FreeHeadshot logo
FreeHeadshot.org

Privacy Policy

Last updated: 2026-10-09·Email us with questions

This page explains exactly what data FreeHeadshot collects, why we collect it, how long we keep it, and who else gets to see it. It is intentionally specific. We process face photos, which under GDPR and several US state laws is treated as a special category of personal data, and we owe you the most direct possible explanation of what we do with it.

The 30-second version

If you read nothing else, read this list. Every claim here is repeated in detail further down, with the lawful basis attached.

  • Your photo and your headshots are stored so you can come back to them. If you use the site as a guest, the photo you uploaded and the headshots we made are deleted from our storage 30 days after they were made. If you have an account, they stay in your gallery until you delete them or delete the account.
  • We do not build a face template. We never compute or store a face embedding, and we do not run face recognition. We do keep a short numeric fingerprint of the uploaded image (a hash of its pixels, not of your face) so the same photo cannot claim the free set many times.
  • We do not train any AI model on user photos. Ever. The models we use are pretrained by Google and other vendors. Your face is not training data.
  • If you create an account we keep your email, plan status, and a short metadata trail of your generations (style picked, timestamps, image counts). The headshots themselves are kept in your gallery, as described above.
  • We do not sell personal data. We do not share it with advertisers or data brokers. We do not load Google AdSense or Facebook Pixel anywhere on the site.
  • You can email [email protected] at any time to get a copy of your data, delete it, or opt out of anything. We reply within 24 hours on weekdays.

Who runs this site

FreeHeadshot.org is operated by a small team you can reach at [email protected]. The legal controller for the data you submit on this site is the entity behind that email address. If you are a EU/EEA resident and need a formal name for a GDPR Article 30 record, write to that address and we will provide the legal entity and registered service-address information on request.

For routine privacy contacts (data subject requests, deletion, complaints), the same email is the fastest path. We do not run a separate ticketing system that buries privacy questions inside support workflows. Privacy mail goes to a human inbox.

What we collect

Three categories. Nothing else. If you can think of a category we collect that is not in this list, please email us so we can either add it or stop collecting it.

1. The photo or photos you upload

When you use the studio at /studio, you submit one or more photos. Until the moment you press Generate, the photo lives only on your device. When you press Generate, your browser uploads it over HTTPS to our server, which sends it to Google's Gemini API for image generation, then returns the generated images to your browser. Both the photo you uploaded and the generated headshots are then saved to our image storage. For a guest they are deleted 30 days after they were made. For an account they are kept in your gallery until you delete them. We also keep a short numeric fingerprint of the uploaded image, a hash of its pixels, so that one photo cannot be used to claim the free set again and again. It cannot be turned back into a picture and it is not a face template.

2. Account data (only if you create an account)

Most users never need to. The free tier requires no account. If you upgrade to a paid tier or sign in for any reason, we store: your email address, the plan you are on, a Supabase user identifier, and a small history of generation events (style chosen, time, success or failure, an image count). Your generated headshots and the photo you uploaded for them are stored with your account so that your gallery and your downloads work. You can delete any set, or all of them, at any time from your dashboard or in the iPhone app.

3. Technical and payment data

Standard request metadata that every website receives: IP address, user agent, the referring URL, the path you hit, response status, response time. We keep these as security logs for 30 days, then they get rotated out. If you pay, our processor Freemius sees the card details. We never see card numbers, only the last four digits and a customer ID for receipts.

How we treat face data specifically

Face images are biometric data when used to identify or distinguish a person. Under GDPR Article 9 they are a special category of personal data. Under several US state laws including California's CPRA, Illinois BIPA, Texas CUBI, and the Washington My Health My Data Act, biometric identifiers carry extra obligations on companies that process them. We follow these rules in practice, not just on paper.

