Privacy Policy
Updated and effective:
This policy describes the current ImageFly service at imagefly.app, including its public guides and manuals, invited-user workspace, Recipe Builder, Technical Chatbot and downloaded recipes. ImageFly's site administrator operates the service and is the contact for privacy requests.
1. Information we process
When you sign in, we process your email address and ImageFly access code. Account records contain your email, access status, expiry, renewal history and creation time. Authentication uses salted password hashes rather than readable passwords; newly issued or reset website access codes also have an encrypted cloud copy so an administrator or assistant can resend the same code to your account email. This copy is retained until reset or account removal; invitation information supplied by your administrator may separately contain your access code. In cloud-login deployments, the browser or updater derives an access-code proof; Cloudflare D1 stores account records, salts, peppered verifiers and hashed session tokens. The private verification secret is stored separately from the database. Cloudflare R2 stores Prototype Apps release ZIPs and version information; these downloads require a signed-in, enabled account.
When you submit a job, we store the file link or prompt you provide, chosen workflow or AI agent, parameters, language, job identifiers, timestamps, status, progress, activity messages and results. AI jobs can also include generated answers, recipes, blocks and related working files.
For image analysis, we access the submitted Google Drive file's contents and metadata, including its identifier, name, size, type and ownership information, download a copy to the backend workstation, and create output files and download links.
Website requests include technical information such as IP address, requested URL, browser information and request time. Cloudflare processes request traffic to deliver and protect the site. The backend uses the forwarded IP address and account identifier to limit sign-in attempts. Operational diagnostics may contain job identifiers and error messages.
Administrator access and user-management actions record the acting administrator, action, target account and time. Access codes are not included in these audit records.
Access-code applications include your email and required name, organization and purpose. Administrators and assistants review them. We email the decision and, on approval, the access code through the configured mail provider (Gmail / SMTP or Resend). Pending or failed notification contents are encrypted in cloud storage for retry; the encrypted contents are removed after the sending server accepts the message. Mailbox passwords and API keys are encrypted and are not returned to browsers. Mail providers and recipients may retain email copies.
2. Why we use this information
We use this information to authenticate invited users, check file ownership, queue and run the analysis you request, generate recipes or answer questions, deliver results, preserve your job history, troubleshoot failures and protect the service from abuse.
We do not sell personal information or use it for targeted advertising. The website currently has no advertising or third-party analytics scripts. Submitting data for a job does not make that data a public website page.
3. Google Drive access and Google API data
The current workspace uses the administrator's authorized Google Drive receiving account. You share a selected input file with the receiving email shown in the workspace and submit its link. ImageFly checks that the file belongs to the email you used to sign in. Website visitors are not asked to enter their Google password or grant the website OAuth access to their entire Drive.
The administrator's Google authorization requests drive.readonly to read files accessible to that receiving account and drive.file to create and manage app-created result files. The analysis runner uses the submitted file, rather than browsing your Drive for unrelated files. We store the receiving account's authorization credentials on its backend to maintain that connection.
Results are uploaded to an app-created private folder in the administrator's Drive and shared with the job owner's email as a reader. They are not deliberately shared with anyone who has a link. The operator and the named recipient can access these files, subject to Google Drive permissions.
ImageFly's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google API data is used for the requested user-facing analysis and result delivery, not advertising, resale, credit decisions or training general-purpose AI models. Human access to Google API data is limited to your affirmative permission to view specific data, necessary security investigation, applicable legal requirements, or other uses allowed by that policy.
You can stop future input-file access by removing the receiving account's permission in Google Drive. This does not erase copies already downloaded or generated. The administrator can revoke the app's Google authorization in their Google account. To remove stored copies or operator-owned result files, contact the administrator using the details below.
4. Recipe Builder and Technical Chatbot
These features run Codex or Claude Code on the selected backend workstation. Your prompt and relevant recipe code or reference material are sent to the selected AI provider: OpenAI for Codex, or Anthropic for Claude. If you put personal information, file contents or private links in a prompt, that information is also part of the AI request.
Submitting a Google Drive image-analysis job does not automatically send its input image to these AI services. Generating or downloading a recipe does not automatically execute it in Dragonfly.
Provider handling, retention and any model-improvement use of AI request content depend on the backend's account type, settings and applicable provider terms. This policy does not promise zero retention or a universal no-training setting for AI prompts. Ask the administrator about the configured provider before submitting confidential material. We retain prompts, answers and generated packages in the backend job history.
5. Cookies and browser storage
The workspace uses an essential imagefly_session cookie to maintain your sign-in. In production it is Secure, HttpOnly and SameSite=Lax. Its default lifetime is about 12 hours and can be configured by the administrator; signing out revokes that session.
The administration page uses a separate necessary imagefly_admin_session cookie, restricted to administrator API paths, with Secure, HttpOnly and SameSite=Strict in production. Its default lifetime is one hour. Signing out or revoking administrator access invalidates the session.
Browser local storage saves your language preference under imagefly.language. You can remove it by clearing this site's browser data. Blocking the session cookie prevents the signed-in workspace from working, but the public guides and this policy can be read without signing in.
6. Downloaded recipes and local Dragonfly files
The website provides recipe ZIP downloads. You extract the files and choose the generated Python script in Prototype Apps → Recipe Executor on your computer. The website does not automatically install or execute these files.
