Privacy Policy
K Headshot
Effective date: August 18, 2026 Last updated: September 3, 2026
Read this first: your face
Most services that turn selfies into AI pictures do not tell you what happens to your face. We looked at ten of them. None explained it properly. So here it is, at the top, before anything else.
| Question | Answer |
|---|---|
| What do you do with my photo? | We send it, along with a text instruction, to a third-party AI model that produces a new image. Then we send that image back to you. |
| Who is the third party? | Google, through the Gemini API. See Section 5. |
| Do you sell my face? | No. We do not sell, lease, trade, or otherwise profit from face data. Not to anyone, ever, for any price. |
| Do you train AI on my face? | No. We do not train, fine-tune, or improve any AI model with your photo. We require our AI provider by contract not to either, and we use its paid tier specifically because its terms say it does not use what we send to improve its products. |
| Do you identify me? | No. We do not run facial recognition. We do not try to work out who you are, match you against any database, or build a searchable face template. We are not building technology to do that. |
| How long do you keep it? | Your photo: we do not keep it. It is held in memory only for as long as it takes to make your images, and is never written to our storage. Free previews are not stored either. The file you pay for is the one exception: when you buy a download, we store that finished image — not your photo — for up to 30 days, because that is how we hand it to you. See Section 7.1. |
| Can I make you delete it? | For your photo, there is nothing for us to delete — we never stored it in the first place. If you have paid for a download, email privacy@kheadshot.com and we will delete that file. You withdraw consent simply by not uploading again. Section 9. |
| Is this "biometric" information? | Depending on the law where you live, a face photo and information derived from it may be treated as biometric data, biometric information, or sensitive personal information. We handle it as if it is. See Section 4. |
This box is a summary. The sections below are the actual policy.
1. Who we are and what this covers
1.1 K Headshot ("we", "us", "our") is operated by Epikohub LLC, a California limited liability company, at 12100 Wilshire Blvd, 8th Floor, Los Angeles, CA 90025.
1.2 This Privacy Policy explains what personal information we collect through the K Headshot website at kheadshot.com, why we collect it, who we share it with, how long we keep it, and what you can do about it.
1.3 It applies to the website and the service on it. It does not apply to other companies' websites you reach from ours.
1.4 The Service is for adults in the United States. We do not knowingly collect information from anyone under 18, and no part of the Service is directed to children. See Section 10.
1.5 Using the Service means you accept this policy. For face data specifically, we ask for your separate, affirmative consent before you upload — see Section 4.4.
2. What we collect
| Category | What it is | Where it comes from | Why we have it |
|---|---|---|---|
| Face data (your photo) | The photograph you upload, and the AI-generated images made from it | You | To make the images you ask for. Nothing else. See Section 4 |
| Your style choices | Which style you picked, background colour, and any text you type in the custom box | You | To build the instruction sent to the AI model |
| Waitlist email | The email address you type into the waitlist form — and nothing else. No name, no company, no reason for signing up. We store it in lower case with a randomly generated identifier and the date and time you signed up | You, if you choose to join the waitlist. The form appears only after you have used up your free previews, and joining is entirely optional | To send you one message when paid credits go on sale, and for nothing else. It is never attached to your photograph, your session, or any generation. How long we keep it, and the honest limits of that, are in Section 7.2 |
| Purchase records | What you bought, when, amount, currency, a payment reference, and the email address you gave at checkout | Stripe, when you buy credits | To deliver what you paid for, connect your purchase to your credit balance, handle refunds, keep tax and accounting records, and prevent fraud |
| Payment card details | Card number, expiry, security code | You, entered directly into Stripe | We never receive or store these. Stripe handles them |
| Technical information | IP address, browser type, device type, and time of request | Your browser, automatically | To keep the Service running, apply rate limits, and prevent abuse |
| Generation logs | Which model ran, which style, how long it took, whether it succeeded, and what it cost us | Our own systems | To run the business, find failures, and control cost. These logs do not contain your photo or the text of your prompt |
| Support messages | What you write to us, and what we write back | You | To answer you |
| Consent records | That you confirmed you are 18 or older and consented to face-data processing, and when — written as one row in our database. That row holds exactly five things: an opaque session identifier, the consent version, a fingerprint (SHA-256 hash) of the exact words you agreed to, a salted hash of your IP address, and the time. Never your photograph, and never your IP address in the clear — the table is built to refuse both. Section 7.2 has the details | You and our systems | To prove that we asked before collecting, and which words were on screen when you agreed |
We do not collect precise geolocation, contacts, social-media profiles, browsing activity on other sites, or any information about your health, race, religion, politics, sexuality, or union membership. We do not ask your age range, gender, or ethnicity as a product input.
