How We Handle Your Photo
No legal jargon. Here's exactly what happens.
Step 1
Upload
Photo sent over encrypted HTTPS to private AWS storage in us-west-2.
Step 2
Process
AWS Rekognition checks faces; Replicate BRIA or remove.bg removes backgrounds; Anthropic may explain failures.
Step 3
Download
Photo + print sheet emailed to you. Download link valid 24 hours.
Step 4
Delete
Application cleanup deletes operational photos within 24 hours; S3 lifecycle rules are the backstop.
Troubleshooting replay safeguards
PostHog session replay is enabled so our troubleshooting team can reproduce photo-flow failures. Canvas pixels can include a displayed photo or signature and are retained for 30 days. Input values are masked in your browser before transmission, URL query values are redacted, network headers and bodies are disabled, and browser Do Not Track is respected. Replay access is restricted and reviewed periodically.
What We Don't Do
- PhotoPass never uses your photos to train its own AI models
- Never sell photos or use them for advertising
- Never sell or license your photos
- Never store operational photo files beyond 24 hours
- Never require an account or login
What We Use
- AWS S3 — encrypted storage (AES-256)
- AWS Rekognition — face detection
- Replicate BRIA — primary background removal
- remove.bg — fallback background removal
- Stripe — payment (PCI-DSS Level 1)
- Anthropic Claude — failure explanations
- AWS SES — transactional email delivery
- PostHog — 30-day troubleshooting replay, including canvas pixels
Why No Account?
No account means no reusable login profile. Your email and order metadata are retained for 90 days for delivery, refunds, and support, then deleted or anonymised. Operational photos remain under 24 hours.
Want the full legal version?
Read our complete Privacy Policy or reach out to us directly with any questions.