Headshot

Privacy Policy

26 September 2026

Headshot has to send your selfie somewhere: the headshot is made on a server, not on your phone. This page says exactly what happens to it, and every sentence here is enforced by the code that runs it.

Your selfie is processed, not stored

When you check a selfie or make a headshot, the selfie is sent to our server over HTTPS, held in memory for the seconds the request takes, and then discarded. It is never written to a disk, saved in a database, placed in a log file or attached to an error report. The same is true of the headshot made from it: it is sent back to your phone and not kept.

What the check says about your selfie

Before anything is made, the selfie is checked: one person, sharp and well lit, facing the camera, aged 16 or over — and what must stay exactly as it is, such as glasses, hair, a head covering, a beard, visible marks, an approximate skin tone and age range. That description is sent back to your phone inside a signed token, so it cannot be altered, and is kept there with your shoot; our server keeps none of it. If the person appears to be under 16, no headshot is made and nothing is kept.

No faceprint

The app finds your face in the photo on your phone, with Apple's Vision framework, to guide the camera and to crop exports. The position of the face is sent with the selfie so the server can measure the light on it. No faceprint or other biometric template is created or kept — on your phone, on our server or by the AI providers.

The AI providers

fal.ai makes the headshot. Google's Gemini model, reached through OpenRouter, checks the selfie and compares each headshot with it. Your selfie is sent to them as part of the request, and the app asks for your permission on its first screen before anything is sent. The image provider is asked to return the result directly and not to keep it, and requests to the language model are restricted to endpoints with a zero data retention policy. No name, email or account identifier is sent with an image, because we do not have one.

There is no account

There is nothing to sign up for. Your device registers itself and receives a random identifier, kept in the device's Keychain so that your credits survive a reinstall. We do not ask for, receive or store your name, email address, phone number or location.

What our server keeps

Numbers only: your credit balance; whether the free headshot was used; a hash of this installation's recovery key (the app keeps the key, so it can sign back in as itself if its tokens expire); the Apple transaction number, product and credits of each purchase, and any refund; for seven days after each headshot, a random identifier and how many free redos it has used; for a day, the identifier your phone gives each headshot request, so a request it sends twice is made once; for two days, a one-way fingerprint of your network address (not the address) to count free headshots per address; and for each request, the look that was chosen (purpose, clothes, background, retouching, HD, how many), whether it succeeded, how long it took and the credits it cost. Nothing that describes your face.

Your shoots stay on your device

Your selfies, your headshots and the check's description of each selfie are stored on your device only, in app storage that is excluded from iCloud and computer backups. There is no sync and no copy on our side, so we cannot recover them — deleting the app, or Delete all data in the app, removes them.

Purchases

Credit packs are sold by Apple. We use RevenueCat to learn which purchases belong to your device's random identifier, so the server can add their credits. RevenueCat receives that identifier and the purchase information Apple provides — not your name, your email or any photo.

Analytics and tracking

The app contains no third-party analytics, no advertising and no tracking. We see only the aggregate, anonymised statistics Apple provides to all developers, and the purchase figures RevenueCat reports.

Security records

To stop abuse, the server records the network (IP) address and the app and system version string of requests, alongside the random device identifier, and uses them only to limit requests and to spot misuse. They are not shared with the AI providers and are deleted on request.

Children

Headshot is for people aged 16 and over and is not directed at children. It refuses selfies of people who appear to be under 16.

Your rights and choices

You can withdraw the permission to send selfies, and erase everything on your device, with Delete all data in the app; the permission is asked for again before the next selfie is sent. We hold no photo, name or email address of yours. To have the records on our side removed or copied to you, use Write to us in the app — the email includes this installation's identifier — or write to the address below.

Changes to this policy

If a future version of Headshot changes what is sent or what is kept, we will update this page and its date before that version is released.

Contact

alcmdnc@gmail.com