Privacy Policy
Last updated: September 18, 2026
This privacy policy explains how Beautiful Photos ("we", "us", "our") collects, uses, and protects your information when you use our Chrome extension and beautifulphotos.app (the "Service"). For privacy questions or requests, contact mailbox@beautifulphotos.app.
The extension and the website handle different data. Website analytics described below do not run inside the extension's new-tab page.
The extension at a glance
- You do not need a Beautiful Photos account.
- The extension does not read your browsing history, the contents of other websites, passwords, or payment information.
- Photos and photo history are cached on your device. Photo history means images shown by Beautiful Photos, not your browser history.
- Settings and personal reminder text use Chrome's sync storage, which can synchronize them through Google when Chrome Sync is enabled.
- Requests for photos send your IP address and a randomly generated installation identifier to our infrastructure. We use these to serve photos and limit abuse.
Data stored by the extension
Local storage. The extension stores downloaded photo data, photo metadata, recent photo history, language preferences, and a random installation identifier in Chrome's local extension storage. It can also store a temporary API access token. This lets it display cached photos quickly, remember your choices, and communicate with the photo service.
Chrome sync storage. Display options, the selected photo lock, personal reminder text, and the installation date are stored using Chrome's sync storage. Google may synchronize these between your browsers according to your Chrome settings. We do not receive your personal reminder text or a copy of your synced settings on our servers. Sync storage is not a private vault; avoid putting passwords or other sensitive information in a reminder.
The extension uses the storage and unlimitedStorage permissions for these settings and image caches. Access to Beautiful Photos domains allows it to request photographs from our API. It replaces the new-tab page and does not request permission to read your browsing history or the contents of arbitrary websites.
Photo requests and infrastructure
When the extension requests a photo, our infrastructure receives your IP address, a randomly generated installation identifier, the requested API route, and request parameters such as a photo ID or photo filter. Standard connection information, such as request time and browser headers, can also be processed by the servers handling the request.
The installation identifier distinguishes installations for request limits. It is not your name, email address, or Google account ID. Our Cloudflare D1 database stores rate-limit records containing the IP address, installation identifier, API endpoint, request count, and reset time. IP addresses and identifiers can be personal data even when they do not include a name.
Photo requests pass through our API proxy and Cloudflare. We use Unsplash to obtain photos and their attribution details. Your browser also connects to image delivery servers, including Unsplash's image CDN, to download photos; those servers receive your IP address and ordinary request information, including image size parameters. We do not send your personal reminders to Unsplash.
When you follow a photographer, source, or download link, the destination service handles that request under its own privacy policy. Unsplash may record image delivery and download activity associated with those requests.
The website
The website uses Google Analytics to measure visits and interactions. It also uses Yandex Metrica with click maps, link tracking, and Webvisor session replay enabled. These services can use cookies or similar identifiers and process page addresses, referral information, browser and device information, approximate location, and interactions such as clicks and scrolling. Webvisor can replay interactions with this website. It does not record activity inside the extension or on unrelated websites.
The website uses a language cookie named lang. Its interactive photo demo can store cached photo information and a random visitor identifier in browser local storage and send photo requests to our API. This website storage is separate from the extension's storage.
The website is hosted using Yandex Object Storage, and our API uses a reverse proxy and Cloudflare. Hosting and network providers process connection information to deliver and secure these services.
You can manage cookies and site storage through your browser, block analytics requests with browser privacy tools, and use the Google Analytics opt-out add-on. Blocking storage or network requests may affect the demo or language preferences. Use of the website does not constitute consent to processing where separate consent is required by law.
Messages and external pages
If you email us, we receive your email address, message, and any attachments you choose to send. Our mailbox is hosted by Mango Mail, which transmits and stores this correspondence so we can respond to you. Mango Mail also processes email metadata for abuse prevention and describes sampling emails for spam and abuse prevention in its privacy policy. Please send only information needed for your request.
The extension can open an external feedback page when it is uninstalled. If you choose to submit feedback there, the page and its form provider process what you submit under the privacy information shown on that page. Visiting external links can disclose standard connection information to their operators.
Who receives data
The services involved in the data flows above include:
- Google: Chrome Sync for extension settings, and Google Analytics for website measurement. See Google's Privacy Policy.
- Cloudflare: API hosting, D1 storage, and network security. See Cloudflare's Privacy Policy.
- Unsplash and its image delivery infrastructure: photographs, attribution, and image requests. See Unsplash's Privacy Policy.
- Yandex: website hosting and website measurement through Metrica and Webvisor. See Yandex's Privacy Policy.
- Mango Mail: delivery and storage of support correspondence and email security. See Mango Mail's Privacy Policy.
- Our API proxy hosting provider: server hosting and processing connection information for photo requests.
We may disclose data when required by law or when necessary to investigate abuse and protect the Service. We do not sell extension user data, provide it to data brokers, or use or transfer it for personalized advertising, creditworthiness, or lending decisions.
Chrome Web Store Limited Use
Our use of data obtained through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
We use extension data only to provide and improve its new-tab features and related operation, support, and security. Transfers are limited to what is needed for those purposes, compliance with law, protection against abuse, or a developer merger, acquisition, or asset sale with the user's explicit prior consent.
Human access to extension user data is limited to cases where the user explicitly consents to access to specific data, where access is necessary for security or legal compliance, or where data is aggregated and anonymized for internal operations in accordance with applicable law. For example, we read the information you choose to send when asking us for help.
Storage periods and deletion
Local extension data remains in your Chrome profile until it is replaced, cleared, or removed with the extension. You can edit or clear personal reminder text in the extension's settings. Synced copies are managed through Chrome and Google; removing the extension from one device does not itself guarantee deletion of every synced copy.
The API's rate-limit window is one hour. Expired rate-limit rows are removed when subsequent API requests run the cleanup. This is not a promise that every server log is deleted after one hour. Infrastructure logs and provider records follow the relevant service settings and retention policies.
We keep support correspondence for handling the request and any necessary follow-up or legal obligations. You can ask us to delete it. Website cookies and local storage remain until they expire or are cleared; analytics records are subject to the settings and retention policies of the analytics services.
To clear website data, use your browser's controls for beautifulphotos.app. To remove the extension, open Chrome's extension settings and choose Remove for Beautiful Photos. For data held by us, email mailbox@beautifulphotos.app. We cannot retrieve reminder text that we do not hold or erase data controlled independently by Google, Unsplash, or other services on your behalf.
Your rights and processing grounds
Depending on your location, you may have rights to access, correct, delete, or receive a copy of personal data, restrict or object to processing, withdraw consent, or complain to a data protection authority. Contact us to exercise these rights. We may need enough information to verify the request without collecting unnecessary additional data.
Where data protection law requires a legal basis, delivering the features you request may involve contractual necessity, and protecting the API and handling support may involve legitimate interests, subject to your rights. Legal obligations may also require processing. Processing that legally requires consent must rely on that consent; this policy does not replace it.
Security and international processing
Our production website and photo API use HTTPS. We limit the data used for each function, but no storage or transmission system can be guaranteed completely secure.
The infrastructure and providers described above may process data outside your country. The protection and rights available can differ by location. Transfers must follow applicable data protection requirements, and independent providers explain their international processing practices in their policies.
Children and policy changes
Beautiful Photos is not directed at children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and delete it where appropriate.
We will update this page when our data practices change and revise the date above. Material changes requiring further notice or consent will be handled as required by applicable law.
Contact
Send privacy questions and requests to mailbox@beautifulphotos.app. The Czech location reference on the Contact page is not a postal address for privacy requests.