Privacy Policy
K Headshot
Effective date: August 19, 2026 Last updated: August 19, 2026
Read this first: your face
Most services that turn selfies into AI pictures do not tell you what happens to your face. We looked at ten of them. None explained it properly. So here it is, at the top, before anything else.
| Question | Answer |
|---|---|
| What do you do with my photo? | We send it, along with a text instruction, to a third-party AI model that produces a new image. Then we send that image back to you. |
| Who is the third party? | Google, through the Gemini API. See Section 5. |
| Do you sell my face? | No. We do not sell, lease, trade, or otherwise profit from face data. Not to anyone, ever, for any price. |
| Do you train AI on my face? | No. We do not train, fine-tune, or improve any AI model with your photo. We require our AI provider by contract not to either, and we use its paid tier specifically because its terms say it does not use what we send to improve its products. |
| Do you identify me? | No. We do not run facial recognition. We do not try to work out who you are, match you against any database, or build a searchable face template. We are not building technology to do that. |
| How long do you keep it? | We do not keep it. Your photo is held in memory only for as long as it takes to make your images, and is never written to our storage. See Section 7.1. |
| Can I make you delete it? | There is nothing for us to delete — we never stored it in the first place. You withdraw simply by not uploading again. Section 9. |
| Is this "biometric" information? | Depending on the law where you live, a face photo and information derived from it may be treated as biometric data, biometric information, or sensitive personal information. We handle it as if it is. See Section 4. |
This box is a summary. The sections below are the actual policy.
1. Who we are and what this covers
1.1 K Headshot ("we", "us", "our") is operated by Epikohub LLC, a California limited liability company, at 12100 Wilshire Blvd, 8th Floor, Los Angeles, CA 90025.
1.2 This Privacy Policy explains what personal information we collect through the K Headshot website at kheadshot.com, why we collect it, who we share it with, how long we keep it, and what you can do about it.
1.3 It applies to the website and the service on it. It does not apply to other companies' websites you reach from ours.
1.4 The Service is for adults in the United States. We do not knowingly collect information from anyone under 18, and no part of the Service is directed to children. See Section 10.
1.5 Using the Service means you accept this policy. For face data specifically, we ask for your separate, affirmative consent before you upload — see Section 4.4.
2. What we collect
| Category | What it is | Where it comes from | Why we have it |
|---|---|---|---|
| Face data (your photo) | The photograph you upload, and the AI-generated images made from it | You | To make the images you ask for. Nothing else. See Section 4 |
| Your style choices | Which style you picked, background colour, and any text you type in the custom box | You | To build the instruction sent to the AI model |
| Waitlist email | The email address you type into the waitlist form — and nothing else. No name, no company, no reason for signing up. We store it in lower case with a randomly generated identifier and the date and time you signed up | You, if you choose to join the waitlist. The form appears only after you have used up your free previews, and joining is entirely optional | To send you one message when paid credits go on sale, and for nothing else. It is never attached to your photograph, your session, or any generation. How long we keep it, and the honest limits of that, are in Section 7.2 |
| Purchase records | What you bought, when, amount, currency, a payment reference, and the email address you gave at checkout | Stripe, when you buy credits | To deliver what you paid for, connect your purchase to your credit balance, handle refunds, keep tax and accounting records, and prevent fraud |
| Payment card details | Card number, expiry, security code | You, entered directly into Stripe | We never receive or store these. Stripe handles them |
| Technical information | IP address, browser type, device type, and time of request | Your browser, automatically | To keep the Service running, apply rate limits, and prevent abuse |
| Generation logs | Which model ran, which style, how long it took, whether it succeeded, and what it cost us | Our own systems | To run the business, find failures, and control cost. These logs do not contain your photo or the text of your prompt |
| Support messages | What you write to us, and what we write back | You | To answer you |
| Consent records | That you confirmed you are 18 or older and consented to face-data processing, and when — written as a single line to our server log. Section 7.2 explains exactly what that line contains and how long it survives | You and our systems | To show that we asked before collecting |
We do not collect precise geolocation, contacts, social-media profiles, browsing activity on other sites, or any information about your health, race, religion, politics, sexuality, or union membership. We do not ask your age range, gender, or ethnicity as a product input.
