imagegrain

Privacy Policy

Last updated: September 20, 2026

Overview

imagegrain is primarily a local film-grain tool. The website editor and the Claude Desktop / stdio MCP server process photos on your device and do not upload them. The optional hosted MCP endpoint at imagegrain.com/mcp is different: a photo you or your assistant send there is processed transiently on our server and then discarded. We do not use cookies, analytics, or tracking scripts. This policy explains those paths and your rights under the EU General Data Protection Regulation (GDPR).

Data Controller

Maximilian Braun
Burgstallgasse 10
93309 Kelheim
Germany
Email: maximilian.braun@posteo.de

Browser Editor: Photos Stay on Your Device

When you choose a photo in the editor, it is loaded and processed entirely on your device using your browser's built-in canvas technology. The image is never transmitted to our servers or any third party, and we never gain access to it. Grain and film-look effects are applied locally, and when you download the result, the file is generated and saved directly by your browser. Exported files also have EXIF metadata (such as location and camera information) stripped automatically.

Desktop Extension and MCP Server

The optional Claude Desktop extension and the open-source MCP server in this repository apply the same grain engine on your own computer. They read a photo from a local file or from image data included in the tool call, process it in memory, and write a new file only if you asked for one. They do not upload your photos to imagegrain.com or to any other server, they do not create an account, and they do not send analytics. In Claude Desktop, the grained photo is returned in the chat so you can view and download it. A file is written only if you explicitly ask for an output path. Anthropic's own products may retain conversation content under their terms; that is separate from this software.

Hosted MCP and Muse Connector

If you or an assistant such as Muse call https://imagegrain.com/mcp, the still photo in that request is sent to a server we operate. This is the only imagegrain surface that receives photo bytes. Legal basis: performance of a requested service (Art. 6(1)(b) GDPR).

Photos are decoded, grained, and re-encoded in memory. Input and output buffers are discarded when the request finishes. We do not store photos, do not use them for training, and do not build user profiles from them. Re-encoding strips EXIF metadata such as location and camera information. Infrastructure logs may include IP address, time, request size, and status code; they do not include image bodies. Muse, Meta, or any other assistant that called the endpoint may retain conversation attachments under their own terms.

Server Log Data

Like virtually all websites, when you visit imagegrain.com our hosting infrastructure automatically records a small set of technical information transmitted by your browser, typically including: your IP address, browser type and version, operating system, referring page, and the date and time of the request. This happens automatically as a function of how the internet works and is not linked to any other data we hold, because we hold none. This data is processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in operating a secure and stable website, and is automatically deleted by our hosting infrastructure after a short period unless retention is required to investigate a security incident.

Cookies & Local Storage

This website does not set any cookies and does not use browser local storage or session storage. No consent banner is shown because none of the technologies that would require one are in use. If this ever changes - for example, if we add analytics in the future - we will update this policy and request your consent first, where required by law.

No Analytics or Tracking

We do not use Google Analytics, advertising pixels, or any other analytics or tracking service. Hosted MCP operational logs are described above and are not used to profile you.

Fonts

This site uses the Geist typeface, which is self-hosted as part of our website build. Font files are served directly from our own domain rather than loaded from Google's servers at page-load time, so no data about you is sent to Google in order to display this page.

No Accounts or Forms

There is no account creation, login, contact form, or newsletter signup on this website. We do not collect your name, email address, or any other personal data that you might otherwise submit through such features, because they do not exist here.

Your Rights

Under the GDPR, you have the right to request access to, rectification of, or erasure of your personal data, to request restriction of or object to its processing, and to data portability. Since we do not collect or store personal data beyond short-lived server logs, most of these rights will typically have nothing to act on - but you are welcome to contact us at any time using the email address above with any question or request.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach
Germany
www.lda.bayern.de

Changes to This Policy

If we ever change how this website handles data — for example, by adding analytics, a contact form, or changing hosted MCP retention — we will update this page and revise the date at the top. We encourage you to review this policy periodically.

View our Imprint·View our Terms