Privacy Policy
Ultimo aggiornamento:
Questo documento è fornito in inglese.
This policy explains what bringphotosback.com collects, why, who processes it and what rights you have. The short version: your photos are used only to produce your results, they are deleted after 30 days, we never use them to train AI models, and we do not sell personal data.
The data controller is the operator of bringphotosback.com. For anything in this policy, including any request about your own data, write to [email protected].
What we collect
Photos you upload. Processed to produce the restoration, colorization, sharpening or animation you asked for, and nothing else. They are held in private storage - not publicly listed, not indexable - for up to 30 days so that you can download your results, then deleted automatically along with the results. You can have them removed sooner: write to support@ and we delete them.
Your email address, if you buy generations or ask for a sign-in link. It identifies your account, carries the sign-in links you request, and delivers your receipts. We do not send marketing email.
Payment data. Payments run through Stripe. Your card details are entered on Stripe’s own checkout page - we never see them and never store them. What reaches us is the fact of the purchase: which pack, the amount, the date, and the email address you paid with.
Technical data. A hashed identifier derived from your IP address and browser characteristics, used to enforce the free preview limit and to keep automated abuse off the service. Upload forms are protected by Cloudflare Turnstile. This data exists for security and capacity, not for profiling.
Referral mark. If you arrive through a partner link, a first-party cookie records which link it was, so that a later purchase can be credited to that partner. It is a short code stored by your own browser under our domain. It is not passed to any third party and is not used to track you anywhere else.
Cookies are covered in full, one row per cookie, in our Cookie Policy.
Legal bases
Where the GDPR or UK GDPR applies: processing your photos, your email address and your purchase record is necessary to perform the contract you enter when you use the service. The technical data and the abuse controls rest on our legitimate interest in keeping the service available and paid work protected.
Who processes it
We use a small number of processors, each for one job:
| Processor | Purpose | Where |
|---|---|---|
| Cloudflare | Hosting, file storage, security, cookieless analytics | Global edge network |
| fal.ai | AI processing of the photo you upload | United States |
| xAI, via fal.ai | AI processing for photo animation | United States |
| Resend | Sending sign-in links and receipts | United States |
| Stripe | Payment processing | United States and EU |
Photos are transferred to the AI processors over an encrypted connection, processed automatically, and are not retained by them beyond processing. No processor is permitted to use your photos to train AI models.
International transfers. Several of these processors are based in the United States, so personal data may be transferred outside the EEA and the UK. Those transfers are made under the European Commission’s Standard Contractual Clauses, and under the UK International Data Transfer Addendum where the UK GDPR applies, together with the technical measures described above.
How long we keep it
| Data | Retention |
|---|---|
| Uploaded photos and generated results | 30 days, then deleted automatically - sooner on request |
| Account: email, balance, purchase record | Until you ask us to delete it |
| Technical and abuse-control data | Short-lived, and held only in hashed form |
Records we are legally required to keep for accounting purposes are kept for as long as that obligation lasts, and for nothing else.
What we never do
- We never use your photos or results to train AI models.
- We never sell personal data, and we do not share it for cross-context behavioural advertising.
- We never publish your photos or show them to anyone else.
- We never send marketing email unless you ask for it.
Your rights
You can ask us to:
- give you a copy of the data we hold about you (access);
- correct anything inaccurate;
- delete your data;
- object to or restrict processing;
- send you your data in a portable form.
Write to [email protected] from the address concerned and we answer within one month. If you are in the EEA or the UK you may also complain to your national data protection authority.
If you are a California resident, the CCPA and CPRA rights to know, delete, correct and opt out apply to you. There is nothing here to opt out of: we do not sell or share personal information, and we do not offer financial incentives in exchange for data.
Children
The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has sent us personal data, write to support@ and we delete it.
Changes
If this policy changes materially, the date at the top of this page changes with it.