makeidpic

Trust

Privacy Policy

Last updated July 29, 2026.

A solid draft, not a substitute for legal review

The business entity and jurisdiction operating makeidpic have not been finalized yet. This policy is written in good faith to describe how the service actually works today, but it is not a substitute for review by a qualified privacy lawyer, and it will be revisited once the business entity, jurisdiction, and final sub-processor list are locked in — before this service takes real payments or processes personal data at any scale.

The short version

  • We don't have accounts — no profile, password, or login is ever tied to you.
  • We don't store your photo. Most processing happens in your browser; the one step that touches a server doesn't save anything either.
  • We never create or store a biometric template or faceprint.
  • The only personal data we collect directly is the email address Stripe captures at checkout, solely to send you a receipt.
  • Our analytics don't use cookies and don't track you individually.
  • Stripe and Replicate are the only outside companies that ever handle your data, for payment processing and image enhancement respectively.

What we process, and where

Your photo. For the free tier, and for the paid tier in the United States, United Kingdom, Canada, and China, your photo is processed entirely inside your browser: cropping, positioning, and compliance checks all run as on-device computation, and the image itself is never transmitted to us.

For the paid tier's AI enhancement step, available for other supported countries, your photo is sent once, over an encrypted connection, to a serverless function we operate, which forwards it in memory to Replicate for processing and returns the result. It is not written to a database or disk at any point.

Payment and email. Checkout is handled by Stripe. We never see or store your card details. Stripe captures your email address at checkout so we can send you a payment receipt — we don't use it for marketing, and there is no newsletter to opt out of because there is no list.

Analytics. We use Plausible, a privacy-focused, cookieless analytics tool that reports aggregate usage, such as page views and referrers, without tracking individuals across sites or building a profile of you.

Technical logs. Like almost any website, our hosting infrastructure (Vercel) automatically logs standard technical data, such as IP address, browser type, and timestamps, for security and reliability. These logs are about the request, not your photo's content, and are not linked to anything you upload.

What we retain

  • Photos: none. Not temporarily, not in a backup, not for troubleshooting. Once your session ends, or immediately after an enhancement request completes, your photo is gone from every system we control.
  • Payment records are retained by Stripe under Stripe's own retention policy, as our payment processor — not something we control directly.
  • Analytics data is aggregate and non-identifying, retained per Plausible's standard practice.

No biometric templates or faceprints

Face-landmark detection is used only to position an initial crop guide as a starting point — the coordinates it produces are used transiently, in your browser's memory, for that one geometric purpose. We never generate, store, or transmit a biometric template, faceprint, or other persistent representation of your face. See our Security page for the full architecture.

Sub-processors

We share data with exactly two outside companies, each for one narrow purpose:

  • Stripe — payment processing for the paid-tier upgrade, including your checkout email for receipts. See Stripe's privacy policy.
  • Replicate — the hosted image-inference API used only for the paid tier's enhancement step, on countries where that is legally permitted. See Replicate's privacy policy.

Cookies

makeidpic does not use tracking or advertising cookies, and our analytics (Plausible) is cookieless by design — that is why we don't show a cookie-consent banner or maintain a separate cookie policy.

The one exception is outside our control: Stripe Checkout may set strictly-necessary cookies during the payment step itself, for example for fraud prevention and session integrity. These are exempt from consent requirements under ePrivacy/GDPR guidance because they are necessary to provide a service you have requested (completing a purchase), and they are not used to track you across other sites.

Your rights under the GDPR and UK GDPR

If you are in the EEA, UK, or Switzerland, you have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to lodge a complaint with your local supervisory authority. In practice, most of these are trivially satisfied for photo data because we never store it in the first place. For the checkout email Stripe holds on our behalf, contact us and we'll help coordinate a request with Stripe as needed.

Your rights under the CCPA/CPRA

If you are a California resident, you have the right to know what personal information is collected, to request deletion or correction of it, and to opt out of the sale or sharing of personal information. We do not sell or share personal information, and we will not discriminate against you for exercising any of these rights. Contact us to make a request.

Who this service is for

makeidpic is intended for use by adults, either creating a photo of themselves or of a dependent in their care, such as a parent preparing a baby's or child's passport photo. It is not designed for children to use directly as the ones operating the tool or making decisions about their own data within it.

International data transfers

Because Stripe and Replicate operate internationally, your payment and (for the enhancement step) photo data may be processed outside your own country. We rely on our sub-processors' own compliance mechanisms, such as standard contractual clauses, to cover these transfers. This area, like the rest of this policy, is pending formal legal review as our business entity and jurisdiction are finalized.

Changes to this policy

We may update this policy as the service, its sub-processors, or applicable law change. We'll post the revised version here with an updated date at the top; continued use of the service after a change means you accept the update.

Contact us

Questions about this policy, or a data-rights request? Visit our Contact page.