Privacy
Your face, your photos, your call.
The short version: we use your photos to make your pictures, we keep them for 30 days, and we delete them. We do not train anything of ours on them, we do not sell them, and we do not show them to anyone.
Last updated 18 September 2026. Headshot DP is operated by Rudra Tech Capitals LLC, 4030 Wake Forest Road, Suite 349, Raleigh, NC 27609, United States. That company is responsible for everything described on this page, and it is who you are dealing with. Contact support@headshotdp.com.
What we collect
- The photos you upload. Used to build a model of your face and nothing else.
- Your email address. How you sign in and how we tell you your pictures are ready.
- Your name and occupation, if you choose to give them. Occupation only affects the settings your pictures are taken in.
- The choices you make in the picker — outfit, setting, lighting, framing, and any words you add yourself. These become the instructions your pictures are made from.
- A record of your consent — what you agreed to, when, the exact wording you were shown, and roughly where and on what you agreed. That last part exists so you can prove what you agreed to as easily as we can.
- Payment records. Card details go straight to Stripe and never reach our servers. We store an order number, the amount, and a card label such as “Visa ending 4242”.
- Basic technical logs kept to run and secure the service — request times, errors, and what each job did.
We do not ask for your date of birth, address, phone number, or anything else we have no use for. What is listed above is the whole of it.
Why we are allowed to do this
If you are in the UK, EU or somewhere with comparable law, these are the legal bases we rely on:
- Your permission for anything to do with your face. The law treats this as the most sensitive kind of information there is and requires us to ask outright, so we ask separately, before anything is uploaded, and you can take it back at any moment.
- Performing our contract with you — making and delivering the pictures you ordered, and taking payment for them.
- Our legitimate interests — keeping the service secure, preventing fraud and abuse, and keeping the records a business has to keep. We do not rely on this for anything to do with your face.
- Analytics and advertising cookies — in the EU, the UK and Switzerland, only with your consent; everywhere else they are on unless you turn them off.
Biometric information
Building a model of your face counts, legally, as handling biometric information, and we treat it as the most sensitive thing here. We ask for explicit consent before anything is uploaded, we record that consent against the exact wording you were shown, and you can withdraw it at any time — which deletes everything immediately.
We never use your images to identify you, to verify identity, to match you against any other person, or in any dataset of ours. The model built from your photographs exists to make your pictures and is deleted with them. If you are in Illinois, Texas, Washington or another state with a specific biometric statute, that is the whole of our retention schedule: thirty days, then permanent destruction.
Who else processes your data
We use a small number of companies to run this. Each acts on our instructions under contract, may only use your data to provide their service to us, and may not use it for their own purposes or to train their own models.
- Astria — trains the model on your photographs and makes your pictures. Gets your photographs and the description of the look you chose.
- OpenAI — an alternative route to the same image model. When it is in use, your photographs are sent as references with each request. Gets your photographs and the description of the look you chose.
- Anthropic — writes the wording that describes each look. It receives only your picker choices as text — “navy blazer, city street, evening light” — and never your photographs, your email, or anything that identifies you.
- Stripe — takes payment. Receives your card details directly; we never see them.
- Vercel — runs the website and holds your pictures. They are kept in a locked store: nobody can reach a picture of you without being signed in as you.
- Supabase — hosts the database holding your account, orders, consent record and job history. No images are stored there.
- Resend — sends your sign-in codes and the email that says your pictures are ready. Receives your email address.
- Trustpilot — asks for a review. Once your pictures are delivered, the email saying so is copied to Trustpilot, which receives your name, your email address and your order number, and sends you one invitation to review us. Only after a purchase, only once, and never with any of your pictures.
- Google Analytics — counts visits, and only if you allow it. Never receives anything that identifies you; see below.
- Meta — tells us which advert someone arrived from, and only if you allow it. This one is different from the rest of this list and we would rather say so plainly: Meta uses what it receives for its own advertising purposes, not only ours. It is told that a purchase happened, what it was worth, and a scrambled version of your email address that it can match against an account it already has. It is never told which pictures are yours, and it is not loaded at all on the pages that would name them. See below.
We do not sell your data, and we share it with nobody outside this list except where the law requires it — for example a valid court order, which we would tell you about unless we were forbidden to.
Where your data goes
These providers operate on servers that may be outside your country, including in the United States. Where your information leaves the UK or Europe, we have contracts in place that hold those companies to the same standards you would have at home. Our host is also certified under the arrangement the UK and EU recognise for sending information to American companies — the Data Privacy Framework — which is the formal answer if anyone asks you how this is allowed. If you would rather your photographs were not handled outside your country, do not upload them — we cannot offer this service without doing so, and we would rather say that plainly than bury it.
