Skip to content
Security and Privacy

AI headshot privacy and security

Face photos are biometric data, so AI headshot privacy has teeth here: what happens to yours, including the unflattering parts.

Security and Privacy workflow

Four AI Headshot Privacy Commitments

Each one is enforced by code, and each has a way to check it.

Your photos never train any model

Every provider in our routing must carry a reviewed training-exclusion position before it can receive an image. A provider with no reviewed position is unroutable - the guarantee is structural, not a promise.

Uploads are deleted on a stated schedule

Default 30 days after generation, or 7 if your organisation chooses. A scheduled sweep enforces it and we alert ourselves on a single overdue photo.

You can delete them immediately

One button on the shoot page erases every photo you uploaded, right away. Your finished headshots are unaffected.

Every image is marked as AI-generated

Delivered headshots carry embedded content credentials, and we measure whether that marking survived our own processing rather than assuming it did.

Security and Privacy use cases

How AI headshot privacy protects uploaded photos

From upload to deletion.

Encrypted in transit and at rest

TLS on the way in, encrypted storage at rest. Uploaded selfies live in a private bucket prefix that is denied at the edge and never publicly addressable.

Never publicly linkable

There is deliberately no public-URL field on an uploaded photo. Internal access uses short-lived signed grants measured in minutes.

Consent recorded against exact wording

Before processing we show precisely what is collected, why, and for how long, then record your agreement against a hash of that exact text - so what you agreed to is provable years later.

No face embeddings stored

Likeness scoring compares images and keeps only a number. We never produce or persist a face vector, because a stored embedding is a stored biometric identifier.

Compliance Posture

Including where we are strong and where we are still building.

Our consent flow is built to the standard biometric statutes expect: notice displayed rather than linked, a separate unbundled written release, a stated purpose and retention period, and an append-only record. It is enforced server-side, so it cannot be bypassed by a client.

Biometric privacy law

The Lifecycle of an Uploaded Photo

Every stage, in order.

Security and Privacy steps

Upload

Sent directly to a private bucket prefix over TLS. We verify the stored object matches what was declared, because a presigned URL is not a promise about its contents.

Check

Validated for usability before any credits are spent. Rejected photos still fall under the same retention and deletion rules.

Generate

Sent once to a provider contractually excluded from training on it, used to render your headshots, and not retained by us for any other purpose.

Delete

Erased on your retention schedule, or immediately on request. Storage bytes are deleted before the record is marked purged, so a failure can never look like a success.

Before You Upload

Data minimisation starts with the customer. These four choices reduce unnecessary personal information and keep control of the account and its outputs with you.

Camera capturing only the portrait information needed for a headshot

Upload only photos you are allowed to use

Use your own image or one you have permission to process. Do not upload another person's portrait, confidential workplace material, or identity documents.

Crop out information the model does not need

A head-and-shoulders crop avoids sharing screens, badges, addresses, family members, or other background details that do not improve the result.

Protect access to the account

Use a unique password or supported social sign-in, keep recovery access current, and review active sessions before starting a sensitive team rollout.

Delete early when you are finished

The retention window is a maximum, not a requirement. Use the deletion controls as soon as you have downloaded the outputs you intend to keep.

Operational Controls

The unglamorous parts that actually matter.

Security and Privacy features

Least-privilege access

Production access is scoped and logged; sensitive administrative actions are written to an append-only audit trail.

Rate limiting

Per-IP and per-account limits on upload and generation paths, with bounded concurrent private uploads per identity.

Content moderation

Inputs and generated outputs are both screened, and uploads are checked for apparent minors with a fail-closed default.

Published subprocessors

The vendors that process photos are listed, so you always know who is involved.

Retention monitoring

Overdue deletions are alerted on as incidents rather than tracked as a queue depth.

Breach notification

Affected customers are notified promptly on any confirmed personal-data breach.

Your Photos, Your Control

Face photos are biometric data. We treat them that way in the product, not just in the policy page.

Uploads are used once to generate your headshots and are never used to train, fine-tune, or improve a model. No exceptions, and every provider we route to is contractually bound to the same rule.

No AI training

AI headshot privacy questions

Individuals and security reviewers











Questions We Have Not Answered?

Security reviewers are welcome to send a questionnaire. We would rather answer it precisely than have you guess.