Privacy
TL;DR: photos are deleted after 7 days. We never train AI on your face. Refused uploads are deleted within seconds.
What we store
- Your uploaded photo, in a private storage bucket, with a 7-day auto-delete.
- The critique text we generate (no PII).
- Your email (only if you create an account).
- Anonymous abuse-prevention hashes (sha256 of your IP + a daily salt). No raw IPs.
What we never store
- Face embeddings or biometric features. We don’t generate or persist them.
- EXIF metadata — stripped before storage.
- Raw IP addresses.
Refused uploads
Photos flagged as NSFW, of minors, screenshots, or non-people are deleted from storage within seconds of detection. We log the refusal category only, no image content.
Subprocessors
We use Supabase (database + storage), Groq (vision + text AI, zero-retention), Vercel (hosting), Polar (payments), Resend (transactional email), and PostHog (analytics).
Delete your data
Email hello@picwingman.com from your account email — we’ll delete everything within 7 days.