Privacy Policy
Your images never leave your device. This policy explains that, and everything else we do and do not collect.
Effective date: 2026-08-22 · Last updated: 2026-08-22 · Version: 1.0
The short version. Every image you open in Invo is processed inside your own browser. Images are never transmitted to us or to anyone else, so we cannot see them, store them, or share them. What we do collect is limited to standard server logs and, if advertising is enabled, advertising cookies set by Google. Details below.
1. Who we are
This website, Invo — The Image Editor at invo.testationery.in
("Invo", "the Service"), is operated by Tirth Enterprise, Rajkot, Gujarat, India
("we", "us", "our").
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary in respect of personal data processed through this website. For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), where applicable, we are the Data Controller.
Contact for privacy matters: privacy@testationery.in
2. Scope of this policy
This policy applies to invo.testationery.in and its subpages. It does not apply to
any other website, including testationery.in, or to third-party websites reachable
through links on this site, each of which operates under its own policy.
By using the Service you confirm you have read this policy. Where the law requires your consent for a specific processing activity, we ask for it separately and by an affirmative action — we do not treat continued browsing, or a pre-ticked box, as consent.
3. Your images are not collected
This is the single most important thing in this document, so it has its own section.
All image processing in Invo — decoding, converting, compressing, resizing, cropping, and everything else — is performed locally, inside your web browser, using WebAssembly and the browser's own graphics capabilities. When you select or drag a file into a tool:
- The file is read from your device's storage directly into your browser's memory.
- It is processed there, on your own processor.
- The result is written back to your device when you press Download.
At no point is your image, or any part of it, transmitted to our servers, to Tirth Enterprise, or to any third party. No copy is retained anywhere. We have no technical means of accessing your images, and no image data is logged, cached server-side, or backed up.
This also applies to metadata contained within your files, including EXIF data and GPS coordinates. Where a tool displays such metadata to you (for example the EXIF viewer), that reading happens in your browser and the values are shown only to you.
You can verify this yourself: load any tool page, disconnect your device from the internet, and the tool will continue to work normally. You may also inspect network activity using your browser's developer tools while converting a file.
Everything stored in memory is discarded when you close or reload the tab. Invo does not use cookies, local storage, or any other browser storage to retain your files or your activity.
4. What we do collect
4.1 Server log data
Our hosting provider automatically records standard technical information when your browser requests a page. This is inherent to how the web works and applies to every website you visit. It includes:
- Your IP address
- The date and time of the request
- The page or file requested, and the HTTP response code
- Your browser type and version, and your operating system (the "user agent")
- The referring page, where your browser supplies one
Purpose: operating and securing the website, diagnosing faults, detecting abuse and denial-of-service activity, and producing aggregate statistics about which tools are used.
Legal basis: under the DPDP Act, this is processing for the legitimate use of providing the service you have requested. Under the GDPR, our legitimate interests (Article 6(1)(f)) in operating a secure and functioning website.
4.2 Analytics
We may use a web analytics service to count visits and understand which tools are used. Analytics records page views, approximate location derived from IP address, device category and referral source. It does not and cannot record the content of any image you process.
Where analytics relies on cookies or similar technologies that are not strictly necessary, we seek your consent where the law requires it.
4.3 Advertising
This site may display advertising in order to cover hosting costs. Where advertising is enabled, it is served by Google AdSense. Google and its partners may set and read cookies, or use similar identifiers, in order to serve and measure advertisements. This may include personalised advertising based on your prior visits to this and other websites.
Google's use of advertising cookies is governed by Google's privacy and terms for partner sites. You may opt out of personalised advertising at Google Ads Settings, or opt out of third-party vendor cookies at aboutads.info/choices.
Advertisers and ad networks have no access to your images. Advertising is rendered in a separate part of the page and is technically incapable of reaching the image data held in your browser's memory by the tools.
4.4 Information you send us voluntarily
If you contact us by email — to report a bug, ask a question, or exercise a right under section 9 — we receive whatever you choose to include: your email address, your name if you give it, and the content of your message. We use it solely to respond to you.
4.5 What we never collect
- Your images, or any data derived from them
- Account credentials — Invo has no accounts and no login
- Payment information — Invo is free and processes no payments
- Government identifiers, financial information, health information or biometric data
- Contact lists, calendars, files or any other data from your device
5. Cookies and similar technologies
Invo itself sets no cookies for tracking, analytics or personalisation. No cookie is required for any tool to function.
| Category | Set by | Purpose | Typical duration |
|---|---|---|---|
| Strictly necessary | Hosting provider | Security, load balancing and abuse prevention | Session |
| Analytics | Analytics provider, if enabled | Aggregate visit counts | Up to 24 months |
| Advertising | Google and its partners, if enabled | Ad serving, frequency capping, measurement | Up to 24 months |
You can block or delete cookies through your browser settings. Doing so does not affect any Invo tool, because none of them depend on cookies.