How long we keep things
- Photos, models and generated pictures — 30 days from upload, then permanently deleted, here and at the providers. Download what you want before then.
- Consent records and receipts are kept after that. They are the proof of what you agreed to and what you paid, and deleting them would remove your evidence as well as ours. Tax law also requires us to keep records of sales.
- Your account and order history stay until you ask us to close the account.
- Technical logs are kept only as long as they are useful for security and debugging.
Security
- There is no web address that shows a picture of you to whoever happens to have it. You have to be signed in as you. The full-size versions need a link that only appears on an order you have paid for, and that link stops working shortly after.
- The pictures you look at before paying are watermarked and small on purpose. The clean, full-size version is never sent to your screen until you have bought it.
- Signing in uses a six-digit code emailed to you. It works once, expires after ten minutes, and stops working after five wrong guesses. We never keep the code itself — only a scrambled version we can check against, which cannot be turned back into the code.
- We keep no card numbers. Stripe holds those.
No system is perfectly secure. If we ever discover a breach affecting your data we will tell you, and the relevant regulator, as quickly as the law requires and sooner if we can.
Where your data is kept
Our website, database and your pictures are hosted in the United States, and the companies that make your pictures work there too. We are not going to claim European hosting we do not have. If that matters to you, it is better that you know before you upload than after.
Everything is encrypted on its way to us and while it sits with us, using the same standards banks and every serious website use. That is table stakes rather than something to boast about, but it is true.
Backups
Our database is backed up, as any responsible service’s is. When you delete your data we delete it from the live system straight away, and it disappears from backups as those are rotated and overwritten — a matter of days, not indefinitely. Nobody looks at a backup except to restore the service after a failure.
Your photographs and pictures are not in those database backups. They live in a separate store, and deleting them deletes them.
Who can see your photographs
Almost nobody, almost never. Your pictures are not browsable by our staff, and there is no internal gallery of customers. Access exists only for fixing a specific problem you have told us about, and it is limited to the people who need it to do that.
We do not look at your photographs to review them, moderate them, pick examples, or for any other reason of our own.
If something goes wrong
If we ever discover a breach affecting your data, we will tell you and the relevant regulator within 72 hours of finding out, and sooner if we can. We will tell you what happened, what was affected, and what we are doing about it — in plain terms, not a press release.
What we send you
Three kinds of email at most, and only one of them is optional.
Two always: the code that signs you in, and the message that says your pictures are ready. Those are the ones you asked for by using the product, and there is no way to switch them off short of closing your account.
One more, at most once ever: if you start a set and stop part-way through adding photos, we send a single message saying what the uploader accepts. It is help finishing the thing you began rather than an offer, and there is no second one — not a week later, not on your next set.
And the last only if you ticked the box for it. There is an optional checkbox on the consent screen — unticked, and nothing depends on it — that says “email me occasionally about new styles and offers”. The only other way onto that list is giving us your email for the 50% family offer, which says the same thing beside the box you type it into. We send the code to that address once, straight away. Do neither and you will never hear from us about anything else.
This page used to say there was no marketing at all, and we said that if we ever wanted to send you something else we would ask first. That checkbox is the asking. Anyone who signed up before it existed is not on that list and will not be added to it — they agreed to the old sentence, and a change of policy is not a change of their answer.
Every one of those emails carries an unsubscribe link that works without signing in, because somebody who wants out should not have to remember a password to get out. It takes effect immediately and it does not stop your sign-in codes.
The infrastructure underneath us
We did not build our own data centres, and we are glad we did not. The companies whose infrastructure we run on are audited to standards a business of our size could not reach alone:
- Vercel, which runs the website and stores your pictures, holds SOC 2 Type 2, ISO 27001:2022 and PCI DSS. Their current reports and the list of everyone they in turn rely on are published at security.vercel.com — you can check that yourself rather than take our word for it.
- Stripe, which handles every payment, is certified at the highest level the card industry defines. Your card number goes straight to them and never touches anything of ours.
Those certificates belong to them, not to us. They mean the ground we are standing on is solid — the servers, the network, the physical security, the way access is controlled inside those companies. They do not say anything about the choices we made on top: how long we keep your photographs, who here can look at them, what we send to whom. Nobody can audit that for us, so the rest of this page describes it plainly instead, and every line of it is something you could hold us to.
