Toolporten · Background remover
Last updated: 2026-08-31
Applies to: Toolporten (toolboxes, dashboard, MCP) and the public product websites (/remove-bg, /make-qr, /pdf-to-md, /product-shot, /product-reel, /tools/stl-convert, /tools/video-to-gif, /tools/image-convert, /tools/image-listing-carousel).
Controller: CraftyNord AB (Sweden) operates Toolporten and these public products.
Toolporten processes account identifiers (Clerk subject or a local persona), toolbox configuration, API key hashes (not plaintext secrets), billing identifiers, and a credit/usage ledger for toolbox MCP.
When you upload an image to /remove-bg, /product-shot, /tools/image-convert, or /tools/image-listing-carousel, a video to /product-reel or /tools/video-to-gif, a PDF to /pdf-to-md, an STL to /tools/stl-convert, generate a QR on /make-qr, open an MCP upload link (/u/{token}), or send a public URL to a public-product tool, the file is processed on the Toolporten server you are using (the Railway/app host). Do not upload files you are not prepared to process on that host. Public image/PDF/video/STL MCP does not accept pasted base64.
Website cutouts run in memory for the request. The MCP result PNG is returned as base64 (and an object-store URL only when R2/media storage is configured).
/remove-bg, /make-qr, /pdf-to-md, /product-shot, /product-reel, /tools/stl-convert, /tools/video-to-gif, /tools/image-convert, /tools/image-listing-carousel: request bytes and the result are held for the duration of the HTTP request so we can return the file. We do not keep a copy as a product feature.ProductShotDailyUsage table is unused — /product-shot shares the same public-product meters as /remove-bg. /product-reel weekly counts live on ProductReelWeeklyUsage (UTC ISO week key), not a day column.tp_dfp: a necessary HttpOnly cookie (30 days, Secure, SameSite=Lax). /remove-bg, /pdf-to-md, /product-shot, /tools/stl-convert, /tools/video-to-gif, /tools/image-convert, and /tools/image-listing-carousel use it (with your IP) to apply the 3 free uses per UTC day when you are not signed in, and to reduce obvious self-referral abuse. /product-reel uses the same cookie for weekly anonymous meters (not a UTC-day reset). /make-qr does not set or require this cookie. Same cookie on /product-shot and /tools/stl-convert — not a second fingerprint cookie. It is not an advertising tracker. There are no ads and no analytics pixels./remove-bg, /pdf-to-md, /product-shot, /tools/stl-convert, /tools/video-to-gif, /tools/image-convert, and /tools/image-listing-carousel (website session or /mcp/{slug} OAuth). /product-reel signed-in clean downloads are 3 per UTC week. They are optional on /make-qr (QR is free without an account). The legacy ProductShotDailyUsage table is unused. /tools/stl-convert has no 10-pack; toolbox MCP still meters 1 local credit for stl_convert_format. /tools/video-to-gif meters 2 local credits for video_to_gif. /tools/image-convert and /tools/image-listing-carousel meter 1 local credit.tp_ref and tp_creator_ref: first-touch friend-invite or creator attribution. They are not essential and are set only when you follow an invite or creator link (/r/…, /c/…). A normal visit to /remove-bg, /make-qr, /pdf-to-md, /product-shot, or /product-reel does not set them.We do not use your uploads, toolbox payloads, or cutout results to train machine learning models. The background remover is a local ImageSharp heuristic (edge / salience cutout), not a third-party ML API and not remove.bg.
Payment is handled by Stripe. Sign-in may be handled by Clerk. Their processing is under their privacy policies. We store Stripe customer/subscription ids and Clerk subject ids needed to run billing and login.
CraftyNord AB (Sweden) is the controller. To ask for access, correction, or deletion of personal data, open a GitHub issue on [JimmyAstromska/Toolporten](https://github.com/JimmyAstromska/Toolporten/issues). We do not publish a separate privacy email.