Privacy Policy
Last updated: August 4, 2026
1. How Your Photo Is Handled
Operational photo files are permanently deleted within 24 hours. We use them only to provide and troubleshoot the Service with the processors disclosed below.
Step 1 — You upload your photo
Your photo is sent over an encrypted HTTPS connection to our application and AWS infrastructure in us-west-2. It is never transmitted to our processors unencrypted.
Step 2 — Processing
Your photo can be processed by AWS Rekognition, Replicate (BRIA), remove.bg, and Anthropic. Original, cropped, transparent-background cache, and delivery files are stored temporarily in private AWS S3 storage. When checkout starts, we retain a limited numeric compliance record for support, including check results, pose estimates, the policy version, and keyed fingerprints of the submitted input set and evaluated output that cannot recreate the photo.
Step 3 — Delivery
After payment, your compliant photo and print sheet are emailed to you via AWS SES. A download link is generated that expires after 24 hours.
Step 4 — Deletion
Operational photo files and photo-derived cache artifacts are deleted within 24 hours of upload. Application cleanup runs before the 24-hour limit and S3 lifecycle rules provide a backstop. Download links also expire within 24 hours.
What we never do with your photos:
- PhotoPass never uses them to train its own AI or machine learning models
- Never disclose them except to the service processors listed in this policy
- Never sell, license, or monetize your photos
- Never retain operational photo files beyond the 24-hour window
- Never manually inspect photo files outside a specific support, security, or reliability investigation (and only within the 24-hour window)
2. What Data We Collect
Processed photo
After editing, the final cropped image is uploaded to AWS S3 for compliance checks and print-sheet generation. Stored temporarily — deleted within 24 hours.
Email address
Provided at checkout so we can deliver your photo. Not used for marketing unless you explicitly opt in.
Payment information
Processed by Stripe. We never see or store your card number, CVV, or billing details.
Document type selection
Used to apply the correct photo dimensions and compliance rules.
Analytics (PostHog)
Product analytics and 30-day session replays used for troubleshooting. Replays intentionally record canvas pixels and can therefore include your photo or signature. Inputs are masked, URL query values are redacted, and network request/response headers and bodies are not recorded. We respect your browser's Do Not Track setting.
3. How We Use Your Data
- Generate your compliant passport photo and print sheet
- Run compliance checks on the processed image
- Send your photo via email after payment
- Process your payment through Stripe
- Provide customer support if you contact us
PhotoPass does not use your photos to train its own AI models, sell them, or use them for advertising. We disclose them only to the processors needed to operate, secure, and troubleshoot the Service, subject to their applicable data-processing terms.
4. Data Retention
| Data | Retention | How deleted |
|---|---|---|
| Operational photos and image cache | Less than 24 hours from upload | Application cleanup plus S3 lifecycle backstop |
| Download links | 24 hours from payment | Signed URL expiry (automatic) |
| Email address | 90 days | Scheduled deletion or anonymisation |
| Order metadata | 90 days | Scheduled database cleanup and anonymisation |
| Compliance diagnostics (no image) | Less than 24 hours if checkout is not completed; 90 days after verified payment | Independent scheduled purge plus order anonymisation |
| Payment records | Per Stripe's policy | Managed by Stripe |
| PostHog session replays | 30 days | PostHog retention policy |
| Product analytics | 90 days | PostHog retention policy |
After 90 days, PhotoPass removes or anonymises the email, support diagnostics, tokens, and other order identifiers. Limited non-identifying transaction records may remain, while Stripe retains payment records under its own legal and retention obligations.
5. Third-Party Services
AWS
Private S3 storage and Rekognition face analysis in us-west-2. Operational photo objects are deleted within 24 hours.
Replicate (BRIA)
Primary AI background-removal processor. Provider output links are copied immediately into our private short-lived storage.
remove.bg
Fallback background-removal processor when the primary provider is unavailable.
Stripe
Secure payment processing. PCI-DSS Level 1 compliant.
AWS SES
Transactional email delivery of your photo download link.
Cloudflare
Website hosting and CDN.
Anthropic (Claude)
Used for generating plain-English explanations when a compliance check fails. The cropped photo may be sent to Claude's Vision API for analysis. Anthropic does not use API inputs for training. See Anthropic's privacy policy: anthropic.com/privacy
PostHog
Product analytics and troubleshooting session replay. Canvas pixels can include photos. Replays are retained for 30 days; inputs, query secrets, and network headers/bodies are excluded by client-side configuration.
7. Your Rights
For all users:
- Request deletion of your data at any time
- Request a copy of any data we hold about you
- Withdraw consent for data processing
For EU/EEA residents (GDPR):
- Right to data portability
- Right to restrict processing
- Right to object to processing
- Right to lodge a complaint with your local data protection authority
- Legal basis for processing: contract performance (delivering your photo order)
For California residents (CCPA):
- Right to know what personal information we collect
- Right to delete your personal information
- Right to opt out of the sale of personal information
- We do not sell your personal information
Since photos are automatically deleted within 24 hours, in most cases there is no photo data remaining by the time a request is made. Email support@photopass.ai for any data request and we will respond within 48 hours.
8. Security Measures
We do not store passwords because we do not have user accounts. We do not store payment card details because Stripe handles all payment processing.
9. Children's Privacy
PhotoPass does not knowingly collect personal information from children under 13. Passport photos of minors should be taken and submitted by a parent or legal guardian.
10. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Continued use of PhotoPass after changes constitutes acceptance of the revised policy.
11. Contact Us
For privacy-related questions or data requests, email support@photopass.ai and we'll respond within 48 hours.