Create photo

Privacy

Privacy-first photo processing.

We built Passport Visa Photo Studio so you can make a passport, visa or ID photo with minimal data movement and clear choices.

Published: | Last updated:

1. Image handling

Your browser performs cropping, resizing, rotation, preview watermarking, validation and final compositing locally.

When you request background preparation, the image is sent to the configured processor, which may be PhotoRoom, remove.bg or Cloudflare Images. That provider's processing and retention terms apply. The temporary Cloudflare Images upload path makes a best-effort deletion request after processing.

2. Analytics and attribution

When GA4 is configured, Google can receive page, referrer, campaign, browser and device information plus pseudonymous client or session identifiers, and may use _ga or related browser storage. Plausible, Umami or Cloudflare analytics load only when separately configured.

Photo pixels and face-validation measurements are not sent to analytics. Campaign fields used for checkout attribution are limited and kept in session storage; arbitrary page or referrer query strings are not retained.

3. Payments and follow-up email

Stripe Checkout processes payments and receives the checkout details and email needed for the transaction. We do not see or store card details.

When review follow-ups are enabled, the checkout email is read from Stripe and sent through Resend for one review and support message about 24 hours after a recorded download. Delivery status is stored in Stripe metadata to prevent duplicate sends.

For Family 3 packs, Cloudflare D1 stores only hashed Stripe session, restore/access-token and redeemed-job identifiers, plus the credit balance, status and expiry. No photos or checkout email addresses are stored there. Resend may send a private restore link to the address already held by Stripe.

For agency subscriptions, Cloudflare D1 stores Stripe customer and subscription identifiers, hashed restore/access-token and redeemed-job identifiers, the plan, billing status, cancellation flag, credit balance and billing-period dates. It does not store agency names, checkout email addresses or photos. Resend may send a private restore link to the address already held by Stripe.

4. Photo draft retention

Immediately before Stripe checkout, the original and prepared photo plus crop settings are saved in IndexedDB on this device so the result can be restored after payment. This browser copy is not uploaded to our application server.

The draft expires after 24 hours and is removed while the site remains open or the next time the site is opened after expiry. Starting another photo removes or replaces it immediately. Closing the tab alone may not erase IndexedDB storage.

5. Cookies and browser storage

If Google Analytics is enabled, it may set analytics cookies such as _ga. The editor may also keep non-sensitive country preferences locally, while checkout attribution is limited to the current browser session.

A Family 3 pack uses a secure, HTTP-only first-party access cookie for up to seven days. It contains a random access token, not a photo, email address or card detail.

Agency access uses a secure, HTTP-only first-party cookie containing a random access token, which may remain on that browser for up to 370 days. Up to three active browser sessions are kept for one organization; authorizing another may revoke the oldest session. The cookie contains no photo, email address or card detail.

6. Contact

Questions about this policy or your photo data? Email contact support.