Legal

Privacy policy

Last updated August 21, 2026

The short version

  • Your selfies are never saved to our servers. They stay in your browser and are sent, over an encrypted connection, to our server only for the moment it takes to forward them to the AI model that generates your headshot. We do not write them to disk, a database, or file storage, and they are not retained past that request.
  • Your generated headshots are saved — that's the product. They are stored privately and only you can access or download them. You can delete them at any time from your photos page.
  • We never sell your data or use your photos to advertise, train models, or anything else — they exist solely to serve them back to you.

What we collect and why

  • Selfie photos (biometric data). The photos you upload or capture contain your face, which may be considered biometric information under some laws. They are used for exactly one purpose — generating and revising your headshot — and are processed as described above: held in memory for the duration of the request, never stored by us. Your browser keeps a local copy (in its own storage, on your device) so your session can resume; clearing your browser data removes it.
  • Generated photos. Stored in our file storage (Amazon Web Services S3) under your account, and delivered to you through access-controlled, expiring links. Kept until you delete them or your account.
  • Account data. Your name, email address, and a securely hashed password (or your Google account identifier if you sign in with Google). Stored in our database (Neon) to operate your account.
  • Purchase and credit history. Which credit packs you bought and how credits were spent. Payments are processed by Stripe — we never see or store your card number.
  • Technical logs. Basic error and performance monitoring (Sentry) so we can fix problems. These do not include your photos.

Who processes your data

We use a small set of service providers, each only for the purpose listed: Google (Gemini API — generates your headshot from your selfie), Amazon Web Services (stores generated photos), Neon (database for accounts and credits), Stripe (payments), Resend (verification and password-reset emails), and Sentry (error monitoring). Your selfie is shared with exactly one of these — Google's Gemini API — and only to produce the image you asked for, subject to Google's API data-use commitments.

Deleting your data

You can delete any generated photo from your photos page — deletion removes it from our file storage, not just the list. To delete your account and everything attached to it, email us at [email protected] and we will complete the deletion within 30 days.

Contact

Questions about this policy or your data: [email protected]. See also our terms of service.