Privacy
V3KTR is a browser-based image-FX compositor. Your images are processed on your own machine and never reach us. This page explains what we do collect, why, who else touches it, and how to make us stop — in plain language, no surprises.
Who's collecting it
V3KTR is run by Patrick John Martin (ABN 77 516 147 302), a sole trader based in the Australian Capital Territory, Australia, trading under the registered business name V3KTR2173. That’s who’s responsible for the data described here, and who to contact about it: [email protected].
Your images never leave your device
V3KTR processes images entirely in your browser, on your own GPU. Your images are never uploaded to us, never stored by us, and never seen by us. There is no server to send them to — the site is a static site. Nothing you make here is used to train anything.
One thing worth being precise about, because it’s the obvious follow-up question: the image never goes out, but the model comes in. The depth feature downloads a machine-learning model (about 50MB) to your browser the first time you use it, then caches it. That download is a normal web request, so the services hosting it — jsDelivr and Hugging Face — see your IP address, the same way any site you visit does. They don’t see your images, because your images never go anywhere.
What we collect
- Your email address — if you subscribe to new-FX updates, send us a message, or create an account.
- Account data — your email, your licence status, and the Looks you save. Paid use needs an account so we can attach your licence and sync your Looks across devices. The free tier needs no account at all.
- Anything you type into a message — the contact form sends us what you wrote, plus your name and email.
- Anonymous crash reports — when the app hits an error it sends us a compact report: the error message, the app version, your browser, your GPU vendor, and which effects were in the stack. No image data, no account details, nothing that identifies you. It’s how a one-person operation finds out something is broken for people it can’t see.
- Usage analytics — only if you agree (see below). Pages visited, rough location derived from your IP address, device and browser type.
Why we collect it
- Email updates — because you asked for them. You can unsubscribe any time and we’ll stop.
- Account and licence data — because we can’t give you what you paid for without knowing who paid.
- Crash reports — to fix bugs and keep the app stable.
- Analytics — to understand what’s useful. Only with your consent.
We don’t sell your data. We don’t share it for advertising. We don’t build a profile on you. If that ever changed we’d have to say so here first, and it isn’t going to.
If you’re in the EU or UK and want the formal version of the above: consent for marketing email and analytics; contract for your account and licence; legitimate interests for security and crash diagnostics.
Cookies and analytics
We use Google Analytics to see which pages get read. It sets cookies, so we ask first and it doesn’t load unless you say yes. Decline and no analytics cookies are set at all — the site works exactly the same. Your choice is remembered in your browser, and you can change it any time from the banner or by clearing your site data.
If you accept, Google Analytics may link your visit across v3ktr.com and the app so a single session isn’t counted twice.
The site sets no other tracking cookies. There are no ad networks, no pixels, and no third-party trackers.
Who else touches it
We’re one person, so we use other people’s infrastructure. Here’s all of it, and what each one sees:
- Supabase — hosts our database and sign-in. Your email, licence status, saved Looks and the anonymous crash reports live here.
- Polar — our merchant of record. Polar takes your billing details at checkout and passes us your email and licence status. We never see or store your card details.
- Cloudflare — hosts and serves the site. Sees IP addresses and request logs, as any web host does.
- Web3Forms — delivers the email-signup and contact-form submissions to us.
- Google Analytics — usage analytics, only with your consent.
- jsDelivr and Hugging Face — serve the depth model to your browser. They see the request (and therefore your IP), not your images.
These services run in various countries, including the United States and the European Union, so your data may be stored or processed outside Australia. Each is a substantial provider with its own privacy commitments; we’ve picked them on that basis. If you want to know exactly where something sits, ask and we’ll tell you.
How long we keep it
- Email subscriptions — until you unsubscribe, then we remove you.
- Account data and saved Looks — until you delete your account or ask us to.
- Purchase and licence records — we have to keep these for tax and record-keeping (generally five years under Australian law), even after an account is closed. It’s the one thing we can’t delete on request.
- Crash reports — 12 months, then deleted.
- Messages you send us — as long as the conversation is useful, then deleted.
Your rights
Email [email protected] and you can:
- get a copy of what we hold about you;
- have it corrected;
- have it deleted (except the purchase records noted above);
- unsubscribe from email;
- withdraw analytics consent at any time.
No forms, no hoops. It goes to a real person and we’ll sort it. If you’re in the EU or UK you also have the right to object to processing and to data portability, and you can complain to your local data protection authority. In Australia, you can complain to the Office of the Australian Information Commissioner.
Security
Everything is served over HTTPS. Account data sits in Supabase behind row-level security so one account can’t read another’s. Crash reporting is insert-only — the app can send a report but can’t read anything back. We don’t hold card details at all, because Polar does that.
No system is perfectly secure, and we’re not going to pretend otherwise. If there’s ever a breach that could cause you serious harm, we’ll tell you and the relevant regulator promptly — and we’ll tell you what actually happened, not a press release.
Children
V3KTR isn’t aimed at children and we don’t knowingly collect data from anyone under 16. If you think a child has given us personal information, email us and we’ll delete it.
Changes
We may update this policy — most likely to name a new service as the app grows. The date at the top always reflects the current version. If a change materially affects how we handle data you’ve already given us, we’ll email account holders rather than quietly editing the page.
Questions about this page? [email protected]. If something here is unclear or reads as unfair, say so — that’s useful and it gets fixed.

