Effective August 11, 2026

Privacy Policy

What stays on your device, which limited network requests occur, and the choices available when you use privacy.photos.

1. The short version

Your selected photos, crops, face-analysis results, and generated print image stay in your browser. They are not uploaded to privacy.photos, our analytics, Hugging Face, or Stripe. Network requests still occur to load the website and machine-learning model files, optionally measure page use, and open an external support link if you choose it.

2. Scope and controller

This Policy describes how TableHQ LLC(“we,” “us,” or “our”) handles personal information through privacy.photos. It does not govern Hugging Face, Stripe, a print service, a government authority, or another site you visit from a link.

3. Photos and local processing

When you select a photo, browser code reads it into temporary memory. Format conversion, thumbnails, background segmentation, face analysis, positioning, cropping, tiling, preview, and download occur on your device. The browser may create temporary object or data URLs containing the image. The Service does not submit the photo, its file name, form values, analysis, or output to our server.

Photo working state normally disappears when you reload or close the page. A downloaded output remains wherever your browser, operating system, backup provider, shared device, or print service stores it. Use their controls to delete those copies.

4. Model downloads and browser cache

The first use of background removal or automatic face positioning can cause your browser to download machine-learning model files from Hugging Face. Hugging Face receives an ordinary network request, which can include your IP address, browser details, requested model, and request time, but the model runs locally and the request does not include your photo.

Your browser may cache model files, including in IndexedDB or its ordinary web cache, to avoid downloading them again. These cached files are model code and weights, not your selected photo. You can remove them by clearing site data and browser caches.

5. Website requests and technical logs

Like most websites, our server and infrastructure receive the IP address, request time, requested path, response status, referrer, and browser or device information needed to deliver and secure the site. We may retain limited logs for reliability, security, abuse prevention, and troubleshooting, then delete or aggregate them when they are no longer reasonably needed.

6. Limited audience measurement

We may enable Umami to understand aggregate page use and performance. The configured tracker excludes URL searches and fragments, respects the browser's Do Not Track setting, does not use analytics cookies, and does not load session replay. We do not send selected photos, photo-derived values, or form values to analytics.

When enabled, measurement may include the site and page path, referrer, browser and device category, approximate location derived from an IP address, performance data, and event time. The deployment's analytics provider processes that request only to operate audience measurement for us.

7. Preferences and communications

A light or dark theme preference and related client hints may be stored in your browser or an essential preference cookie. Blocking or clearing them resets those choices but does not prevent local photo processing.

If you contact us, we receive your contact details, message, and any information you choose to include. Do not email photos or identity documents when a description of the issue is sufficient.

8. Voluntary support links

If you choose an external support link, Stripe or the linked payment page receives the information ordinarily disclosed by your browser and any contact, billing, and payment details you provide there. We may receive a contribution record and payment status but do not receive complete payment-card numbers. Merely using the photo tool does not send information to Stripe.

9. How we use information

We use the limited information we receive to:

  • deliver the site and remember requested preferences;
  • understand aggregate use and improve performance;
  • respond to messages and support requests;
  • process and reconcile voluntary contributions;
  • prevent abuse, diagnose failures, and protect the Service; and
  • comply with law and enforce our agreements.

We do not sell personal information, share it for cross-context behavioral advertising, use photos for model training, or make decisions with legal or similarly significant effects based solely on automated processing.

10. How we disclose information

We may disclose received information to:

  • providers for hosting, security, audience measurement, model-file delivery, and payment processing;
  • advisers or authorities when reasonably necessary to comply with law, protect rights and safety, or investigate abuse; and
  • a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice.

Because we never receive your selected photo through the tool, we cannot disclose that photo from our servers.

11. Legal bases

Where data-protection law requires a legal basis, we process service delivery and requested support information to perform our contract with you; security, limited audience measurement, reliability, and improvement data for our legitimate interests; information needed to satisfy legal obligations; and information based on consent where we specifically request it. You may withdraw consent for future processing at any time, without affecting earlier processing.

12. Retention and international processing

We retain technical, analytics, support, contribution, security, and dispute records only as long as reasonably necessary for their purpose and legal obligations, then delete or de-identify them. We do not retain photo working data because we do not receive it.

We and our providers may process received information in the United States and other countries whose laws differ from those where you live. Where required, we use a recognized transfer mechanism or another lawful safeguard. Contact us to ask about safeguards applicable to your information.

13. Security

Keeping photo computation in your browser reduces transmission risk. We also use reasonable measures designed to protect the limited information we receive. No browser, device, network, or storage system is completely secure. Protect shared devices and review where your downloads and backups are saved.

14. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to appeal a denied request. You may also complain to your local data-protection authority. You have the right to object to processing based on legitimate interests where applicable.

Submit a request to hi@quietcolin.com. We may verify your identity and authority before completing it. We will not discriminate against you for exercising a privacy right. Because we do not sell personal information or share it for cross-context behavioral advertising, there is no sale or targeted-ad opt-out to exercise.

15. Children

The Service is not directed to children under 13. A parent or guardian should supervise any child's use, including the handling of photo files and downloads. If you believe a child sent us personal information outside the local tool, contact us so we can investigate and delete it where appropriate.

16. Changes and contact

We may update this Policy as the Service or law changes. We will post the new effective date and provide reasonable notice of material changes. Questions and privacy requests may be sent to hi@quietcolin.com.