LEGAL · PLAIN ENGLISH
What we collect, how we use it, and what we will never do with your photos.
Your selfies and generated portraits are used for exactly one purpose: to create your headshots. Nothing else.
These are the same commitments stated on our Trust page. They are not fine print — they are how the product works.
To generate your portraits, your selfies are sent to the configured AI providers — currently Google Gemini as primary and OpenAI as fallback — only when needed to provide the service. Provider processing is governed by the relevant API terms and data controls. We do not intentionally submit your photos for model training.
All photos — selfies and generated portraits — are stored in private buckets. Access requires authentication; every URL is a short-lived signed link that expires after one hour. There are no permanent public URLs that could leak your images.
Access is further restricted at the database level: row-level security policies ensure only your authenticated account can read or delete your data.
Selfies are scheduled for permanent deletion no later than day 29 after upload, keeping the public promise below 30 days even if a scheduled job runs late.
Generated portraits are stored separately and remain available in your private gallery until you delete them. The source-selfie schedule never removes your delivered portraits.
You can delete source selfies and generated results sooner from the Privacy panel inside Studio. For account or payment records that cannot be removed through that control, email hello@dynexhq.com.
We use session cookies set by Supabase (our authentication provider) to keep you signed in. These are strictly necessary for the service to function.
We use Vercel Web Analytics for anonymous, aggregate measurement of public pages and a small set of product events. Vercel Web Analytics does not use cookies and does not create a profile that follows you across websites. Public page URLs are recorded without query parameters or fragments; page views for Studio, login, authentication, and API routes are excluded. Product events contain only fixed labels and counts — never your name, email, account or pack ID, filenames, image URLs, or photo contents. We do not use advertising cookies or third-party tracking pixels.
Questions about this policy? Write to hello@dynexhq.com — a human answers.