Privacy Policy
Last updated:
This policy explains what HairstyleAtlas collects, what we do with it, how long we keep it, and what we may do with it in future. Plain words, no hedging. If anything here is unclear, ask us and we will make it clearer.
1. Photos and Renders
To create a render we store the photo you submit and process it with AI image models, including models run by third-party providers on our behalf. We use it to produce the render you asked for, to show it back to you, and to re-run it if it comes out wrong. We also use photos, renders and the technical record around them to operate, secure, test and improve the service, as set out in sections 8 to 10. Your photos and renders stay in your library while your account is open, and you can delete any of them sooner.
2. No Faceprint, No Identification
HairstyleAtlas does not build or retain a biometric faceprint in order to identify anyone. We do not run face recognition, we do not try to work out who you are from a photo, we do not match your face against any database, and we do not share face data with anyone who does. The processing is about hair: where your hairline sits, how your hair falls, how the light behaves. Nothing about it is designed to identify you, and we do not keep a template whose purpose is identification.
3. Information You Give Us
Separately from any photo, you give us information when you create an account or contact us:
- Account information (email address, and a name if you choose to give one)
- Your style preferences from setup, such as hair texture and length
- Payment information, handled by Stripe (see section 6)
- Messages you send to support, and anything you attach to them
4. Information Collected Automatically
Like most websites, we log technical information when you visit:
- Device and browser type, operating system, and screen size
- IP address, access times, and the pages you viewed
- Referring page, so we know which sites send people here
- Error and performance data when something breaks
- How you use the product: which styles you open, which renders you keep, download or discard, and how long a render took
5. Cookies and Analytics
Strictly necessary cookies keep you signed in and keep the site secure, and those we set without asking because the site does not work without them. Everything else waits for you. Our consent banner is run by Cookiebot, which records your choice and the IP address it came from. Product analytics run on PostHog and load only after you accept analytics cookies; the same applies to any advertising measurement we run. Decline, and we do not load them. You can change your mind at any time, and we re-ask periodically rather than treating one click as permanent consent. We also honour a Do Not Track signal from your browser.
6. Payments
Payments are processed by Stripe. Card numbers go straight to Stripe and never reach our servers - we never see or store your card details. We keep the minimum Stripe returns to us: a customer reference, which plan you are on, the last four digits and card brand for your receipts, and your billing status. Stripe processes this as a controller in its own right under its own privacy policy.
7. Email
We email you about your account: sign-in links, receipts, renewal and cancellation notices, and replies to support. These are service emails and you cannot opt out of them while you have an account. Marketing email is separate, is opt-in, and every message carries an unsubscribe link that works in one click.
8. How We Use What We Collect
We use this information to:
- Run the service, sign you in, and keep your library available to you
- Produce the renders you ask for, and re-run them when one comes out wrong
- Take payment, send receipts, and manage subscriptions and refunds
- Answer your support messages
- Spot abuse, fraud and automated scraping, and keep accounts secure
- Investigate incidents, enforce our Terms, and establish, exercise or defend legal claims
- Measure, test and improve the product, including the models, prompts and settings behind a render
- Develop new features and new services, including ones that do not exist yet
- Produce aggregate and anonymised statistics and datasets (see section 10)
- Market our own service, on the terms in section 10
- Meet our legal, tax and accounting obligations
9. Our Legal Bases
Under the GDPR we need a legal basis for each use. Ours are:
- Performance of a contract: creating your account, rendering, storing your library, billing and support
- Legitimate interests: security, abuse and fraud prevention, service measurement and improvement, de-identified and aggregate analysis, defending legal claims, and business transfers. You can object to any of these at any time and we will stop unless we have compelling grounds not to
- Consent: analytics and advertising cookies, marketing email, using your identifiable photographs to train models, and using a render in which you are recognisable in our marketing. Consent is always separate, always optional, and you can withdraw it at any time
- Legal obligation: tax, accounting and lawful requests from a competent authority
10. Improvement, Training and Marketing
We want to be straight about this rather than bury it. We may use what we collect to improve HairstyleAtlas and the AI models behind it. What we may do depends on whether the data identifies you:
- De-identified and derived data - measurements, quality scores, prompt and parameter records, failure cases, timings - carries no photograph and does not identify you. We use it freely to test and improve the service, and we may keep it indefinitely. Our basis is legitimate interests and you can object
- Aggregate and anonymised datasets are no longer personal data, and this policy stops applying once data is genuinely anonymous. We may use, retain, publish, license or sell such datasets without further reference to you
- Your identifiable photographs and renders are used to train or fine-tune a model only where you have given separate permission for it. It is off unless you give it, and you can withdraw it at any time
- Marketing: where a render shows a recognisable person we ask first and use it only if you agree, because your likeness is protected separately from data protection law. Where an image is not identifiable - a crop, a composite, an aggregate - we may use it without asking
11. Where Training Cannot Be Undone
One honest limit. If you allow your images to be used for training and later withdraw that permission, we stop using them and remove them from future training runs. We cannot remove what a model has already learned, because a trained model does not store your photograph and cannot be unpicked back into the images it was built from. Withdrawing stops what happens next; it does not reach backwards into a model that already exists.
