Privacy Policy
Last updated:
This policy explains the information used when you browse FunPFP, create an account, save pictures, submit artwork or report a problem. It covers the new FunPFP service; an older version of the website may use different services.
For support, privacy requests and rights concerns: info@funpfp.com.
Information we use
Browsing public galleries and downloading individual images does not require an account. Hosting providers receive network information, such as an IP address and request details, to deliver pages, prevent abuse and operate the service. This is separate from the aggregate analytics described below.
When you register, our authentication provider processes your email address, password and session information. Your password is handled by Supabase authentication; it is not displayed in your public profile. We use an account ID, username and account role to provide access to your account and manage submissions.
- Account data: email address, username, authentication records and account status.
- Content data: submitted images, titles, descriptions, categories, tags, origin labels and publication status.
- Activity you choose to save: favorites, collections and reports, including review or report reasons.
Public and private information
Published images, their titles and descriptions, assigned categories and tags, uploader usernames and approved public collections can be viewed by other visitors. Do not put private information into public metadata or artwork.
New submissions are reviewed before publication. Private collections and unpublished submissions are restricted by access controls. Authorized administrators and moderators may access information needed for review, support or abuse handling. Your login email is not included in public image metadata.
Why we use this information
We use account information to authenticate you, protect access and synchronize saved content. We use submitted files and metadata to process images, organize the library and display approved content. Reports and review information help us investigate misuse, ownership disputes and technical problems.
We do not sell account email addresses or use upload metadata as an advertising audience list. Provider processing and advertising, if enabled, are described separately below.
Browser storage and image processing
Sign-in uses authentication cookies. Favorites can be stored in local storage in your browser and, when signed in, in your account. Administrator bulk-upload recovery can store selected files and batch metadata in IndexedDB on that device so an interrupted batch can be resumed.
Uploads may be resized and converted to WebP, with a smaller thumbnail for galleries. Original uploads are held in restricted storage; approved processed images are served publicly. Clearing browser site data removes local favorites and saved batches, but does not delete records held in your account.
Aggregate analytics
We count successful public page responses and image download responses by day, page, broad traffic-source category, country and device category. These aggregate records contain no IP address, account email, full referrer URL, search terms or unique visitor identifier. They use no analytics cookie. Country and device categories are derived from the request before aggregation.
Staff traffic, recognized bots, prefetches, automatic gallery fetches and requests carrying Do Not Track or Global Privacy Control signals are excluded from these counters. Repeat visits and unrecognized automated requests may still count. These exclusions apply to our aggregate counters; they do not promise that network providers stop processing the request.
Service providers and international processing
Cloudflare provides hosting, image storage and aggregate analytics storage. Supabase provides authentication and database services. These providers may process technical and account information to operate, secure and maintain their services. Their infrastructure may process information outside your country.
An email delivery provider may be configured for account verification and password recovery. Email delivery is not yet configured on this preview. We update this policy when the service changes materially.
Advertising
Google AdSense is not active on this new preview. If ads are enabled, Google and participating advertising partners may use cookies, device identifiers, IP addresses and similar technologies to deliver and measure advertisements, prevent fraud and personalize ads where permitted. Advertising has different data practices from our own aggregate counters.
Before ads are activated, FunPFP will provide the applicable consent controls and update provider disclosures. See Cookies & Advertising for details and links to Google privacy choices.
Retention and deletion
Account records, synchronized favorites and collections remain stored while they support an active account. Uploads and review records remain stored while needed for processing, publication, moderation or a dispute. There is currently no automatic expiry schedule for these records or aggregate daily counters.
You may request account deletion or removal of your content through Contact. We verify ownership before changing account records. Where applicable, information may need to be retained for an unresolved report, security investigation or legal obligation. Provider backups and caches may remain for their normal lifecycle; deletion is not a promise of immediate removal from every backup or from copies already downloaded by visitors.
Your choices and privacy requests
You can remove favorites, change available profile settings and manage your collections through your account. You can clear browser storage using your browser settings. Contact us to request access, correction, a copy of account information or deletion, and identify the account and request without sending a password.
Privacy rights and the basis for processing depend on your location. We assess applicable requests under the rules that apply to the service and the requester. You may also contact the relevant privacy regulator where that right applies.
Children and policy changes
Do not create an account if you are under 13 or below the age required to use this service independently where you live. A parent or guardian can contact us about an account or image containing a child’s personal information.
The date on this page identifies the latest update. Significant changes to account processing or advertising will be reflected here.