MetaCleaner is an online tool for removing common EXIF and C2PA metadata from photos. Photos are processed temporarily for cleaning purposes and deleted immediately afterwards.
1. Data controller
The data controller is:
All in Style s.r.o.
Smetanova 2401
760 01 Zlín
Czech Republic
Company ID: 27684059
VAT: CZ27684059
Contact for privacy inquiries: [email protected]
2. How MetaCleaner works
MetaCleaner removes metadata from photos. You upload a photo, the service strips common hidden metadata, and returns the cleaned file for download.
- EXIF metadata may contain technical information about the device, date, software or location.
- C2PA / Content Credentials may contain information about a file's origin or edits.
- C2PA processing takes place on a secure server, not locally in the browser.
- Photos are stored on the server only for the minimum time required for processing, then deleted.
MetaCleaner does not use photos to train AI models, does not sell them, and does not store them long-term.
3. Data we process
| Data | Why we need it | How long we keep it |
|---|---|---|
| Email address | Magic link login, service communication, e-book, transactional and optional marketing emails. | For as long as you use the service or until a deletion request, unless the law requires longer retention. |
| Credit balance | To track how many photos you can still clean. | For the lifetime of your account or until a valid deletion request. |
| Transaction data | Purchase records, credit activation, accounting and tax obligations. | For the period required by accounting and tax regulations. |
| Photos | Solely for metadata removal and returning the cleaned file. | Temporarily during processing only; deleted immediately after. |
| Technical data & server logs | Security, service operation, error resolution and abuse prevention. | For the period necessary for operations, security and incident resolution. |
4. Legal basis for processing
We process personal data only when we have a valid legal basis under GDPR:
- Performance of a contract — to provide the service, login, credits and cleaned files.
- Legitimate interest — service security, abuse prevention, basic operations and customer communication.
- Legal obligation — accounting, tax and statutory requirements.
- Consent — for voluntary marketing subscriptions or e-book sequences where consent is required.
5. Payments via Stripe
Payments are processed by Stripe. MetaCleaner does not store card numbers, security codes or complete payment details — these are entered directly into Stripe's payment interface.
We receive basic payment information from Stripe — payment status, amount, currency, email and transaction ID — to activate credits and fulfil accounting obligations.
Stripe's Privacy Policy: stripe.com/privacy.
6. Emails via Brevo
We use Brevo to send emails. Brevo may store your email address and information required for delivery — magic links, e-book links, service messages, credit notifications or follow-up email sequences.
You can unsubscribe from marketing emails at any time via the link in the email or by contacting us at [email protected].
Brevo's Privacy Policy: brevo.com/legal/privacypolicy.
7. Hosting & technical infrastructure
The service runs on Hetzner VPS hosting in the European Union, primarily in Germany. The application, credit database and temporary photo processing all run on this server.
Hetzner's Privacy Policy: hetzner.com/legal/privacy-policy.
8. Cookies
MetaCleaner uses only technical or session cookies — or equivalent technical storage — necessary for login, session management and service security.
We do not use analytics, advertising or remarketing cookies.
9. Who receives your data
We share your data only to the extent necessary to operate the service:
- Stripe — payment processing.
- Brevo — email delivery and sequences.
- Hetzner — hosting and server infrastructure.
- Accountants or tax advisors — only where required to fulfil legal obligations.
We do not sell personal data to third parties.
10. Transfers outside the EU
Some providers, particularly Stripe and Brevo, may process data outside the European Economic Area as part of their services. Where this occurs, they use appropriate GDPR-compliant legal mechanisms such as standard contractual clauses.
11. Your rights
Under GDPR you have the right to:
- access your personal data,
- rectify inaccurate data,
- erasure of data where it is no longer necessary or there is no lawful basis for retention,
- restriction of processing,
- data portability,
- object to processing,
- withdraw consent where processing is based on consent,
- lodge a complaint with a supervisory authority.
To exercise your rights, write to [email protected].
12. Security
We apply reasonable technical and organisational measures to protect data. Access uses passwordless magic links. Photos are processed temporarily and deleted immediately after.
No online service can guarantee absolute security. We recommend not uploading files containing exceptionally sensitive information unless strictly necessary.
13. Changes to this policy
We may update this policy from time to time — for example, when the service, providers or legal requirements change. We will notify you of material changes by email or via a notice on the website.
14. Contact
For questions about privacy or to exercise your rights, write to [email protected].