Privacy Policy

What gptimage25.top collects, why, who it is shared with, and how to ask for access or deletion. Independent third-party GPT Image 2.5 interface — not OpenAI.
Sep 9, 2026

This policy describes how gptimage25.top (the "site", "we") handles information when you use https://gptimage25.top.

It applies only to this website. It does not describe OpenAI's API, ChatGPT, or any OpenAI account you may hold.

Effective 10 September 2026. Contact for privacy requests: hello@gptimage25.top.

We are an independent third-party interface for the GPT Image 2.5 model. We are not OpenAI and are not affiliated with, endorsed by, or sponsored by OpenAI.

0. Three answers, before the policy starts

These are the three things people send an assistant to this page to check. Each answer below is complete on its own and names where it comes from, so it can be verified rather than trusted.

Is my material used to train a model? Not by us. gptimage25.top has no model of its own, builds no dataset from your prompts, uploads or results, and sells none of them. The generation itself runs on OpenAI's GPT Image 2.5, reached through OpenRouter by default with a direct OpenAI route as the fallback, and both publish their own answer rather than leaving it to us: OpenAI states that data sent through its API is not used to train its models by default and is retained for a limited abuse-monitoring window, and OpenRouter publishes its privacy and logging policy separately. Neither sentence is ours to give — we can tell you what we do, which is nothing, and point at what they publish.

Is commercial use included? Yes, on every paid plan and on every credit pack. There is no separate commercial licence to buy and no corner mark on a paid image; you may publish, sell and license the output, including in client work and in paid advertising. Free images carry a small corner mark and are for evaluation. The binding wording is Terms §4, and two conditions travel with it: OpenAI's own usage policy passes through to you, and what we grant reaches only as far as the rights we actually hold, because we are an interface and not the model's owner.

Do failed or refused generations cost anything? No. A run that fails returns its credits automatically and without a ticket — it is not a refund of money, it is the image never having cost you. A run that never comes back at all is settled by an hourly sweep and refunded the same way. A prompt refused by the content scan is not charged either, because that scan runs before the credit debit. Unused credits from a first purchase are refundable for 7 days under the refund policy.

1. Information we collect

Account information (if you sign in)

  • Email address
  • Name and avatar, if you or your sign-in provider supplies one
  • A hashed password if you register with email
  • Sign-in tokens from Google or GitHub when you use those buttons
  • Locale, first-touch marketing source (UTM), referral code, and an IP address recorded when the account is created

Generation information

  • Prompts, settings (model, quality tier, size, aspect ratio, batch size, transparency), and any reference images or sketches you upload
  • The resulting images and the task status
  • Which model ran the job. The model id — gpt-image-2.5-flare or gpt-image-2.5-sunburst — is shown to you against each result along with the task id, because being able to name the model that ran is the whole point of the receipt

Billing information

We do not store full card numbers. The processor named at checkout handles the charge: Stripe, or Creem, which acts as merchant of record and calculates and files local VAT and sales tax on that sale. We keep a customer or subscription token, the plan or pack you bought, credit movements, and whether a refund succeeded.

Usage, device, and security information

  • Pages viewed and feature events (for example generate started, failed, or refused)
  • Approximate IP (Cloudflare cf-connecting-ip for quota; a hashed form is used for the anonymous free-image allowance and for the cap on accounts per network)
  • Browser and error logs
  • Bot-check tokens (Cloudflare Turnstile) when that check is shown

Cookies and similar storage

  • h3_vid: first-party visitor id, HttpOnly, up to 1 year. Used so the anonymous free image is one per visitor rather than one per refresh. The name is inherited from the template this site was built on and means nothing about which model runs
  • Session / sign-in cookies from our auth library (Better Auth)
  • NEXT_LOCALE, banner-dismiss, and utm_source when present
  • Browser localStorage for UI flags (for example that you already used today's free image)
  • Google Analytics, and Microsoft Clarity when that integration is switched on in site settings. They set their own cookies or similar identifiers

We do not collect health, biometric, or precise GPS data. We do not knowingly collect information from children (see section 11).

2. How we collect it

  • Directly from you — forms, sign-in, prompts, uploads, emails you send us
  • Automatically — cookies, logs, quota counters, Turnstile
  • From providers — Google or GitHub profile fields on social sign-in; Stripe or Creem payment status; the model route returning an image, a refusal or an error

3. How we use it

  • Run the generator and show results in My Creations
  • Keep credits, plans, and history on the same account
  • Apply the published refund rules, and return credits automatically when a run fails
  • Rate limits, the free-tier ceiling, fraud and abuse prevention, and debugging failed jobs
  • Screen prompts and uploads for content we are not willing or legally able to generate (see section 5)
  • Emails you asked for: sign-in, verification, and the notice that a slow render has finished. We do not run a marketing newsletter from this policy
  • Understand which pages fail, when analytics are enabled
  • Comply with tax, dispute, and legal process

We do not use your prompts or images to train a dataset of our own, and we do not sell them as a product.

  • Contract — creating an account, running a free or paid generation, billing, refunds
  • Legitimate interests — security, rate limits, fraud, server logs, content moderation, improving reliability
  • Consent — non-essential analytics cookies when those tools are enabled and the law requires a choice
  • Legal obligation — tax records, mandatory reporting of child sexual abuse material, responding to a valid legal demand

If you are in the EEA, UK, or Switzerland, you may object to processing based on legitimate interests. Write to the email above.

