PRIVACY & DATA

Your local scan
stays local.

Local measurements stay in your browser. Optional AI actions send only the data you separately approve. This page explains the difference and how purchase access works.

What happens to your photo now

JPG and PNG files are validated and decoded in your browser. Measurement pipelines preserve original image bytes; bounded image copies are used for iris sampling, previews and exports. Camera access is requested only when you choose it; no audio is requested. Local processing keeps photos and landmarks in browser memory. Nothing is uploaded merely by selecting a photo or taking a picture. The optional text and photo-analysis steps below send different data only after separate explicit consent.

Your current photo, local measurements, completed AI results and plan follow you across this site in the same tab. “Clear photo & results” releases them and any report snapshots. Choosing a different photo starts a new session, preventing results from different photos from mixing. The app does not save them to localStorage, IndexedDB or a user profile. Your own downloaded copies remain on your device. Closing or reloading the page starts a new session; browser and operating-system memory handling is outside our direct control.

Optional DeepSeek text advice

After a local scan, you can inspect the exact template labels and up to four ratios that would be sent. Only after you check consent and click Generate AI style notes does this app send them through its server to DeepSeek-V4.1-Flash. No photo, face landmarks, name or filename is sent. These measurements are still personal information. DeepSeek processes them under its own policies; do not assume zero provider retention.

The submitted measurement summary is not saved. In paid mode, successful AI text responses are encrypted in the billing database for delivery recovery for up to 20 minutes. Development mode uses a temporary in-memory result cache for the same period. Server logs record only request ID, status, model and available token/cost metadata. “Clear photo & results” or “Clear AI result” removes the browser result; it does not delete data already received by DeepSeek. “Stop waiting” ends your wait in this browser; the server may finish the original task so you can retrieve it with “Continue request — no additional credit”. It cannot guarantee provider cancellation. Public AI access requires a purchased credit and verified same-origin request.

Optional DeepSeek photo analysis: skin, color and apparent age

These three tools first compute local photo signals. For the cloud step you can inspect the exact JPEG copy (maximum edge 1536 pixels, up to 2 MB). The browser re-encodes it without the original file metadata. You must separately confirm photo permission, adult status and consent, then click Analyze photo with AI. Only that copy and the selected tool go through our local server to DeepSeek-V4.1-Flash using its image-understanding API. No filename, landmarks, local samples or arbitrary user prompt are included. Hiding the local map photo or changing its overlay does not change this clearly previewed cloud copy.

Our application does not persist the uploaded photo. In paid mode, successful AI observations are temporarily encrypted for delivery recovery. Requests necessarily pass through server/provider memory. Our logs contain only request ID, status, selected tool, model and available usage/cost metadata, never the image or generated observations. Result JSON downloads do not contain photos. Local map downloads may include photos or identifying outlines.

AI providers and international processing

DeepSeek receives approved measurement summaries or re-encoded photos and processes personal data in China. Its published policy does not promise zero retention or a fixed API deletion window and says personal data may be used to improve or train its technologies, subject to available opt-out rights. Grsai and its downstream providers receive approved re-encoded photos and prompts; Grsai states that processing is in China, API and security logs are generally retained for 6–24 months, content is retained short-term as needed for service and troubleshooting, and protected input or output is not used for foundation-model training without explicit consent. Neither provider guarantees immediate deletion; contact Vban LLC for assistance with provider requests.

DeepSeek and Grsai are separate providers. Grsai is not a direct OpenAI API connection. Clearing the browser session does not delete data already received by these providers. Contact the operator above about access or deletion requests.

Clear photo & results”, “Clear AI result” and “Stop waiting” do not retract images already sent to DeepSeek. Cancellation or failure can still incur provider charges. Developer mode is restricted to loopback access. Paid mode checks a private purchase cookie and reserves credits in a transactional database before AI access.

Optional Grsai hairstyle and studio previews

The report and Style studio tools can send a separately previewed JPEG (up to 1536 px / 2 MB) and a fixed, inspectable editing prompt to Grsai after photo rights, adult status and Grsai consent are confirmed. Each new Generate action creates one job using gpt-image-2.5, 1024 × 1024, quality auto. Grsai is a separate third-party service, not our DeepSeek text provider or a direct OpenAI API connection. No name, filename, landmarks, scores, full report or report preference form is sent. Selected studio editing choices are sent as instructions, not measurements. The provider notice above applies to Grsai and its downstream processors.

