Privacy Policy
Last updated: 20 July 2026
Immaginia (“we”, the “Controller”) respects your privacy. This policy explains what data we process when you use www.immaginia.com and its tools, why, and what rights you have. Questions: info@immaginia.com.
1. Data Controller
The data controller is Web Agency S.r.l.s., which operates the “Immaginia” service, with registered office at Via Roberto Lepetit 19, 00155 Rome (RM), Italy — VAT and Tax Code 16018121000. Contact: info@immaginia.com.
2. What data we collect
Account data: email, display name and password. The password is stored only as an encrypted hash, never in clear text. If you sign in with Google or GitHub, we receive your email, name and profile picture from them.
Content you create: the projects, designs and files you upload, so we can save and show them back to you.
Minimal operational data: technical logs and cookies strictly necessary for authentication and security.
Aggregated, anonymous traffic statistics via Vercel Analytics, with no profiling cookies and without identifying you personally.
3. AI processing runs in your browser
Many of Immaginia’s “magic” features — background removal, Magic Layers, text recognition (OCR), magic eraser — run directly in your browser. The images you work on are NOT sent to our servers for these operations: they stay on your device.
4. Why we process data
To provide the service and the features you request (performance of the contract).
To authenticate you and keep your account secure (legitimate interest and performance of the contract).
For Google/GitHub sign-in and technical cookies, based on your use of the service and your consent.
To prevent abuse, spam and fraudulent activity (legitimate interest).
5. Who we share data with
We do not sell your personal data. We rely on providers that process data on our behalf, only to run the service: hosting (Vercel), database (Neon), file uploads (UploadThing), email delivery (our SMTP provider or Resend), social sign-in (Google, GitHub) and — when you buy a subscription — payments (Stripe Payments Europe, Ltd.). We may disclose data only where required by law or a competent authority.
6. Payments: what goes through Stripe, and what stays with us
When you buy a subscription the payment is handled by Stripe Payments Europe, Ltd., acting as a processor on our behalf and, for its own anti-money-laundering and tax duties, as an independent controller.
Your card details never pass through us and we never see them: Stripe collects them on its own pages. For each purchase we keep only your Stripe customer and subscription identifiers, the plan, the billing period, the renewal date, the payment status and the boxes you ticked before ordering. We need them to give you what you bought, to send the order confirmation and to meet accounting obligations.
The legal basis is performance of the contract (art. 6.1.b GDPR) for what is needed to give you the subscription, and legal obligation (art. 6.1.c) for accounting records, which Italian law requires us to keep for ten years.
Stripe’s policy: https://stripe.com/privacy. If you ask us to delete your account but we hold an invoice in your name, the accounting data stays for the mandatory period: it is the only case in which we cannot delete everything at once.
7. Public content
If you choose to publish a design in the community gallery, that content and your username become publicly visible. You can remove it at any time from your settings.
8. How long we keep it
We keep account data and your projects while your account is active. You can delete individual projects or request account deletion: data is removed, subject to any legal obligations.
9. Your rights (GDPR)
You have the right to access, correct, delete, restrict or object to the processing of your data, and to data portability. To exercise them, write to info@immaginia.com. You may also lodge a complaint with a supervisory authority (in Italy, the Garante per la protezione dei dati personali).
10. Minors
Immaginia is not intended for children under 14. We do not knowingly collect personal data from children.
11. Cookies
Technical cookies, needed for sign-in and sessions, are always there: without them the site cannot recognise you.
Beyond those we use third-party measurement tools — Google Analytics, to understand which pages are actually useful, and the Meta pixel when we run ads. These are profiling cookies and we treat them as such: they are not loaded until you say yes in the banner, and if you do not choose, the answer is no. They do not “load and then switch off”: without your consent those scripts are never even requested.
You can change your mind at any time by clearing this site’s data in your browser: the question comes back on your next visit.
12. International transfers
Some providers may process data outside the EU/EEA, with appropriate safeguards in place (for example the European Commission’s standard contractual clauses).
13. Changes to this policy
We may update this policy over time. The date shown at the top indicates the latest version in force.
Authoritative version: Italian. Other languages are provided for convenience.