Photanora

Privacy Policy

Last updated 2 September 2026

This policy explains what Photanora does with personal data, and what rights you have over it. It applies to photanora.com.

Photanora is the controller of your personal data. You can reach us at [email protected].

1. What stays on your device

The editing itself runs in your browser. Brush strokes, selections, filters and adjustments are computed locally and are not streamed to us as you work.

An image you open from your computer stays in the browser as a local reference. Its pixels are only sent to us if you save a canvas that contains them, or export a file.

2. What we collect

Content you save. Canvas settings (name, size, resolution, colour mode), the layer and document data behind your canvases, and any images you upload or export. These are stored on our servers so your work can be restored.

A session identifier. A random value generated in your browser and stored there, which links your browser to your canvases. It is not tied to your name, and we do not ask you to create an account.

Technical data. Our servers record the IP address, browser user agent, requested address, response status and timestamp of requests, in ordinary server logs. We use these to keep the Service running and secure.

Analytics data, only if you agree. See section 5.

We do not ask for your name, postal address or payment details, and we do not knowingly collect special categories of data. Note that any personal data contained inside an image you upload is content you have chosen to give us, and is covered by section 3.

3. Why we use it, and on what legal basis

To provide the editor and store your work — performance of our agreement with you (Article 6(1)(b) GDPR).

To keep the Service secure, prevent abuse, and diagnose faults — our legitimate interests in operating a safe and functioning service (Article 6(1)(f) GDPR).

To measure how the Service is used through analytics — your consent (Article 6(1)(a) GDPR). You may withdraw it at any time, and the Service works fully without it.

To comply with legal obligations, including responding to lawful requests (Article 6(1)(c) GDPR).

4. Cookies and browser storage

We use a small number of strictly necessary entries in your browser’s local storage to run the editor: a session identifier, the list of canvases you had open, and your cookie choice. These are required for the Service to work, are never used for advertising, and are therefore set without consent as permitted by the ePrivacy Directive.

Anything that is not strictly necessary — currently only analytics — is loaded solely after you accept it. If you decline, no analytics script is loaded and no analytics cookie is set.

You can change or withdraw your choice at any time using the "Cookie settings" link at the bottom of this page. Withdrawing is as easy as giving consent.

The table below lists everything we store.

NameCategoryPurposeLifetime
photanora.sessionStrictly necessaryIdentifies your editing session so your canvases reappear when you return. Stored in your browser, never used for advertising.Until you clear your browser storage
photanora.canvasesStrictly necessaryRemembers which canvases you had open and which one was active, so the editor restores the same tabs.Until you clear your browser storage
photanora.consentStrictly necessaryRecords the cookie choice you made here, so we do not ask again and do not load anything you declined.12 months
_ga, _ga_*AnalyticsGoogle Analytics. Counts visits and measures which features are used, so we know what to improve. Set only if you accept analytics.Up to 24 months

5. Analytics

If you accept analytics, we load Google Analytics 4, provided by Google Ireland Limited, which acts as our processor. It collects the pages you view, approximate location derived from a truncated IP address, device and browser type, and how you move through the Service.

We have IP anonymisation on, we do not enable Google Signals or advertising features, and we do not use analytics data to identify you personally or to build advertising profiles.

Google may transfer data outside the European Economic Area. Those transfers rely on the EU-U.S. Data Privacy Framework and on the European Commission’s Standard Contractual Clauses.

If you decline, none of the above happens: the script is never requested.

6. Who else sees your data

Our hosting and storage providers, who run the servers and object storage on which the Service operates, acting as processors under contract.

Google, as described in section 5, and only if you consented.

Authorities or advisers, where we are legally required to disclose, or where we must establish or defend legal claims.

We do not sell personal data, we do not share it with advertisers, and we do not use your content to train machine learning models.

7. Where your data is held

The servers and object storage that run the Service are located in Germany. Where a processor transfers data outside the European Economic Area, we rely on an adequacy decision or on Standard Contractual Clauses together with appropriate additional safeguards.

8. How long we keep it

Your editing session, and every canvas, layer, uploaded image and exported file belonging to it, is deleted once the session has not been opened for 30 days. A job runs once a day, removes the records from our database and the files from our object storage, and this deletion is permanent — we keep no archive copy.

Opening Photanora again restarts the 30 days. If you clear your browser storage you lose the identifier that links you to your work, and the session is deleted 30 days later.

Deleting a canvas in the editor removes it from your session straight away. Its files are erased when the session itself is deleted, because layers are shared between the canvases of one session and can still be in use.

Server logs: up to 30 days, then deleted.

Your cookie choice: 12 months, after which we ask again.

If you want everything associated with your session erased sooner, write to [email protected] and we will do it.

9. Security

All traffic between your browser and the Service is encrypted with TLS. Stored objects are reachable only through our own domain, and access to production systems is restricted.

No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify the competent supervisory authority and, where required, you.

10. Your rights

Under Articles 15 to 21 GDPR you have the right to access your personal data; to have it corrected; to have it erased; to restrict or object to how we use it; to receive it in a portable form; and to withdraw consent at any time without affecting processing carried out before you withdrew it.

To exercise any of these, write to [email protected]. Because we do not run accounts, please write from the browser session concerned or give us enough detail to identify it — we may need to ask for more information before acting, and we will not use anything you send for another purpose.

We answer within one month. You also have the right under Article 77 GDPR to complain to a supervisory authority, in particular in the member state where you live, work, or where you believe the breach occurred. In Germany the competent authority is the data protection supervisory authority of the federal state in which we are established.

11. Children

The Service is not directed at children under 16. We do not knowingly collect their personal data. If you believe a child has provided us with personal data, write to us and we will delete it.

12. Changes to this policy

We may update this policy. The date at the top of the page shows when it last changed. If a change materially affects how we use your data, we will ask for your consent again or give notice in the Service before it takes effect.

13. Contact

Privacy enquiries and rights requests: [email protected]. We answer within one month, as Article 12 GDPR requires.

Terms of ServicePrivacy PolicyImpressumBack to the editor