LEGAL · PLAIN ENGLISH
What we collect, how we use it, and what we will never do with your photos.
Your selfies and generated portraits are used for exactly one purpose: to create your headshots. Nothing else.
These are the same commitments stated on our Trust page. They are not fine print — they are how the product works.
To generate your portraits, your selfies are sent to the configured AI providers — currently Google Gemini as primary and OpenAI as fallback — only when needed to provide the service. Provider processing is governed by the relevant API terms and data controls. We do not intentionally submit your photos for model training.
All photos — selfies and generated portraits — are stored in private buckets. Access requires authentication; every URL is a short-lived signed link that expires after one hour. There are no permanent public URLs that could leak your images.
Access is further restricted at the database level: row-level security policies ensure only your authenticated account can read or delete your data.
Selfies are scheduled for permanent deletion no later than day 29 after upload, keeping the public promise below 30 days even if a scheduled job runs late.
Generated portraits are stored separately and remain available in your private gallery until you delete them. The source-selfie schedule never removes your delivered portraits.
You can delete source selfies and generated results sooner from the Privacy panel inside Studio. For account or payment records that cannot be removed through that control, email support@signalportrait.com.
We use session cookies set by Supabase (our authentication provider) to keep you signed in. These are strictly necessary for the service to function.
We use Vercel Web Analytics for anonymous, aggregate measurement of public pages and a small set of product events. Vercel Web Analytics does not use cookies and does not create a profile that follows you across websites. Public page URLs are recorded without query parameters or fragments; page views for Studio, login, authentication, and API routes are excluded. Product events contain only fixed labels and counts — never your name, email, account or pack ID, filenames, image URLs, or photo contents. For DYNEX advertising links, Signal Portrait accepts only a fixed campaign, channel and creative label and keeps that attribution in the current tab's session storage until the tab session ends. Arbitrary campaign text is discarded.
Meta advertising measurement is optional and disabled until you explicitly accept it. If accepted, the Meta Pixel may store the _fbp and _fbc advertising identifiers. We send only checkout-start and confirmed-purchase events with the pack tier, purchase value and currency. A purchase is reported only after Stripe confirms that it is paid; the browser and server use the same random event identifier so Meta can discard duplicates. We do not send Meta your photos, email address, account ID, filenames or image URLs. You can reject or withdraw this optional consent at any time using “Privacy choices” in the footer; withdrawal prevents tracking on future checkout sessions and removes those first-party advertising cookies from this site. A paid purchase may still be reported when its Stripe checkout began while consent was granted.
When Whop is selected as the purchase measurement provider, it requires a new, separate opt-in; a previous Meta choice does not authorize Whop. Signal Portrait keeps the Whop Pixel disabled until you choose “Allow ad measurement.” After you allow it, the Pixel runs only for the homepage and pricing page. It may create advertising cookies and IDs, including _wuid, and use browser and device signals, including fingerprinting. It receives only the public page and validated campaign labels and click IDs; private routes and unknown query values, fragments and referrers are excluded. Our integration does not provide Whop with photos, email, phone, account ID, filenames or image URLs.
A confirmed Stripe purchase may be sent server-side with its value and currency only after Stripe confirms it is paid. Checkout reads only a genuine Pixel-created _wuid; it does not invent one or emit a browser Purchase event. Declining or withdrawing stops new browser measurement, clears Whop IDs, cookies and campaign storage owned by this integration, and blocks new Whop checkout contexts. Requests already sent cannot be recalled. A purchase may still be reported if its Stripe checkout began while this consent was granted, because that checkout keeps the provider and consent snapshot from its start.
Questions about this policy? Write to support@signalportrait.com — a human answers.