SIGNALPORTRAIT

LEGAL · PLAIN ENGLISH

Privacy Policy

What we collect, how we use it, and what we will never do with your photos.

EFFECTIVE DATE · 2026

What we collect

  • Selfies you upload. The photos you submit to generate your headshots. They are stored in a private, access-controlled bucket — there are no public URLs.
  • Generated portraits. The AI headshots we produce for you. Stored in a private bucket, accessible only through short-lived signed URLs (1-hour expiry) tied to your account.
  • Email address. Collected when you sign in via magic link or Google OAuth. Used to identify your account and send you your results.
  • Payment data. Handled entirely by Stripe. We never see, store, or process your card number. We only receive a confirmation that payment succeeded and the pack tier you purchased.

How your photos are used

Your selfies and generated portraits are used for exactly one purpose: to create your headshots. Nothing else.

  • We never use your photos to train, fine-tune, or benchmark any AI model — ours or anyone else's.
  • We never sell or share your photos with data brokers, advertisers, or any third party for marketing purposes.
  • We never use your face in our own marketing without your written permission.

These are the same commitments stated on our Trust page. They are not fine print — they are how the product works.

AI processing

To generate your portraits, your selfies are sent to the configured AI providers — currently Google Gemini as primary and OpenAI as fallback — only when needed to provide the service. Provider processing is governed by the relevant API terms and data controls. We do not intentionally submit your photos for model training.

Storage and access

All photos — selfies and generated portraits — are stored in private buckets. Access requires authentication; every URL is a short-lived signed link that expires after one hour. There are no permanent public URLs that could leak your images.

Access is further restricted at the database level: row-level security policies ensure only your authenticated account can read or delete your data.

Retention and deletion

Selfies are scheduled for permanent deletion no later than day 29 after upload, keeping the public promise below 30 days even if a scheduled job runs late.

Generated portraits are stored separately and remain available in your private gallery until you delete them. The source-selfie schedule never removes your delivered portraits.

You can delete source selfies and generated results sooner from the Privacy panel inside Studio. For account or payment records that cannot be removed through that control, email hello@dynexhq.com.

Cookies and analytics

We use session cookies set by Supabase (our authentication provider) to keep you signed in. These are strictly necessary for the service to function.

We use Vercel Web Analytics for anonymous, aggregate measurement of public pages and a small set of product events. Vercel Web Analytics does not use cookies and does not create a profile that follows you across websites. Public page URLs are recorded without query parameters or fragments; page views for Studio, login, authentication, and API routes are excluded. Product events contain only fixed labels and counts — never your name, email, account or pack ID, filenames, image URLs, or photo contents. We do not use advertising cookies or third-party tracking pixels.

Contact

Questions about this policy? Write to hello@dynexhq.com — a human answers.