3. Why we use it
We use personal information only to:
- create the images you ask for;
- deliver them to you — today that means returning them in the same response that carried your photo in, with nothing stored afterwards, so there is no re-download window to speak of (Section 7.1);
- take payment, apply your credits, and handle refunds and chargebacks;
- answer your questions and provide support;
- keep the Service secure — rate limiting, abuse prevention, fraud prevention;
- keep the Service working — monitoring, debugging, and cost control;
- send you transactional messages such as a receipt for a purchase, which today is issued by Stripe, and any notice we are required to give you;
- meet legal, tax, and accounting obligations, and respond to lawful requests;
- enforce our Terms of Service; and
- tell you once, if you asked us to, on the day paid credits go on sale — that is the only thing your waitlist email is for (Section 2).
We do not use your information for behavioural advertising, profiling, automated decisions with legal effects, or to build or improve AI models.
Email, and what we can actually do with it. We do not run a marketing list and we send no marketing email. We collect an email address in exactly two places: the waitlist address in Section 2, and the checkout email that comes with a purchase. The waitlist address is used for the single notice you asked for when credits open, and the checkout email is used to attach your purchase to your credit balance and to handle refunds — neither is used for marketing. We will not add it to another list, will not sell, rent, or trade it, will not attach it to your photograph, and will not use it to contact you about anything else without asking you first. That notice has not gone out yet — no email has ever been sent to a waitlist address — and when it does go out it will identify us accurately and carry a one-click unsubscribe link and our postal address.
4. Face data — the section that matters
4.1 What we mean. "Face data" means the photograph of your face that you upload, the images the Service generates from it, and any information derived from either.
4.2 How the law may see it. Depending on the law of the state where you live, face data may be treated as biometric data, biometric information, or sensitive personal information. We handle your face data as if it is, everywhere in the United States, regardless of whether a particular statute applies to us.
4.3 The specific purpose, and the specific term.
- Purpose: we collect and process your face data for one purpose only — to generate the AI images you requested, and to deliver them to you. We do not use it for identification, verification, security, advertising, analytics, model training, research, or any other purpose.
- Term: we do not retain face data at all. It exists in memory only for the duration of the single request that generates your images, and is never written to our storage. See Section 7.1.
4.4 Your consent, and how we ask for it. We collect and process face data only with your informed, affirmative consent, which you give by checking the consent box shown before you upload. That box tells you, in plain language, what we collect, why, who we send it to, and how long we keep it. You are not required to consent — but without consent we cannot make images for you, because the photo is the whole product.
The consent text below is the exact wording shown on screen before you upload. If the two ever differ, this document is the one that governs.
Before you upload. I am 18 years or older and the photo I am uploading is a photo of me. I consent to K Headshot collecting and processing my photograph — which may be treated as biometric information where I live — for the sole purpose of generating the AI images I request, and to K Headshot sending it to its AI processing provider (Google) for that purpose. I understand that K Headshot does not store my photograph or the images generated from it — they are held in memory only for as long as it takes to make my images, and are not kept afterwards — that it will never sell my photograph, and that it will never use it to train AI. I can withdraw this consent at any time by not uploading another photo, and because my photograph is never stored there is nothing left for anyone to delete.
4.5 We do not sell it. We do not sell, lease, trade, or otherwise profit from face data. We have never done so and we do not intend to.
4.6 We do not disclose it. We do not disclose, redisclose, or otherwise disseminate face data to anyone, except: (a) to the AI processing provider that generates your image, acting on our instructions only (Section 5); (b) to the infrastructure providers that host the Service, acting on our instructions only (Section 6); (c) where you have specifically told us to; or (d) where a valid warrant, subpoena, or court order requires it.
