Privacy Policy
Last updated July 20, 2026.
The 30-second version
- We don't require a password or email to use the free preview.
- We strip EXIF metadata from your photo on upload.
- We retain source photos for retries for up to 7 days. After that, they are blocked from use and queued for automatic deletion, with cleanup retried until storage confirms removal. Generated portraits are retained so you can return to them.
- We never use your photos to train AI models or opt them into provider training.
- We don't sell your data. Period.
What we collect
- Pet photos you upload. Used to generate your portrait and support retries and customer service. After 7 days they are blocked from further use and queued for automatic deletion; cleanup retries until storage confirms removal. You can ask us to delete them sooner at any time. After the image bytes are deleted, we may retain limited operational metadata—such as file type, dimensions, size, upload time, and deletion time—without retaining the source photo.
- Generated portraits. We keep these so you can return to preview, download, or re-download them. Authorized staff may review a watermarked portrait when reasonably needed for customer support, refund decisions, abuse prevention, or generation-quality monitoring. You can ask us to delete generated portraits anytime.
- Email address—when you give it to us. Collected at Stripe checkout, when you request a secure access link, or when you ask to be notified about prints. Used for receipts, purchase recovery, service messages, and requests you initiate. Print-interest addresses receive a confirmation link; unconfirmed requests are removed after expiration and are never eligible for launch mail. Never sold.
- Product and performance signals. Page views, generation latency, success/failure events, style selections, checkout starts, and downloads. When enabled, Vercel Web Analytics is configured without advertising cookies or cross-site identifiers.
- IP address. When our trusted hosting proxy supplies it, we hash it into short-lived abuse-prevention counters. We do not store the raw address in those counters.
What we don't collect
- Your name, billing location, or phone number directly in our application. Stripe may collect some of these fields during checkout for payment, fraud, receipt, or tax purposes.
- Your camera roll, location, or device contacts.
- Tracking cookies for ads. We don't run ads.
Who sees your photo
Two parties touch your image:
- Us. Automated systems process, deliver, and store your portrait so you can return to it. Access is limited to authorized operators with a legitimate support, safety, fraud-prevention, or quality-monitoring need. Source uploads leave the active system after the short retry window; staff quality review normally uses the retained watermarked portrait instead.
- OpenAI. Your photo is sent to OpenAI's image-edit API as the reference for generation. OpenAI's data handling policy applies during that call. OpenAI does not use API inputs or outputs to train its models unless an API customer explicitly opts in. Our organization's sharing controls are disabled, and we do not opt customer uploads into model training. OpenAI's standard abuse-monitoring logs may retain API inputs and outputs for up to 30 days, subject to its policy, legal requirements, and any approved retention controls on our account. See OpenAI's current API data controls.
Service providers
- Stripe. Processes payments and may calculate applicable tax.
- Replit. Hosts the application runtime and may process ordinary request and infrastructure logs.
- Vercel. Provides private image storage and, when enabled, privacy-focused web analytics.
- Resend. Delivers purchase, one-time access, and requested print-interest confirmation emails when email delivery is enabled.
Access links and browser sessions
We place an HttpOnly, same-site session cookie so this browser can reopen private portraits and orders. A checkout email can request a short-lived, one-time link to connect another browser. Session and access-token database records are hashed. To deliver an access email, the pending email queue briefly contains the working one-time link; its message body is erased after successful delivery or a terminal delivery failure.
Children
The service is not intended for children under 13. If we learn we've received data from a child under 13, we delete it.
Your rights
You can ask us to delete source uploads, generated portraits, memorial text and pages, and account-access data: contact. We verify requests before deleting private media. Deleting purchased artwork also removes future re-download access. We may retain limited transaction, refund, security, and legal records where reasonably necessary or legally required.
Changes
If we change this policy materially, we'll surface a notice in the app before the change takes effect.
Contact
Questions about privacy: contact.