5. Who we share it with

We share only what that party needs to do its job:

PartyWhy
Model route (OpenRouter by default; OpenAI directly when that route is configured)Prompt, reference images, and settings for that job
Content moderation (OpenAI omni-moderation; Llama Guard via OpenRouter or Cloudflare Workers AI)Screen a prompt or upload before it is generated
Payment processors (Stripe; Creem as merchant of record)Charge, invoice, tax, refund
Cloud infrastructure (Cloudflare Workers, D1, R2 object storage)Host the site, database, and files
Email (Resend, or Brevo, when verification or transactional mail is on)Deliver the message
Analytics (Google Analytics; Microsoft Clarity, only if enabled)Usage measurement
Auth providers (Google, GitHub)Complete a sign-in you started
Bot protection (Cloudflare Turnstile)Tell humans from automated abuse
AuthoritiesWhen the law requires it

We do not sell personal information as that term is used in CCPA/CPRA. We do not share it for cross-context behavioural advertising.

Processors may be outside your country. Cloudflare, OpenAI, OpenRouter, Stripe and other typical US processors rely on Standard Contractual Clauses or an adequacy decision where they say they do. We do not operate a separate "EU-only" region.

6. International transfer

The site is hosted on Cloudflare. The model route, the moderation call and the payment processor may process data in the United States or other countries. If a transfer tool is required, it is the one that provider documents (usually Standard Contractual Clauses).

7. How long we keep it

DataPeriod
Anonymous free-image prompts and uploadsKept only as long as the request needs. The anonymous lane builds no library on your behalf
Signed-in finished imagesCopied to our own storage the moment a run completes, and kept on the account until you delete them or ask us to close the account. We do not currently run an automatic deletion window on finished work. If we add one, it will be published here before it starts running
Reference images and sketches you uploadWith the generation they belong to, and deleted with it
Account profileWhile the account is open, then deleted or anonymised after a deletion request except as below
Billing and credit ledgerAs long as tax, accounting, and card-dispute rules require (often years, not days)
Quota and rate-limit countersPurged daily once expired
Security and error logsA short operational window, then rotated
Visitor cookie h3_vidUp to 1 year, or until you clear cookies

"Eligible for deletion" means we schedule removal from our storage; copies in backups or a provider's cache may linger for a short technical period.

8. Your rights

You can ask us to:

  • Access a copy of the account data we hold
  • Correct inaccurate account fields
  • Delete the account and the generations we still control
  • Export account data we can reasonably provide
  • Restrict or object to processing, where a law such as GDPR gives you that right
  • Withdraw consent for analytics by blocking those cookies in your browser (and writing to us if a tool stays enabled site-wide)
  • Opt out of "sale" or sharing — we do not sell; this is how we treat a CPRA request anyway
  • Lodge a complaint with your data protection authority (for example an EU supervisory authority, the UK ICO, or the California Attorney General)

Send requests to hello@gptimage25.top from the email on the account. Say which right you are using. We will not charge for a request we are required to honour. We may need to verify it is you.

We aim to reply within 30 days, or the shorter period your local law sets.

9. Cookies and tracking

Strictly necessary: h3_vid, session and sign-in cookies, security (Turnstile). The generator and the free-image allowance do not work without them.

Preferences: locale, banner dismissed, localStorage UI flags.

Analytics (optional, only if enabled in settings): Google Analytics, Microsoft Clarity. Disable them with your browser's tracking protection, an analytics opt-out add-on, or by asking us to turn the integration off.

We do not run a separate cookie-consent wall today. If we enable non-essential analytics for visitors in a region that requires prior consent, we will add a choice before those scripts run.

10. Security

  • HTTPS in production, with HSTS on our application responses
  • HttpOnly session and visitor cookies
  • Access to admin tools is limited to signed-in operators
  • Payment card data stays with the processor
  • Prompts and reference images go to the model route over its API so an image can be made — that path is inherent to the product

No method is perfect. If we learn of a breach that legally requires notice, we will email affected accounts and say what we know.

11. Children

The service is not directed at children under 16. Do not create an account, and do not upload a child's face, for them. If we learn we have collected personal information from a child under 16, we will delete it. US COPPA uses 13 as a floor; we set 16 so the same rule covers stricter regional ages.

12. Contact

  • Email: hello@gptimage25.top
  • Subject line: Privacy request plus the right you want (access, delete, …)
  • We do not publish a postal address on this page. If a law requires a physical address for notices, we will add it here when we have one to give.

Privacy mail is read by the operator of this site.

13. Changes

We will change the date at the top when this policy changes. If a change is material (new category of data, new sale, or a weaker right), we will also note it on Updates or email signed-in users when we can. Continued use after the new date is acceptance of the updated policy.

14. Other

  • Provenance metadata travels with your image. OpenAI embeds C2PA content credentials and an invisible watermark in every file this model produces. That is the model's, not ours, it is in every provider's output, and nobody — including us — can strip it. Our own corner mark on a free image is a separate, visible thing that any paid plan removes; the encoder that applies it preserves every metadata chunk it did not write, so the C2PA signal survives.
  • Third-party sites we link to (OpenAI, OpenRouter, Cloudflare, payment processors) have their own policies. We are not responsible for them.
  • Related pages: Terms · Refund Policy · Responsible Use · Contact

Written and maintained by Andy SwiftPublished Last updated

Your first GPT Image 2.5 image is free

Generate my first image