4.7 We do not identify you. K Headshot does not identify or authenticate the people in the photos you upload, does not match faces against any database, does not create or store a searchable face template or faceprint, and is not developing technology to do any of those things.
4.8 What our AI provider is contractually required not to do. We require our AI processing provider, by contract, not to use face data to train generalized AI models or to build pooled face-training datasets, and to act only on our instructions. See Section 5.
4.9 How we protect it. We store and transmit face data using a reasonable standard of care for our industry, and in a manner at least as protective as the way we handle our own confidential and sensitive information. See Section 8.
4.10 You can withdraw. You can withdraw your consent at any time, and the way you do it is simply to stop uploading — we hold no face data between requests, so withdrawal takes effect the moment you stop and there is nothing left for us to erase (Section 7.1, Section 9). Withdrawing does not make our earlier processing unlawful, and it does not undo images already delivered to you.
4.11 State-specific note. If you live in a state with a specific biometric-privacy law — including Illinois, Texas, and Washington — that law may give you rights in addition to those described elsewhere in this policy. We have built the controls in this Section 4 to meet the substance of those laws: a written notice of what we collect and why, a published retention position — we do not retain face data at all, so there is no retention term to run and no destruction schedule to keep (Section 7.1) — your affirmative consent before collection, a prohibition on selling or profiting from face data, a prohibition on disclosing it without your consent, and a reasonable standard of care in storing and transmitting it. Whether any particular statute applies to us is a legal question we do not decide in this document. Nothing here is a waiver of your rights or an admission of anything.
5. The AI provider
5.1 Who. Image generation is performed by Google LLC through the Google Gemini API. Your photo and the text instruction built from your style choices are transmitted to Google for processing, and the generated image is returned to us.
5.2 What tier we use, and why it matters. We use Google's paid Gemini API tier. Google's published terms for the paid tier state that Google does not use prompts or responses to improve its products, and Google acts as our data processor under a Data Processing Addendum. Google's free tier does not carry those commitments — content sent through it may be used to improve Google's products and may be reviewed by humans. We do not send your photo through a free tier.
5.3 What Google may do. Google may retain content briefly for abuse monitoring and to comply with law, as described in its own terms. We do not control that retention. Google's terms for the Gemini API are published at ai.google.dev/gemini-api/terms, and Google's privacy policy at policies.google.com/privacy.
5.4 If we change providers, we will update this section and this policy before your data goes anywhere new.
6. Who else touches your information
We share personal information only with service providers who work for us, on our instructions, under contract. We do not sell it and we do not share it for cross-context behavioural advertising.
| Provider | What it does | What it can see |
|---|---|---|
| Google LLC (Gemini API) | Generates the image | Your photo and the text instruction. See Section 5 |
| Stripe, Inc. | Processes payments | Your payment details, email, and purchase amount. We never see your full card number |
| Vercel Inc. | Runs the website and the servers | Traffic and request data, including IP address |
| Cloudflare, Inc. (R2) | Holds waitlist sign-ups | No face data. The Service stores no images at all (Section 7.1), so no photograph reaches this provider. It holds waitlist sign-ups where sign-ups are switched on: one small file per sign-up containing an email address, a random identifier, and a timestamp (Sections 2 and 7.2) |
Waitlist sign-ups are collected on our own site. If we ever move that form to one hosted by someone else, we will name that company in this table before we switch it on. The same promise covers the payments database: purchase records and checkout emails will live in a managed database, and we will name that provider in this table before the first sale.
We keep this list current, and the table in this section is that list — there is no separate page. If we add a provider that touches your personal information, we add a row here before it starts work.
We may also disclose information (a) to comply with law or a valid legal request, (b) to protect our rights, safety, or property or those of others, or (c) to a buyer as part of a merger, acquisition, or sale of assets — in which case face data remains subject to this policy, or we obtain fresh consent.
7. How long we keep things
7.1 Face data. We do not keep it.
Your photograph, and the images generated from it, are held in memory only, for the duration of the single request that makes your images. They are not written to a database, a bucket, a disk, or a backup of ours. The generated preview is returned in the same HTTP response that carried your photo in, and when that response ends nothing of either remains on our side.
