Privacy Policy
Privacy Policy
Last updated April 20, 2026
1. Who we are
Photona AI, Inc.("Photona", "we", "us", "our") operates Photona.ai and related services that let you create professional AI-generated headshots from photos you provide.
2. Information we collect
- Account information, such as your email and profile details from sign-in providers like Google or Facebook.
- Photos you upload to create headshots, stored in our Supabase uploads bucket.
- Generated headshots and related outputs, stored in our Supabase headshots bucket.
- Payment and purchase metadata processed by Stripe. We do not store full card numbers.
- Usage and device data, including analytics and cookie-related data from PostHog and Meta Pixel.
3. How we use your information
- To authenticate your account and provide the product you requested.
- To generate headshots by securely sending selected image inputs to OpenAI image-generation APIs.
- To process payments and manage credits through Stripe.
- To send transactional communications, such as login links and purchase confirmations.
- To analyze aggregate usage and improve reliability, quality, and product experience.
We do not use your uploaded photos to train our own models, and we do not sell your photos.
4. Service providers and subprocessors
We use trusted vendors that process data on our behalf, including:
- Supabase (authentication, database, and file storage)
- OpenAI (image-generation infrastructure)
- Stripe (billing and payments)
- Google and Meta (OAuth sign-in and advertising signals)
- PostHog (product analytics)
- Supabase Auth email services for transactional auth emails
5. Data retention
We retain uploaded photos and generated headshots while your account is active so you can access your results. You may request deletion of your account and data at any time. We may delete inactive account data after 24 months.
6. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict some processing. California residents may have rights under CCPA/CPRA, including rights related to sharing for cross-context behavioral advertising. EEA/UK residents may have rights under GDPR Articles 15-22.
To exercise rights, contact us at support@photona.ai.
7. Children
Our services are not intended for children under 18, and we do not knowingly collect personal information from children under 18.
8. Security
We use administrative, technical, and organizational safeguards to protect your data, including encryption in transit (TLS), encryption at rest through our infrastructure providers, role-based access controls, and monitoring. No system is perfectly secure, but we work to protect your information using industry-standard practices.
9. International data transfers
Your information may be processed in the United States and other countries where our service providers operate. These countries may have different data protection laws than your country of residence.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will post an updated version with a revised "Last updated" date.
11. Contact us
For privacy questions or requests, contact support@photona.ai.
Mailing address: Photona AI, Inc., Delaware, United States.