Privacy Policy
Last updated: 8 August 2026
Your privacy matters to us. This policy explains what Uppic collects, how we use it, how long we keep it, and what you can control — including specifics of an image-hosting service such as image privacy settings, EXIF metadata, and QR scan analytics.
On this page
1. Data we collect
- Account data — email, display name, password (always stored as a hash, never in plain text), and account settings.
- Uploaded files — images, file names, sizes, formats, and the options you choose, such as privacy level and expiry date.
- Image metadata (EXIF) — such as camera model, capture date, and GPS coordinates, handled according to your settings (see the EXIF section below).
- Usage data — such as upload counts, storage used, QR creation history, and system event logs.
- Device and connection data — browser type, operating system, and IP address, used for security and abuse prevention.
- QR scan analytics — aggregate scan data (see the QR analytics section below).
- Cookies — as described in the Cookie Policy (/cookies).
- Payment data — processed by external payment providers; we store only transaction status and plan history, never card numbers.
2. How we use data
- Providing the core service — storing, processing, and serving files according to your settings.
- Authentication, account security, and preventing fraud or abuse.
- Billing and plan management.
- Improving the service using aggregate usage data.
- Essential communication, such as verification emails, security alerts, and service-change announcements.
- Complying with applicable law, including Thailand's Personal Data Protection Act (PDPA).
We do not sell your personal data, and we do not use your images for advertising or AI model training.
3. Image privacy
Every uploaded image has one of three privacy levels, each controlling access differently:
Level | Who can view | Details
- Public | Everyone | Accessible via link, may appear in public areas of the service, and may be indexed by search engines.
- Unlisted | Anyone with the URL | Not listed publicly and tagged noindex so search engines do not index it — but anyone who receives the URL can open it.
- Private | Only you | Requires signing in to your account; files are served through an authorization check.
Important: Unlisted is NOT Private. An unlisted link is simply not announced publicly — anyone holding the URL (for example, if it is forwarded in a chat) can view the image without signing in. For sensitive images, use Private.
4. Image metadata (EXIF)
Photos from cameras and phones usually embed EXIF metadata such as camera model, capture date and time, and the GPS coordinates of where the photo was taken — which can unintentionally reveal your home or workplace.
- Remove all metadata — strips every EXIF field from the published file.
- Remove GPS only — keeps camera/date information but strips location coordinates.
- Preserve everything — keeps original EXIF intact (useful for photographers who want capture details shown).
The default is to automatically remove sensitive metadata, protecting your privacy from the start. You can change this option when uploading.
5. QR scan analytics
For Dynamic QR codes, the system records scan statistics so QR owners can analyze usage. Per scan we record:
- Scan time
- Device type (mobile / desktop / tablet)
- Browser and operating system
- Approximate country (coarse IP-based lookup, not precise location)
- Referrer, when available
- IP addresses are anonymized before analytics are stored.
- Statistics are presented in aggregate — not as individual profiles of the people who scan.
- Analytics data has limited retention, as described in the retention section below.
7. Storage and retention
- Image files are kept in access-controlled object storage.
- Files with an expiry date are deleted automatically when they expire.
- When you delete an image or your account, the files and related data are removed from primary systems, and backup copies rotate out within 30 days.
- System logs containing IP addresses are kept for up to 90 days for security, unless needed for an abuse investigation.
- Detailed QR scan analytics are retained per your plan; older data is collapsed into aggregate statistics.
- Financial records and receipts may be kept longer as required by accounting and tax law.
8. Third-party processors
We use external providers only as needed to run the service. Each accesses only the data required for its role, under data-protection agreements. Processor categories include:
- Infrastructure and object-storage providers, for storing files.
- CDN providers, for serving files (when enabled).
- Payment providers, for processing plan payments.
- Email delivery providers, for verification and notification emails.
9. International transfers
Some infrastructure, such as CDN or payment providers, may be located outside Thailand. In those cases we ensure transfers have appropriate safeguards as required by the PDPA and other applicable law.
10. Data security
- Connections are encrypted with HTTPS/TLS.
- Passwords are hashed with a modern algorithm (Argon2).
- Uploads are validated by real file type (magic bytes) and re-encoded to reduce the risk of malicious files.
- Two-factor authentication (TOTP 2FA) and device session management are supported.
- More details are on the Security page (/security).
11. Your rights
Under the PDPA and applicable data-protection law you have the following rights, most of which are self-service in the Dashboard:
- Access and copy — export your data and file listings.
- Rectification — update your account information at any time.
- Erasure — delete individual images, or delete your entire account and related data from settings.
- Object to or restrict certain processing, and withdraw consent you previously gave.
- Lodge a complaint with Thailand's Personal Data Protection Committee (PDPC) if you believe we are handling data improperly.
For rights not available in the Dashboard, contact support@aihubincome.com — we respond within 30 days.
12. Children
The service is not designed for children under 13, and we do not knowingly collect their data. If you are a parent or guardian and believe your child has provided us data, please contact us so we can delete it.
13. Changes to this policy
We may update this policy from time to time. For changes that materially affect your rights, we will notify you by email or in-service announcement before they take effect. The last-updated date is shown at the top of this page.
14. Contact
Questions about privacy or exercising your rights? Reach us via the contact page (/contact) or email support@aihubincome.com.