So there is no retention period, because there is nothing retained. There is no destruction schedule, because there is nothing to destroy on a schedule. "We store it for thirty days and then delete it" would be a weaker promise than the one we are actually making, and we are not going to make the weaker one.
This is a statement about our systems, not about our AI provider's. Google may hold content briefly for abuse monitoring and legal compliance under its own terms — Section 5.3 — and we do not control that.
If we ever build a feature that has to store face data — for example, letting you re-download a purchase days later — we will publish the retention period and the destruction schedule in this section before that feature is turned on, and we will not apply it retroactively to any photograph given to us under this version of the policy.
7.2 Everything else.
Some rows in this table describe things that do not exist yet. We have not built accounts, credits, or purchases, so nothing of that kind has ever been collected and none of those periods has ever run. A row marked not yet in use is a commitment about a feature we have not turned on, not a description of data we hold. The rows that describe live behaviour today are generation logs, rate-limit counters, support messages, and — each with an important qualification in its own row — consent records and the waitlist email.
| What | How long | Why |
|---|---|---|
| Purchase and tax records | Not yet in use. 7 years | Tax, accounting, and anti-fraud recordkeeping |
| Waitlist email | In use — and this promise is weaker than it sounds. Read the paragraph below it. Marked for deletion two years after you sign up. Nothing in our systems carries that deletion out yet, so treat two years as the longest we intend to hold it, not as something that happens by itself | To send you the single notice you asked for when credits open |
| Generation logs (no photo, no prompt text) | In use. 12 months | Debugging, cost control, and abuse investigation |
| Rate-limit counters (IP-based) | In use. Same day only, in memory | Rate limiting. Not written to disk |
| Support messages | In use. 24 months | To handle follow-ups and disputes |
| Consent records | Partly in use, and weaker than it sounds — read the next paragraph. Today: one line written to our server log, kept only as long as our host keeps that log, and not recoverable once the log rotates | To show that we asked before collecting. We are not able to promise more than this yet, so we do not |
On consent records, precisely. The consent text you agree to is consent version 4, and the exact wording appears in section 4.4 above. When you tick the consent box we write a single line to our server log recording an opaque session identifier, the consent version, a fingerprint (SHA-256 hash) of the exact words you agreed to, and a salted hash of your IP address — never your photograph and never your IP in the clear. That line is not a durable record: it lives in ordinary server logs, our hosting provider rotates and discards those on its own schedule, and we have no database, no query interface, and no way to retrieve your specific consent months later on request. So we do not claim to keep consent records indefinitely, and we do not claim to be able to produce yours.
On the waitlist email, precisely. If you join the waitlist, your address ends up in two places. First, one line in our server log, written the moment it arrives and before we try to save it, so that an address is not lost if the save fails. That line contains your address in readable form, and it lives for as long as our hosting provider keeps its logs — a period we do not set, cannot query, and will not overstate. Second, one small file in our object storage, holding your address, a randomly generated identifier, and the moment you signed up. That file is stamped with a marker saying it may be deleted two years after sign-up.
Here is the part most policies would leave out. We have written that two-year mark onto the file, but we have not yet built the scheduled job that reads those marks and deletes what has expired. So "two years" is the limit we have set for ourselves and the point after which the file is fair game for deletion — it is not an automatic erasure that happens on its own today, and we are not going to describe it as one. When the deletion job exists, this paragraph will say so plainly, and not before.
What is not in either copy: no photograph, no session identifier, no detail of anything you generated, and no IP address. Your IP is checked against a rate limit held in memory and is never written down beside your address — an address and a face must never meet on one line of a log whose retention we do not control. And where sign-ups are not switched on, nothing is kept at all: the form refuses and tells you so, instead of accepting an address it would quietly drop.
Getting off the list. Email privacy@kheadshot.com and we will delete your address from the waitlist. The single notice we send, when it goes out, will also carry a one-click unsubscribe link.
