Privacy Policy
What LGTMate collects, and how it is handled.
Last updated: September 6, 2026
1. Editing happens in your browser
The image you pick on the create page is not sent to the server until you press Publish. Drawing the text and exporting the PNG both happen inside your browser. If you only download the result, no copy of your image is left on the server.
2. What we collect
- Published images
- The image itself, its tags, the publish time, and its dimensions. Stored only when you publish. Metadata such as capture time and location is stripped and the image is re-encoded before we store it.
- Account information
- Your email address, display name, and a hash of your password. If you sign in with GitHub or Google, we receive your email address and display name from that service. We never store the password itself.
- Information used to count posts made without an account
- A hash of the posting token issued to your browser, and how many posts that browser has made. We do not store the token itself.
- Hashed IP address
- Stored when you publish or send a report, to limit abuse. We do not store the raw IP address, only a hash computed with a secret key. The original address cannot be recovered from it.
- Reports
- The reason given, any optional detail, and the time received.
- Records of image views
- For each published image, the time it was last viewed and how many hours had at least one view. This tells us which images are unused. We do not record who viewed it: no IP address, user agent, or referring page.
We use no third-party analytics service, and we do not send browsing records anywhere.
3. Kept only in your browser
Your favorites and your theme (light or dark) are stored only in your browser (localStorage) and are never sent to the server. Clearing your browser data removes them.
4. How we use it
- Running the Service and delivering published images.
- Acting on reports and investigating breaches of the terms.
- Defending against unauthorised access and bulk posting.
- Investigating faults and improving quality.
5. Cookies
We use cookies to keep you logged in, to protect against CSRF, to count posts made without an account, and to remember your display language. We use no advertising or tracking cookies.
6. Service providers
We do not pass what we collect to third parties, except where the law requires it. We rely on the following providers to run the Service.
- Cloudflare, Inc.
- DNS, content delivery, the connection to our server, access control for the admin pages, the object storage that holds the images (Asia-Pacific), and forwarding for our contact address.
- SAKURA Internet Inc.
- The server running the application and the database (in Japan).
- Resend, Inc.
- Sending email confirmation and password reset messages (Tokyo region).
- GitHub, Inc. and Google LLC
- Only if you use GitHub or Google sign-in: authentication and passing us your email address and display name.
Some of these providers operate facilities outside Japan, so the information above may be handled outside Japan.
7. Advertising
We show no advertising. If we ever do, we will explain the provider and what it collects on this page before we start.
8. Retention and deletion
- A post you delete disappears immediately, and the stored image file is erased after seven days.
- A post hidden by an administrator is kept, not deleted, for as long as investigating reports requires.
- Backups are stored encrypted and discarded after a limited period. We do not look inside them except to restore the Service.
9. Deleting your account
There is no self-service account deletion. To have your account deleted, email contact@lgtmate.com. Let us know as well if you still have published posts.
An image published without logging in cannot be deleted by the person who posted it. To have one removed, use Contact and include the URL of the image.
10. Contact
For questions about this policy, use Contact.