About this notice

This notice covers Clearcut at clearcut.sh, including the editor and API. Clearcut is provided by chern0.dev, 71000 Sarajevo. Contact support@clearcut.sh about your data or a privacy request. Payment providers also publish their own notices for information they collect directly.

Information we process

When you use the editor or API, we process your images, filenames, editing instructions, optional background prompts, results and request status. An image can contain personal information about you or someone else. Only upload images you have permission to process.

We keep hashed credit-claim records to prevent duplicate free allowances, including after an account is deleted. For accounts, we store your name, email address, session records, API key hashes, credit balance and usage records. If you choose a password, we store its hash. Google sign-in also stores your Google account identifier, profile picture and sign-in tokens. Stored OAuth access and refresh tokens are encrypted. Email sign-in links are stored as hashes and expire after 15 minutes. We also process request information, including IP addresses and browser information, to deliver the service and limit abuse. We derive daily identifiers from IP addresses to enforce free limits.

When you buy credits, we receive order, subscription, refund and customer identifiers from Polar. Your full payment-card details are handled by the payment provider, not stored by Clearcut. If you contact support, we receive the information you include.

Google sign-in and Google user data

Google sign-in is optional. If you choose it, Clearcut requests only your basic identity information: your Google account identifier, name, email address, email verification status and profile picture. We use this information to create or identify your Clearcut account, sign you in, and connect your images, credits and purchases to the correct account. We do not request access to Gmail, Drive, Google Photos or other Google content.

This account information is stored in our Cloudflare-hosted database. Stored OAuth access and refresh tokens are encrypted, and connections to Clearcut use HTTPS. Access to account actions and stored images requires the appropriate session, API key or signed link. If you buy credits, we send your account name and email address to Polar for checkout and billing. Cloudflare processes your email address to deliver account messages. We do not send your Google sign-in tokens to our image-processing providers.

We also send your Clearcut account identifier, name and email address to PostHog to connect product activity and technical problems to your account. This helps us provide customer support and improve Clearcut. This includes those details when you use Google sign-in; we do not send Google access or refresh tokens.

We do not sell Google user data, use it for advertising, or use it to train AI models. Clearcut’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

We retain Google account information while needed to provide your account, subject to the account and billing retention rules below. You can remove Clearcut’s connection from your Google Account connections. Removing that connection does not delete your Clearcut account or billing records. Contact support@clearcut.sh to request deletion of your Clearcut account and associated Google account information. We verify the request and explain any records we must retain.

How we use this information

We use images and instructions to perform the edits you request. Account and billing records let us authenticate you, apply credits, provide receipts and resolve payment problems. We use technical records to investigate failures, prevent fraud and enforce limits. We do not use your images to train Clearcut models or publish them as promotional examples.

Where data-protection law requires a legal basis, service delivery relies on performing our agreement with you; service security and support rely on legitimate interests; required financial records rely on legal obligations. If a feature requires consent, we will ask before using it.

Image expiry and other records

Images in Clearcut expire 60 minutes after their job is created, for signed-in users and guests alike. Access stops at expiry, and background cleanup removes the stored files. Deletion may take additional time if cleanup is retrying. Download finished images before they expire. We do not provide long-term image storage or recovery.

Small job and usage records, including filenames and credit costs, are kept for about seven days. Daily allowance records are cleaned up after eight days. Browser editing data is cleared as expired jobs are reconciled when the editor runs; closing the browser can delay local cleanup. You can remove it through your browser’s site-data controls.

Account and billing records have separate lifetimes. They remain while needed to provide your account, maintain the credit ledger, resolve disputes and meet applicable record-keeping obligations. Image expiry does not delete these records. Service-provider logs and backups follow their own retention rules.

Services that process data

Cloudflare hosts the website, account database and temporary image storage, and handles transactional email and email forwarding. Modal runs background removal, Smart Brush and image processing. Modal’s retention notice states that function inputs and outputs may remain for up to seven days.

