IMSTUDIO

Security

How IMStudio protects your work

Effective July 24, 2026 · Last updated July 24, 2026

The most important security feature of IMStudio is architectural: your work stays on your machine.

On-device by design

Editing, effects, and AI background removal all run in your browser. Your images are not uploaded to be processed — we never receive them, so they can't be leaked, subpoenaed, or trained on from our side. The only image data that ever reaches our servers is a project you explicitly back up.

No passwords

IMStudio has no passwords to steal. Sign-in is handled by Google, which means your account inherits the protections on your Google account — including two-factor authentication if you use it. We never see or store credentials.

Data in transit and at rest

All connections to imstudio.app and our backend use TLS. Cloud Backup data is encrypted at rest on our infrastructure provider (Supabase, on AWS).

Access controls

Every cloud record — your profile, your backups, your synced library — is scoped to your account with row-level security enforced at the database layer, not just in application code. Server-side credentials never ship to the browser.

Payments

Checkout happens on Paddle, our PCI-DSS-compliant merchant of record. Your card details are entered on Paddle's systems and never pass through imstudio.app.

Account deletion

You can delete your account yourself, from inside the app. Deletion is immediate and complete: your account record, your backups, and your synced data are removed, and any active subscription is canceled. Everything on your device stays exactly where it is.

Reporting a vulnerability

If you believe you've found a security issue, email support@imstudio.app with “[security]” in the subject. We'll acknowledge within 72 hours, keep you informed as we fix it, and credit you if you'd like. We won't pursue legal action against good-faith research that respects user data and privacy.