Privacy Policy
ByteSquish ecosystem privacy notice
Effective and last updated: 10 September 2026
1. Who We Are and Scope
ByteSquish ("ByteSquish", "we", "us" or "our") operates bytesquish.com, imagetools.bytesquish.com, account.bytesquish.com, authenticator.bytesquish.com and the related APIs (together, the "Services"). For personal data whose purposes and means we determine, ByteSquish acts as the data controller under the GDPR and the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). This notice applies subject to the laws and phased rules that are in force for your use of the Services.
2. Personal Data We Process
- Account and contact data: name, email address, password hash, verification and password-reset records, account status and communications with us.
- Authentication and security data: session tokens, passkey credential identifiers and public keys, one-way Authenticator vault PIN hashes, email 2FA settings, purpose-bound OTP hashes, failed-attempt counters, IP address, optional approximate trusted-device location, browser/device details, login timestamps and security events.
- Push-notification data: an opaque browser push endpoint, public encryption key, authentication secret, browser details and notification registration timestamps when you enable tap-to-approve login notifications.
- Authenticator data: third-party service issuer, account label, TOTP algorithm, digit and timing settings, and the associated encrypted TOTP secret.
- Image and prompt data: images, filenames, file metadata, prompts and generated or processed outputs submitted to the Image Toolkit or API.
- Developer and usage data: API credential records, request counts, timestamps, feature usage, rate-limit information and diagnostic logs.
- Visit analytics: a pseudonymous visitor identifier, signed-in account identifier when available, ByteSquish application and page visited, visit time, browser details, and country, region, city and approximate coordinates derived from the network address. Visitor and network identifiers are stored as one-way hashes rather than plaintext IP addresses in the analytics record.
- Device preferences: necessary authentication storage, theme and language preferences, including the Google Translate preference when used.
ByteSquish Account two-factor authentication uses codes delivered to your verified email; it does not use TOTP codes from ByteSquish Authenticator. We store a purpose-bound cryptographic hash of each email code, not the plaintext code, together with its expiry and attempt count. The plaintext code is necessarily provided to our email-delivery provider for delivery.
ByteSquish Authenticator uses the same ByteSquish Account. Issuer names and account labels are stored as readable entry metadata so they can be displayed, while TOTP secrets are synchronised to the Service encrypted at rest using AES-256-GCM. A decrypted secret is delivered only to an authenticated and unlocked mobile browser over HTTPS so that browser can generate the current code. Treat access to your ByteSquish Account, vault credential and verified email as access to these entries.
3. Purposes and Legal Grounds
We process personal data only as reasonably necessary for the following purposes and legal grounds:
- Contract and requested service: create and secure accounts, authenticate users, process images, provide API features and deliver requested support.
- Legitimate interests: understand aggregate usage by application and country, prevent fraud and abuse, secure the Services, enforce limits, diagnose faults and improve reliability, provided those interests are not overridden by your rights.
- Consent: optional browser permissions such as camera access and approximate location, and optional communications where consent is required. You may deny or withdraw permission without affecting earlier lawful processing.
- Legal obligations: comply with applicable law, lawful requests, accounting, dispute and security obligations.
Under the DPDP Act, processing is based on your consent or a recognised legitimate use, as applicable. We do not sell personal data or use uploaded images to train our own AI models.
4. How Image Data Is Handled
Guest image operations are generally processed in memory to return the requested result. Images saved for signed-in history, generated outputs and associated database records are scheduled for automatic deletion seven days after creation. You may delete eligible images sooner from the Service. Some AI features transmit the submitted image or prompt to our contracted AI infrastructure solely to produce the requested output. Removing EXIF metadata discards that metadata from the produced output; keep your original if you need it.
5. Service Providers and Disclosures
We disclose only the data reasonably needed to:
- hosting, database, security, email-delivery and technical support providers;
- your browser or operating-system push service, which receives an encrypted login-notification payload when you enable push approval;
- Cloudflare infrastructure for supported AI processing;
- Google Translate when translation is enabled;
- an IP geolocation provider used to describe approximate sign-in location in security alerts;
- professional advisers, regulators, courts or authorities where legally required; or
- a successor in a merger, financing, reorganisation or sale, subject to appropriate safeguards and notice where required.
Processors must act on our instructions and protect the data. We do not disclose personal data to third-party advertisers.
6. International Transfers
Providers may process data outside your country. Where the GDPR applies, we use a lawful transfer mechanism such as an adequacy decision or approved contractual safeguards and supplementary measures where appropriate. Transfers from India are subject to restrictions notified under applicable DPDP law.
7. Retention and Deletion
- Images and generated outputs: up to seven days when saved by the Service, unless deleted sooner or preservation is legally required.
- Email security codes: ordinarily 10 minutes, after which they expire; only a purpose-bound hash, expiry and attempt information are stored.
- Trusted-device data: the signed browser token ordinarily expires after 30 days. Its account-bound location fingerprint becomes unusable when that token expires or relevant account security state changes.
- Push subscriptions: until you disable notifications, the browser invalidates the subscription, or you permanently delete your ByteSquish Account. Invalid subscriptions are removed when the push service reports that they have expired.