Google provides optional sign-in using your name, email address and profile picture. Clearcut requests no access to your Gmail, Drive or other Google content.

PostHog provides product analytics and error tracking in our EU-hosted PostHog project. It receives page paths, browser and device information, and events such as starting image processing, exporting an image or opening checkout. For signed-in users, these events are linked to your account identifier, name and email so we can investigate support requests. PostHog browser analytics do not send uploaded images, image URLs, filenames, editing prompts, passwords, sign-in tokens or payment-card details. Screen recordings and automatic form or click capture are disabled. We filter query parameters and error messages before sending browser events. Server error reports include the affected job and account identifiers, processing stage, quality mode, timing, error type, code locations and software version. We use them to diagnose failed processing, sign-in, email and billing operations. These reports exclude image contents, prompts, credentials and raw request data.

When you open support chat, Crisp provides messaging and receives your messages, any attachments you choose to send, browser and network information, and a chat session identifier. If you are signed in, we provide your account identifier, name and email so we can find your account and reply. This also applies to accounts created with Google sign-in. The chat loads in a separate support page, without the editor’s image URLs or sign-in parameters. Chat attachments and conversations are support records; they do not follow the editor’s 60-minute image expiry. Contact us to request deletion of support records, subject to records we need to keep for an unresolved issue or legal obligation. See Crisp’s privacy policy.

Datafast provides website traffic and campaign attribution analytics. It receives page addresses with sensitive query parameters removed, referring pages, campaign tags, browser and device information, IP addresses and visitor/session identifiers. Its script uses analytics cookies to connect visits and may detect checkout identifiers for payment attribution. We do not send uploaded images, editing prompts or sign-in tokens to Datafast. See Datafast’s privacy policy.

We also import customer, product, order, subscription and refund records from Polar into PostHog to understand purchases and reconcile billing activity. These records can include customer names, email addresses, billing contact information, customer and transaction identifiers, amounts, currencies, dates and payment or subscription status. This billing import is separate from browser analytics and uses read-only access to Polar. It does not include full payment-card numbers or security codes. PostHog records follow its retention settings; image expiry does not delete analytics records. See PostHog’s privacy policy.

Magic Background sends your prompt and reduced-size reference images to fal. We request no stored input/output JSON and a one-hour lifetime for generated media. These settings do not mean that every provider record is deleted within one hour. See fal’s retention controls and privacy policy.

Polar handles checkout, subscriptions and refunds as merchant of record. See Polar’s privacy policy. Provider infrastructure may process data outside your country, including in the United States. Clearcut does not promise EU-only storage or processing.

Cookies and browser storage

We use essential session cookies to keep you signed in, a signed guest cookie for temporary image ownership, and browser storage for editing state. Sessions are configured for up to 14 days and the guest cookie for up to 30 days; these do not extend image expiry. PostHog uses analytics cookies and browser storage to connect visits and product activity. Its cookie lifetime is configured for 30 days; browser storage can remain until cleared. We respect your browser’s Do Not Track setting for PostHog analytics. Datafast also uses visitor and session cookies for traffic and campaign attribution; these can persist until their expiry or until you clear them. Opening support chat lets Crisp store a session cookie, configured to expire after 30 days of inactivity, and a local account marker used to separate conversations when accounts change. Clearcut does not use advertising trackers. Blocking essential storage can prevent sign-in or recovery of editing state.

Your choices and requests

You can remove an image from the editor and revoke an API key in your account. Contact support@clearcut.sh to request account deletion, access to your data, correction or an export. Depending on applicable law, you may also have rights to object, restrict processing, withdraw consent or complain to a data-protection authority.

We may need to verify ownership before responding. We cannot recover images that have expired. Some billing or security records may need to remain after an account-deletion request; we will explain any applicable exception. Do not send passwords, API keys or sensitive images in a support email.

Changes to this notice

We will update this page when our data practices change. Material changes will be communicated through the service or by email where appropriate.