Skip to content
ziplyPRIVATE · LOCAL
CompressOfflinePricing Privacy
Last updated August 4, 2026

Privacy by architecture

Ziply is designed to process selected images locally instead of sending them to our backend.

Image processing

Files selected in the compressor are read through browser File APIs, decoded and encoded in a local Worker, and returned through local Blob URLs. Ziply does not provide a server route for image uploads, remote transcoding, or image-storage ingestion.

Account and subscription data

Ordinary Free processing does not create an API account. When you request billing or another account feature, the optional FastAPI service can store a one-way keyed hash of a random device identifier, an internal user identifier, plan status, Stripe customer and subscription identifiers, and timestamps needed to operate and secure the service.

If you configure account recovery, Ziply stores only a separately keyed one-way value derived from your recovery code and the time it was created. Ziply does not store or return the raw recovery code. Anyone with the saved code can access the associated account, so keep it private and rotate it if it may have been exposed.

Optional aggregate telemetry

Telemetry is disabled until you opt in. Events use coarse buckets such as batch-size band, input/output-size band, duration band, chosen format, and encoder type. They are sent without the session token and stored without a user link. The client does not send filenames, paths, image contents, previews, hashes, image metadata, or exact byte counts.

Advertising and consent

Compressor routes do not load Google AdSense or other third-party advertising JavaScript. Such code would share the document containing selected filenames and local preview URLs, which is outside Ziply's media boundary.

Any future production advertising is restricted to a separate media-free browsing document that has never owned selected files, filenames, previews, outputs, or generated Blob URLs. It also requires a Google-certified consent-management platform exposing the applicable current IAB consent signals, approved commercial policies, a published contact, a valid ads.txt entry, and disabled Auto Ads/overlay formats. A local button cannot grant consent or bypass the consent platform. The control below can add a browser-local opt-out or return control to the consent manager.

Current browser preference: Waiting for the consent manager

Payments

Checkout and subscription management redirect to Stripe. Ziply does not collect complete card numbers. Signed Stripe events are reduced to the identity, price, subscription, status, and timing fields required to provide and reconcile Premium access.

Browser storage and offline cache

The browser may store a random device ID after you request an account feature, signed session state, telemetry preference, and cached application assets. The recovery code is shown in memory during setup but is not placed in Ziply browser storage. Clearing site data removes local account values; use your separately saved recovery code to restore the account. Selected images and generated outputs are not added to Ziply's service-worker cache.

Retention and your choices

  • Selected images and outputs: not received or retained by the Ziply backend. Browser copies remain until you remove them, revoke their local Blob URLs by leaving or refreshing the page, or clear site data.
  • Account and recovery records: retained while the account is active. After a verified deletion request, they are removed from the active database within 30 days unless a legal or fraud-prevention obligation requires a limited record.
  • Stripe and subscription references: retained while the subscription or related dispute is active and for up to seven years after the last transaction where needed for tax, accounting, chargeback, or legal compliance. Stripe separately controls its own payment records.
  • Aggregate telemetry: retained for up to 13 months. It is stored without a user or session link and can be deleted earlier when no longer operationally useful.
  • Security and service logs: retained for up to 30 days unless a specific security, abuse, or legal investigation requires longer preservation.
  • Support correspondence: retained for up to 24 months after the request closes, or longer when tied to an unresolved billing, security, or legal matter.
  • Backups: encrypted backup copies expire within 35 days. Data deleted from the active system can remain in a protected backup until that backup expires; restored backups must reapply recorded deletion requests before normal service resumes.

To request access to or deletion of account data, email support@ziplyapp.io with the subject “Privacy request.” Ziply may request limited information needed to verify control of the account. Legally required financial or anti-fraud records may be retained after account deletion, but they will not be used to restore product access.

Contact

Questions about this notice or Ziply's data practices can be sent to support@ziplyapp.io.

Security boundary

No web application can promise security against a compromised browser, malicious extension, infected operating system, or modified deployment. Ziply's narrower, testable commitment is that the supplied application does not intentionally transmit selected images to its API or third parties, and automated checks reject image-bearing backend routes.

ziplyPRIVATE · LOCAL

Fast media utilities that keep the original bytes on your device.

support@ziplyapp.io
ToolsImage compressorJPEG to WebPPNG to WebP
CompanyPricingRecover PremiumPrivacyTermsContact
© 2026 ZiplyZero uploads. Zero server-side media retention.