Trust & privacy
How we handle your child's photo
This page is maintained by the Tiny Hero Portraits team to answer common questions about how we collect, store, and delete the photos you upload. It is not a regulatory certification and is updated as our practices change.
Encrypted in transit and at rest
Uploads use HTTPS and are written to a private storage bucket. Files are scoped to your account โ no one else can read them through the app, even other signed-in users.
EXIF & GPS stripped client-side
Before a photo leaves your browser we re-encode it through a canvas, which removes EXIF metadata including GPS coordinates, capture timestamp, and camera serial.
Auto-deleted after 7 days
A scheduled job deletes uploaded photos and unpurchased preview images after 7 days. Portraits attached to a paid order are retained so you can re-download them.
Owner-scoped access
Database row-level security and storage policies restrict reads to the user that uploaded each photo. Admin access is logged.
What we collect
- The photo(s) you upload for portrait generation.
- The child's first name, age, and any optional notes you provide to guide the artwork.
- Your account email, order history, and the theme/scene you selected.
- Basic analytics events (page views, funnel steps) used to improve the product.
What happens to uploads
When you upload a photo we store it in a private bucket keyed to your account. We send a resized copy to our image generation provider to render the portrait you previewed. The original upload and any preview images that aren't tied to a paid order are automatically deleted after 7 days by a scheduled cleanup job. Purchased portraits remain available so you can re-download them from your order history.
Subprocessors
We use the following processors to deliver the service:
- Lovable Cloud โ managed database, authentication, and storage hosting.
- OpenAI โ portrait image generation.
- Replicate โ upscaling of purchased portraits.
- Stripe โ payment processing. We never receive or store your full card number.
[TODO for owner: add jurisdiction(s) of operation, DPA links for each subprocessor, and any additional analytics tools you wire in.]
Your choices
- Delete a photo at any time from your account โ write to us using the contact below for assistance.
- Unsubscribe from marketing email using the link in any newsletter.
- Request a copy or deletion of your account data by emailing the security contact below.
[TODO for owner: confirm whether you want to surface a self-serve "Delete my account" button and link the policy text for the jurisdiction(s) you operate in.]
Security contact
[TODO for owner: replace with a dedicated security/privacy address if you have one, and add the legal entity name and registered address.]
Questions about a specific order? Visit help.