Privacy Policy
Last updated: 25 August 2026
Product Photo Studio is a website at productphoto.bnj.app, operated by Hugo Software. This page explains exactly what happens to your data. It is deliberately specific, because the honest answer is different for the two halves of the tool.
The short version
The browser studio — cropping, background removal, shadows, file naming, the ZIP — runs entirely on your own computer. Your photographs are not uploaded and we never receive them.
AI operations are the exception. They cannot run in a browser, so if you use one, your photograph really is sent to our server and on to a processing provider. We say so on the button, and we describe it in full below. AI operations are currently switched off, so no photographs are being transmitted at all today.
We do not ask for your name, your email address or a password.
1. The browser studio: nothing is uploaded
Choosing a marketplace preset, cropping, removing a plain background, adding the contact shadow, encoding the JPEG or PNG, renaming files and building the ZIP archive all happen inside your browser tab, in JavaScript.
There is no endpoint on our servers that accepts a product photograph for any of this, and there will not be one. Your photographs are not sent anywhere, not stored by us, and not seen by us.
The practical consequence, stated plainly: if you close the tab, the results are gone. We cannot recover them for you, because we never had them.
2. AI operations: what is transmitted
Three operations — cutting a product out of a busy background, placing it on a new scene, and enlarging a small photograph — require an image model, which cannot run in a browser tab.
If you choose one of these, the photograph is:
- sent to our API server at
productphoto.bnj.app/api, - forwarded to our own image-processing service at
qiler.bnj.app, - forwarded from there to fal.ai, a third-party generative-image provider, which performs the processing and returns a result.
The job record (which operation, when, whether it succeeded, and the URL of the result so you can fetch it) is stored on our server. The submitted image and the output are kept for a short period — no longer than 7 days — so the result can be delivered and problems investigated, and are then deleted.
Please do not submit photographs containing people, documents or anything else you would not want processed by a third party.
As of the date above, AI operations are not enabled. No image budget is connected, the endpoint returns an error, and credits are not for sale. This section describes how the feature works when it is turned on.
3. What we store on our servers
We do not have user accounts. If you buy credits, we create a licence code in the form BNJ-XXXXXXXX and show it to you. Against that code we store:
- the licence code itself,
- your credit balance,
- a ledger of credit purchases and credit spends, with timestamps,
- the Stripe customer identifier created by your purchase.
We do not store your name, your email address or your postal address. Keeping no email address is a deliberate choice — it is also why we cannot email you a lost licence code, so please keep it somewhere safe.
We may issue an anonymous random device token to limit abuse of free usage. It is not linked to you as a person.
4. Payments
Payments are handled by Stripe. When you buy a credit pack you are taken to Stripe's own checkout page and enter your card details there. We never see, receive or store your card number. Stripe processes that data as an independent controller under its own privacy policy.
Payments are not enabled at the time of writing.
5. Analytics
We use Umami, a privacy-focused analytics tool we host ourselves at uma.bnj.app. It is cookieless, does not follow you across websites, and does not build a profile of you.
It records the page you viewed, the referring page, a coarse indication of browser, operating system and device type, and a country derived from your IP address. The IP address itself is not stored.
6. Storage on your own device
We use your browser's localStorage to remember your interface preferences — the marketplace preset, fill ratio, background choice, SKU prefix, language and light/dark mode — and your licence code if you have one. This stays on your device and is never sent to us. Clearing your browser data removes it.
We do not set tracking cookies.
7. Where the data lives
Our servers are virtual machines hosted by Hetzner in Germany. Stripe and fal.ai process data on their own infrastructure under their own terms.
8. Your rights
Because we hold almost nothing about you, most requests are simple. You can ask us what is stored against your licence code, ask for it to be deleted, or ask for a copy. Deleting a licence code also deletes its remaining credits, and this cannot be undone.
Write to [email protected].
9. Children
The service is aimed at people selling goods online and is not directed at children.
10. Changes
If this policy changes, the date at the top changes with it. Material changes will be noted on the site.
Contact
Hugo Software — [email protected]