Privacy Policy
Last updated: July 14, 2026
Your photos and video never leave your device. MakeHDR processes everything locally in your browser using WebAssembly — photos and video alike. We do not upload, store, or have any access to your files.
What we collect
If you create an account: your email address, name (optional), and a hashed password (or your Google or Apple account identifier). For billing we store your plan and Paddle customer references — card details are handled exclusively by Paddle. For purchases made inside the iPhone, iPad or Mac apps, billing is handled by Apple and we store only your subscription status.
What we don't collect
Your photos, videos, their metadata, or any derivative of them. They are processed in your browser's memory — and, in the MakeHDR apps, locally on your device — and never transmitted to our servers.
Third-party services
We use the following services to operate MakeHDR: Paddle (paddle.com) — payment processing for web purchases, acts as Merchant of Record and handles billing data including email and payment information. Apple (apple.com) — Sign in with Apple, and payment processing for purchases made inside the iPhone, iPad and Mac apps, where Apple is the Merchant of Record. Google (google.com) — OAuth sign-in; if you use Sign in with Google, Google receives authentication requests and we store your Google account ID, email and avatar. PostHog (posthog.com) — product analytics, receives page views and feature usage events. On the web it's loaded only after you accept the cookie banner, and your user ID, email and plan are included if you are signed in. In the iPhone, iPad and Mac apps it runs in anonymous mode only — never linked to your account — and can be turned off anytime from Account → Share Analytics. Sentry (sentry.io) — error monitoring, receives crash reports, stack traces and browser or device information; in the apps it's controlled by the same Share Analytics toggle. Resend (resend.com) — transactional email delivery, receives your email address to send password reset and verification emails. Vercel (vercel.com) — hosting and cookieless page-view analytics; like any host, its servers see your IP address in request logs. Upstash (upstash.com) — rate limiting for sign-in and email endpoints, processes your IP address transiently. Neon (neon.tech) — database hosting for account data.
Cookies & local storage
MakeHDR uses a few essential cookies: sign-in and security cookies, set only once you have an account, and a locale cookie that remembers the language you chose. Paddle, our checkout provider, also sets a bot-protection cookie on the pages that show pricing. None of these are used for tracking. On the web, analytics (PostHog) is loaded only after you press Accept on the cookie banner — once accepted, it stores its own cookies and local-storage entries. Your choice is saved in your browser's local storage; if you decline, no analytics cookies are set and everything keeps working. The iPhone, iPad and Mac apps don't show a cookie banner — instead, analytics and crash reporting can be turned off anytime from Account → Share Analytics, and are anonymous either way.
Data deletion
You can permanently delete your account and all associated data at any time from your account page. This also cancels any active subscription. To request deletion of any data held by our third-party analytics provider (PostHog), contact support@makehdr.com.
Contact
Questions: support@makehdr.com