Privacy Policy
How Realistic AI Headshots collects, uses, shares, and deletes personal data and portrait photos.
Last updated: Sep 18, 2026
1. Who we are
Realistic AI Headshots is the trading name of an independently operated online service that provides personalized AI professional headshots. The individual merchant operating the Service acts as the data controller for personal data handled through this website unless another party is identified at the point of collection.
Privacy requests and questions may be sent to support@realisticaiheadshots.com.
2. Scope
This Privacy Policy applies to our website, account area, purchase flow, upload workflow, AI training and generation process, result gallery, support communications, and related emails. It does not control the independent privacy practices of third-party websites you visit through external links.
3. Information we collect
We may collect:
- Account and contact information: name, email address, authentication records, language, and support messages.
- Portrait inputs: the photos you upload, upload metadata, selected presentation, professional looks, and instructions needed to generate your order.
- Generated content: temporary personal-model identifiers, generation requests, generated portraits, archives, edit history, and technical status records.
- Order and payment records: package, price, currency, payment status, payment-processor customer or checkout-session identifiers, refund status, and billing-related contact information. We do not store complete payment-card numbers.
- Device and usage information: IP address, browser, operating system, timestamps, requested pages, security events, and diagnostic logs.
- Cookies and similar technologies: essential session, authentication, security, language, and preference cookies. If optional analytics or third-party sign-in is enabled, those providers may set or read additional identifiers as described below.
4. Why and how we use information
We use information to:
- create and secure accounts and verify email addresses;
- accept uploads, process one-time payments, and fulfill purchased orders;
- train a temporary personal image model and generate selected professional looks;
- store, display, package, and deliver results through the user’s account;
- send transaction, security, progress, completion, and support emails;
- prevent abuse, fraud, unauthorized access, duplicate processing, and payment disputes;
- diagnose failures, retry technical work, provide support, and improve reliability; and
- comply with payment, tax, accounting, legal, and regulatory obligations.
Where applicable law requires a legal basis, processing is based on performance of our contract with you, compliance with legal obligations, our legitimate interests in operating and protecting the Service, and consent where required. You may withdraw consent for future optional processing, but this does not affect processing already lawfully completed or data we must retain.
We do not use portrait uploads or generated results for advertising, sell them, publish them as examples without separate permission, or use them to train a general public model.
5. Service providers and disclosures
We disclose only the data reasonably required for each category of provider to perform its role:
- AI model training, image generation, and editing providers: portrait inputs, generation or editing instructions, necessary technical identifiers, temporary personal-model training, portrait generation, and edited results.
- Network, security, content-delivery, and private-storage providers: request and security information, private portrait assets, downloadable archives, and related storage metadata.
- Website hosting and computing providers: website delivery, server execution, deployment, diagnostic information, and operational logs.
- Managed database providers: account, order, workflow, retention, and other production records required to operate the Service.
- Payment processors: payment processing, fraud prevention, invoices, refunds, and payment disputes.
- Transactional email providers: account, transaction, completion, deletion, and support-related email delivery.
- Authentication and optional analytics providers: sign-in and, only if enabled, analytics or related measurement features.
Providers process information under their own applicable terms and privacy commitments. We may also disclose information when legally required, to enforce our agreements, to investigate fraud or security incidents, or as part of a merger, financing, acquisition, or transfer of the Service with appropriate notice and safeguards.
6. International transfers
Our users and providers may be located in different countries. Information can therefore be processed outside your place of residence, including in Hong Kong, the United States, and other locations used by our providers. Where required, we rely on contractual protections, provider data-protection terms, or another lawful transfer mechanism.
7. Portrait storage and retention
We minimize retention of portrait assets:
- Unpaid draft uploads are scheduled for deletion after 7 days of inactivity.
- Training photos for a successful order are scheduled for deletion 7 days after delivery, allowing a short technical-recovery period.
- The temporary personal model held by our AI generation provider is retained for the period included with the purchased plan: 30 days for Essential, 60 days for Professional, and 90 days for Personal Brand. We enable the provider renewal needed to cover that period and schedule deletion at the plan deadline. Legacy or test First Shoot projects use a 30-day compatibility period. If you begin an Additional Look checkout before expiry, an unfinished checkout or payment session can retain the model for up to 24 hours. Once payment is recorded, the model remains protected while fulfillment is pending.
- Generated portraits and downloadable archives use the same plan-based retention period: 30 days for Essential, 60 days for Professional, and 90 days for Personal Brand. Additional Look results are retained for 30 days.
- Pending or orphaned upload objects are deleted after their short upload-validation window.
Deletion runs through recurring maintenance and retry queues. If a provider or storage operation temporarily fails, the item remains queued for another deletion attempt rather than being treated as successfully removed.
Account, order, invoice, fraud-prevention, audit, and support records may be retained longer when reasonably necessary for tax, accounting, security, dispute, contractual, or legal requirements. Those records are separated from deleted portrait assets where practical.
You should download purchased portraits before the expiry date displayed in your account. A verified account-deletion request starts deletion sooner, subject to required records and operations already needed to resolve a payment or legal dispute.
8. Cookies and analytics
Essential cookies are required for sign-in, session security, language, checkout continuity, and fraud prevention. Disabling them can prevent the Service from working.
If enabled with your permission, an optional analytics provider may process page views, approximate location derived from IP address, device and browser information, referrals, and product events such as account creation, checkout initiation, and completed purchases. We use this information to understand aggregate site performance, diagnose funnel drop-off, and improve the Service. We do not send portrait photos, generated images, payment-card details, or form contents to the analytics provider.
Optional analytics remains disabled unless you select “Allow analytics.” You can withdraw or change that choice at any time through “Cookie settings” in the website footer. Withdrawing consent stops future analytics collection in that browser and removes the optional analytics cookies that we can remove from this website. You can also restrict cookies through your browser, but essential features may stop working.
Third-party sign-in is optional. Choosing it sends authentication information to the selected identity provider, which returns the account information needed to sign you in; that provider’s own privacy terms also apply.
9. Security
We use HTTPS, access controls, private object storage, short-lived signed download links, protected provider credentials, webhook verification, and operational logging. No system can guarantee absolute security. Please use a unique password and notify us promptly if you believe your account or photos have been accessed without permission.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete personal data, withdraw consent, and complain to a data-protection authority. You may update account information or request account deletion through account settings. For other requests, email us from the address associated with your account so we can verify your identity.
We aim to respond within the period required by applicable law. We may ask for additional information when reasonably necessary to verify identity and protect another person’s privacy.
11. Children
The Service is not directed to children. Do not upload a minor’s photo unless you are the parent or legal guardian and have authority to do so. If we learn that a minor’s data was submitted without valid authorization, we will take reasonable steps to delete it.
12. Changes to this policy
We may update this Policy as the Service, providers, or law changes. Material changes will be identified by the “Last updated” date and, where appropriate, by an account or email notice.