Privacy Policy

Last updated: January 2026

1. Introduction

Snaplit ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered professional headshot service.

By using our Service, you consent to the data practices described in this policy. If you do not agree with our policies, please do not use our Service.

2. Information We Collect

2.1 Photos You Upload

Our Service is designed to generate professional headshots from your casual photos. You upload 8-10 photos of yourself, and our AI trains a personalized model to generate professional headshots. If you upload images containing other people (including minors), you confirm you have the necessary rights and consent.

When you use our Service, your photos are:

  • Stored on our servers and Supabase's infrastructure for processing purposes
  • Sent to Replicate's AI infrastructure to train a personalized LoRA model using your facial features
  • Used exclusively to generate your specific headshots and not for training general AI models
  • May be retained temporarily during the AI training and generation process
  • Not used for facial recognition or identifying individuals beyond the scope of your headshot generation

AI Training Consent: By uploading photos, you explicitly consent to your images being used to train a personalized AI model (LoRA) via Replicate's infrastructure. This is necessary to generate accurate, identity-preserving professional headshots.

2.2 Automatically Collected Information

We automatically collect certain information when you visit our website:

  • Session Data: Anonymous session identifiers to track your session
  • IP Address: Your IP address for security and rate limiting purposes
  • Device Information: Browser type, operating system, and device type
  • Usage Data: Pages visited, time spent on site, and interactions with our Service

2.3 Payment Information

When you make a purchase, payment information is collected and processed by Stripe, our payment processor. We do not store your full credit card number, CVV, or other sensitive payment details on our servers. We only receive confirmation of successful payments and basic transaction details.

3. How We Use Your Information

We use the information we collect to:

  • Process your photos Using AI technology to train a personalized model and generate professional headshots
  • Process payments for headshot packages ($9.99 for 5 headshots)
  • Provide customer support and respond to inquiries
  • Improve our Service and develop new features
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues or fraud
  • Comply with legal obligations

4. Data Retention

We retain different types of data for different periods:

Data TypeRetention Period
Uploaded photosAs needed for service operation
Generated imagesAs needed for service operation
Session data30 days
Analytics data90 days
Payment recordsAs required by law (typically 7 years)

5. Third-Party Services

We use the following third-party services that may collect and process your data:

Replicate

Purpose: AI model training (LoRA) and image generation

Your photos are sent to Replicate's servers to train a personalized AI model and generate your headshots. Visit replicate.com/privacy for their privacy practices.

Stripe

Purpose: Secure payment processing

Stripe handles all payment information. Visit stripe.com/privacy for their privacy policy.

Supabase

Purpose: Database and file storage

Your data is stored on Supabase infrastructure. Visit supabase.com/privacy for their privacy policy.

PostHog

Purpose: Analytics and usage tracking

We use PostHog to understand how our Service is used. Visit posthog.com/privacy for their privacy policy.

Vercel

Purpose: Website hosting and delivery

Our website is hosted on Vercel. Visit vercel.com/legal/privacy-policy for their privacy policy.

Cloudflare

Purpose: DNS management and content delivery network

We use Cloudflare for DNS and CDN services. Visit cloudflare.com/privacypolicy for their privacy policy.

6. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data is transmitted over encrypted connections (HTTPS/TLS)
  • Photos are stored in secure cloud storage with access controls
  • Payment information is handled by PCI-compliant payment processor (Stripe)
  • We use rate limiting and monitoring to prevent abuse
  • Regular security reviews of our systems and practices

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

7.1 For All Users

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Deletion: Request deletion of your personal data
  • Right to Correction: Request correction of inaccurate personal data
  • Opt-out of Analytics: Disable analytics tracking in your browser settings

7.2 For EU/EEA Residents (GDPR)

Under the General Data Protection Regulation, you have additional rights:

  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Restrict Processing: Request limitation of how we use your data
  • Right to Object: Object to processing of your personal data
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

7.3 For California Residents (CCPA)

Under the California Consumer Privacy Act, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Opt-out of the sale of personal information (Note: We do not sell your personal information)
  • Non-discrimination for exercising your privacy rights

To exercise any of these rights, please contact us at snaplitreachout@yahoo.com. We will respond to your request within 30 days.

8. Children's Privacy

Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to the transfer of your information to countries outside your country of residence, including the United States.

When we transfer data internationally, we ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.

10. Cookies and Tracking

We use cookies and similar tracking technologies to:

  • Session Cookies: Essential for the Service to function (e.g., tracking your upload session)
  • Analytics Cookies: Help us understand how visitors use our website

You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our Service.

11. Disclaimer & Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:

  • We provide this Service and our data practices on an "AS IS" and "AS AVAILABLE" basis without warranties of any kind
  • We do not guarantee the absolute security of your data, though we implement reasonable security measures
  • We are not liable for any unauthorized access, data breaches, or security incidents caused by third parties, hackers, or circumstances beyond our reasonable control
  • We are not responsible for the privacy practices or data handling of third-party services (Replicate, Stripe, Supabase, PostHog, Vercel, Cloudflare)
  • Any data you submit is at your own risk

IN NO EVENT SHALL WE BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM DATA PROCESSING, STORAGE, OR ANY PRIVACY-RELATED MATTERS.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes. Changes are effective when they are posted on this page.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at: snaplitreachout@yahoo.com

For data protection inquiries or to exercise your privacy rights, please include "Privacy Request" in your email subject line.