DRAFT: pending final review

Privacy Policy

Last updated: June 2026

This Privacy Policy explains what information PicFast collects, how it is used, and how long it is kept. PicFast is a media offload service for WordPress sites. Using the service means your images are fetched, optimized, and served from PicFast's cloud infrastructure.

1. What we collect

Data Why we collect it Retention
Account email address To identify your account, send login links, and send transactional messages (quota warnings, billing receipts) Until account deletion + 30 days
Site URL To associate your media library with your account and verify site ownership Until site disconnection + 30 days
Image URLs Provided by the plugin so our crawler knows which files to fetch and optimize Until site disconnection + 30 days
Image content (the actual files) Fetched from your server by PicFastBot, optimized, and stored on the CDN so they can be served to your visitors Until site disconnection + 30 days
Bandwidth usage (aggregate counts) To enforce plan limits and show you your usage in the plugin dashboard 90 days rolling

We do not collect post content, page content, visitor IP addresses, cookies, or any personally identifying information about your site's visitors.

2. Where data is processed and stored

PicFast's infrastructure runs on AWS (Amazon Web Services). Images are stored in S3 and served via CloudFront (Amazon's CDN). Your account data is stored in a managed PostgreSQL database hosted on Neon. All data is processed within AWS's us-east-1 region unless CloudFront edge caching moves a served image closer to a visitor.

3. How images are served

Once an image is stored on the CDN, it is publicly accessible via a PicFast CDN URL. These URLs are what WordPress rewrites image tags to point at. Anyone who can view your site can load those images. This is by design, because your images were already public on your server.

4. Sharing

We do not sell your data. We do not share it with third parties except:

5. Retention and deletion

When you disconnect your site from PicFast (via the plugin's Disconnect button or by uninstalling the plugin), all data associated with your site (image files, image URLs, and site metadata) is queued for deletion and fully purged within 30 days. Your account email is retained until you delete your account. You can delete your account from the account dashboard or by emailing privacy@picfast.app.

6. Your rights

Depending on where you are located, you may have rights to access, correct, or delete the personal data we hold about you. To exercise any of these rights, email privacy@picfast.app. We will respond within 30 days.

7. Cookies

The PicFast service website uses no third-party tracking cookies. We set a single session cookie when you log in to the account dashboard; it is deleted when you log out or close your browser.

8. Children

PicFast is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at the address below and we will delete it promptly.

9. Changes to this policy

We may update this policy. Material changes will be communicated by email at least 14 days before they take effect. The "last updated" date at the top of this page reflects the most recent revision.


Privacy questions: privacy@picfast.app