Data Protection & Confidentiality

Privacy Policy

Last Updated: September 28, 2026

Our Uncompromising Privacy Guarantee: Zero Image Storage

When you upload an image to Remove Backgrounds Online:

  • 100% In-Memory RAM Processing: Your picture is decoded in temporary volatile RAM, processed automatically, and converted into a transparent PNG.
  • No Disk Writing: Your image files are never saved to hard drives, cloud buckets, or file systems.
  • Zero Image Retention: We never store, archive, or retain your photographs or resulting cutouts.
  • Immediate Memory Purge: Once the processed PNG stream is transmitted back to your browser, all memory buffers holding your image are immediately discarded.

1. Introduction

This Privacy Policy explains how Remove Backgrounds Online ("we", "us", or "our") collects, uses, and safeguards information when you visit https://removebackgrounds.online.

We believe privacy is a fundamental human right. Our architecture is deliberately designed so that we collect only the bare minimum data required to authenticate users and operate the service.

2. Information We Collect

We collect information in the following categories:

Account Information (Registered Users Only)

When you sign in using Google OAuth or email credentials via Firebase Authentication, we receive:

  • Your Google account email address and unique User ID (UID).
  • Your public profile display name and profile picture URL (if provided by Google).
  • Account creation timestamp and processed image counter stored in Cloud Firestore.

Uploaded Image Data (Ephemeral Only)

Image files (JPG, PNG, WEBP) uploaded for background removal are held temporarily in volatile memory (RAM) solely for the runtime duration of the background segmentation algorithm. They are never written to persistent storage or linked to your personal identity.

Technical & Log Data

Standard web server logs may temporarily record anonymous technical metrics including IP address, browser type, referral headers, and HTTP response codes. These logs are used solely for DDoS mitigation, rate-limiting enforcement, and server health monitoring.

3. How We Use Your Information

We use collected information exclusively to:

  • Authenticate your identity when signing in via Google OAuth or email.
  • Record your total processed image counter and maintain your account profile.
  • Execute the requested background removal transformation in real time.
  • Prevent automated bot abuse, fraud, and Denial of Service (DoS) attacks.
  • Provide customer support when you reach out to our team.

We never sell, rent, monetize, or trade your personal information or uploaded images to third parties, advertisers, or data brokers.

4. Third-Party Service Providers

We rely on vetted infrastructure providers to deliver our services securely:

  • Google Firebase Authentication & Firestore: Handles secure authentication, OAuth sign-in, and user profile records under Google Cloud Enterprise security standards.
  • Cloud Hosting Infrastructure: Houses our self-hosted Docker containers and processing services behind encrypted Nginx reverse proxies with SSL/TLS (Let's Encrypt).

5. Cookies & Local Storage

We do not use invasive tracking cookies or third-party marketing beacons.

We utilize essential browser local storage and session tokens strictly to keep you signed in, remember your interface preferences, and maintain offline fallback testing mode. You can clear cookies and local storage at any time via your browser settings.

6. Your Rights (GDPR & CCPA Compliance)

Depending on your location, you possess privacy rights under the European General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA):

  • Right to Access: You can request a summary of personal information we hold about you.
  • Right to Rectification: You can request corrections to any inaccurate account details.
  • Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your account and Firestore user document.
  • Right to Data Portability: You may request an export of your account metadata in a portable JSON format.

To exercise any of these rights, email us directly at privacy@removebackgrounds.online.

7. Data Security Measures

We employ strict industry-standard technical measures to safeguard your data:

  • All web traffic between your browser and our servers is secured using modern TLS 1.3 / HTTPS encryption.
  • Image processing microservices operate in sandboxed, non-privileged Docker container runtimes.
  • Database access rules enforce strict user-only read/write permissions via Firebase Security Rules.

8. Children's Privacy

Remove Backgrounds Online is not directed toward children under 13 years of age (or 16 in the EEA). We do not knowingly collect personal identifiable information from children. If you become aware that a child has provided us with personal data, please contact us immediately for account termination and data purge.

9. Contact Our Data Protection Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or our zero-retention data practices, please contact us: