Privacy

Privacy at Vectopea

Vectopea is a free SVG editor that runs in your browser. This page explains, in plain language, what the site keeps in your browser, what it sends to its server, and which outside services are involved. It describes what the code does today.

Last updated: October 3, 2026

The short version

  • No accounts. There's no sign-up or login, and Vectopea doesn't ask for your name or email.
  • Your files aren't uploaded. SVG files are opened and edited in your browser.
  • Autosave is local. Documents autosave to your browser's local storage on this device.
  • Simple first-party analytics. Vectopea counts pageviews and a few actions, such as exports. It doesn't store your IP address or your full user agent.
  • Google Analytics also runs on the site and sets its own cookies.

Your files

When you open, drop or paste an SVG, or place a raster image, your browser reads the file and the editing happens right there. Vectopea's server has no upload endpoint. The only messages the site's own code sends to it are the analytics and “online now” messages described below, and neither includes file contents or file names.

Exports (SVG, minified SVG and PNG) are made in your browser and saved straight to your device, or copied to your clipboard. The free SVG tools work the same way.

Links that open an SVG in the editor carry the drawing in the part of the address after the #. Browsers don't send that part to the server, and the editor removes it from the address bar once it has opened the file.

What's kept in your browser

Vectopea uses your browser's local storage (kept until you clear it) and session storage (cleared when you close the tab). These aren't cookies. Here's everything it stores:

vectopea:v1Local storage

Your open documents (including any images you placed in them), which document is active, editor settings such as grid and snapping, and your default styles. This is the autosave. It stays until you clear it.

vectopea-themeLocal storage

Light or dark theme, if you picked one.

vp-visitorLocal storage

A random visitor ID for Vectopea's own analytics (see below). It isn't tied to your name, email or files.

vp-sessionSession storage

Marks that a browsing session has started, so the first page you view counts as a new session. Gone when you close the tab.

vp-presenceSession storage

A random ID for the “online now” counter, separate from the visitor ID. Gone when you close the tab.

vectopea:handoffSession storage

Briefly holds a file when you send it to the editor from the homepage or one of the free SVG tools. Removed as soon as the editor opens it.

To remove all of it, clear the site data for vectopea.com in your browser settings. That also deletes your autosaved documents, so export anything you want to keep first.

Vectopea's own analytics

Vectopea runs its own small analytics so it can see which pages and features get used. Your browser sends a short message to Vectopea's server when:

  • a page was viewed
  • an SVG was opened, placed into a design, opened from a share link or loaded into a tool
  • a raster image was placed
  • a blank document was created
  • an SVG, minified SVG or PNG was downloaded, or SVG was copied to the clipboard

Each message contains:

  • the event name;
  • the page path, such as /editor (without the query string or the part after #);
  • the random visitor ID from vp-visitor;
  • for pageviews, whether this is your first visit and whether it's the first page of a session;
  • on the first page of a session only, the address of the page that linked you here and the utm_source tag from the link, if there is one.

The server turns these into daily counts stored in Upstash Redis, a hosted database:

  • how many times each event happened, and on which page paths;
  • for the first page of a session: the referring site as a domain name only (for example google.com, or “direct”, or the utm_source tag), your country as a two-letter code, your device type (mobile, tablet or desktop) and your browser name (such as Chrome or Safari);
  • a count of unique visitors. The visitor ID goes into a Redis HyperLogLog, which estimates how many different IDs it has seen without keeping a readable list of them.

The country comes from a header that Vercel, the host, adds to each request based on your IP address. Device type and browser name are worked out from your user agent. Vectopea doesn't store your IP address (not even hashed), your full user agent, the full referring address, or the contents or names of your files.

How long it's kept: daily counts expire after 400 days (about 13 months). All-time totals (how many times each event has happened, and the all-time unique visitor count) have no expiry set in the code, so they're kept until they're deleted.

Requests that look like bots are ignored. Only the site owner can see the reports, on a password-protected dashboard, and the owner's own visits aren't counted while signed in to it.

The “online now” counter

The homepage shows how many people are using Vectopea right now. To count them, each open tab picks a random ID, kept in session storage as vp-presence and not linked to the analytics visitor ID. While the tab is visible, on any page of the site, it sends that ID to the server about every 30 seconds.

The server stores only that ID and the time it was last seen, in Upstash Redis. No IP address, user agent or page path is stored with it. A tab counts as online if it was seen in the last 75 seconds. Older entries are removed, your browser tries to remove its entry right away when you leave the page, and the whole list expires if no tab has checked in for 150 seconds.

Google Analytics

Every page also loads Google Analytics (gtag.js) from Google. It runs with its default settings: no consent banner or consent mode is set up. Google Analytics collects information about your visit, such as the pages you view, and sets its own cookies, usually named _ga and _ga_ followed by an ID. Vectopea also sends it one custom event when a share link is opened in the editor, recording whether the file opened and the link's source tag.

How Google handles this data is covered by Google's privacy policy. How long Google Analytics keeps it is a setting in Google Analytics, not something in Vectopea's code. Browser extensions that block trackers will usually block it.

Fonts

The icon font is loaded from Google Fonts (fonts.googleapis.com and fonts.gstatic.com), so your browser connects to Google when a page loads. The text fonts are served from vectopea.com itself.

Hosting

Vectopea is hosted on Vercel. Like any web host, Vercel receives every request your browser makes to the site, including your IP address and user agent, and may keep server logs of them. How long those logs are kept is set by Vercel, not by Vectopea's code.

Cookies

Vectopea's own code doesn't set cookies for visitors. The only cookie it sets is vp_admin, which keeps the site owner signed in to the analytics dashboard. It's only set after logging in there with the admin password.

In a normal visit, the cookies set on vectopea.com come from Google Analytics, described above.

Questions

Privacy questions go to privacy@vectopea.com. For anything else, see the contact page or email contact@vectopea.com. You can read more about who makes Vectopea on the About page.

If what the site collects changes, this page and the date at the top will be updated.

Open a file or start from a blank artboard

Two sample documents are waiting in the editor if you just want to look around.

Open the editor