WeddingPicture AI

Legal

Privacy Policy

Last updated 19 September 2026

This policy explains what WeddingPicture AI collects, why, who we share it with, and how long we keep it. We are the data controller for the information described here. Contact us at weddingpictureai@protonmail.com.

The short version

  • • We collect your email, your photograph and what your guests type
  • • Your photograph and every guest description go to Google's Gemini API to generate pictures
  • • We never use your photographs to train AI models, and we never sell them
  • • Payment details go to Paddle and never reach us
  • • Demo photographs are used once and never stored
  • • You can delete everything by emailing us

What we collect

If you create an account

  • Your email address, and your name if you give it. Needed to identify your account and to email you about verification, password resets and purchases.
  • A hash of your password, if you sign up with one. We never store the password itself.
  • Your Google account id and email, if you sign in with Google. We do not receive your Google password.

For your wedding

  • The photograph you upload. Stored so we can build every generated picture on it.
  • A written description of the people in it, generated automatically from the photograph when you upload it, and used to help the AI keep your likeness.
  • Your names, wedding date and any message you write. Shown on your guest page.

From your guests

  • The description they type, and the name they optionally sign it with.
  • The generated picture.
  • A random device identifier, stored in a cookie on their device, so we can enforce the number of tries you allow. It is not linked to any identity and tells us nothing about who they are.
  • A hash of their IP address. We keep only the hash, never the address itself, and use it to stop automated abuse.

If you use the free demo

The photograph you upload for the demo is sent to our AI provider to generate your picture and is never stored on our servers. We keep the description you typed, the resulting picture, your device identifier and a hash of your IP address, so we can enforce the one-try limit.

If you buy something

Paddle handles the payment. We receive a transaction id, what you bought, the amount and currency. We never see or store your card number or billing address.

Who we send it to

Google (Gemini API)Your photograph and every guest description, in order to screen the description and generate the picture.
VercelHosting, and the blob storage that holds your pictures.
NeonThe database holding your account and wedding records.
PaddlePayment processing. Paddle is the merchant of record and is a separate controller for the payment data you give them.
ResendSending verification, password reset and purchase emails.

These providers process data on our instructions under data processing agreements, except Paddle, which acts as its own controller for payments. Some are outside the EEA; transfers rely on Standard Contractual Clauses or an adequacy decision.

We do not sell your data, and we do not use it for advertising. We run no third-party analytics or advertising trackers.

A note about the AI provider

Generating a picture requires sending your photograph and the guest's description to Google's Gemini API. Google processes this to return the image. Under Google's terms for the paid Gemini API, this data is not used to train their models. We have no separate agreement allowing anyone to train on your photographs, and we do not do so ourselves.

Legal bases

  • Performing our contract with you — running your account, generating pictures, taking payment.
  • Legitimate interests — preventing abuse, keeping the service secure, screening content for safety.
  • Consent — uploading a photograph of identifiable people is your decision, and you confirm you have their agreement. You can withdraw it by deleting the photograph.
  • Legal obligation — keeping transaction records for tax purposes.

Biometric data

We do not perform facial recognition, build face templates, or attempt to identify anyone from a photograph. The AI is used to redraw a likeness, not to recognise a person. We never match faces across accounts or against any external database.

How long we keep things

  • Your photograph and generated pictures — until you delete them or close your account.
  • Account records — until you ask us to delete the account.
  • Demo records — the device identifier, description and picture are kept for 12 months so the one-try limit holds. The uploaded photograph is never stored.
  • Hashed IP addresses — stored alongside the picture or demo record they belong to, and removed with it.
  • Purchase records — as long as tax law requires, typically 7 years.

Cookies

We use two, both strictly necessary, and neither used for advertising or analytics:

  • A session cookie, so you stay signed in.
  • A device cookie, a signed random identifier that enforces how many pictures a guest may make.

Because both are strictly necessary for a service you asked for, no consent banner is required.

Your rights

If you are in the EU, EEA or UK you have the right to access, correct, delete, restrict or object to our processing of your data, and to receive a copy in a portable format. Email weddingpictureai@protonmail.com and we will respond within 30 days. You can also complain to your national data protection authority.

Guests who want a picture of themselves removed can ask the couple, or email us directly.

Children

The service is not for anyone under 18. We do not knowingly collect data from children, and we automatically refuse photographs that appear to show a minor. If you believe a child's data has reached us, email weddingpictureai@protonmail.com and we will delete it.

Security

Data is encrypted in transit. Passwords are hashed with bcrypt. Access to production data is limited to what is needed to operate the service. No system is perfectly secure, but if a breach affects your data we will tell you and the relevant authority as the law requires.

Changes

We will update this page when our practices change, and email account holders about anything material. See our Terms of Service for the rest of the agreement.

Contact

weddingpictureai@protonmail.com