Privacy Policy
Effective from September 2, 2026
1. Data controller
The controller of your personal data is UnknownHorizons s.r.o., company ID 23276070, registered office Na Folimance 2155/15, 120 00 Prague 2 – Vinohrady, Czech Republic. Privacy contact: [email protected].
2. What data we process
- Account: email address, a password hash — never the password itself — and, if you sign in with Google, your Google identifier. Registration date and number of purchased photoshoots.
- Uploaded photos: the photos of your face you upload for training. These are biometric data, a special category of personal data under Art. 9 GDPR. We process them solely on the basis of your explicit consent, which you give by uploading them.
- Trained model and generated photos: the outputs of the Service created from your photos, including whether the photos show a man or a woman (used in the AI prompt).
- Payment data: payments are processed by Stripe. We keep only the transaction identifier, amount, date and status. We have no access to your card number.
- Technical data: IP address, browser type and request logs needed for security and operation.
3. Purposes and legal basis
- Providing the Service (account, model training, generating and delivering photos, payment) — performance of a contract, Art. 6(1)(b) GDPR; for face photos your explicit consent, Art. 9(2)(a) GDPR.
- Security and operation (logs, abuse prevention) — legitimate interest, Art. 6(1)(f).
- Accounting and tax (payment records) — legal obligation, Art. 6(1)(c).
We do not use your photos or model to train other models, for marketing or profiling, and we do not sell them or make them available to third parties for their own purposes.
4. Processors and recipients
We rely on the following providers, who process data on our instructions:
- fal.ai (Features and Labels, Inc., USA) — AI model training and photo generation. Processes uploaded photos, the trained model and generated photos. All of this data is set to expire at fal.ai automatically within 24 hours.
- Neon (Neon, Inc., USA; data stored in an EU data centre – Frankfurt) — database: accounts, photoshoot records, links to generated photos, payment records.
- DigitalOcean (DigitalOcean, LLC, USA) — application hosting; processes technical data and data passing through the application.
- Stripe (Stripe Payments Europe, Ltd., Ireland) — payment processing; Stripe is an independent controller for payment data.
- Google (Google Ireland Ltd.) — Google sign-in, if you use it; passes us your email and account identifier.
- Cloudflare (Cloudflare, Inc., USA) — network protection and CDN in front of the website; processes IP address and technical data.
Some providers are based in the USA. Transfers are safeguarded by the European Commission's adequacy decision (EU–U.S. Data Privacy Framework) or standard contractual clauses. We do not share data with anyone else unless required by law.
5. Retention
- Uploaded photos, trained model, generated photos: deleted automatically within 24 hours of creation — both by us and by fal.ai. We do not store uploaded photos at all; they are discarded once sent to fal.ai.
- Account: until you ask us to delete it.
- Payment records: for the period required by tax and accounting law (generally 10 years).
- Technical logs: at most 30 days.
6. Cookies
We use only strictly necessary cookies; no marketing or analytics cookies. That is why there is no cookie banner.
session— keeps you signed in; 30 days.g_state,g_verifier— secures Google sign-in; 10 minutes.__cf_bm— Cloudflare bot protection; 30 minutes.
7. Your rights
Under the GDPR you have the right:
- to access your data and obtain a copy,
- to have inaccurate data corrected,
- to erasure ("right to be forgotten") — we delete your account within 7 days of the request; photos and the model are deleted automatically within 24 hours,
- to restriction of processing and to object to processing based on legitimate interest,
- to data portability,
- to withdraw your consent to the processing of photos at any time — withdrawal does not affect the lawfulness of prior processing,
- to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.
Send requests to [email protected]. We reply within 30 days at the latest.
8. Children
The Service is intended for persons aged 18 or over. We do not knowingly process children's data; uploading photos of minors is prohibited.
9. Security
All data is transmitted encrypted (HTTPS), passwords are stored as bcrypt hashes, and access to the database and providers is protected by keys and restricted to the Operator.
10. Changes
We may update this policy; the current version is always on this page. Effective from September 2, 2026.