We value your privacy

We use strictly necessary cookies to keep you signed in. We would also like to set optional analytics cookies to help us improve MediaForge. You can choose to accept or decline these optional cookies below. Read our Cookie Policy for more information.

Privacy Policy

Last updated: July 2026

1. Local-First Architecture

At MediaForge, we believe your data belongs to you. All file conversions, metadata stripping, resizing, and optimizations are performed completely locally inside your browser using WebAssembly, WebGL, and JavaScript. When you process a file without uploading it to our CDN, the file never leaves your device.

If you choose to host a file on our CDN, the file is uploaded directly to Cloudflare R2 via a presigned URL. Our server then performs a brief, automated verification pass to ensure metadata was properly stripped (defense-in-depth). During this pass, the file is temporarily downloaded to server memory, re-stripped, and immediately discarded — no metadata content is ever logged, stored, or retained. Only the cleaned file remains on the CDN.

2. Information We Collect

We collect only the minimum information necessary to operate the service:

  • Email address — for account creation, authentication, and transactional emails (verification, password reset, welcome)
  • Name (optional) — for personalizing your experience
  • Subscription plan & region — to manage billing and apply correct pricing
  • Usage metrics — file sizes, operation counts, and bandwidth for quota tracking
  • File metadata (CDN uploads only) — filename, MIME type, dimensions, and content hash for deduplication. We never store the contents of your original metadata (GPS, camera model, etc.)

We do not collect phone numbers, physical addresses, or any data beyond what is listed above.

3. Data Protection & Security

We employ industry-standard security measures to protect your data:

  • HTTPS for all communications
  • Passwords hashed with bcrypt
  • JWT access tokens (15-minute expiry) kept in memory only — never stored in localStorage
  • Refresh tokens stored hashed (SHA-256) in the database with HttpOnly, Secure, SameSite cookies
  • Rate limiting on authentication endpoints
  • Security headers (HSTS, CSP, X-Frame-Options, Referrer-Policy)

4. Cookies & Analytics

We use a single functional session cookie (HttpOnly refresh token) to keep you signed in. We do not use third-party tracking cookies, advertising trackers, or behavioral analytics. We may use privacy-preserving, anonymized analytics to understand application performance.

5. Your Rights Under the Digital Personal Data Protection Act, 2023 (India)

MediaForge acts as the Data Fiduciary for your personal data. If you are a resident of India, you have the following rights under the DPDP Act as a Data Principal:

  • Right to Information — You can view all personal data we hold about you and the identities of all Data Processors we share it with through your Dashboard settings.
  • Right to Correction — You can update your account information through your Dashboard settings.
  • Right to Erasure — You can permanently delete your account and all associated data (files, subscriptions, usage records) with a single action from your Dashboard settings. Deletion is immediate, cascading, and irreversible.
  • Right to Nominate — You may nominate another person to exercise your rights on your behalf in the event of your death or incapacity via the Settings page.
  • Right to Withdraw Consent — You can withdraw your consent for optional processing (e.g., analytics) at any time.
  • Right to Grievance Redressal — You have the right to register a grievance with our Grievance Officer, and subsequently appeal to the Data Protection Board of India.

6. European Union Privacy Rights (GDPR)

If you are a resident of the European Economic Area (EEA), you have the right to access, rectify, or erase any personal data we have collected. You also have the right to data portability and to restrict processing of your data. To exercise these rights, please contact us at [email protected]. We will respond to all requests within 30 days.

7. International Data Transfers & Third-Party Processors

To provide the service, we use the following third-party processors. Your data may be transferred to and processed in the countries listed below:

ProviderPurposeCountry / Region
CloudflareDNS, CDN, SSL termination, reverse proxy, and R2 object storageGlobal network (HQ: USA)
NeonPostgreSQL database hostingSingapore
BigRockVPS infrastructure for MediaForge API, Docker, Nginx, and RedisIndia (India-region VPS plan; exact physical datacenter not publicly disclosed by the provider)
Dodo PaymentsBilling, subscriptions, payment processing, and Merchant of Record servicesUnited States & India
ResendTransactional email deliveryUSA
SentryError monitoring and application diagnosticsEuropean Union (EU)
GoogleOAuth authentication and identity verificationUSA

We ensure each processor maintains appropriate data protection standards. No card or payment details are stored on our servers — all payment processing is handled by Dodo Payments.

8. Data Retention

  • Account data — retained until you delete your account
  • CDN files — retained until you delete them or your account
  • Refresh tokens — expire after 7 days; expired tokens are purged hourly
  • Password reset tokens — expire after 1 hour; expired tokens are purged daily
  • Operations logs — purged after 365 days
  • Webhook events — purged after 90 days
  • Billing records — Dodo Payments retains transaction records independently as required by law

9. Children's Privacy

MediaForge is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data without parental consent, please contact us, and we will take steps to remove such information and terminate the child's account.

10. Business Transfers

If MediaForge is involved in a merger, acquisition, or sale of all or a portion of its assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal data, as well as any choices you may have regarding your personal data.

11. Grievance Officer & Contact

In accordance with the Digital Personal Data Protection Act, 2023, we have appointed a Grievance Officer to address your concerns regarding data processing:

Grievance Officer

Email: [email protected]

We will acknowledge your grievance within 24 hours and resolve it within 30 days. For any questions about this privacy policy, data practices, or to exercise your rights, you may also write to us at the email above.

Escalation: If you are unsatisfied with the resolution of your grievance, or if we fail to respond within the stipulated time, you have the right to register a complaint with the Data Protection Board of India.