Snapassport

Privacy Policy

Last updated: July 21, 2026

This document is provided in English. Translations elsewhere on this site are for your convenience only and are not legally binding.

Snapassport helps you create a passport or visa photo that meets published government specifications. To do that we have to process a photo of a face — yours or the person you are making the photo for. This page explains, in plain language, what we collect, why, how long we keep it, and the choices you have.

Who we are

Snapassport is a Solo Guy Lab product. Solo Guy Lab publishes and operates this service from San Francisco, California and is responsible for the data practices described in this policy.

Biometric data, in plain terms.

We compute a numeric “face-geometry signature” (a face embedding) from your photo. This is biometric / special-category personal data. We use it for one purpose only: to confirm that our AI edit did not change who you are. We never use it to identify you, match you across photos, build a profile, or sell it.

What we collect

  • The photo you upload (or the demo photo you choose), plus the cropped, cleaned, and AI-corrected versions we generate from it.
  • A face embedding derived from your photo — a 512-number mathematical summary of facial geometry (ArcFace). It cannot reconstruct your photo. We use it solely as an identity anchor: after the AI fixes lighting, crop, or background, we compare the edit to this signature to make sure it is still you. If the similarity drops too far, we reject the edit.
  • Validation measurements derived from the photo (head height, head angle, background uniformity, color, and similar metrics) used to show you a pass/fail report.
  • Your email address, only if you reach checkout — collected by our payment processor so we can send your order and receipt.
  • Basic technical and usage data (an anonymous session cookie, and aggregate product analytics and error reports) to run and improve the service. We never log the bytes of your image.
  • Your IP address and approximate location (city, region, postal code, and country, derived from your IP by our network provider), along with your browser type (User-Agent) and approximate time zone. We store these tied to your anonymous session to prevent fraud and abuse and to debug problems. We remove the IP, city, region, postal code, browser, and time zone after up to 90 days. We may retain the coarse country for aggregate country-level analytics and recommendation diagnostics. None of these details are sent to our analytics or error-monitoring vendors.

Why we are allowed to process it (legal basis)

For the photo and the face embedding, our legal basis is your consent, which you give by uploading your photo after we show you our processing notice (a dismissible banner linking to this policy and our Terms). Because the embedding is special-category / biometric data, we do not process it unless you upload, and you can withdraw consent at any time by not completing — or by deleting — your photo (see “Retention” and “Your rights”). For payment and order email, our basis is performing the service you asked for.

Purpose limitation — what we do NOT do

We use your photo and its embedding to create and validate your passport photo. If you give separate, optional consent in our first-visit notice, we may also use eligible image-derived data to train, evaluate, and improve Snapassport's own models and services. We do not use your photo for advertising, surveillance, or training third-party identity models. We do not sell your personal data and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the CCPA.

How long we keep it (retention)

Your uploaded photo, every generated image, and the derived face embedding are automatically deleted from our primary storage within 28 days. Deletion happens on a schedule regardless of whether you finish — the embedding is stored on the same record as the photo and is destroyed with it. We keep a minimal order and payment record (for example: order id, amount, email, refund status) for legal, tax, and accounting purposes; that record does not include your photo or your face embedding.

Separately from your photo, we keep your IP address and detailed approximate location (city, region, and postal code) tied to your anonymous session for a short window — up to 90 days — for fraud and abuse prevention and debugging, then automatically remove those fields. We may retain the coarse country on the anonymous session for aggregate country-level analytics and to diagnose country-based document recommendations. This technical metadata never includes your photo or face embedding.

Messages sent through our Google Workspace/Gmail mailbox—including contact correspondence, receipts, service notices, and offers—leave an intentional, durable copy in our Sent history for customer support and order-history purposes. When a message includes a purchased or requested photo or PDF, that Sent copy also includes the attachment. These copies are separate from the automatic 28-day deletion from our primary photo storage and remain until an authorized support operator deletes them or we complete a verified deletion request. Access is restricted to authorized support operators.