Concretely, this is how a face photo moves through our system:

  1. You hit Generate. Your browser uploads the photo over a TLS 1.3 connection to our Vercel-hosted endpoint.
  2. The endpoint immediately forwards the photo to Google's Gemini 2.5 Flash Image API. The forwarding is server-to-server over Google's encrypted endpoint.
  3. Gemini returns generated image bytes to our server.
  4. Our server runs post-processing in memory (cropping, light tone correction, optional watermark). The post-processing is deterministic image math, not AI.
  5. Before generating, the same Google service checks that the photo shows a face and whether the person looks under 18. If they do, we ask for a parent or guardian to agree first.
  6. The finished images are returned to your browser, or to the iPhone app. They are also saved to our image storage, together with the photo you uploaded.
  7. For a guest, those stored files are deleted 30 days after they were made, by a job that runs every day. If you buy a pack within those 30 days, the set is attached to your new account instead and stays in your gallery.
  8. For an account, the files stay until you delete the set or the account. Deleting removes the files from storage, not only the entry from your gallery.
  9. Couple styles use a photo of a second person. The person making the headshot confirms that the other person is an adult, is with them, and agrees. We refuse a couple style if either face looks under 18. The second photo is stored and deleted exactly like the first, and in the iPhone app it is only ever sent to Google.
  10. On the website, if Google's service is unavailable, the photo may be processed by OpenAI's image API instead, under the same rules. In the iPhone app the photo is only ever sent to Google.
  11. Any face embedding (a high-dimensional vector representation of your facial features) that exists inside the Gemini pipeline lives only inside that single generation request and is gone when the request returns. We do not extract embeddings on our side and we do not store them.

Why we're allowed to process face data

Under GDPR we rely on two lawful bases that have to coexist for biometric processing:

  • Article 6(1)(b) — contract performance. You asked us to generate a headshot. We cannot do that without processing the photo. The processing is necessary to deliver the service you requested.
  • Article 9(2)(a) — explicit consent. Because face data is special-category data, contract performance alone is not enough. The act of uploading a photo into the studio with knowledge of how the system works (which is what this page exists to communicate) constitutes explicit consent for the single, narrowly-scoped purpose of generating your headshots. You can withdraw that consent at any time by closing the page before Generate, or by emailing us afterward to demand deletion of any residual data.

Under US frameworks (CCPA/CPRA, BIPA, CUBI, MHMDA) we rely on the user-initiated nature of the upload. You are the data subject, you are the one initiating the processing, and the processing is necessary to deliver the result you requested. Where a state law requires an explicit written release for biometric processing (Illinois BIPA is the strictest), the act of submitting the photo with awareness of this policy satisfies the written-release requirement under the same logic.

How long anything sticks around

This is a question we get often, so it gets a table. These are the real periods, enforced by the systems described on this page.

WhatHow long we keep itWhy
Your uploaded photo, as a guest30 days, then deleted by a daily jobSo a purchase made within 30 days can still deliver the same set clean
Your uploaded photo, with an accountUntil you delete the set or the accountYour gallery, re-downloads, support
Generated headshots, as a guest30 days, then deleted by a daily jobSame reason
Generated headshots, with an accountUntil you delete the set or the accountYour gallery and downloads
Numeric fingerprint of the uploaded imageCompared for 180 days; kept with the generation recordStops one photo claiming the free set repeatedly. Not a face template, cannot be turned back into an image
Generated images on your deviceUp to youCopies you download are yours and outside our control
Face embeddingsZero seconds beyond the generation callWe do not extract or persist embeddings
Generation record (style, time, count, IP address, device identifier, and the age bracket the check above returned). Contains no imageUntil you ask us to delete itThe one free set rule, fraud prevention, quota accounting, support
Account email and Supabase user IDUntil you ask us to deleteAuthentication, contacting you about your purchase
Payment metadata (last 4, Freemius ID)7 yearsTax and chargeback record requirements
Server access logs (IP, user agent, route)30 daysSecurity, debugging, abuse investigation
Email correspondence with our support address3 yearsOngoing customer relationship and audit trail
Deletion record (email, account age, plan, number of sets made, IP addresses and sessions seen). Contains no imageKept after the account is deletedStops a deleted account being used to take the free set again; abuse investigation
Photos you report from the app (which set and photo, when, your account)Until you delete the accountReviewing the report
Android phone record: a one-way hash of the phone's Android ID and the date it took its free headshot. No name, email, photo or accountKept after the account is deletedOne free headshot per phone

Other companies that touch the data

We use a small number of third-party services to run the site. Each one is bound by a data processing agreement that mirrors the commitments we make to you. We list every one of them by name so you know exactly who has access to what.

