
AI headshot privacy and security
Face photos are biometric data, so AI headshot privacy has teeth here: what happens to yours, including the unflattering parts.

Four AI Headshot Privacy Commitments
Each one is enforced by code, and each has a way to check it.
Your photos never train any model
Every provider in our routing must carry a reviewed training-exclusion position before it can receive an image. A provider with no reviewed position is unroutable - the guarantee is structural, not a promise.
Uploads are deleted on a stated schedule
Default 30 days after generation, or 7 if your organisation chooses. A scheduled sweep enforces it and we alert ourselves on a single overdue photo.
You can delete them immediately
One button on the shoot page erases every photo you uploaded, right away. Your finished headshots are unaffected.
Every image is marked as AI-generated
Delivered headshots carry embedded content credentials, and we measure whether that marking survived our own processing rather than assuming it did.

How AI headshot privacy protects uploaded photos
From upload to deletion.
Encrypted in transit and at rest
TLS on the way in, encrypted storage at rest. Uploaded selfies live in a private bucket prefix that is denied at the edge and never publicly addressable.
Never publicly linkable
There is deliberately no public-URL field on an uploaded photo. Internal access uses short-lived signed grants measured in minutes.
Consent recorded against exact wording
Before processing we show precisely what is collected, why, and for how long, then record your agreement against a hash of that exact text - so what you agreed to is provable years later.
No face embeddings stored
Likeness scoring compares images and keeps only a number. We never produce or persist a face vector, because a stored embedding is a stored biometric identifier.
Compliance Posture
Including where we are strong and where we are still building.

The Lifecycle of an Uploaded Photo
Every stage, in order.

Upload
Sent directly to a private bucket prefix over TLS. We verify the stored object matches what was declared, because a presigned URL is not a promise about its contents.
Check
Validated for usability before any credits are spent. Rejected photos still fall under the same retention and deletion rules.
Generate
Sent once to a provider contractually excluded from training on it, used to render your headshots, and not retained by us for any other purpose.
Delete
Erased on your retention schedule, or immediately on request. Storage bytes are deleted before the record is marked purged, so a failure can never look like a success.
Before You Upload
Data minimisation starts with the customer. These four choices reduce unnecessary personal information and keep control of the account and its outputs with you.

Upload only photos you are allowed to use
Use your own image or one you have permission to process. Do not upload another person's portrait, confidential workplace material, or identity documents.
Crop out information the model does not need
A head-and-shoulders crop avoids sharing screens, badges, addresses, family members, or other background details that do not improve the result.
Protect access to the account
Use a unique password or supported social sign-in, keep recovery access current, and review active sessions before starting a sensitive team rollout.
Delete early when you are finished
The retention window is a maximum, not a requirement. Use the deletion controls as soon as you have downloaded the outputs you intend to keep.
Operational Controls
The unglamorous parts that actually matter.

Least-privilege access
Production access is scoped and logged; sensitive administrative actions are written to an append-only audit trail.
Rate limiting
Per-IP and per-account limits on upload and generation paths, with bounded concurrent private uploads per identity.
Content moderation
Inputs and generated outputs are both screened, and uploads are checked for apparent minors with a fail-closed default.
Published subprocessors
The vendors that process photos are listed, so you always know who is involved.
Retention monitoring
Overdue deletions are alerted on as incidents rather than tracked as a queue depth.
Breach notification
Affected customers are notified promptly on any confirmed personal-data breach.
Your Photos, Your Control
Face photos are biometric data. We treat them that way in the product, not just in the policy page.

AI headshot privacy questions
Individuals and security reviewers
Questions We Have Not Answered?
Security reviewers are welcome to send a questionnaire. We would rather answer it precisely than have you guess.