Back to Home

Privacy Policy

Last updated: February 18, 2026 · GDPR compliant

1. Controller (Data Responsible)

2. Data We Collect and Why

Photos you upload

You upload two parent face photos to generate baby predictions. These images are processed solely for AI image generation and are automatically deleted within 24 hours of upload. Generated result images are available for 7 days after generation, then permanently deleted. We never store, analyse, or share your photos for any other purpose.

Payment information

Payments are processed by Lemon Squeezy (Merchant of Record). We never see or store your credit card or payment details. Lemon Squeezy handles all payment data under their own Privacy Policy and applicable PCI DSS standards. As Merchant of Record, Lemon Squeezy also handles tax collection and compliance.

Technical data

We temporarily process your IP address for rate-limiting purposes (preventing abuse) only. IP addresses are not logged or stored beyond the immediate request.

3. Legal Basis for Processing (Art. 6 GDPR)

Your photos are processed on the basis of:

  • Contract performance (Art. 6(1)(b) GDPR) — processing is necessary to deliver the service you paid for.
  • Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — face photos may qualify as biometric data; by uploading and initiating processing, you give explicit consent to their temporary processing solely for AI generation.

4. Retention & Automatic Deletion

  • Uploaded parent photos: deleted within 24 hours of upload.
  • Generated baby prediction images: available for 7 days after generation, then permanently and automatically deleted.
  • No user accounts are created. No images are permanently stored.
  • After the above periods, no personal data relating to your session remains.

5. Third-Party Processors

To deliver the service, we share your photos with the following processors under Data Processing Agreements (Art. 28 GDPR). Transfers to the USA are made under Standard Contractual Clauses (Art. 46(2)(c) GDPR).

Replicate, Inc. (USA) — AI Image Generation

Your parent photos are sent to Replicate's API to generate baby face predictions. Replicate processes images solely for inference and does not train models on your data. replicate.com/privacy

Anthropic, PBC (USA) — AI Text Processing

We may use Anthropic's Claude API for text-based processing (e.g. content moderation, prompt generation). No photos are sent to Anthropic. anthropic.com/privacy

Lemon Squeezy (USA) — Payment & Merchant of Record

All payment processing is handled by Lemon Squeezy as Merchant of Record. We do not receive or store payment data. lemonsqueezy.com/privacy

Cloudflare, Inc. (USA) — Hosting & CDN

The service runs on Cloudflare Pages and Workers. Cloudflare may process request metadata (IP address, headers) as part of its infrastructure. cloudflare.com/privacypolicy

6. Biometric Data (Art. 9 GDPR)

Face photographs may constitute biometric data under Art. 9 GDPR. We process this data exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), given when you upload photos and initiate the prediction. The data is not used for any purpose other than generating your predictions, is not shared beyond the processors named above, and is automatically deleted within 24 hours.

7. Cookies & Analytics

We do not use tracking or advertising cookies. We use Plausible Analytics — a privacy-first, cookie-free analytics tool that does not process personal data and does not track individuals across sites. No consent banner is required as no personal data is processed.

8. Your GDPR Rights (Art. 15–22 GDPR)

You have the right to:

  • Access (Art. 15) — request a copy of any personal data we hold about you.
  • Rectification (Art. 16) — correct inaccurate personal data.
  • Erasure (Art. 17) — request deletion of your data ("right to be forgotten").
  • Restriction (Art. 18) — request restriction of processing.
  • Data portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interests.
  • Withdraw consent (Art. 7(3)) — withdraw consent at any time without affecting prior processing.

Since we hold no persistent personal data (all data is auto-deleted within 24 hours), most rights are automatically fulfilled after that period. To exercise any right before deletion, contact us at hello@babyfacepredictor.com

9. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. If you are based in Germany, the competent authority depends on your federal state. The general supervisory authority for cross-border matters within Germany is the Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI).

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in law or service. The current version is always available at this URL. Material changes will be noted at the top with a new "Last updated" date.

11. Contact

For any privacy-related questions or to exercise your rights, contact us at hello@babyfacepredictor.com