Skip to main content

GDPR & privacy - how does Headshotly handle my data?

Updated over 5 months ago

Headshotly follows GDPR and international privacy standards to make sure your photos, personal data, and AI models are protected, private, and under your control.

1. We Follow Global Privacy Laws

Headshotly complies with:

  • GDPR (Europe) – General Data Protection Regulation

  • CCPA (California, USA) – California Consumer Privacy Act

  • Other regional data protection laws where applicable

This means you have full rights over your personal data — to access it, download it, or permanently delete it.

2. What Data We Collect (Only What’s Needed)

We collect:

  • Your email and account info (to log you in and send updates)

  • Your uploaded photos (to train your AI model and generate results)

  • Technical details like IP address, device, browser type (for security and analytics)

3. How Your Data Is Used

We only use your data to:

Train your personal AI face model

Generate headshots, thumbnails, team photos, etc.

Improve your dashboard experience and credit system

Send account updates, receipts, or password reset emails

4. Storage & Deletion Policy

  • Uploaded photos are automatically deleted within 7–30 days after your model is trained

  • AI-generated images and models stay in your account until you delete them

  • You can permanently delete everything - photos, models, and account - anytime

  • Once deleted, the data cannot be recovered

5 . Security Measures We Use

  • End-to-end encrypted uploads (HTTPS + SSL)

  • Secure cloud storage (AWS)

  • Limited employee access, only when support is requested

  • Regular security audits and data protection practices

In simple words:

You own your data. You control your data. You can delete your data. And we protect it.

Did this answer your question?