOnly)
refreshTokenKeeps you signed in / session rotationNo (HttpOnly)
csrfTokenCross-site request forgery protectionYes
isLoggedIn"Session active" flag for the app UIYes

The cookies above are strictly necessary for authentication and security. They use `SameSite=Lax` and are marked `Secure` in production.

With your consent (see Section 1.5), Google Analytics also sets analytics cookies — typically `_ga` and `_ga_*` — to measure aggregate usage, and Google Ads may set advertising cookies to measure ad conversions. Neither category is set unless you opt in to it via the cookie banner, and you can withdraw consent at any time.

In addition to cookies, our website stores small amounts of data in your browser's local storage and session storage for functionality only: your cookie/analytics consent choice (so we apply it and don't ask again); short-lived interface state (e.g. a flag to re-open the sign-in dialog after a redirect), which is cleared automatically; and, after a server-side job, the file names and temporary download links of your most recent results, kept so they survive a page reload. This last entry stays only in your browser and is removed automatically after about one hour.

When you sign in with Google, Google's own script may additionally set cookies under Google's control (see Section 1.2).

1.8 Payments and billing data

Purchases are processed by Paddle.com as Merchant of Record. When you buy credits, Paddle collects and processes your payment and billing information (e.g. name, email, billing address, card data). Sevio does not receive or store your card details. We receive only a transaction reference and the email/identifier needed to credit your account. See Paddle's Privacy Notice for how they handle your data. See also our Refund Policy.

1.9 Reviews you submit

If you submit a review, the author name shown on your account, your rating, and the review text are published publicly on the Service after moderation. Do not include information you are not comfortable making public, or other people's personal data.

If you delete your account, your reviews are not deleted but anonymized — the author name is replaced with "Anonymous" and the review is detached from your account, while the rating and text remain visible and continue to count toward aggregate ratings.

2. How We Use Information

  • To provide and operate the Service (process your images, manage your account and sessions)
  • To authenticate you and keep your account secure
  • To enforce usage limits and prevent abuse (rate limiting, brute-force lockout)
  • To send transactional emails (see Section 5)
  • To monitor, maintain, and improve reliability and performance, including through usage analytics

We do not sell your personal data.

3. How Long We Keep Data

  • Files processed on our servers are typically deleted automatically within about one hour of processing — input files shortly after processing, and output files together with their download links (presigned URLs) usually about one hour after they are created. Files optimized in your browser are never uploaded. Please download your results promptly.
  • Account data is retained while your account exists.
  • Sessions / refresh tokens expire on rotation; refresh tokens have a 7-day lifetime.
  • Usage analytics events are linked to your account via your user identifier and are therefore personal data. They are currently retained without a fixed deletion schedule. On account deletion, the user identifier on these events is removed, but the event records remain.
  • Google Analytics data (collected only with your consent) is retained by Google according to our Google Analytics retention settings and Google's own policies.
  • Google Ads data (collected only with your consent) is retained by Google according to Google's own policies.

4. Service Providers (Sub-processors)

We share data with the following providers strictly to operate the Service:

ProviderPurposeData shared
GoogleSign in with GoogleGoogle ID token → email and basic profile; Google script runs in your browser
Google Analytics (Google)Usage analytics — only with your consentPseudonymous usage events, cookie identifiers, IP-derived approximate location
Google Ads (Google)Advertising performance / conversion tracking — only with your consentPseudonymous conversion events, cookie identifiers
Cloudflare R2Temporary file storageUploaded/processed images (kept ≤ ~1 hour)
Cloudflare (network/CDN)Traffic proxying, real client IP and countryIP address, two-letter country code
ResendTransactional email deliveryRecipient email address, email content
Fly.io, Inc. (Frankfurt, EU)Backend application hosting; queues, quotas, rate limiting (self-hosted Redis)Account and related data processed by the backend; hashed identifiers and counters
Neon, Inc. (PostgreSQL)Application databaseAccount and related data
Paddle.com Market Ltd (Merchant of Record)Payment processing, billing, taxes, refundsName, email, billing address, card/payment data (collected by Paddle; we receive only a transaction reference and status)

Beyond the providers listed above, Sevio may link to or integrate with websites and services that we do not own or control. We do not control or manage such third-party services and recommend that you review their own privacy policies.

5. Transactional Emails

We send service emails via Resend, including: email verification, password reset, email-change confirmation, and security notifications (e.g. sign-in from a new device, session termination). These emails may reference your email address and, for security notifications, the relevant sign-in IP address, device, and approximate country. We do not send marketing email unless you opt in.

6. Security

We apply modern technical and organizational measures to protect your data. Passwords are stored only in a secure hashed form, authentication tokens are kept in HttpOnly cookies and never stored in plaintext, and we apply rate limiting and other safeguards against abuse.

You are responsible for keeping your account credentials confidential. If your credentials are lost, shared, or handled carelessly, third parties may gain unauthorized access to your account and data; we are not liable for losses resulting from such access.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your Rights

Depending on your jurisdiction (e.g. GDPR / CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing.

You can update your name and email in your profile settings, and you can delete your account yourself at any time directly from your profile. You can also request deletion of your account or an export of your data by contacting us at support@sevio.tech

8. Children

The Service is not intended for use by children under 13, and we do not knowingly collect their data.

9. International Transfers

Some of our service providers may process data outside your country of residence. We take reasonable steps to ensure an appropriate level of protection for such transfers.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

11. Contact

Questions or requests: support@sevio.tech