Privacy Policy
Last updated: March 24, 2026
TL;DR
- Your uploaded photos are deleted within 24 hours.
- We never sell your data.
- Generated images are retained while your account is active.
- You can request deletion of all your data at any time.
- Analytics only run with your consent.
1. Data Controller
SelfieAI ("we", "us", "our") is the data controller responsible for processing your personal data. For privacy inquiries, contact us at privacy@selfieai.app.
2. Data We Collect
We collect the following categories of personal data:
- Photos you upload: Used solely for AI image generation, deleted within 24 hours.
- Email address: Optional, used for account creation and photo delivery.
- Payment data: Processed by Pix (AbacatePay) or Stripe. We do not store payment card details.
- Device information: IP address, browser type, device type for security and rate limiting.
- Usage data: Pages visited, features used, generation counts (anonymized analytics).
- Cookies: Essential cookies for service operation; analytics and marketing cookies only with consent.
3. Legal Basis for Processing
We process your data based on the following legal bases:
- Consent: Analytics cookies, marketing communications, and photo upload processing.
- Contract performance: Processing payments and delivering the image generation service.
- Legitimate interest: Security measures, fraud prevention, and service improvement.
- Legal obligation: Tax records, legal compliance, and responding to legal requests.
4. Third-Party Processors
Your data may be processed by the following third-party services:
- Google Gemini: AI image generation (photos sent for processing, not stored).
- AbacatePay: Pix payment processing (Brazil).
- Stripe: International payment processing.
- Vercel: Hosting and content delivery.
- Upstash: Rate limiting and session management (Redis).
- Meta/Facebook: Conversion analytics (with consent only).
- PostHog: Site usage analytics (with consent only).
- Resend: Transactional email delivery.
- Sentry: Error monitoring (anonymized).
5. Data Retention
- Uploaded user photos: Deleted within 24 hours after generation.
- Generated images: Retained while your account is active, or 7 days for guest users.
- Account data: Retained for 30 days after a deletion request, then permanently deleted.
- Analytics data: Anonymized after 26 months.
- Payment records: Retained for 5 years per tax regulations.
- Security logs: Retained for 90 days.
6. Your Rights Under GDPR (EU Users)
If you are located in the European Economic Area, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate personal data.
- Right to erasure: Request deletion of your personal data ("right to be forgotten").
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interest.
- Right to restrict processing: Request limitation of data processing.
- Right to withdraw consent: Withdraw consent at any time (does not affect prior processing).
To exercise your rights, email privacy@selfieai.app. We will respond within 30 days.
7. Your Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to know: You may request disclosure of the categories and specific pieces of personal information we collect.
- Right to delete: You may request deletion of your personal information.
- Right to opt-out of sale: We do not sell your personal information. If this changes, you will have the right to opt out.
- Right to non-discrimination: You will not receive discriminatory treatment for exercising your privacy rights.
8. Do Not Sell My Personal Information
We do not sell your personal information. We do not share your personal data with third parties for their own marketing purposes. The data shared with our processors is solely for providing the service as described in this policy.
9. International Data Transfers
Your data may be transferred to and processed in countries outside your jurisdiction, including the United States (where our hosting provider Vercel is located). We ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements with all third-party processors.
10. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- HTTPS encryption for all data in transit.
- Temporary and restricted access to photo storage.
- Rate limiting and brute-force protection.
- Regular security assessments.
11. Cookies
We use cookies and similar technologies. For detailed information about the cookies we use and your choices, see our cookie consent banner. You can manage your cookie preferences at any time by clicking "Cookie Settings" in the footer.
- Essential: Required for the service to function (session, security). Always active.
- Analytics: Help us understand how you use the service (PostHog). Requires consent.
- Marketing: Used for conversion tracking (Meta Pixel). Requires consent.
12. Children's Privacy
Our Service is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Data Deletion Requests
To request deletion of your data, you can:
- Email privacy@selfieai.app with the subject "Data Deletion Request".
- Use the account deletion feature in your account settings (if authenticated).
We will process your request within 15 business days and confirm deletion via email.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact
For privacy-related inquiries:
- Email: privacy@selfieai.app
- General support: support@selfieai.app
This Privacy Policy should be read in conjunction with our Terms of Service.