Privacy Policy and Data Handling
Plain-language data handling for Favicon.now tools, optional accounts, saved projects, public-site checks, analytics, and downloads.
How data moves through Favicon.now
- 01
Local editing and package generation
Source artwork is loaded into the editor in your browser for composition and preview. When you request a downloadable ZIP, the rendered square and any optional sanitized SVG source are sent to the package endpoint and processed in memory. Ordinary downloads are not intentionally retained as a user asset library.
Do not submit artwork containing information you do not want processed for the requested conversion. Generated downloads remain your responsibility after they reach your device.
Continue with the browser-based favicon generator for the practical next step.
- 02
Optional Google sign-in
The generators, downloads, checkers, and guides do not require an account. If you choose Google sign-in, Favicon.now receives a stable Google account identifier, verified email address, and display name through OpenID Connect. A profile-picture claim may be present in Google’s response, but Favicon.now does not intentionally store it.
The service stores an account session cookie so it can recognize your signed-in browser. The cookie is HTTP-only, uses SameSite protection, and is marked Secure on the HTTPS production deployment. Favicon.now does not request Google Drive, contacts, Calendar, Gmail, or publishing permissions.
Continue with the optional Google sign-in screen for the practical next step.
- 03
Saved favicon projects
Choosing Save to dashboard stores the rendered 512×512 PNG, project name, optional website URL, source mode, package settings, sharing state, and creation or update dates. The original upload and optional SVG source are not stored with the project. Saved projects are hidden from other users and private by default; authorized Favicon.now administrators can review the rendered sample and project metadata for support, abuse prevention, and service quality.
You can update a project label, download its generated package again, or delete the project from the dashboard. Deleting it removes the saved preview record and disables the corresponding sharing token. Database backups or infrastructure snapshots may persist temporarily under the host’s normal retention controls.
Continue with the favicon generator and save workflow for the practical next step.
- 04
Public sharing links
A saved project becomes publicly reachable only when its owner turns sharing on. The random sharing URL exposes the project title, optional attached website, rendered preview, and downloadable generated package. Shared pages are marked noindex by default, but anyone who receives the URL can open it while sharing remains enabled.
Turning sharing off immediately makes the public route unavailable in the application. Do not attach a website or title containing information you do not want recipients to see.
Continue with the sharing and attribution toolkit for the practical next step.
- 05
Public website checks and extraction
The checker and extractor request only the public URL you submit and the public icon or manifest destinations discovered from it. Localhost, private address ranges, and non-public network targets are blocked. The service does not sign in to the submitted website or access private CMS files.
For each checker or extractor request, Favicon.now stores the submitted public URL, final resolved URL, tool type, outcome, HTTP status or score when available, optional signed-in account ID, and date for up to the configured activity-retention period. Query strings and fragments are removed before storage, and this activity record does not add an IP address or user agent. Authorized administrators use it for service quality, support, and abuse review. Do not use these tools to probe systems you do not own or have permission to test.
Continue with the public favicon checker for the practical next step.
- 06
Traffic analytics
Public pages use Clicky, a third-party traffic analytics service, to measure visits, referrers, device and browser categories, navigation patterns, and basic engagement. The Clicky script is not loaded on login, authentication, dashboard, API, or private sharing routes.
Analytics requests can disclose the public page URL, IP address, user agent, referrer, and similar network metadata to Clicky. Browser or service settings may use cookies or comparable identifiers. Favicon.now uses this information for aggregate site improvement rather than advertising profiles; Clicky publishes its own privacy terms at clicky.com/terms/privacy.
Continue with how Favicon.now measures and improves public pages for the practical next step.
- 07
Service logs and security
Infrastructure can record request time, URL, IP address, user agent, response status, and diagnostic information needed to operate, secure, and troubleshoot the service. Retention depends on operational and hosting controls and should be limited to legitimate reliability, abuse-prevention, and security needs.
The service does not intentionally include advertising profiles or cross-site marketing pixels. Reverse proxies, hosting providers, and the disclosed Clicky analytics service can process the network metadata required for delivery, measurement, reliability, and abuse prevention.
Continue with how Favicon.now processes and tests files for the practical next step.
- 08
External links and policy changes
Guides link to third-party specifications and platform documentation. Those destinations operate under their own privacy terms. Favicon.now does not control their logging, cookies, or content after you follow an external link.
Material changes to data handling should be reflected on this page with a revised update date. Continue using the service only when the current policy is acceptable for the artwork and public URLs you submit.
Continue with the sourcing and update policy for the practical next step.
Last updated: July 31, 2026