Being honest about what we are not
We are a small operation. Our providers’ certificates are theirs; we do not hold a SOC 2 certificate of our own, we do not run a formal penetration testing programme, and we do not promise a particular uptime figure. Everything on this page describes what we actually do rather than a standard we would like to be measured against. If you need those assurances for a company purchase, we are probably not the right supplier yet, and we would rather tell you that than imply otherwise.
For businesses
If you are buying this for a team and your legal department needs a data processing agreement, email us and we will sign one.
Deleting your data
There is a delete control on your order page. It removes your photos, your model and every picture made from it, immediately and permanently, with no way to recover them. You can also email support@headshotdp.com and ask us to do it. We keep the consent record and the receipt, as above.
Your rights
Wherever you live, you can ask us to show you what we hold, correct it, delete it, hand it over in a portable form, or stop using it. You can withdraw consent at any time without giving a reason, and doing so does not make what we did before it unlawful.
If you are in the UK or EU you may also complain to your data protection authority — in the UK, the Information Commissioner’s Office. In California you have the rights to know, delete, correct and opt out of sale or sharing; we do not sell or share personal information as those words are defined there, and we will not discriminate against you for exercising any of this. In India, you may withdraw consent and request erasure under the Digital Personal Data Protection Act.
Email us and we will action it, normally within a few days and always within a month. We will not make you jump through hoops or charge you.
Children
This service is for adults. You confirm you are 18 or over before you upload anything. If we learn we hold a child’s photographs we delete them immediately.
Automated decisions
Your pictures are made by an automated system, which is the product. No automated decision is made about you — nothing here judges you, scores you, or decides anything that affects your rights.
What we do not do
- Train our own models on your photos.
- Sell or rent your photos, your email, or anything else about you.
- Show your pictures to anyone else, including as examples.
- Let any advertiser see your photographs, or learn which pictures are yours.
- Use your face for anything other than the pictures you asked for.
That fourth line used to read “track you across other websites”, and we have changed it rather than quietly leaving it there. Unless advertising cookies are off, Meta is told that a purchase happened and what it was worth, together with a scrambled form of your email address — which is how it recognises you as someone who saw one of our adverts. That is cross-site measurement and the old wording was no longer true of it. Turn them off and none of it happens; the wording below describes exactly what does.
Cookies, analytics and advertising
The cookie that keeps you signed in is strictly necessary — without it the site cannot know it is you — so it is always on.
We also count, in our own records, how people move through the site: which pages are seen, whether a free preview was made, whether it led to a purchase, and which advert or post someone first arrived from. Two cookies of ours do this — a random visitor number and a 30-minute session number — and they follow the same answer as the analytics below: off until you allow them where you are asked, and off whenever you say no. They hold no name, email or picture, and nothing from them is sold or shared.
We use Google Analytics to count visits and see which pages get used, and the Meta pixel and LinkedIn's Insight Tag to tell whether an advert we paid for brought somebody here. In the EU, the UK and Switzerland they are off until you allow them: Google's cookies are set to denied before anything of Google's loads, and the Meta and LinkedIn tags are not on the page at all until you say yes. Everywhere else they are on when you arrive, and you can turn them off. If your browser sends a Global Privacy Control signal, we treat it as a no. Turned off, nothing is stored by any of them.
One question for all of them, because we do not run one without the others, and offering choices that lead to the same outcome would be a pretence. LinkedIn is told when somebody who arrived from one of our LinkedIn adverts creates an account — not your email address, and nothing about your pictures.
You can change your answer whenever you like — there is a Cookie choices link at the bottom of every page. Saying no later works exactly like saying no the first time.
Even then, Google is told which kinds of page get looked at, never which one was yours. It knows somebody opened a gallery. It is not told whose gallery, or which order, so nothing it receives can be traced back to you or your photographs. We have also turned off the settings that would let Google follow you onto other websites.
Meta is handled differently, because its tag cannot be made to lie about which page it is on. Google’s lets us send a page address of our choosing, so we send one with the identifiers taken out. Meta’s reads the address itself and there is no way to override it — so instead of redacting the address, we do not load it at all on any page whose address names something: not your gallery, not your download, not your checkout, not the admin pages. It runs on the pages a stranger can read and on the ones that name nobody.
Which leaves the purchase itself, the one thing an advertiser actually wants to know. That is sent from our server rather than from your browser: the order reference, what it was worth, and your email address scrambled into a form that cannot be read back. Your name, your address, your telephone number, your IP address and your photographs are not sent, and there is no code here that could send them.
Changes
If this page changes in a way that affects what happens to your data, the consent you gave is recorded against the wording you actually saw — a new policy does not silently apply to an old agreement. Material changes will be notified by email before they take effect.
Questions about any of this: support@headshotdp.com.