12. Who We Share It With
We do not sell your photographs, and we do not share them with advertisers. We share the minimum necessary with the suppliers and parties that run or protect the service:
- Our AI image providers, currently OpenAI, which generate your renders
- Stripe, for payments and refunds
- Cloudflare, which hosts our object storage and sits in front of the site
- Our hosting provider, which runs the servers the service sits on
- Our email provider, for the messages described above
- PostHog, for product analytics, and only when you have consented
- Cookiebot, which records your cookie choice
- Sentry, for error and performance monitoring when something breaks
- Professional advisers, or a competent authority, where the law requires it
- A buyer, investor or successor if HairstyleAtlas is merged, acquired, restructured or sells assets. Your information moves with the service, and this policy continues to apply until the new owner tells you otherwise and gives you the choice the law entitles you to
13. How Long We Keep Things
How long each kind of information lasts:
- Photos you submit, and the renders made from them: while your account is open, and for up to 90 days after you delete it so we can investigate abuse, resolve disputes and defend legal claims
- Account and preference data: while your account is open, then up to 90 days
- De-identified and aggregate data: indefinitely, because it does not identify you
- Invoices and payment records: as long as tax and accounting law requires, typically six to seven years
- Server logs: a short rolling window, then discarded. They never contain your photo
- Backups: overwritten on their own rolling schedule, within 30 days
14. Deleting Your Account
You can delete your account from account settings. Deletion removes your account, your preferences, your library and every render in it from the live service straight away. Copies held for the reasons in section 13 are removed within 90 days, and backups roll off on their own schedule within 30 days. What survives beyond that is the narrow set of billing records we are legally required to retain, which does not include any photograph, and de-identified data that no longer identifies you. If you would rather we erase everything immediately and you have no open dispute with us, ask and we will.
15. Your Rights
Wherever you live, you can exercise all of the following with us, and we will not make you argue about which law applies:
- Access a copy of the personal data we hold about you
- Export your data, including your renders, in a usable format
- Correct anything inaccurate
- Delete your data, in full
- Object to or restrict a particular use, including anything we do on the basis of legitimate interests
- Withdraw consent for analytics, marketing or model training at any time
- Complain to your local data protection authority if we get it wrong. In Slovakia that is the Office for Personal Data Protection (Úrad na ochranu osobných údajov)
16. Security
Traffic is encrypted in transit with TLS. Photos and renders are held in private object storage on Cloudflare R2, which encrypts every object at rest, in a bucket that is not served to the public and is separate from the one that serves our site images. They are readable only through your own signed-in account. Access to production systems is limited to the people who need it and is logged. No system is perfectly secure, and we will tell you promptly if a breach affects you.
17. International Transfers
We are established in the Slovak Republic. Our suppliers operate in the United States and the European Union, so your information may be processed outside the country you live in. Where data leaves the EEA or the UK we rely on the EU and UK Standard Contractual Clauses, or an adequacy decision where one exists, and we require the same standard of protection from every supplier.
18. Children
HairstyleAtlas is not for under-16s and we do not knowingly collect their information. Do not upload a photograph of a child. If you believe a child has created an account or that a child's photograph has been submitted, tell us and we will delete it.
19. Changes to This Policy
If we change how we handle photographs in a way that materially affects you, we will say so at the top of this page and email account holders before the change takes effect. Where a change needs your consent we will ask for it rather than assume it. Smaller edits are reflected in the last updated date above. Continuing to use HairstyleAtlas after a change means the updated policy applies.
20. Who We Are, and Contact
HairstyleAtlas is operated from the Slovak Republic and is the controller of the personal data described here. For any privacy question, a copy of your data, or a deletion request, email our support address from the address on your account. Say what you want and we will action it - we do not require a specific form of words. We answer data rights requests within 30 days, usually much sooner.
Our support address is [email protected]. A person reads it.