Privacy policy
Written to satisfy Articles 13 and 14 of the GDPR
Your photos never leave your computer
The conversion happens entirely inside your browser. Your image files are never sent to our servers or to anyone else, not during the conversion and not after it.
So we store no images and we cannot look at them. The same goes for the location a photo was taken in, which is sometimes stored inside the file: we never see it, and we deliberately do not copy it into the JPG we hand back to you.
Close the browser tab and the copy in memory is gone too.
Who is responsible
ALBR LLC, 169 Madison Ave Ste 11534 Unit 398, New York, NY 10016, USA.
For anything about your data: fotoheic@gmail.com
We have not appointed a data protection officer; we do not meet the thresholds that would require one.
What we collect
Email address: for your account and for the subscription notices we are legally required to send you.
Subscription details: when you signed up, which plan, and when you cancelled. We need these to know whether your access is live.
Payment details: handled only by the payment provider. We never see card numbers or bank details; we only get told whether a payment succeeded.
Server logs: IP address, time of the request, the page requested and the browser used. These are produced automatically on every visit and exist to stop abuse.
Our legal grounds
Account and subscription — Article 6(1)(b) GDPR: we need this to perform the contract you entered into with us.
Invoices and accounting records — Article 6(1)(c): we are legally required to keep them.
Server logs — Article 6(1)(f): our legitimate interest in running the service safely. They are kept briefly and are not linked to your account.
Mandatory subscription notices (confirmation, invoice, notice of the first charge) — Articles 6(1)(b) and 6(1)(c). These are not marketing and cannot be unsubscribed from while the contract is running. We send you no other email.
How long we keep it
Images: not at all. They never reach us.
Account email and subscription details: for as long as the contract runs, and three years after it ends.
Invoices and accounting records: ten years, because tax law requires it.
Server logs: seven days, then deleted automatically.
Who else touches your data
Hosting: Vercel Inc. It serves the pages and produces the server logs described above, under a data processing agreement (Article 28 GDPR).
Payments: Lemon Squeezy, Inc. It sells in its own name and is an independent controller for payment data.
Sending the mandatory emails: through a provider under a data processing agreement.
We use no analytics, tracking or advertising services. There is no Google Analytics on this site, no Meta pixel, and no fonts loaded from anyone else’s servers.
We do not sell data. Ever.
Data leaving the European Union
We are a United States company and our providers are there too. Your account email and the server logs are therefore transferred to the United States.
The basis for that transfer is the European Commission’s adequacy decision on the EU-US Data Privacy Framework and, where that does not apply, standard contractual clauses under Article 46(2)(c) GDPR.
You should know that US authorities can in some circumstances demand access to data held there. Your photos are outside all of this, because they never leave your computer.
Cookies
We set two cookies and both are strictly necessary: one remembers the language you chose, the other keeps you signed in.
Strictly necessary cookies do not require consent.
On your first visit we show a notice at the bottom of the screen with two equally weighted buttons: “Accept all” and “Necessary only”. Declining is exactly as easy as accepting — both buttons look the same and sit side by side.
Only if you accept do we load audience measurement from Google (Google Tag Manager, Google Analytics). If you decline, or decide nothing, that script is never added to the page at all — so it cannot store anything either.
You can change your choice any time under “Cookie settings” in the footer.
No automated decisions
We make no automated decisions and do no profiling within the meaning of Article 22 GDPR.
Your rights
You have the right to access your data (Article 15), correct it (16), have it deleted (17), restrict how we use it (18), take it with you (20) and object to its use (21).
To use any of these, write to fotoheic@gmail.com. We reply within the legal limit of one month. No forms, no ID document — a message from the address you signed up with is enough.
You can also complain to a data protection authority, normally the one where you live. We would rather you told us first, but that is your right and you do not have to come to us first.
If you live in California, the same requests cover your rights under state law. We do not sell or share personal information, so there is nothing for you to opt out of.