Our server polls only that submitted task for a bounded period, fetches the result from numbered file nodes on the provider’s exact aitohumanize.com domain without forwarding the API key, validates it and strips metadata into a 1K JPEG for your browser. Only public IPs are permitted and TLS is checked. If local DNS returns fake/private IPs, a fixed Cloudflare HTTPS DNS query resolves the CDN hostname; this DNS query contains no photo, prompt, task ID or API key. System proxy/DNS settings are not modified. Source photos and prompts are held only during the bounded submission request. In local developer mode, task handles and generated images use a short-lived memory cache. In paid mode, encrypted provider checkpoints are stored in the billing database so a server restart does not cause a duplicate generation. Access to checkpoints and cached AI text expires after 20 minutes; encrypted payloads are purged by the next paid request or scheduled database cleanup. Generated image bytes and original photos are not stored in this database. Billing operation IDs, request hashes, credit usage and order records remain for purchase support. Source photos, provider credentials and checkpoint contents are never included in application logs. Output remains identifiable personal data. Download each image explicitly; report TXT/JSON contains only image status and selected hairstyle metadata, not image bytes or provider URLs. Cancellation, timeout or failure does not guarantee provider cancellation, deletion or refund. Continue queries only the original job without resending the photo or starting another generation. Keep the original page open: Clear, photo replacement or reload loses the browser handle, but does not immediately erase the short-lived server record or stop billing. If submission acknowledgement is lost, no automatic new job is allowed. A deliberate new Generate action may be charged again. Paid attempts reserve one image credit; confirmed failed attempts return it. Uncertain submission status requires support review.

On Cloudflare deployments, Cloudflare Images also processes the photo bytes to validate the image and resize generated previews. We do not save these images to a hosted image library. The free on-device measurement tools do not send photos to this service.

Hair-color-only local protection

When Custom studio changes only hair color, a local hair-segmentation model and existing face landmarks prepare a conservative edit region. Review the green region before any generation: it must cover only hair. Masks and landmarks are not sent to Grsai. Mask preparation failure blocks generation rather than silently switching to a full-image edit.

After a consented generation, the browser samples color from the returned image and blends it into the original hair texture. It does not paste the provider’s face or body. Pixels outside the chosen mask are checked against a decoded 1024px square original baseline, including after PNG encoding. This does not guarantee perfect segmentation, original file bytes, color accuracy or a salon outcome. Protected previews are local composites containing original portrait pixels, not anonymous or untouched provider outputs. Download them as lossless PNG. A failed local blend can retry from the received image in memory without another API request. This received image can remain in the current tab when you switch tools; clearing the session or refreshing releases it. Other edit combinations still use full-image generation without this protection.

Network requests and camera

Your browser downloads application code and model files from this site. These downloads do not contain your photo. Normal web hosting may process IP addresses and request metadata. No analytics, advertising pixels, session recording or third-party fonts are installed in this preview. Camera tracks are stopped after capture, cancellation or leaving the camera view.

Downloads

“Download image (PNG)” exports the displayed photo and optional landmark guides locally. It does not publish a link or upload the image. Be mindful of whom you share it with. Selected tools also offer a local share-card preview and PNG download. Cards exclude the image by default; including your current image is an explicit choice. Neither option posts to social networks. Measurements, scores and photo-hidden landmarks may still identify you.

The report preview combines results from one photo in browser memory. Report TXT/JSON downloads exclude photos, landmarks and local map buffers, but include personal measurements and requested AI results. Nothing is automatically uploaded to create the report. Each optional cloud analysis still needs its own consent. Completed tool results are collected in the report automatically and survive same-tab navigation, not reloads or closing the tab. Existing image-task handles stay only in this tab so you can explicitly continue the same task after returning; navigation never requests a new generation. “Add results to report” creates an optional separate snapshot. No requests are automatically replayed. A local SHA-256 fingerprint prevents combining different photo bytes; it is never exported or uploaded and does not identify a person. “Use draft photo locally” is an explicit local reuse action, not permission for cloud processing. Remove snapshots or clear the draft separately; later tool edits do not alter saved snapshots. TXT/JSON and local printing use selected snapshots; print can optionally include generated images and protected composites, never a separate original portrait. Protected composites contain original portrait pixels outside their edit region and remain identifying personal data. Downloaded files and opened print snapshots remain until you delete or close them. There is no cloud report storage period: reports stay in this tab until you clear, replace, reload or close it.

Stripe payments and purchase access

Personal report purchases use a Stripe-hosted checkout. Card details and billing contact information go directly to Stripe; they do not pass through our payment form. Stripe receives the product, amount and internal order ID, never your photo, measurements or report. Our database stores an opaque buyer ID, a hash of your private recovery code, Stripe order references, payment status and credit usage. A necessary HttpOnly purchase cookie lasts up to one year; it contains no photo or report data. Clearing a photo session does not erase report access, purchased credits or payment records.

Protect your recovery code: anyone holding it can use the associated report access and credits. Recovering purchase access does not recover photos or an unfinished report session. Payment refunds and disputes suspend report access and the remaining credits for that order. Billing records are retained for purchase support, accounting and applicable obligations; contact the operator for the retention period that applies to your purchase. Billing records and provider-held data are not deleted by clearing your browser session. Contact the support address on Pricing about purchase records. Long-term cloud report storage, emailed reports and user profiles are not included.

Use your own photo

Use photos you have the right and permission to process. This preview is intended for adults. No face-based age verification is provided. Do not use it to analyze someone without their permission or to make medical, employment or eligibility decisions.