- Login history: ordinarily 30 days for user-visible security monitoring.
- Visit analytics: ordinarily 90 days, or the shorter period configured for the Service.
- Account data: while the account is active. A user-requested account deletion is scheduled with a 30-day recovery period, after which associated account records, sessions, passkeys, authenticator entries and stored images are deleted, subject to limited legal exceptions.
- Support, security and legal records: only as long as reasonably required for the stated purpose, dispute resolution, fraud prevention or law.
- Authenticator entries: until you remove an entry or permanently delete your ByteSquish Account, subject to backup cycling and lawful preservation.
Backups and provider systems may take a limited additional period to cycle out deleted data.
8. Cookies, Local Storage and External Services
ByteSquish uses an authentication cookie or equivalent browser storage needed for shared sign-in and logout across participating ByteSquish subdomains. The Authenticator additionally uses a necessary, HttpOnly vault-session cookie that expires after two minutes. Local storage may hold the signed trusted-device token and user preferences. Signing out removes the shared application session; clearing site data also removes browser-held preferences and trusted-device data. We do not operate advertising cookies. Account security forms use a first-party image CAPTCHA. Its random challenge identifier, one-way answer hash, purpose and expiry are held temporarily by ByteSquish and are not sent to an external CAPTCHA provider. Where the translation control is available, your browser may contact Google to load that feature; selecting a language may set translation preferences. Google processes that data under its own Privacy Policy and Terms.
If you choose "Trust this device and approximate location", your browser asks for location permission. Coordinates are rounded to approximately two decimal places before transmission and converted on the server into a one-way, account-bound fingerprint. The signed trusted-device token contains that fingerprint, not the coordinates, and is checked together with the current rounded location. Location alone cannot bypass email verification. You may deny or revoke permission; email verification remains available.
The Authenticator requests camera permission only after you select the camera-scanning control. QR recognition is performed in your browser, and camera frames or an image selected for QR scanning are not uploaded merely to decode the authenticator token. The decoded issuer, account label, secret and TOTP settings are sent to ByteSquish only when you choose to save the entry. You can deny camera access and instead paste an otpauth:// URI, enter a secret manually or select a QR image from your device. If you export entries to Google Authenticator, ByteSquish creates the transfer QR codes locally in your browser from the decrypted entries already delivered to your authenticated session. ByteSquish does not send those export QR codes to Google; anyone who obtains one can reproduce the associated verification codes, so you must keep it private. The Service does not provide a QR download control and uses browser-level safeguards against copying, printing and saving it, but a website cannot prevent a device-level screenshot or a photograph taken with another device.
If you enable tap-to-approve login, your browser creates a push subscription and shares its endpoint and encryption material with ByteSquish. A browser or operating-system push service transports the encrypted notification. A login notification can include the requesting device, IP address and a short comparison code. Its Yes or No action carries a separate, single-use, short-lived decision token; it does not contain your ByteSquish password or account session token. Notification permission is optional and can be disabled in the Authenticator or browser settings.
9. Security and Breach Response
We use access controls, HTTPS transport encryption, password and vault PIN hashing, passkeys, single-use purpose-bound email codes, authenticated encryption for stored TOTP secrets, rate limiting, attempt limits, security logging and data minimisation appropriate to the risks. The Authenticator is limited to mobile-browser requests and its vault locks after two minutes, but browser device signals can be imitated. Authenticator secrets must be decrypted to generate codes in your authenticated and unlocked browser, so a compromise of your ByteSquish Account, verified email, vault credential, active session or device could expose them. Keep independent recovery codes for third-party accounts. No system is completely secure. We assess suspected personal-data breaches and notify affected people and authorities when applicable law requires it.
10. Your Privacy Rights
Depending on your location and the provisions currently in force, you may have the right to:
- receive information about processing and access a copy of your personal data;
- correct, complete or update inaccurate personal data;
- request erasure or restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive portable data where GDPR portability applies;
- withdraw consent and complain to your competent supervisory authority;
- use grievance redressal and nominate another person to exercise DPDP rights in the event of death or incapacity; and
- request meaningful human review where a solely automated decision produces a legal or similarly significant effect.
Send a request to hello@bytesquish.com. We may verify your identity and will respond within the period required by applicable law. Some rights are subject to lawful exceptions. You may first use our grievance process and, where unresolved, complain to the Data Protection Board of India or your local GDPR supervisory authority, as applicable.
11. Children
The Services are not directed to children under 18, and we do not knowingly offer accounts to them without legally valid parental or guardian authorisation. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
12. Changes to This Policy
We may update this policy as the Services or applicable laws change. We will post the revised date and provide prominent or direct notice when a material change requires it. We will seek new consent where a new purpose is incompatible with the notice and consent previously given.
13. Contact and Grievance Redressal
ByteSquish's privacy and grievance contact for questions, rights requests and complaints is hello@bytesquish.com. Include "Privacy Request" in the subject and identify the Service involved. This is the single published contact address for ByteSquish legal, privacy, security and general enquiries.
