ZURAPIC
Photo PDF & Documents Design Studio Examples FAQ
Create Login
Privacy Policy Terms of Service Contact

Zurapic / UltraNGX — Privacy Policy

Effective date: September 1, 2026 · Version: 1.0

0. Who We Are

This Privacy Policy explains how Zurapic / UltraNGX ("we", "us") collects, uses, and protects personal data when you use Zurapic and the UltraNGX suite of applications (the "Service"). We are the data controller for the personal data described in this Policy, unless stated otherwise.

For any data-protection matter, or any other question about this Policy, use our Contact page — no account needed to reach us.

1. What Personal Data We Collect

Account data. If you create an account: your email address, a hashed password (never the plain password), and account status (subscription tier, billing state).

Content you upload. Photos, PDFs, and other files you bring into the editor.

Payment data. We do not collect or store card numbers ourselves. Payments are handled entirely by our payment processor (Stripe); we receive only the resulting subscription/transaction status, not your card details.

Feedback you send us. If you use the in-app "Send us a message" form: the message text, an optional reply-to email, and an optional screenshot you choose to attach.

Technical/usage data. IP address, browser/device information, and pages visited, collected via our hosting provider (Cloudflare) for security (e.g. rate-limiting, abuse prevention), and separately via Cloudflare Web Analytics (see §3) for aggregate, cookie-less usage statistics.

2. How We Process Your Content (Photos, PDFs, and Other Files)

Most editing in the Service happens locally in your own browser tab — for those operations, your files are not transmitted to our servers at all.

Most tools in the Service run entirely in your browser. A few specifically send your file (or the relevant part of it) to our servers to be processed and the result returned to you: the Cloud option for AI Background Removal, the Cloud option for AI Object Removal, and server-side export for PDF, SVG, and Sprite Sheet files. (Their "Local" counterparts, where offered, process entirely in your browser instead — nothing is sent anywhere.) We do not use the content of your files to train any AI model, and we do not review, sell, or share your files except as needed to provide the feature you invoked, or as this Policy or the law otherwise requires.

Files sent for this kind of processing are retained only for as long as needed to generate your result, and are deleted automatically shortly afterward — they are not stored long-term or used for any other purpose. Where a third-party AI/cloud infrastructure provider is involved in returning a result, they process the file solely to do so, under confidentiality obligations, and do not retain it afterward.

3. Cookies and Similar Technologies

Strictly necessary cookies only. The Service uses exactly one cookie: a session cookie set when you log in, so the Service knows you’re authenticated. This cookie is essential for the login feature to work and is not used for advertising, analytics, or cross-site tracking.

Analytics. We use Cloudflare Web Analytics, which does not use cookies and does not collect any data that identifies you individually. We do not use Google Analytics or any other analytics product.

We do not use advertising cookies or any third-party ad-tracking pixels of any kind.

4. Legal Basis for Processing (GDPR)

  • Account data, Content, and Payment data: processing is necessary to perform our contract with you (providing the Service you signed up for) — GDPR Art. 6(1)(b).
  • Technical/security data: our legitimate interest in keeping the Service secure and operating correctly — GDPR Art. 6(1)(f).
  • Feedback you voluntarily submit: your consent, given by submitting the form — GDPR Art. 6(1)(a).
  • Any legally required retention (e.g. for tax/accounting records of payments): compliance with a legal obligation — GDPR Art. 6(1)(c).

5. Who We Share Data With

We do not sell your personal data. We share it only with service providers who process it on our behalf, under a data-processing agreement, and only to the extent needed to provide the Service:

  • Stripe — payment processing.
  • Cloudflare — hosting, database, security/rate-limiting, web analytics, and the infrastructure behind our server-side/Cloud-assisted tools.
  • Resend — transactional email (e.g. password-reset links, feedback notifications).

We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Zurapic / UltraNGX, our users, or others — including under the Monitoring & Enforcement Technology provision described in our Terms of Service.

6. International Data Transfers

Some of our service providers (see §5) may process data outside the European Economic Area, including in the United States. Where this happens, we rely on an approved transfer mechanism — such as the EU Standard Contractual Clauses, or the provider’s own EU-US Data Privacy Framework certification where applicable.

7. Data Retention

  • Account data: kept for as long as your account is active, and for a limited period after deletion to allow recovery from an accidental deletion, then permanently erased.
  • Autosave: your in-progress project autosave is stored only in your own browser’s local storage — never on our servers.
  • Feedback submissions (including any attached screenshot): kept for a reasonable period to allow us to follow up, then deleted.
  • Payment/billing records: kept for as long as required by applicable Greek/EU tax and accounting law (typically several years), even after account deletion.

8. Your Rights

If you are located in the EU/EEA (or another jurisdiction with similar rights), you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), subject to our legitimate retention needs described in §7.
  • Restrict or object to certain processing.
  • Receive your data in a portable format, where technically feasible.
  • Withdraw consent at any time, where processing is based on consent (this does not affect processing carried out before withdrawal).
  • Lodge a complaint with a supervisory authority — in Greece, the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, www.dpa.gr), or the authority in your own EU member state.

To exercise any of these rights, contact us via our Contact page. We will respond within the timeframe required by applicable law (generally one month under GDPR).

9. Data Security

We use technical and organizational measures appropriate to the risk — including encryption in transit (HTTPS), hashed password storage, and access controls — to protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Children’s Privacy

The Service is not directed at, and we do not knowingly collect personal data from, anyone under the age of 18 (or the age of legal majority in their jurisdiction), consistent with the eligibility requirement in §2 of our Terms of Service. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes (e.g. by email or an in-app notice) before they take effect. The "Effective date" above reflects the version currently in force.

12. Contact

Questions about this Privacy Policy, or anything else: use our Contact page. No account needed.

PricingPrivacy PolicyTerms of ServiceContact
ZURAPIC
© ZURAPIC. Photo, PDF & Design — in one tab. Created by ultrangx.com