PRIVACY
Your source image stays yours.
Last updated: August 3, 2026
Who is responsible for the data
IconBeast is the controller for account, order, security, quota, and first-party analytics data described here. You can contact the controller at parse-iguana-2q@icloud.com.
Images, projects, and exports
Icon composition and export run locally in your browser. IconBeast does not upload your source artwork or generated web export package to its application database. Projects you choose to save are stored in your browser on that device and can be removed by clearing the site’s local storage.
Free daily exports
The web editor can be used without an account. To provide three free exports per day and prevent automated abuse, the service derives a daily, one-way HMAC identifier from the requesting IP address. The quota record contains that derived identifier, the day, and an export count—not the raw IP address. Our hosting and security providers may still process IP addresses in short-lived network logs needed to deliver and protect the service.
First-party product analytics
IconBeast records limited first-party events such as page views, opening the editor, selecting a platform, uploading an image, completing an export, starting checkout, and downloading the desktop app. Events may include a monthly rotating one-way identifier derived from the request IP address and browser user agent, an anonymous browser session identifier, time, page, locale, platform, referring host, campaign parameters, approximate country/region/city supplied by the hosting network, device category, operating system, browser, and limited event metadata. We do not store the raw IP address in the product analytics database. Analytics never include source artwork, generated icons, passwords, or support-message contents. Raw product events are deleted after no more than 395 days; aggregated reports may be kept longer.
Support conversations
If you open the support window, we store the messages you send, message times, page and referring host, language, conversation status, and an optional name or email address. A random conversation token saved in your browser lets that browser receive our replies without requiring an account. Support messages are visible only to IconBeast through the private 67 Control dashboard and are kept for as long as reasonably needed to answer the request, prevent abuse, and maintain support history. You may ask us to delete an eligible conversation.
Passwordless purchase access
No account is required to edit or export in the free web editor. To purchase, receive, and re-download IconBeast Desktop, you can use a verified email link or Google sign-in without creating a password or handling a license key. We store the email address, optional Google account identifier, verification state, desktop entitlement, hashed one-time access token, and hashed session. Legacy password-based accounts may also retain a password hash and salt; plain-text passwords are never stored. Essential access cookies are HttpOnly, SameSite, and Secure in production.
The hosting and security layer may also set a strictly necessary bot-management cookie (for example, __cf_bm) to detect abusive automated traffic. IconBeast does not use that cookie for advertising or first-party product analytics.
Orders, payment, and desktop delivery
For a desktop purchase, IconBeast stores the purchase identity, internal order identifier, product, amount, currency, payment-provider identifier, payment state, entitlement, and relevant timestamps. Cryptomus processes the cryptocurrency invoice and sends signed status updates to IconBeast. We do not receive wallet private keys. Resend delivers requested access and purchase emails when email access is used. The licensed DMG download is available only to an entitled signed-in purchaser. Desktop release files are stored separately from identity and analytics records.
Service providers and security
Our hosting provider processes requests and security logs. Google processes identity data only when optional Google sign-in is used. The transactional email provider processes the destination address and account messages. If paid checkout is enabled, Cryptomus processes the cryptocurrency payment and returns the order status to IconBeast; IconBeast does not receive a card number or wallet private key. Traffic is encrypted in transit.
Why data is processed
Quota enforcement, abuse prevention, service security, and limited product analytics are processed for the legitimate interests of operating and improving IconBeast while keeping the web editor free. Account, order, payment-status, entitlement, and delivery data are processed to perform the desktop purchase contract and protect paid access. IconBeast does not use analytics identifiers for advertising or sell them to data brokers.
International processing
Hosting, email, and optional identity providers may process data in countries other than yours. Where applicable, IconBeast relies on the provider’s contractual and legal transfer safeguards. Provider-specific terms and locations can change; contact us if you need the current list for a data request.
Your choices and contact
You can use the free web editor without providing an email address. You may clear locally saved projects in your browser. You may request access, correction, deletion, restriction, portability, or object to eligible processing by emailing parse-iguana-2q@icloud.com. You may also complain to the data-protection authority in your country. Quota enforcement is automated but does not produce legal or similarly significant effects.