6. Third parties who may process data
| Party | Role | Data involved |
|---|---|---|
| Hostinger | Web hosting | Server log data, including IP address |
| Google (AdSense) | Advertising, if enabled | Cookie identifiers, IP address, ad interaction data |
| Analytics provider | Aggregate statistics, if enabled | Page views, approximate location, device category |
We do not sell personal data. We do not share personal data with third parties for their own independent marketing purposes. We may disclose information where we are legally required to do so by a court, regulator or law enforcement authority acting under valid legal process.
7. Data retention
| Data | Retention period |
|---|---|
| Your images and anything derived from them | Not retained at all — never received |
| Server access logs | Up to 90 days, then deleted or anonymised |
| Aggregate analytics | Up to 26 months, in aggregate form |
| Email correspondence | Up to 24 months after the matter is closed |
| Records of rights requests and grievances | As required by applicable law, typically 3 years |
Where we no longer need personal data for the purpose it was collected, and no legal obligation requires us to keep it, we delete it.
8. Security
We apply reasonable security safeguards appropriate to the limited nature of the data we hold:
- The entire site is served over HTTPS with a valid TLS certificate.
- The architecture itself is the principal safeguard — image data is never transmitted, so it cannot be intercepted in transit or exposed by a breach of our servers.
- Access to hosting infrastructure is restricted and password protected.
- No database of user data exists, because no user data of that kind is collected.
No system can be guaranteed perfectly secure. In the event of a personal data breach affecting you, we will notify the Data Protection Board of India and affected individuals without undue delay and in accordance with the timelines set out in the DPDP Rules, 2025, and will notify supervisory authorities under the GDPR within 72 hours where that regulation applies.
9. Your rights
9.1 Under the DPDP Act, 2023 (India)
If you are a Data Principal in India, you have the right to:
- Access — obtain a summary of the personal data we process about you and the processing activities undertaken.
- Correction and erasure — have inaccurate or misleading data corrected, incomplete data completed, and data erased where it is no longer required.
- Grievance redressal — raise a grievance with us, through the mechanism in section 10, before approaching the Data Protection Board.
- Nominate — nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
- Withdraw consent — where processing relies on your consent, withdraw it at any time, as easily as it was given. Withdrawal does not affect processing carried out before it.
9.2 Under the GDPR (EEA and UK)
If you are in the European Economic Area or the United Kingdom, you additionally have rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, together with the right to lodge a complaint with your national supervisory authority.
9.3 Under the CCPA/CPRA (California)
If you are a California resident, you have the right to know what personal information is collected and for what purpose, the right to request deletion, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. We do not sell personal information. We do not knowingly process the personal information of anyone under 16 for advertising purposes.
9.4 A practical note
Because we hold so little, most requests are answered quickly. We generally cannot identify an individual from server log data alone, and we hold no images at all — so for many requests the honest and complete answer is that we hold nothing about you beyond a transient log entry.
10. How to exercise your rights, and grievance redressal
Write to us at privacy@testationery.in with the subject line "Data request" or "Grievance", and describe what you are asking for. Include enough detail for us to locate any relevant records — typically the approximate date and time of your visit.
Grievance Officer
Grievance Officer
Tirth Enterprise, Rajkot, Gujarat, India
Email: privacy@testationery.in
Our timelines. We acknowledge every request promptly and aim to resolve rights requests within 7 working days. Where a request is complex we may extend this, and we will tell you why. Grievances are resolved within 90 days at the latest, as required by the DPDP Rules, 2025. Any refusal will state the specific legal basis for it.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India. If the GDPR applies to you, you may complain to your national data protection supervisory authority.
11. Children
Invo is a general-purpose utility and is not directed at children. We do not knowingly collect personal data from children under 18 (under the DPDP Act) or under 16 (under the GDPR) without verifiable parental consent, and we do not undertake tracking or targeted advertising directed at children.
If you believe a child has provided us with personal data, contact us and we will delete it.
12. International transfers
We are based in India and our hosting is provided by Hostinger. Third-party services we use, including Google, may process data on servers located outside India, including in the United States and the European Union. Where such transfers occur, they are made in reliance on the safeguards offered by those providers, including standard contractual clauses where applicable.
13. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you.
14. Changes to this policy
We may update this policy to reflect changes to the Service, our providers, or the law. The effective date at the top of this page always shows the current version. Material changes will be signposted on this page. We encourage you to review it periodically.
15. Contact
Tirth Enterprise
Rajkot, Gujarat, India
Email: privacy@testationery.in
Website: testationery.in
A note on this document. It has been drafted to reflect how Invo actually works and to address the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, alongside the GDPR and CCPA. It is not legal advice. Before relying on it, have it reviewed by a qualified Indian data protection lawyer, and fill in the Grievance Officer name.