Last updated: 1 January 2026
We respect your privacy. We collect the minimum data needed to run ImageSEO. We do not sell your data. We do not train third-party AI models on your images. We are compliant with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).
ImageSEO is a product that generates AI-powered alt text, image filenames, and captions for WordPress websites. The service is accessible at imageseo.io and app.imageseo.io. For the purposes of data protection law, ImageSEO is the data controller of personal data collected through this site and the product.
Questions about this policy should be directed to our support team.
The legal basis for processing is a combination of contractual necessity (you signed up for the service), legitimate interest (product improvement, fraud prevention), and legal obligation (tax and billing records). For marketing emails, consent.
When ImageSEO analyzes an image from your WordPress media library, we send a secure copy to an AI model running on our infrastructure or a trusted AI provider. The model returns suggested alt text, filenames, and captions. The image itself is discarded from our systems within 24 hours.
We never modify or overwrite the original image file on your server. The only data we write back to your WordPress site is text metadata (alt attributes, title attributes, filenames).
If you delete your ImageSEO account, all image-derived metadata we stored is also deleted.
ImageSEO uses large language models and vision models from trusted providers to generate alt text. We do not train third-party models on your images or content. When we send an image to an AI provider, we explicitly opt out of data retention and training where the provider supports it.
Our own models, if any, are trained only on aggregated, anonymized data and never on individual customer content.
We only share data with providers strictly necessary to run the service. These are our “sub-processors”:
We never sell your personal data. We never share it with advertisers. We never pass it to data brokers.
If you are in the EU, UK, or California, you have the right to:
To exercise any of these rights, email us via the support page. We respond within 30 days.
We use strictly necessary cookies for login, language preference, and fraud prevention. We use Google Analytics cookies for anonymous traffic analytics. We do not use advertising cookies. We do not track you across other websites.
You can disable non-essential cookies via your browser settings. The site will still work.
All data is transmitted over HTTPS with TLS 1.2 or higher. Passwords are hashed with bcrypt. Databases are encrypted at rest. Access to production systems is restricted by role, logged, and audited. We use 2FA on all internal tools.
If we ever suffer a data breach that affects your personal data, we will notify you within 72 hours as required by GDPR.
For any privacy-related question, contact us through our support page. We typically respond within 1 business day.
This policy may be updated from time to time. The “Last updated” date at the top reflects the most recent change. Material changes will be communicated by email to active customers.