Skip to content

Security

Your files are yours. imgcanva processes images on your device and never stores them.

Data Privacy

Our commitments

  • No uploads

    Images are opened, edited and saved in your browser.

  • Minimal data

    No accounts, no analytics and no cookies. Our servers keep only what a request needs, for as long as it needs it.

  • Open building blocks

    Image processing uses well-known open-source libraries, listed in our licences.

Product Security

  • Processing on device

    Images are decoded, edited and encoded in your browser with WebAssembly and Web Workers.

  • Encrypted connection

    Every page is served over HTTPS with HSTS.

  • Strict content policy

    A Content Security Policy stops scripts from sending data to other sites.

Internal Security

  • No image storage on our servers
  • End-to-end encrypted phone hand-offs
  • Strict Content Security Policy
  • Rate limits on every server feature
  • Private-network block on URL capture
  • No third-party scripts

Security policy

Scope. This policy covers imgcanva.com and its server features: HTML to image, Send to phone and the meme template service.

Design. Images are processed on your device. Server features receive the minimum they need, keep nothing beyond what the privacy policy describes, and run behind rate limits. Send to phone files are encrypted with AES-GCM in your browser; the key lives in the link's # fragment, which browsers never send to servers. URL capture refuses private, loopback, link-local and cloud metadata addresses, and blocks ad and tracker requests.

Web security. Every page is served over HTTPS with HSTS, a strict Content Security Policy that only allows connections back to this site, and headers that prevent framing and content-type sniffing. No third-party scripts run on the site.

Reporting a vulnerability. If you find a security problem, email legal@imgcanva.com with the steps to reproduce it. Please give us reasonable time to fix it before you disclose it, do not access other people's data, and do not run tests that slow the service down for others. We will acknowledge your report within five working days and keep you informed. We will not take legal action against good-faith research that follows these rules.

Incidents. If an incident affects personal data, we will inform the people affected and the authorities as the law requires.