Last updated: August 29, 2026
DropIMG (“DropIMG,” “we,” “us”) is a temporary image sharing utility. You paste, drop, or choose an image; we give you a short link that expires. Optional accounts add sign-in, history, and DropIMG Pro. This Policy explains what we collect, why, how long we keep it, and your choices.
By using DropIMG you agree to this Policy and our Terms of Use.
noindex so they are not meant for search results.If you sign in, we store the email address you provide so we can send one-time magic links and recognize your account. There is no account password.
When you upload an image we process and store:
We do not store the original filename from your device.
Supported formats: PNG, JPEG, WebP, and GIF. Anonymous and Free uploads are limited to 10 MB. Pro uploads may be up to 50 MB when that limit is enabled. SVG and other formats are rejected.
For JPEG, PNG, and WebP we attempt to strip EXIF and similar embedded metadata before storage. If stripping fails, the upload is rejected. GIF files are stored as uploaded.
Pro users can put a password on a share link. The password value is not stored in plaintext. We store a one-way hash used only to check later unlock attempts. Recipients who unlock a link get a short-lived cookie for that image only.
To rate-limit uploads and reduce abuse we derive a hashed fingerprint from your IP address using a server secret. We store that hash for quota and abuse controls. We do not store raw IP addresses in our application database for uploads.
Cloudflare (our hosting and security provider) may process IP addresses and request metadata as part of operating the network, CDN, DDoS protection, and logs.
You can create a personal integration token for the browser extension or ShareX. The raw token is shown once. After that, DropIMG keeps only a hash of the token. Treat the token like a password. Revoking it stops new uploads from that connection. Existing share links are not changed.
Paid DropIMG Pro checkout is handled by Paddle. Paddle receives the payment and billing information needed to charge you. DropIMG stores the subscription identifiers and status we need to provide Pro (for example whether Pro is active, when the current period ends, and whether cancellation is scheduled). We do not store your full card number.
We record first-party product events in Cloudflare Analytics Engine (for example: a page view, an upload result, a sign-in request, a checkout step, or a dashboard action). Events use low-cardinality fields such as event name, plan, billing interval, upload surface, and reason codes. We do not put raw integration tokens, passwords, or email addresses in analytics.
When you delete your account we:
If billing cancellation fails, the account is not deleted so we do not leave an unpaid or uncanceled subscription behind. Deleted-account cleanup is not always instantaneous for every stored object or log.
The official Chrome / Edge extension can capture the visible tab or a region you draw. Anonymous captures use the same upload rules as the website. If you connect an account, the extension stores your personal token only on that device (not in synced storage). Recent links and language/theme preferences may also stay in local browser storage until you clear them.
Signed-in use needs a session cookie. A language cookie remembers your locale choice. Unlocking a protected image sets a short-lived cookie for that image. Cloudflare may set essential security cookies. We do not use third-party advertising cookies on the product described here.
Share URLs are randomly generated and not listed publicly, but they are not a login. Anyone with the link can open an unprotected image while it is live. A password only helps if you keep that password and the link private.
We use infrastructure providers to run DropIMG, including Cloudflare (Workers, DNS/CDN, object storage, database, email sending, analytics, and security) and Paddle for paid subscriptions. They process data to provide those services to us.
We do not sell your personal information. We may disclose information if required by law, to protect rights and safety, or to address abuse.
DropIMG is delivered over Cloudflare’s global network. Uploads and requests may be processed in data centers outside your country.
DropIMG is not directed at children under 13 (or the equivalent minimum age where you live). Do not upload content that exploits or endangers minors.
Privacy and abuse: abuse@dropimg.io
We may update this Policy as the product changes. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised Policy.