Raspy edits photos in your browser. They are not uploaded, and there is no server that could receive them. This page describes the little that is collected, and how to stop it.
Last updated 27 September 2026
Photos never leave this device. Decoding, editing, and encoding all happen in the page, and no upload path exists in the application — there is no endpoint that a photo could be sent to. Nothing about an image, an edit, a crop, or an export is transmitted anywhere, including to analytics.
Nothing is written to disk. The photo you are editing lives in memory for as long as its tab is open and is gone the moment you close it — which does mean a closed tab loses the edit. Earlier versions kept one draft in IndexedDB; that store is deleted the next time you open Raspy. The offline cache is written so that image data can never enter it.
Exports are re-encoded from raw canvas pixels, which drops EXIF and GPS metadata. A photo you share from Raspy does not carry the location where it was taken.
Your theme, sound, and analytics preferences are kept in this browser’s local storage, under the keys raspy:theme, raspy:sound, and raspy:consent:v2. They are never sent anywhere and are readable only by this site, on this device.
Raspy counts page visits using Google Analytics 4 (property G-SJ63XD3708) and PostHog, to see whether the project is worth continuing. Both measure visits, not use: no photo, edit, crop, or export detail is ever passed to either. Google Signals and advertising personalisation are disabled, and advertising storage is refused in every country. Nothing collected is sold, and none of it is used for advertising.
When analytics is on, Google sets two cookies — _ga and _ga_SJ63XD3708 — which distinguish one browser from another for up to two years. They contain a randomly generated identifier, not your name or anything you have typed. Google also processes your IP address to approximate your country; IP addresses are not retained by Google Analytics. Collected data is retained for 14 months and then deleted automatically.
PostHog receives page views and page leaves only. Click tracking, session recording, heatmaps, error reporting, and surveys are all switched off in the code, not merely in a dashboard. Once you accept, PostHog keeps a randomly generated identifier in two cookies, ph_phc_mQ9BnAswsrtCSW9NrTgYwAdNnyyMTDSuEwS3teT3Dg5J_posthog and ph_phc_mQ9BnAswsrtCSW9NrTgYwAdNnyyMTDSuEwS3teT3Dg5J_posthog_cpm, and in local storage, readable only by this subdomain. If you have not made a choice, it keeps that identifier in memory instead, so nothing is stored and each visit is counted on its own. PostHog processes your IP address to approximate your location.
If you are in the EU, EEA, UK, or Switzerland, analytics storage is refused by default and nothing is stored until you accept. That default is enforced by Google on the basis of your IP address, so it applies whether or not the consent banner appeared for you. Where consent applies, the legal basis is your consent under Article 6(1)(a) GDPR and the ePrivacy Directive.
PostHog has no equivalent of Google’s IP-based default, so for it the decision is made in your browser: if your timezone is anywhere in Europe and you have not accepted, PostHog is not loaded at all. If you accepted analytics before PostHog was added, you are asked again; if you declined, that decline still stands.
You can change your mind at any time, here or from Settings inside the editor. Turning it off stops measurement immediately and expires the analytics cookies already set.
This control reflects the choice stored in this browser. Clearing your browser data resets it, and the banner will ask again.
The site is served as static files by Cloudflare, which processes your IP address and request metadata in order to deliver the page and to protect the service from abuse. This is ordinary server operation and happens for every website; no photo is included, because no photo is ever sent. The legal basis is legitimate interest under Article 6(1)(f) GDPR.
Google and PostHog (analytics) and Cloudflare (hosting) are the only third parties, and all three may process data outside the EEA, including in the United States, where PostHog stores this project’s data. Those transfers rely on the European Commission’s standard contractual clauses and the EU–US Data Privacy Framework. There is no other recipient: no database, no object store, no advertising network, and no analytics beyond the two named above.
Under the GDPR you may request access to your personal data, its correction or erasure, a restriction on its processing, a copy of it in portable form, or object to processing. You may also complain to your national data protection authority.
In practice there is very little to exercise these rights against. Your photos and settings are on your own device and are not accessible to anyone else — clearing your browser data erases them completely. Analytics data is pseudonymous and holds no identifier that could be traced back to you, so a request to delete it usually cannot be matched to a specific person. Turning analytics off, above, removes the cookies that link your visits together.
Raspy is not directed at children and does not knowingly collect personal data from them.
If what is collected changes, this page changes with it and the date at the top is updated. A change that widens what is collected will ask for consent again rather than assume the previous answer.
Raspy is operated by Rashmita Parmanik, who is the data controller. For any privacy question or request, write to rashmitaparmanik9876@gmail.com.