Privacy Policy

Last updated: 2026-08-20

Introduction

At PhotoID Studio we respect your privacy. This policy explains what information we collect when you use our website and desktop application, why we process it, and how long we keep it. It works alongside the End User Licence Agreement shown when you first open the desktop app.

Information We Collect

Account: your email address, name, optionally your Google account details and phone number. Where a flow requires business details, your studio name, address and city. Payment: payments are taken through Paddle. Your card details never reach us and are not stored by us. Licence and device: application version, operating system, device/installation identifier and session events. These exist to verify that a licence is used on one machine. Processing metadata: when you run background removal or retouching we record the operation type, its outcome (success or error code), duration, app version, IP address and country. These records exist for abuse and cost control and contain no image data.

How Your Photos Are Processed

Most of the work happens on your own computer: face detection, cropping, country sizing, print sheet layout and export never leave your machine. Only two steps run on the graphics card in our servers: background removal and retouching. For these, a downscaled copy of the photo is sent; for retouching, only the face area is sent. Your original, full-resolution photo is never sent, and no name, email address or any detail about the person in the photo travels with the image. The server does not send you an edited photo. What comes back is a mask: information describing which areas are background and how much correction each point needs. That information is applied to your original photo on your computer; the finished photograph is created only on your machine. During this the photos are held in memory only, temporarily, and are not stored on our servers.

How Long We Keep Data

Photos: not retained. Images are held in memory only for the duration of the request; they are not written to disk, object storage or any database. They are released once processing completes. Account data: kept for as long as your account exists. When you ask us to delete your account, your personal data is deleted; invoice records that accounting and tax law require us to keep remain for the statutory period. Processing and licence metadata: kept for abuse control and capacity planning, and pruned regularly. Support correspondence: kept for a reasonable period after your request is closed.

Sharing Information

We do not sell your personal information and do not share it with third parties for marketing. To run the service we use only these providers: • Paddle — payment and invoicing. • Modal Labs — background removal and retouching. Only the downscaled image described above is transmitted; no account information is sent. • Resend — transactional email (verification, subscription notices). • Cloudflare — website delivery and security. Where a legal obligation arises, we share the minimum necessary with the competent authority.

Cookies

Our website uses technical cookies for session handling, security verification and language preference. We do not use third-party cookies for advertising or profiling. When we collect visitor statistics we do not seek to identify individuals.

Your Rights

Under GDPR and equivalent laws you have the right to access your data, request correction, request deletion, object to processing, and receive your data in a portable form. To exercise these rights, write to [email protected]. We respond within one month at the latest, after verifying your identity.

Contact

For questions or requests about this policy: [email protected] Data controller: Murat Duru (PhotoID Studio).