  • Google LLC (Gemini API) processes the uploaded photo to check it shows a face, to estimate whether the person is under 18, and to perform the actual image generation. Google's API terms commit to not retaining customer content longer than the service requires and not using it to train Google's models. Region of processing: Google's global edge.
  • Vercel Inc. hosts the application and runs our serverless functions. They see traffic logs, function execution data, and the request bodies that pass through their edge. Region: Frankfurt (eu-central) for European visitors, US East for North American visitors, automatically selected.
  • Cloudflare Inc. sits in front of our DNS as a CDN and DDoS shield. They see the same request metadata as Vercel. Cloudflare's data processing addendum is in place.
  • Supabase Inc. hosts the database that stores your email, plan, and generation metadata when you have an account. Region: EU-central. Encrypted at rest.
  • Freemius, Inc. processes payments. They see card data, billing address, and the transaction amount. We see only the last four card digits and a Freemius customer reference. Region: EU.
  • Google LLC (Google Analytics 4) counts page views and sets its own cookies. It does not receive your photo. If you use an ad-blocker or privacy extension it does not load, and the site works the same without it.
  • Fingerprint Inc. identifies your device so the free tier can tell a new visitor from someone returning for a fifth free set. It receives browser and device characteristics and your IP, never your photo. See the device-recognition section above.
  • Stripe processes card payments, embedded by Freemius at checkout.
  • Resend sends transactional email (sign-in codes, receipts).
  • Cloudflare R2 stores the photos you upload and the headshots we generate, for the periods in the table above.
  • OpenAI may process the uploaded photo on the website only, as a fallback when Google's service is unavailable. It is never used by the iPhone or Android app.
  • Functional Software, Inc. (Sentry), for the iPhone and Android apps only: receives crash reports from the App Store and Google Play builds, in the EU region. No photos, no account identifiers, no IP addresses. See the crash reports section below.
  • Google LLC (Google Play), for the Android app only: in-app purchases, and the Play Integrity service, which tells us that a request comes from our real app on a real phone. We never send your photo through Google Play; the photo goes only to Google's Gemini API, as described above.
  • Apple Inc., for the iPhone app only: Sign in with Apple, in-app purchases, and Apple's DeviceCheck and App Attest services, which tell us that a request comes from a real iPhone that has not already used its free set. Apple does not receive your photo from us.

We don't train on user faces

This is the single most common question we get, so it gets its own section. We do not train, fine-tune, or otherwise improve any machine-learning model using photos that users submit. Not the Gemini model, which we do not control and which Google does not train on customer content under its API terms. Not any downstream model. Not any future model we might build. Not under any commercial pressure. The infrastructure to do so does not exist on our side, and we will not build it.

Where we do use AI training data, it was assembled by the model vendor (Google, in the case of Gemini) from public sources before we ever became their customer. Our role is to call their API, not to train it.

Your rights under GDPR

If you are a resident of the EU, EEA, UK, or Switzerland, GDPR and UK GDPR give you a set of rights against any organization that processes your personal data. Here is the full list and the request channel for each:

  • Right of access — you can ask for a copy of all the data we hold about you. We deliver this within 30 days, usually within 48 hours.
  • Right of rectification — if anything we hold is wrong, you can have it corrected.
  • Right of erasure (right to be forgotten) — you can demand we delete your data. We delete within 30 days unless we have a legal obligation to keep specific records (payment records are required for 7 years by EU tax law).
  • Right to restrict processing — you can ask us to freeze your data in place without deleting it, useful while a dispute is being resolved.
  • Right to data portability — you can ask for your data in a structured machine-readable format (JSON) so you can take it elsewhere.
  • Right to object — you can object to specific processing activities. There are almost none of these on our side because we do not run profiling or direct marketing.
  • Right to withdraw consent — for biometric processing specifically, you can withdraw consent at any time. Doing so prevents future processing but does not undo the generation you already received.
  • Right to lodge a complaint — you can file a complaint with your national data protection authority. We would obviously rather hear from you first so we can fix the problem, but you do not need our permission to contact your regulator.

All of these requests go to [email protected] with the subject line "GDPR request" so we route them quickly. We do not charge for any of them.

US state privacy rights

Several US states give residents rights that overlap with but are not identical to GDPR. The list keeps growing. If you live in one of these states, you have at minimum the rights below. If you live in a state not listed here that has its own privacy law, the same rights almost certainly apply and we will honor them.