7.3 We may keep information longer where a law, a tax rule, or a legal hold requires it. If we do, we keep only what is required, and only for as long as required.
8. Security
8.1 We use reasonable technical and organisational measures appropriate to the sensitivity of face data, including transport encryption (HTTPS/TLS) for everything sent between your browser, our servers, and our providers, access restricted to the people who need it, and security headers on our web responses.
8.2 We handle face data with at least the same care as our own confidential and sensitive business information.
8.3 No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. If a breach affects your personal information, we will notify you and any regulator as required by the law of your state.
8.4 We do not currently hold a SOC 2 or ISO 27001 certification, and we do not claim one.
9. Deleting your data and withdrawing consent
9.0 Read this before the rest of the section. For face data, you do not need to send us a request and you do not need to wait for us to act. We do not keep your photograph or the images made from it (Section 7.1), so withdrawal is immediate and self-executing: stop uploading, and there is nothing of yours left on our side. The request machinery below exists for the other categories in Section 7.2, and for the day face data is stored — it is not the route by which your photo stops existing, because your photo already does not persist.
9.1 You can withdraw your consent at any time, for any reason, and at no cost. Withdrawing consent to face-data processing requires nothing of you but to stop.
9.2 How. Email privacy@kheadshot.com and tell us what you would like us to do. If your request is about something we hold under a particular email address — a waitlist sign-up, or a purchase — write to us from that address, or tell us what it is, so we can find it.
9.3 When. We will act within thirty (30) days and confirm to you in writing when it is done.
9.4 What happens. In almost every case there is nothing for us to erase: we never stored your photo or the images made from it in the first place (Section 7.1). Anything we do hold that is connected to you — a waitlist email address if you gave us one, or a support message you sent us — is erased or anonymised on request unless Section 7.2 requires us to keep it. Images you already downloaded stay on your own device — we cannot reach those. Purchase and tax records are kept as Section 7.2 requires, because the law requires them; they do not contain your photo.
9.5 What you lose. Withdrawing consent means we can no longer generate images for you. Unused credits are not forfeited by a deletion request — see the Refund and Credits Policy.
10. Children
10.1 The Service is for adults. You must be 18 or older to use it, and every person shown in any uploaded photo must be 18 or older.
10.2 We do not knowingly collect, keep, or use personal information from anyone under 18, and no part of the Service is directed to children.
10.3 We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under 13. Under the California Consumer Privacy Act, if we determine a user is under 16, we treat their personal information as Sensitive Personal Information with heightened protection. We do not sell or share the personal information of anyone under 16 — and in fact we do not sell or share anyone's.
10.4 If you believe a child has given us personal information, or that a photo of a minor has been uploaded, email abuse@kheadshot.com immediately. We will delete it and take action on the person responsible.
10.5 We do not run automated age estimation, and we do not analyse faces to guess anyone's age. Doing so would require processing more biometric information about more people, which is the opposite of what this policy is for. Our controls are the contractual ban in the Terms, the confirmation you give before uploading, and the reporting channel above.
11. Your rights
11.1 Rights everyone gets from us. Regardless of where you live in the United States, you can ask us to:
- tell you what personal information we hold about you;
- give you a copy of it;
- correct anything that is wrong;
- delete it (Section 9); and
- withdraw your consent to face-data processing (Section 9).
We will not treat you differently, charge you more, or give you a worse service for exercising any of these.
11.2 California (CCPA/CPRA). If you are a California resident, you also have the right to know the categories of personal information we collect, the purposes, and the categories of third parties we disclose to (all in Sections 2, 3, and 6); the right to opt out of sale or sharing for cross-context behavioural advertising (we do neither, so there is nothing to opt out of); the right to limit our use of Sensitive Personal Information (we already limit face data to the single purpose in Section 4.3); and the right to appeal a decision on your request.
11.3 Other states. If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, or another state with a comprehensive privacy law, you have similar rights — including access, correction, deletion, portability, opting out of targeted advertising, profiling, and sale (we do none of those), and the right to appeal.
