Security & Compliance
How Figimi protects your data: encryption, automatic file deletion, trusted infrastructure, GDPR compliance, and responsible disclosure.
At Figimi, we believe that safeguarding your data is just as important as providing you with fast and dependable tools. This page outlines our security practices and compliance. Figimi is a sole proprietorship of Aymen Lasfar, located in Portugal (European Union).
Encryption in transit
Communication between your web browser and Figimi is conducted over an encrypted channel using industry-standard HTTPS/TLS. The same encrypted channel is used for file transfers to server-side tools.
File handling and automatic deletion
Many tools (text counters, case conversion, comparison and color tools, image compression and OCR) run entirely in your browser. As a result, those files never reach our servers.
With tools that require file processing on our servers, the files are written to an isolated, temporary working directory for the brief period the processing is done.
Uploaded files and outputs are automatically deleted after processing, and in all cases, within one (1) hour.
We do not back up, index, view, or reuse your files. We do not use files for advertising or for training models.
Infrastructure and sub-processors
We have a small number of high-quality providers with good security practices that we rely on:
-
Railway — application hosting and file processing.
-
Supabase — database, administrator authentication, and media for site content.
-
Cloudflare — DNS, TLS, content delivery, and attack mitigation.
-
Google (Analytics, Tag Manager, AdSense) — measurement and advertising, where applicable.
-
Brevo — emails for contact form submissions and service emails.
Each of our providers manages data specifically required for each of their services and manages that data under their own terms of security and privacy.
Access Control
Only the operator of this site has administrative access and therefore can change the content and settings of this site. No user account system requires the storage of personal user profiles. Administrative access is protected with a high level of assurance and authentication.
Data protection and GDPR
Figimi is incorporated in the European Union and therefore processes personal data in compliance with the laws and regulations of the EU General Data Protection Regulation (GDPR). We are committed to data minimization and keeping data for the minimal necessary duration. We honor data-subject rights of access, correction, deletion, and objection. Our principal supervisory authority is the CNPD, the Portuguese data protection authority (cnpd.pt). For further information on what data we process and for what purposes, please refer to our Privacy Policy.
Cookies and consent
Where required by law, your consent is required before we can implement non-essential analytics and advertising cookies, and you may change that consent at any time using the “Manage cookie preferences” link in the footer.
Responsible disclosure
If you believe that you have identified a security issue with Figimi, we appreciate that you have reported the issue responsibly. Please include sufficient detail for us to reproduce the security issue, and allow us sufficient time to resolve the issue before it is reported to the public. Do not access, modify, or delete any data that is not your own while carrying out your research.
Contact
If you have any questions relating to security or compliance, please contact us using the Contact page.