Star Headshot · Privacy
What happens to your photo and account information.
Last updated: 2026-09-24
Local photo checks
Before you authorize generation, photo analysis runs inside your browser using a locally served MediaPipe model. Photos selected for local analysis, facial landmarks, color samples and analysis results are held in browser memory. Local analysis does not send them to our server or train a model. Leaving or reloading the studio clears the session. Downloading a creative brief saves a file on your device that contains your name, presentation preference, measurements and color samples.
Accounts and teams
If you create an account, the service stores your account information and authentication records. Creating a signed-in workspace saves its name, style and member email addresses. Invitations are bound to the invited email address, expire after 14 days, and become invalid when accepted or regenerated. Only hashed invitation tokens are stored. Team owners can manage their workspace members. Preview workspaces are temporary and are not saved to the server.
Cookies and service operation
Authentication uses session cookies. Language selection uses a locale cookie. Server requests may appear in hosting logs. Analytics and support integrations are disabled unless the operator configures them; this page must be updated before enabling additional tracking.
Generation and payment
Generation requires a separate consent and a paid package. Preparing a task uploads 1–3 reference photos to private application storage. Starting generation sends those photos to Volcengine Ark, using Seedream 5.0 pro. Editing sends the selected saved result and its original reference photos. Names, facial landmark coordinates and the local analysis report are not included in these generation requests. Volcengine's handling of received data is governed by its own service policies; the application does not claim that provider processing stays on your device.
References and results are stored privately. Viewing, downloading and deleting require the task owner's authenticated account. Photo access expires seven days after the task was created; expired photos cannot be used to continue that task. You can delete a task's photos from the studio. An in-progress image may need to finish before deletion is available. Expired objects are removed through application cleanup or the storage lifecycle; a failed cleanup is retried. Access expiry does not imply instantaneous physical deletion by every provider.
Stripe hosts checkout. The application stores the order, payment status, purchased entitlement snapshot and usage needed for fulfillment and refunds; it does not receive your full card details. It retains non-image usage records and image fingerprints needed to prevent duplicate delivery, bind the same reference photo to an order, and prevent deleted tasks from restoring used allowances. A refund freezes further use of that order. Photo deletion does not erase payment or fulfillment records.
Photo measurements
The analysis estimates visible geometry and photo signals. It does not identify a person, assess attractiveness or diagnose a health condition. Lighting and camera perspective can change the measurements and sampled colors.
Account data requests
Signed-in users can raise a data or account request through account support. Automatic account deletion is not implemented. The operator name and dedicated privacy contact have not yet been supplied; this notice does not invent those details.