Privacy Policy and Data Handling

Plain-language data handling for Favicon.now tools, optional accounts, saved projects, public-site checks, analytics, and downloads.

How data moves through Favicon.now

  1. Local editing and package generation

    Source artwork is loaded into the editor in your browser for composition and preview. When you request a downloadable ZIP, the rendered square and any optional sanitized SVG source are sent to the package endpoint and processed in memory. Ordinary downloads are not intentionally retained as a user asset library.

    Do not submit artwork containing information you do not want processed for the requested conversion. Generated downloads remain your responsibility after they reach your device.

  2. Optional Google sign-in

    The generators, downloads, checkers, and guides do not require an account. If you choose Google sign-in, Favicon.now receives a stable Google account identifier, verified email address, and display name through OpenID Connect. A profile-picture claim may be present in Google’s response, but Favicon.now does not intentionally store it.

    The service stores an account session cookie so it can recognize your signed-in browser. The cookie is HTTP-only, uses SameSite protection, and is marked Secure on the HTTPS production deployment. Favicon.now does not request Google Drive, contacts, Calendar, Gmail, or publishing permissions.

  3. Saved favicon projects

    Choosing Save to dashboard stores the rendered 512×512 PNG, project name, optional website URL, source mode, package settings, sharing state, and creation or update dates. The original upload and optional SVG source are not stored with the project. Saved projects are hidden from other users and private by default; authorized Favicon.now administrators can review the rendered sample and project metadata for support, abuse prevention, and service quality.

    You can update a project label, download its generated package again, or delete the project from the dashboard. Deleting it removes the saved preview record and disables the corresponding sharing token. Database backups or infrastructure snapshots may persist temporarily under the host’s normal retention controls.

  4. Public sharing links

    A saved project becomes publicly reachable only when its owner turns sharing on. The random sharing URL exposes the project title, optional attached website, rendered preview, and downloadable generated package. Shared pages are marked noindex by default, but anyone who receives the URL can open it while sharing remains enabled.

    Turning sharing off immediately makes the public route unavailable in the application. Do not attach a website or title containing information you do not want recipients to see.

  5. Public website checks and extraction

    The checker and extractor request only the public URL you submit and the public icon or manifest destinations discovered from it. Localhost, private address ranges, and non-public network targets are blocked. The service does not sign in to the submitted website or access private CMS files.

    For each checker or extractor request, Favicon.now stores the submitted public URL, final resolved URL, tool type, outcome, HTTP status or score when available, optional signed-in account ID, and date for up to the configured activity-retention period. Query strings and fragments are removed before storage, and this activity record does not add an IP address or user agent. Authorized administrators use it for service quality, support, and abuse review. Do not use these tools to probe systems you do not own or have permission to test.

  6. Traffic analytics

    Public pages use Clicky, a third-party traffic analytics service, to measure visits, referrers, device and browser categories, navigation patterns, and basic engagement. The Clicky script is not loaded on login, authentication, dashboard, API, or private sharing routes.

    Analytics requests can disclose the public page URL, IP address, user agent, referrer, and similar network metadata to Clicky. Browser or service settings may use cookies or comparable identifiers. Favicon.now uses this information for aggregate site improvement rather than advertising profiles; Clicky publishes its own privacy terms at clicky.com/terms/privacy.

  7. Service logs and security

    Infrastructure can record request time, URL, IP address, user agent, response status, and diagnostic information needed to operate, secure, and troubleshoot the service. Retention depends on operational and hosting controls and should be limited to legitimate reliability, abuse-prevention, and security needs.

    The service does not intentionally include advertising profiles or cross-site marketing pixels. Reverse proxies, hosting providers, and the disclosed Clicky analytics service can process the network metadata required for delivery, measurement, reliability, and abuse prevention.

  8. External links and policy changes

    Guides link to third-party specifications and platform documentation. Those destinations operate under their own privacy terms. Favicon.now does not control their logging, cookies, or content after you follow an external link.

    Material changes to data handling should be reflected on this page with a revised update date. Continue using the service only when the current policy is acceptable for the artwork and public URLs you submit.

Last updated: July 31, 2026