Your photos. Your privacy.
What you provide
We collect uploaded photos, your email address, portrait selections, and the information needed to operate your private session and order. Uploads are used to create portraits. You must be an adult and have permission to upload photos of every person shown.
Private photo storage
Source photos and generated portraits are stored in private Cloudflare R2 storage. The application validates private access before issuing temporary download links. Keep your private gallery link to yourself; anyone holding a valid gallery link may be able to access it.
Portraits are synthetic interpretations and may not perfectly reproduce appearance. The current generation adapter is a demonstration using sample portraits; an external image model is not connected. The identity, processing terms, and retention of any future image provider must be disclosed before enabling it.
Payments, emails, and analytics
Stripe handles payment information. This application keeps order totals, payment identifiers, and payment/webhook records; it does not collect card numbers. Resend is used for transactional messages and private-gallery delivery.
Our analytics wrappers do not send uploaded photos, generated photos, image URLs, signed URLs, or generation prompts to analytics services. PostHog receives allowlisted product events and anonymous identifiers. Optional Meta advertising events require separate advertising consent and are disabled by default. Email marketing is not automatically enabled.
Delete my data
From your private gallery, choose Delete my data and confirm. The request closes photo access, stops portrait processing and pending delivery for that session, and schedules removal of source, preview, and final objects. Removal is retried if storage is unavailable. Already-issued upload links have a settling period; deleted namespaces are swept again to catch late objects.
Eligible contact and tracking data are removed from our application database. Payment records and information under configured accounting, fraud, or retention holds may remain. A deletion request does not automatically cancel a payment or create a refund. It applies to this portrait session, not unrelated sessions that happen to use the same email.
Copies you downloaded or shared, emails already delivered, third-party records, and backups are not erased by deleting the active application data. Provider erasure and backup handling require separate operational review. COMPANY-SPECIFIC TODO: supply the procedures, retention periods, rights, and contact channel for those requests.
Current retention configuration
Automatic expiry cleanup is not enabled. When enabled, it requests photo removal 30 days after the private session expires. Customer deletion requests can be made independently.
Accounting records: no automatic purge period configured. Processed webhook receipts: no automatic purge period configured. These are operational settings, not statements of a legal requirement.
Payment-related email addresses are currently retained for company review of accounting/support obligations. Payment and fraud-retention holds may prevent automatic record removal.