  • California (CCPA/CPRA) — right to know what we collect, right to delete, right to correct, right to opt out of sale and sharing (we do not sell or share for cross-context behavioral advertising), right to limit use of sensitive personal information (we already limit face data to the single use described above), right to opt out of automated decision-making technology (ADMT) under the 2025 CPPA regulations.
  • Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Tennessee, Iowa, Indiana, Delaware, Florida, New Jersey, New Hampshire, Minnesota, Maryland, Kentucky, Rhode Island and any state whose comprehensive privacy law has come into force — equivalent rights apply.
  • You can exercise any of these by emailing the same address. We do not require you to create an account, fill out a form, or submit ID for any request that does not require identity verification.

Illinois BIPA and Texas CUBI specifically

Two state laws on biometric data deserve their own paragraph because they carry the most aggressive enforcement history.

Illinois Biometric Information Privacy Act (BIPA). If you live in Illinois, your face data is a biometric identifier under BIPA. We process it only for the single purpose of generating your headshots, and we keep it for the periods set out in the retention table above: thirty days for a guest, and until you delete it if you have an account. We do not disclose it to any third party except Google's Gemini API for the sole purpose of performing the generation you requested. The act of uploading a photo through our studio constitutes the written release BIPA requires. You can revoke that release by emailing us, in which case we will permanently destroy any residual data we may hold. We will not sell or trade your biometric data under any circumstance.

Texas Capture or Use of Biometric Identifier Act (CUBI). The same commitments apply. We capture biometric identifiers only with your informed consent (provided by uploading a photo with awareness of this policy), we use them only for the requested generation, and we do not retain them beyond the time reasonably necessary.

International data transfers

Some of our processors are based in the United States. Where your data is transferred from the EU/EEA to the US, the transfer relies on the EU-US Data Privacy Framework certifications held by Google, Vercel, and Cloudflare, plus Standard Contractual Clauses as a backup mechanism. We have signed SCCs with every processor that transfers EU data outside the EEA. You can request copies of the relevant SCCs by email.

Children and age

FreeHeadshot is not intended for users under the age of 16, and not at all for users under 13. We do not knowingly collect data from anyone under 13. We do not market the service to minors. If you are a parent or guardian and you believe your child has used the service, email us and we will delete all related data.

Cookies and analytics

We set one essential first-party cookie, fh_aid, which holds a random identifier for your browser so the studio remembers your session and so the free tier can tell whether this browser has already had its free set. It lasts up to 365 days. You can delete it at any time from your browser settings, and nothing about the paid product stops working if you do.

For analytics we use Google Analytics 4, which counts page views and sets its own cookies. If you have an ad-blocker or privacy extension active, it does not load, and the site works exactly the same without it. We do not run advertising pixels, remarketing tags, or session recorders, and we do not sell or share data with brokers.

Device recognition and abuse prevention

The free tier gives every person one set of headshots. Generating a set costs us real money on every request, so we have to be able to tell a new visitor apart from someone who has come back for a fifth free set with fresh cookies. Two things do that job, and neither is used for advertising, profiling, or anything other than deciding whether a request gets a free generation.

The first is Fingerprint (fingerprint.com), a third-party device-identification service. Its script runs on our pages, reads technical characteristics of your browser and device, and returns a stable identifier for that browser. We store that identifier against your generations so the free-set limit survives a cleared cookie or an incognito window. Fingerprint acts as our processor, is contractually barred from using the data for its own purposes, and is listed with its region in the sub-processor table in our DPA.

The second is a small script we host ourselves. It reads a handful of ordinary browser properties, your user agent, language, time zone, screen size, processor count, device memory, platform, and how your device draws a short line of text to a canvas, and reduces all of it to a single one-way hash. Your browser computes that hash and sends it to us with each generation; we never receive the underlying properties, and the hash cannot be reversed back into them. We use it only to count generations within a single day. It exists so the free-tier limit keeps working when the third-party service is unavailable.

Neither identifier is linked to advertising networks, sold, shared, or used to build a profile of you. If you object to device recognition under GDPR Article 21, email [email protected] and we will handle your account manually instead.

Crash reports in the iPhone app

This section is about the FreeHeadshot apps only, on iPhone and on Android. The website sends nothing to the service described here.

From version 1.0.1, the App Store build of the app reports its own crashes to Sentry, in the EU region (de.sentry.io). It sends a report only when something has gone wrong: an error the app did not handle, an error inside the Flutter framework it is built on, a crash in iOS itself, and once per launch if a request that should have carried the app's App Attest signature left without one.

A report carries the app version, the iPhone model, the iOS version, and a short trail of what the app was doing just before: which screens you moved between and the addresses of our own server calls, never what those calls contained.

