Privacy Policy

Last updated: August 4, 2026

1. How Your Photo Is Handled

Operational photo files are permanently deleted within 24 hours. We use them only to provide and troubleshoot the Service with the processors disclosed below.

Step 1 — You upload your photo

Your photo is sent over an encrypted HTTPS connection to our application and AWS infrastructure in us-west-2. It is never transmitted to our processors unencrypted.

Step 2 — Processing

Your photo can be processed by AWS Rekognition, Replicate (BRIA), remove.bg, and Anthropic. Original, cropped, transparent-background cache, and delivery files are stored temporarily in private AWS S3 storage. When checkout starts, we retain a limited numeric compliance record for support, including check results, pose estimates, the policy version, and keyed fingerprints of the submitted input set and evaluated output that cannot recreate the photo.

Step 3 — Delivery

After payment, your compliant photo and print sheet are emailed to you via AWS SES. A download link is generated that expires after 24 hours.

Step 4 — Deletion

Operational photo files and photo-derived cache artifacts are deleted within 24 hours of upload. Application cleanup runs before the 24-hour limit and S3 lifecycle rules provide a backstop. Download links also expire within 24 hours.

What we never do with your photos:

  • PhotoPass never uses them to train its own AI or machine learning models
  • Never disclose them except to the service processors listed in this policy
  • Never sell, license, or monetize your photos
  • Never retain operational photo files beyond the 24-hour window
  • Never manually inspect photo files outside a specific support, security, or reliability investigation (and only within the 24-hour window)

2. What Data We Collect

Processed photo

After editing, the final cropped image is uploaded to AWS S3 for compliance checks and print-sheet generation. Stored temporarily — deleted within 24 hours.

Email address

Provided at checkout so we can deliver your photo. Not used for marketing unless you explicitly opt in.

Payment information

Processed by Stripe. We never see or store your card number, CVV, or billing details.

Document type selection

Used to apply the correct photo dimensions and compliance rules.

Analytics (PostHog)

Product analytics and 30-day session replays used for troubleshooting. Replays intentionally record canvas pixels and can therefore include your photo or signature. Inputs are masked, URL query values are redacted, and network request/response headers and bodies are not recorded. We respect your browser's Do Not Track setting.

3. How We Use Your Data

  • Generate your compliant passport photo and print sheet
  • Run compliance checks on the processed image
  • Send your photo via email after payment
  • Process your payment through Stripe
  • Provide customer support if you contact us

PhotoPass does not use your photos to train its own AI models, sell them, or use them for advertising. We disclose them only to the processors needed to operate, secure, and troubleshoot the Service, subject to their applicable data-processing terms.

4. Data Retention

DataRetentionHow deleted
Operational photos and image cacheLess than 24 hours from uploadApplication cleanup plus S3 lifecycle backstop
Download links24 hours from paymentSigned URL expiry (automatic)
Email address90 daysScheduled deletion or anonymisation
Order metadata90 daysScheduled database cleanup and anonymisation
Compliance diagnostics (no image)Less than 24 hours if checkout is not completed; 90 days after verified paymentIndependent scheduled purge plus order anonymisation
Payment recordsPer Stripe's policyManaged by Stripe
PostHog session replays30 daysPostHog retention policy
Product analytics90 daysPostHog retention policy

After 90 days, PhotoPass removes or anonymises the email, support diagnostics, tokens, and other order identifiers. Limited non-identifying transaction records may remain, while Stripe retains payment records under its own legal and retention obligations.

5. Third-Party Services

AWS

Private S3 storage and Rekognition face analysis in us-west-2. Operational photo objects are deleted within 24 hours.

Replicate (BRIA)

Primary AI background-removal processor. Provider output links are copied immediately into our private short-lived storage.

remove.bg

Fallback background-removal processor when the primary provider is unavailable.

Stripe

Secure payment processing. PCI-DSS Level 1 compliant.

AWS SES

Transactional email delivery of your photo download link.

Cloudflare

Website hosting and CDN.

Anthropic (Claude)

Used for generating plain-English explanations when a compliance check fails. The cropped photo may be sent to Claude's Vision API for analysis. Anthropic does not use API inputs for training. See Anthropic's privacy policy: anthropic.com/privacy

PostHog

Product analytics and troubleshooting session replay. Canvas pixels can include photos. Replays are retained for 30 days; inputs, query secrets, and network headers/bodies are excluded by client-side configuration.

6. Cookies & Analytics

Essential cookies only

PhotoPass uses cookies required for the website to function:

  • Stripe checkout session cookie (payment processing)
  • Vercel analytics (anonymous, no PII)

PostHog analytics and session replay

We use PostHog to understand editor reliability and troubleshoot failures. Session replay is enabled for all sessions and records canvases at four frames per second, so photo or signature pixels displayed in a canvas can be transmitted to PostHog. Replays are retained for 30 days. Input values are masked in the browser before transmission, URL queries are redacted, network headers and bodies are disabled, and we respect the “Do Not Track” browser setting.

Replay access is limited to the troubleshooting team, reviewed periodically, and used only for support and reliability investigations. You may ask us to locate and delete a replay by emailing support with the approximate time and browser used.

We do not use:

  • Advertising or retargeting cookies
  • Facebook Pixel, Google Ads, or any ad tracking
  • Third-party tracking cookies of any kind

7. Your Rights

For all users:

  • Request deletion of your data at any time
  • Request a copy of any data we hold about you
  • Withdraw consent for data processing

For EU/EEA residents (GDPR):

  • Right to data portability
  • Right to restrict processing
  • Right to object to processing
  • Right to lodge a complaint with your local data protection authority
  • Legal basis for processing: contract performance (delivering your photo order)

For California residents (CCPA):

  • Right to know what personal information we collect
  • Right to delete your personal information
  • Right to opt out of the sale of personal information
  • We do not sell your personal information

Since photos are automatically deleted within 24 hours, in most cases there is no photo data remaining by the time a request is made. Email support@photopass.ai for any data request and we will respond within 48 hours.

8. Security Measures

All data transmitted over encrypted HTTPS connections
Photos stored in AWS S3 with server-side encryption (AES-256)
No photos stored on local servers or employee devices
Stripe PCI-DSS Level 1 compliant payment processing
Application hosted on Vercel with automatic security updates
Backend hosted on Render with isolated containers

We do not store passwords because we do not have user accounts. We do not store payment card details because Stripe handles all payment processing.

9. Children's Privacy

PhotoPass does not knowingly collect personal information from children under 13. Passport photos of minors should be taken and submitted by a parent or legal guardian.

10. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Continued use of PhotoPass after changes constitutes acceptance of the revised policy.

11. Contact Us

For privacy-related questions or data requests, email support@photopass.ai and we'll respond within 48 hours.