studioheadshot.ai
Privacy & your photos

Your face is the whole product. Here’s where it goes.

You are handing us photographs of your face, which is about as personal as data gets. This page says plainly what happens to them, who else sees them, and how to get them deleted.

The short version. Your uploads are stored privately, are never public, and are sent to two AI providers — OpenAI and Anthropic — because that is how the headshots get made. We don’t sell your data, we don’t use your photos to train any model, and we run no advertising or analytics trackers of any kind. Email support@studioheadshot.ai and we will delete everything.

Who we are

This site is operated by studioheadshot.ai, which is the data controller for the information described here. Questions, requests and complaints all go to support@studioheadshot.ai.

What we collect

  • Your photographs. The reference photos you upload, and the headshots we generate from them. Both are held in private storage that is not readable without being signed in as you.
  • A fingerprint of each photo. A short perceptual hash, used to spot the same image uploaded twice. It cannot be turned back into the picture.
  • Your Google account basics. Sign-in is Google only, so we receive your email address, your name and your profile picture. We never receive your Google password.
  • Your consent record. Which version of the consent wording you accepted, and when.
  • Order and delivery records. What you bought, what it cost, the Stripe payment reference, and when you first downloaded each image. That last one exists so we can honour the refund policy without arguing with you.
  • Generation metadata. The prompt used for each image and the internal likeness and quality scores that decide which frames make your final set.
  • Anything you type into the corporate enquiry form — name, work email, company, team size and your message.

We do not ask for and never receive your card number. Payment details go straight to Stripe.

Who else sees your photos

Making an AI headshot necessarily means sending your face to the companies that run the models. Under the API terms we use, our model providers do not train their models on what we send them. They may retain it briefly — typically up to 30 days — for abuse monitoring, then delete it. We have no other subprocessors, and we do not sell, rent or share your data with anyone for their own marketing.

Our providers are all based in, or process data in, the United States. If you are outside the US, using studioheadshot.ai means your photos are transferred there.

How long we keep things

Until you ask us to delete them, or 30 days after your order — whichever comes first, once you ask. Being precise about this matters more than sounding tidy, so: deletion today is a manual process that we carry out on request, not an automatic sweep that runs on a timer. Email support@studioheadshot.ai and your uploads, your generated images and your account are removed within 30 days. We will keep a minimal payment record where tax law requires it, which is the amount, the date and the Stripe reference — never your photos.

We would rather tell you it is manual than imply a job that doesn’t exist. When automatic expiry ships, this paragraph changes.

Your rights over this

Whatever jurisdiction you are in, you can ask us to show you what we hold, correct it, delete it, or send it to you in a portable form. Email support@studioheadshot.ai from the address on your account and we will reply within 30 days. There is no form and no fee.

If you are in the UK or EU, our legal basis for handling your facial images is your explicit consent, which you give at upload and can withdraw at any time by asking us to delete. Withdrawing consent doesn’t undo generation that has already happened, and it doesn’t by itself entitle you to a refund — that is what the refund policy is for. You also have the right to complain to your data protection regulator.

Some places — Illinois and Texas among them — treat facial data as regulated biometric information with its own rules. We treat every upload to that standard regardless of where you live: consent first, disclosed recipients, no sale, deletion on request.

Cookies

Only the ones that keep you signed in. There is no analytics, no advertising pixel, no session recorder and no third-party tracker on this site — which is why you have not been asked to dismiss a cookie banner. Clearing your cookies signs you out and nothing else.

Security

Photos live in private storage buckets with per-user access rules enforced by the database, so one customer cannot reach another’s images. Traffic is encrypted in transit. That said, no service can promise a breach will never happen, and you should weigh that the way you would for anything you upload anywhere.

Children

studioheadshot.ai is for adults. Don’t use it if you are under 18, and don’t upload photographs of anyone who is. If we learn we hold a child’s images we delete them.

Changes

If we change how your photos are handled in any way that matters, we will update the date at the foot of this page and, where the change is significant, tell you directly before it takes effect.

Last updated 6 August 2026 · Terms · Privacy · Refunds