It never carries your photo, your headshots, a picture of your screen, your email address, your account identifier, a sign-in token, your name, or anything you typed. The app removes email addresses and tokens from every message before it is sent and attaches no user to the report. On arrival, our Sentry project is configured to discard IP addresses and to scrub emails, tokens, authorization values and passwords. Nothing in a crash report is linked to your account, and none of it is used for tracking, advertising or analytics.

Sentry deletes the reports automatically at the end of its retention window: at most 90 days, and 30 days on the free plan. We keep no copy of them anywhere else. In Apple's App Privacy terms this is “Crash Data” under Diagnostics, not linked to you.

The Android app

FreeHeadshot on Google Play works the same way as the iPhone app, and everything on this page applies to it. The differences:

  • Purchases go through Google Play. We receive the purchase token, the order number, which pack was bought and whether it was a test purchase. We never see card details.
  • One free headshot per phone.The app sends a one-way hash of the phone's Android ID (the ID itself never leaves the phone) and a Google Play Integrity check, which tells us the request comes from our real app on a real phone. We keep the hash with the record of the free headshot. If you delete your account, we keep only that one-way hash and the date, with no name, email, photo or account attached, so that each phone gets one free headshot.
  • Crash reports go to Sentry in the same way as for the iPhone app, described in the section above.
  • Your photo is only ever sent to Google, for the headshot, as in the iPhone app.
  • Reporting a photo. If you report one of your headshots from the app, we store which set and photo, when, and your account, and use it only to review the report.

To delete your account and photos without the app, see how to delete your account.

Security practices

Concrete security measures rather than marketing language:

  • Transport encryption. TLS 1.3 across all endpoints. HSTS preload list submission. No HTTP fallback for any production traffic.
  • At-rest encryption. All data on Supabase and Vercel storage is encrypted with AES-256.
  • CSP. A Content-Security-Policy header on every page restricts scripts and connections to a whitelist of named domains and sets frame-ancestors to none to prevent clickjacking. Inline scripts are currently permitted, so the policy limits where code can come from rather than blocking inline execution outright.
  • Standard hardening headers. X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy restricting microphone and geolocation. Camera is available to our own pages so the studio can offer a webcam capture.
  • Authentication. Magic-link by default. No password storage. Sessions expire after 30 days of inactivity.
  • Row-level security. Database access is gated by Supabase RLS policies so even a compromised server token cannot read another user's records.
  • Minimal access. The number of humans with production database access is small enough that we can name them on request. Access is audited.
  • No advertising or session-recording scripts are loaded on any page. Two third-party scripts do run: Google Analytics for page counts, and Fingerprint for the device recognition described above. Neither receives your photo.

If something goes wrong

In the event of a security incident affecting personal data, we follow the GDPR Article 33 timeline: notification to the relevant supervisory authority within 72 hours of becoming aware of the breach, and notification to affected users without undue delay where the breach is likely to result in a high risk to user rights. Under US state laws, we follow the applicable notification timelines, which range from immediately (in some states) to 60 days.

Changes to this policy

When we update this page, the "Last updated" date at the top of the page changes. For material changes (anything that broadens what we can do with your data, narrows your rights, adds a new processor, or changes a retention period), we will:

  • Send an email notice to anyone with an account at least 30 days before the change takes effect.
  • Show a banner on the homepage and the studio for at least 14 days announcing the change.
  • Keep the previous version of the policy archived. If you want a copy of a prior version, email us.

If a change is purely cosmetic (a typo fix, clearer wording, no change in meaning), we will just update silently.

Contact and complaints

For any privacy question, request, or complaint, email [email protected]. We reply within 24 hours on weekdays. Use the subject line that fits:

  • GDPR request — for access, deletion, portability, or any other GDPR right
  • CCPA request — for California-specific rights
  • BIPA opt-out — for Illinois biometric opt-out
  • Privacy complaint — for anything else, including reporting a perceived violation

If we cannot resolve your complaint to your satisfaction, you can lodge a formal complaint with your national or state data protection authority. We would obviously prefer you give us a chance to fix the issue first, but we will not stand in the way of you contacting your regulator.

Related pages: Terms of Service, Refund Policy, Acceptable Use Policy, About FreeHeadshot.

Questions? Email [email protected]. We reply within 24 hours on weekdays.

Open the studio