Zero Data Mining Privacy by Design

Privacy & Data Security Policy

ImageEngine is engineered as a stateless edge delivery network. We do not store, profile, sell, or analyze visitor personal data.

🔒

Stateless In-Memory

Images undergo transformations in volatile serverless RAM. We never store image binaries in persistent databases or secondary storage.

🚫

Zero Tracking / Cookies

Our edge responses contain zero tracking pixels, analytics cookies, or behavioral beacons. Requests are strictly stateless.

🌍

GDPR & CCPA Ready

Since no personal identifiable information (PII) is gathered or retained, your integration with ImageEngine automatically complies with global privacy mandates.

1

Information We Process

When an end-user browser requests an asset via ImageEngine, our edge edge nodes receive the standard technical headers required to negotiate image formats and delivery:

  • Accept Header: Used solely to determine modern codec support (e.g. WebP, AVIF).
  • IP Address: Processed ephemerally at Cloudflare's edge PoP to route traffic to the geographically nearest server and protect against DDoS attacks. IP addresses are not logged permanently or linked to individual identities.
  • Referer / Origin: Evaluated to ensure the requesting domain is an approved tenant.
2

Tenant Isolation & Origin Security

Every organization routing assets through ImageEngine is assigned a unique, cryptographically enforced tenant namespace. An origin cannot access or manipulate assets belonging to another registered tenant.

All communications between clients, Cloudflare Edge, ImageEngine compute lambdas, and your origin server are strictly encrypted using TLS 1.3.

3

Diagnostic Logging

To maintain 99.9% uptime and safeguard infrastructure health, we retain aggregated technical telemetry (HTTP status codes, transformation duration, cache hit ratios) in rolling 72-hour log buffers. These logs are automatically rotated and permanently purged.

4

Contact Information

If you have questions regarding our edge privacy architecture or data security practices, submit an inquiry via our contact form at https://grisma.info.np/contact.