Recipes run in your local Dragonfly environment and may read or write the inputs and outputs specified by the script. Review the included instructions and script before running it. Downloaded files and local results remain on your computer until you remove them. The Online Update menu remembers your email and access code as plain text in local shared settings, separate from the installation folder. Login cookies remain in memory. It checks account validity before downloading and before opening the installer.
The website no longer offers Local Assistant installation or import buttons. Previously installed assistants and their downloaded files or backups remain until you remove them. Legacy recipe handoff links, where used by existing installations, contain a random, single-use download capability valid for ten minutes; the backend retains its hash and related account/job records, not your access code in the link.
7. Providers, access and international processing
Cloudflare provides website hosting and the gateway/tunnel to the backend. Google provides Drive storage and file transfer. OpenAI or Anthropic handles requests when you choose the corresponding AI feature. These services receive the information needed for the functions described above and process it under their applicable terms and privacy policies.
Authorized site administrators maintain the backend workstation and its stored records. The protected administration page lets authorized administrators manage accounts and inspect each user's submitted prompts, analysis and AI task history, answers, logs and recipe packages. Access to Google Drive file contents remains governed by the limited-use conditions in section 3. The active workstation can be changed to another administrator-configured computer. Backend and provider processing may take place outside your country; this service does not offer a country-specific data-residency guarantee.
We may disclose information where required by applicable law or where necessary to investigate abuse or protect service security. Following a link to another website subjects your interaction with that website to its own privacy practices.
8. Retention and deletion
The current service does not implement a single automatic deletion period for account records, administrative audit records, job history, prompts, answers, downloaded inputs, generated outputs, recipe packages or working directories. These can remain on the backend until the administrator removes them. Signing out or cancelling a job is not a deletion request.
Google Drive results remain in the operator's Drive until removed there. Browser preferences and local Dragonfly files remain under your local control. Expiring sessions and recipe download capabilities limit access; expiration does not delete the underlying job or recipe.
Contact the administrator to request access, correction, deletion, or cessation of processing of your information. Identify your account email and relevant job IDs or files, but do not send passwords or access codes. We may need to verify your identity and explain any security or legal reason that limits a request. Separately held provider records and backups are subject to their applicable retention and deletion processes.
9. Security and your choices
The public service uses HTTPS, protected sign-in sessions, account-scoped job access and guarded access to the backend. These measures reduce unauthorized access but do not guarantee that every system or transfer is risk-free.
You can read public pages without an account, choose whether to submit an analysis or AI request, remove a file's Drive sharing permission, sign out, clear browser storage, and uninstall the Local Assistant's website integration. Please submit only data that you are entitled to share and process.
10. Children and policy updates
ImageFly is intended for scientific and technical users, rather than a service directed to children. If you believe a child has provided personal information without appropriate authorization, contact the administrator.
We will publish revisions on this page and update its date. Material changes to how information is collected, used or shared will be brought to affected users' attention, with additional consent requested where required.
Cloud messages, activity and Prototype Apps licensing
When these cloud services are activated, Cloudflare D1 stores your contact details, private messages with administrators, license requests, challenge codes, shared authorization membership, app entitlements and signed license files. Challenge v2 includes the full Dragonfly activation key and a machine identifier hash. Administrators can review these records; other users can only access their own messages and requests. Administrator-approved members of a shared Dragonfly key can download that authorization’s license history.
Daily activity counters record successful user logins, signed-in page visits, messages, license requests and license downloads. Page visits are counted at most once per page per five-minute interval; background polling and administrator actions do not count. These counters do not measure desktop plugin usage. Activity starts when cloud tracking is activated; older activity cannot be reconstructed.
The signing private key is kept separately as a Cloudflare Worker secret and is never sent to users. Records are retained for support, authorization history and re-download until removed by the administrator under a privacy request. Archiving hides user downloads but retains administrative records. Disabling an account or changing entitlements cannot revoke an already downloaded offline license. Contact the administrator to request correction or deletion.
11. Optional Prototype Apps usage reporting
The online edition offers an optional account binding in Online Update. After you agree and enable it, it records plugin identifiers, opening and last-observed times, approximate window-open durations, completion state, package and Dragonfly versions, and a random installation identifier with your chosen device label. These records are linked to your ImageFly account in Cloudflare D1. Full administrators can view individual history and aggregate statistics; users can view their own history and submit or replace a 1–5 rating and optional comment for each used plugin.
This reporting does not include images, file names or paths, script contents, or access codes. It runs directly between the client and Cloudflare without the workstation Tunnel. Window-open time includes idle time and overlapping windows are counted separately. Tools without windows record calls only. Abnormal exits keep the last checkpoint as an estimate; old versions and users who do not enable reporting are not covered.
Pending records stay in a local outbox for up to 30 days and upload after connectivity returns. The device upload token is stored in plain text locally; its hash is stored in the cloud and it cannot sign in or manage your account. Stop reporting in Online Update to remove the binding and discard pending records, or revoke a device in your usage page to reject further uploads. Requests already in transit may complete. Uploaded records and ratings remain for product support and statistics until the administrator removes them under a privacy request. Rebinding is required after expiry, revocation or an access-code reset.
12. Contact and privacy requests
Contact the ImageFly site administrator at the email below, or the administrator who invited you. Include your account email and the subject of your request.