Skip to content
ziplyPRIVATE · LOCAL
CompressLearnPricing Privacy
Last updated August 31, 2026

Privacy by architecture

Ziply is designed to process selected images locally instead of sending them to our backend.

Image processing

Files selected in the compressor are read through browser File APIs, decoded and encoded in a local Worker, and returned through local Blob URLs. Ziply does not provide a server route for image uploads, remote transcoding, or image-storage ingestion.

Account and subscription data

Ordinary Free processing does not create an API account. When you request billing or another account feature, the optional FastAPI service can store a one-way keyed hash of a random device identifier, an internal user identifier, plan status, Stripe customer and subscription identifiers, and timestamps needed to operate and secure the service.

If you configure account recovery, Ziply stores only a separately keyed one-way value derived from your recovery code and the time it was created. Ziply does not store or return the raw recovery code. Anyone with the saved code can access the associated account, so keep it private and rotate it if it may have been exposed.

Optional aggregate telemetry

Telemetry is disabled until you opt in. Events use coarse buckets such as batch-size band, input/output-size band, duration band, chosen format, and encoder type. They are sent without the session token and stored without a user link. The client does not send filenames, paths, image contents, previews, hashes, image metadata, or exact byte counts.

Advertising and consent

Ziply limits its Adsterra display banners and adjacent sponsored placements to the Free homepage, the image-compression tool page, and manually selected, substantive Learn articles. Account, pricing, legal, contact, and company pages do not mount them. Premium visitors and visitors whose account state is unresolved do not load Ziply ad or affiliate units.

When you explicitly allow editorial advertising, the Adsterra banner can collect or receive browser and device information such as IP address, cookie or local-storage identifiers, user-agent data, referring and viewed pages, approximate location derived from IP, ad interactions, and information needed to deliver, measure, secure, and prevent fraud in advertising. Adsterra and participating advertising vendors may use cookies, pixels, or similar technologies. Learn more in Adsterra's privacy policy and cookie policy.

On the homepage, the third-party advertisement runs inside a sandboxed frame served from the separate api.ziplyapp.io origin. Browser same-origin protections prevent that frame from reading the compressor page or its file picker. Selected files, filenames, previews, output bytes, and generated Blob URLs are not intentionally provided to the advertising frame. The script remains unloaded until you make an affirmative browser-local choice.

You can withdraw that choice below at any time. When third-party advertising is disabled or unavailable, Free visitors may see a first-party Ziply Premium promotion in the reserved sponsor placement instead. Ziply uses contained 300 by 250 display placements; automatic, sticky, social-bar, interstitial, and popunder formats are not part of this implementation.

Current browser preference: No advertising choice saved

Affiliate links

Some Free pages contain a clearly labeled Stake.us affiliate promotion. If you follow its campaign link, Stake receives the campaign identifier in the URL and controls the information collected on its site under its own privacy policy. Ziply may receive a financial or promotional benefit if you register or take qualifying action through that link. The link is marked as sponsored, and Ziply does not receive the images selected in the compressor through this placement.

Payments

Checkout and subscription management redirect to Stripe. Ziply does not collect complete card numbers. Signed Stripe events are reduced to the identity, price, subscription, status, and timing fields required to provide and reconcile Premium access.

Browser storage and offline cache

The browser may store a random device ID after you request an account feature, signed session state, telemetry preference, and cached application assets. The recovery code is shown in memory during setup but is not placed in Ziply browser storage. Clearing site data removes local account values; use your separately saved recovery code to restore the account. Selected images and generated outputs are not added to Ziply's service-worker cache.

Retention and your choices

  • Selected images and outputs: not received or retained by the Ziply backend. Browser copies remain until you remove them, revoke their local Blob URLs by leaving or refreshing the page, or clear site data.
  • Account and recovery records: retained while the account is active. After a verified deletion request, they are removed from the active database within 30 days unless a legal or fraud-prevention obligation requires a limited record.
  • Stripe and subscription references: retained while the subscription or related dispute is active and for up to seven years after the last transaction where needed for tax, accounting, chargeback, or legal compliance. Stripe separately controls its own payment records.
  • Aggregate telemetry: retained for up to 13 months. It is stored without a user or session link and can be deleted earlier when no longer operationally useful.
  • Advertising preferences and reports: your Ziply browser-local advertising choice remains until you change it or clear site data. Adsterra and participating vendors control the identifiers they place after you allow the banner and process them under their own policies. Ziply may access aggregated Adsterra performance and payment reports and retains business and tax records for the periods required by law.
  • Security and service logs: retained for up to 30 days unless a specific security, abuse, or legal investigation requires longer preservation.
  • Support correspondence: retained for up to 24 months after the request closes, or longer when tied to an unresolved billing, security, or legal matter.
  • Backups: encrypted backup copies expire within 35 days. Data deleted from the active system can remain in a protected backup until that backup expires; restored backups must reapply recorded deletion requests before normal service resumes.

To request access to or deletion of account data, email support@ziplyapp.io with the subject “Privacy request.” Ziply may request limited information needed to verify control of the account. Legally required financial or anti-fraud records may be retained after account deletion, but they will not be used to restore product access.

Contact

Ziply is operated by Capital Trans Group in Virginia, United States. Questions about this notice or Ziply's data practices can be sent to support@ziplyapp.io.

Security boundary

No web application can promise security against a compromised browser, malicious extension, infected operating system, or modified deployment. Ziply's narrower, testable commitment is that the supplied application does not intentionally transmit selected images to its API or third parties, and automated checks reject image-bearing backend routes.

ziplyPRIVATE · LOCAL

Fast media utilities that keep the original bytes on your device.

support@ziplyapp.io
ToolsImage compressorJPEG to WebPPNG to WebPOffline compressor
LearnAll guidesChoose an image formatPNG quantizationQuality settings
CompanyAboutPricingRecover PremiumPrivacyTermsContact
© 2026 Capital Trans Group. Ziply is a product of Capital Trans Group.Zero uploads. Zero server-side media retention.