Skip to content

Privacy notice (pre-launch draft)

How IDPhotos handles photo previews, uploads and billing data

2026/09/17

IDPhotos is a pre-launch service. The operator's legal identity, hosting regions and support channel must be confirmed before public payments are enabled.

Local studio and scanner

The studio, scanner, print layout and compression tools process images on your device. Portraits, document scans and imported PDFs are not uploaded. Images are held in page memory; save your exports before closing or reloading the page. Custom specifications and recent background colors are saved in this browser's local storage. You can remove them through the specification manager or your browser settings. Model/runtime downloads do not send your images to a model provider.

Optional cloud processing and drafts

The separate cloud studio uploads your original only when you confirm server processing. Its local preview does not upload the photo.

A draft, including the original, is saved in this browser's IndexedDB so it can survive login or payment navigation. Clear it with the editor's “Clear local draft” action. Drafts older than 24 hours are removed the next time the editor reads them; a closed browser cannot run a timed deletion.

Server input and results are stored in private object storage. Delivery access ends 24 hours after submission. Scheduled cleanup removes expired files in batches. You can delete a photo from its history sooner; deletion revokes access immediately and requests object deletion. Account deletion revokes access and schedules cleanup of remaining photos.

We do not use uploaded photos to train a model. Face detection helps position the crop; no identity-matching face embeddings are stored. The processing service strips metadata from output images.

Account, billing and service records

We use your email for login, verification and account messages. Payment verification, credit ledger entries and processing statuses are retained separately from image files. Payment is handled by Alipay; this application does not collect card details. Deleting a photo does not erase financial records.

First-party usage events record page visits, preview readiness, checkout and job outcomes, and download requests. Events do not contain original images, face coordinates or image filenames. Download requests are not proof that the user saved a file.

Service providers and contact

The intended stack uses Cloudflare for the application, database and private storage; a separately operated CPU image service; a verification-email provider; and Alipay. Actual provider regions, retention for financial records and the accountable support contact must be reviewed and disclosed before launch.

For a child's photo, a parent/guardian should operate the service and confirm their authority. Process only images you are authorized to use. Keep identity-document and bank-card scans in the local scanner; do not submit them to the cloud portrait service.