Privacy

Privacy built for secure image handling

Uploads are processed server-side, OpenAI secrets are never exposed client-side, and generated outputs are stored locally in the project public directory for this deployment.

We only send uploaded images to secure server routes for transformation requests. Client-side code never receives the API key.

Generated results are written to the local public generated directory for this deployment and surfaced through the history API.

For production deployments, add retention controls and authenticated user storage before handling sensitive employee or customer data.

Privacy | DropShot