11.4 How to exercise a right. Email privacy@kheadshot.com. Tell us what you want and which email address or order you are asking about.
11.5 Verification. We will take reasonable steps to confirm it is really you before we act, usually by replying to the email address the request came from and asking you to confirm details only you would know, such as the date and amount of a purchase. We will not ask you for a photo of your ID or a selfie to verify a request — that would mean collecting more sensitive information to protect your sensitive information.
11.6 Timing. We respond within 45 days, and may extend once by another 45 days where the law allows, telling you why.
11.7 Appeals. If we refuse, we will tell you why and how to appeal. Send appeals to privacy@kheadshot.com with "Appeal" in the subject. We respond to appeals within 45 days. If we deny your appeal, you may contact your state Attorney General.
11.8 Authorized agents. You may use an authorized agent, with written proof of authority. We may still contact you directly to confirm.
12. Washington and Nevada — consumer health data
12.1 If you live in Washington or Nevada, your state's consumer health data law may treat biometric data as consumer health data. Whether any such law applies to us is a legal question this policy does not decide, and nothing in this section is an admission that it does.
12.2 We collect one thing that could fall in that category: the photograph of your face and the images generated from it. We collect it only with your consent, only to generate the images you requested, and we keep it only for the period in Section 7.1 — which is to say, we do not keep it at all.
12.3 We do not sell consumer health data. We have never sold it and we do not intend to. If that ever changed, we would first obtain a separate, signed authorization from you as the law requires — a checkbox would not be enough.
12.4 We share it only with the processors listed in Section 6, who act on our instructions and may not use it for their own purposes.
12.5 You can ask us to confirm what we hold, to delete it, and to withdraw your consent, using Section 9. You may appeal a refusal under Section 11.7.
13. Cookies and tracking
13.1 As of the effective date of this policy, the Service uses no advertising cookies, no third-party analytics, no tracking pixels, and no cross-site trackers. We do not fingerprint your device.
13.2 We use only what is strictly necessary to make the site work and to keep it secure. Today that means one cookie of ours, and two small notes your own browser keeps for you:
kh_sid, a session cookie. Set the first time you generate an image or start a checkout — you do not need an account and there is nothing to sign in to. It carries a random identifier and a signature, and nothing about you: no name, no email address, no photograph. We use it to count your free previews, to apply limits fairly, and to connect a purchase to the previews made in the same session. It is HttpOnly, SameSite=Lax, sent only over HTTPS, and expires after 30 days.- Two values kept in your browser's own local storage. One remembers that you ticked the consent box, and which version of it; the other remembers that you already joined the waitlist, so the page does not ask you twice. These stay on your device, are not transmitted to us, and clearing your browser data removes both.
13.3 If we ever add analytics, we will update this section before turning it on, and we will not send face data to any analytics provider.
13.4 We honour Global Privacy Control signals as an opt-out of sale and sharing. Since we do neither, the signal changes nothing about how we handle your data — we say it here so you know we are not ignoring it.
14. Automated decisions
We do not use your personal information to make automated decisions that produce legal or similarly significant effects about you. The AI generates a picture. It does not decide anything about you.
15. Changes to this policy
15.1 We may update this policy. The "Last updated" date at the top will change and the new version will be posted here.
15.2 If we make a material change to how we handle face data, we will notify you and ask for your consent again before applying it to data we already hold. A change to this document alone will never expand what we may do with a photo you already gave us.
16. Contact us
| Legal entity | Epikohub LLC (a California limited liability company) |
| Business address | 12100 Wilshire Blvd, 8th Floor, Los Angeles, CA 90025 |
| Privacy and data requests | privacy@kheadshot.com |
| Abuse, minors, and likeness reports | abuse@kheadshot.com |
| General support | support@kheadshot.com |
If you are not satisfied with our response, you may contact your state Attorney General.
We wrote this because almost nobody in this category does. If any part of it is unclear, email us and we will explain it — and if the explanation is better than the text, we will change the text.