GIMPBot

Privacy Policy

Effective 27 August 2026.

The short version

We store your email address, a hash of your token, and a record of each request: how many tokens it used, what it cost, when it happened and which GIMP version you were on. We do not store your images, your prompts, or the code the model generates. There is no analytics product on this site and nothing here profiles you for advertising; the cookies that do exist are described below.

What we hold, and why

DataWhy
Email addressIdentifies the account and receives sign-in links
Token hashAuthenticates the plug-in. We store only a hash, so we cannot read your token or use it
IP address at signupRate-limiting signups. Not recorded for ordinary chats
Per-request usageToken counts, cost, status, timestamp, GIMP version. This is how credits are counted and how we know what the service costs to run
PurchasesWhat you bought and when, so balances can be explained and refunds handled
DownloadsThat a download happened, which version, which operating system and which country. Not tied to you: no address is recorded and nothing links a download to an account
InstallsHow the installer finished — installed, or why not — with the version, operating system, country and which GIMP series it installed into. This is how we tell a broken installer from one that worked. Same as downloads: no address, no path, no machine name, and nothing links it to an account. Set GIMPBOT_NO_TELEMETRY=1 before running the installer to send nothing

What goes to the model

To answer a request, we send OpenAI your message and a downscaled preview image of the canvas you have open, so the model can see what you are describing. This is necessary for the product to work.

OpenAI processes it to generate the response. Under their API terms, content sent through the API is not used to train their models. We do not keep a copy of either the image or the message once the request completes.

Each request carries an opaque identifier derived from your account so that abuse can be attributed to one user rather than to the whole service. It is a salted hash and does not contain your email address.

Cookies and advertising

Signing in sets one cookie, which keeps you signed in. It is not used for anything else and it is not shared.

The site also loads Google’s advertising tag. Its only job here is to tell us whether an ad we paid for led to a purchase, so that we know which advertising is worth buying. It does not see your images or anything you type into GIMP — the plug-in never loads it, and it exists only on this website.

If you are in the EEA, the UK or Switzerland, that tag is configured to store nothing. It sets no cookie and Google receives no identifier for you, so we see an estimate rather than a count. That is the default and there is nothing for you to click: we would rather measure less than put a consent banner in front of you.

Payments

Polar processes payments as merchant of record. They receive whatever you give them at checkout. We receive a record that a purchase happened, for what, and for how much. We never see card details.

Email

Sign-in links are sent through Cloudflare's email service. We send no marketing email.

How long we keep it

Account and purchase records are kept while the account exists, and afterwards only as long as needed for accounting. Sign-in links expire in 15 minutes. Usage records are kept to understand costs and are not tied to the content of any request.

Your rights

Email hello@gimpbot.com to get a copy of what we hold about you, correct it, or have your account and data deleted. If you are in the UK or EU, you have these rights under the GDPR and can complain to your data protection authority.

Who holds this data

Z Industries, LLC is the data controller for the information described above. Email hello@gimpbot.com with any question about it, including a request to delete it.