One narrow exception: when we send your photo to our AI vision and image-editing providers, copies of the image you upload and the AI-edited image are also captured by our LLM-observability vendors (PostHog AI Observability and LangSmith — see “sub-processors” below) so we can review the quality of those AI results. PostHog automatically drops the captured image content after about 30 days; LangSmith retains it only for as long as our tracing project does, and we delete those traces on the same basis. These copies are used solely for quality review and never for any other purpose.

Who processes data on our behalf (sub-processors)

We use the following vendors to operate the service. We share only what each needs, and we do not authorize any of them to use your data for their own purposes:

  • Cloudflare R2 — encrypted, private photo storage (served only via short-lived signed URLs).
  • Google (Gemini) — AI image editing that corrects fixable issues.
  • Fireworks AI — AI vision checks used during photo validation.
  • Modal — on-demand GPU compute that separates you from the background (image matting). It receives the photo, computes a background mask, and returns it; the image is processed only for that request and is not stored by our service.
  • Stripe — payment processing and checkout. We never see your card number.
  • Google Workspace/Gmail — transactional, support, and offer email. Messages and any included photo/PDF attachments are retained in restricted-access Sent history as described under “Retention.” Cloudflare Email Sending remains our rollback email provider.
  • PostHog — product analytics. Aggregate usage analytics never include your image; separately, PostHog AI Observability receives the image content you upload and the AI-edited result so we can review AI quality, and drops that captured image content after about 30 days.
  • Google Analytics — aggregate website traffic and funnel measurement. We send page paths with only advertising-attribution parameters and event names without photo, order, session, email, or image data. In consent-restricted regions, Analytics storage remains denied.
  • LangSmith — AI tracing for the vision and image-editing steps; it receives the input photo and the AI-edited image as trace attachments so we can debug and review AI quality.

Your photo is sent to the storage and AI providers above (R2 for storage; Gemini and Fireworks for the AI edit and vision checks; Modal for background matting) for the purpose of making and validating your photo, and — for quality review of those AI steps — copies of the photo and the AI-edited result are captured by our LLM-observability vendors (PostHog AI Observability and LangSmith). Your 512-number face embedding is computed on our own service and is not sent to any of these vendors.

International transfers

Some of the providers above operate in the United States and other countries, so your data may be processed outside your home country. Where required, transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Most data is deleted from primary storage within 28 days; exceptions are email messages and included attachments retained in our restricted Google Workspace Sent history and limited image copies captured by our LLM-observability vendors for quality review, which are retained for their own short windows (PostHog drops the captured image content after about 30 days) as described under “Retention.” Gmail's acceptance of a message and its appearance in Sent history do not prove delivery to the recipient.

Your rights

Depending on where you live (for example under the GDPR, UK GDPR, CCPA/CPRA, or BIPA), you may have the right to access, correct, delete, or port your personal data, to withdraw consent, and to object to or restrict processing. Because we already delete everything from primary storage within 28 days, the fastest way to exercise your delete right is simply to not complete your order, or to email us. To make any request, contact privacy@snapassport.com. We will not discriminate against you for exercising these rights.

Children

Snapassport is intended for adults creating photos for themselves or for a child in their care. The service is not directed to children, and you may not create an account or submit your own information if you are under 16 (or under 13 where that is the applicable age). A parent or legal guardian may create a compliant photo of their child; by doing so you confirm you have the authority to provide consent on the child’s behalf.

Security

Photos are stored encrypted in private storage and are reachable only through short-lived signed URLs. We never log image bytes. No system is perfectly secure, but we limit what we collect, limit who can process it, and delete it quickly.

Changes & contact

If we change this policy we will update the date above. Questions or requests: privacy@snapassport.com.

Snapassport is an independent service. It is not a government agency and is not affiliated with, endorsed by, or operated on behalf of any passport, visa, or other government authority. This page describes our practices and is not legal advice.