3. Why we use it
We use personal information only to:
- create the images you ask for;
- deliver them to you — a free preview comes back in the same response that carried your photo in, with nothing stored afterwards; a file you have paid for is held in our object storage for up to 30 days, because a download needs a file to point at (Section 7.1);
- take payment, apply your credits, and handle refunds and chargebacks;
- answer your questions and provide support;
- keep the Service secure — rate limiting, abuse prevention, fraud prevention;
- keep the Service working — monitoring, debugging, and cost control;
- send you transactional messages such as a receipt for a purchase, which today is issued by Stripe, and any notice we are required to give you;
- meet legal, tax, and accounting obligations, and respond to lawful requests;
- enforce our Terms of Service; and
- tell you once, if you asked us to, on the day paid credits go on sale — that is the only thing your waitlist email is for (Section 2).
We do not use your information for behavioural advertising, profiling, automated decisions with legal effects, or to build or improve AI models.
Email, and what we can actually do with it. We do not run a marketing list and we send no marketing email. We collect an email address in exactly two places: the waitlist address in Section 2, and the checkout email that comes with a purchase. The waitlist address is used for the single notice you asked for when credits open, and the checkout email is used to attach your purchase to your credit balance and to handle refunds — neither is used for marketing. We will not add it to another list, will not sell, rent, or trade it, will not attach it to your photograph, and will not use it to contact you about anything else without asking you first. That notice has not gone out yet — no email has ever been sent to a waitlist address — and when it does go out it will identify us accurately and carry a one-click unsubscribe link and our postal address.
4. Face data — the section that matters
4.1 What we mean. "Face data" means the photograph of your face that you upload, the images the Service generates from it, and any information derived from either.
4.2 How the law may see it. Depending on the law of the state where you live, face data may be treated as biometric data, biometric information, or sensitive personal information. We handle your face data as if it is, everywhere in the United States, regardless of whether a particular statute applies to us.
4.3 The specific purpose, and the specific term.
- Purpose: we collect and process your face data for one purpose only — to generate the AI images you requested, and to deliver them to you. We do not use it for identification, verification, security, advertising, analytics, model training, research, or any other purpose.
- Term: we do not retain the photograph you upload at all. It exists in memory only for the duration of the single request that generates your images, and is never written to our storage. Free previews are not retained either. The one thing we do keep is the finished high-resolution file you have paid for, and we keep it for up to 30 days, only so that we can deliver it to you. See Section 7.1, which sets out both halves and is precise about how much of the deletion happens automatically today.
4.4 Your consent, and how we ask for it. We collect and process face data only with your informed, affirmative consent, which you give by checking the consent box shown before you upload. That box tells you, in plain language, what we collect, why, who we send it to, and how long we keep it. You are not required to consent — but without consent we cannot make images for you, because the photo is the whole product.
The consent text below is the exact wording shown on screen before you upload. If the two ever differ, this document is the one that governs.
Before you upload. I am 18 years or older and the photo I am uploading is a photo of me. I consent to K Headshot collecting and processing my photograph — which may be treated as biometric information where I live — for the sole purpose of generating the AI images I request, and to K Headshot sending it to its AI processing provider (Google) for that purpose. I understand that K Headshot never stores my photograph — it is held in memory only for as long as it takes to make my images — and stores the images it makes for me only if I pay to download one, in which case that one file is kept for up to 30 days so it can be delivered to me, and I can ask for it to be deleted sooner (privacy@kheadshot.com). K Headshot will never sell my photograph and will never use it to train AI. I can withdraw this consent at any time by not uploading another photo.
4.5 We do not sell it. We do not sell, lease, trade, or otherwise profit from face data. We have never done so and we do not intend to.
4.6 We do not disclose it. We do not disclose, redisclose, or otherwise disseminate face data to anyone, except: (a) to the AI processing provider that generates your image, acting on our instructions only (Section 5); (b) to the infrastructure providers that host the Service, acting on our instructions only (Section 6); (c) where you have specifically told us to; or (d) where a valid warrant, subpoena, or court order requires it.
4.7 We do not identify you. K Headshot does not identify or authenticate the people in the photos you upload, does not match faces against any database, does not create or store a searchable face template or faceprint, and is not developing technology to do any of those things.
4.8 What our AI provider is contractually required not to do. We require our AI processing provider, by contract, not to use face data to train generalized AI models or to build pooled face-training datasets, and to act only on our instructions. See Section 5.
4.9 How we protect it. We store and transmit face data using a reasonable standard of care for our industry, and in a manner at least as protective as the way we handle our own confidential and sensitive information. See Section 8.
4.10 You can withdraw. You can withdraw your consent at any time, and the way you do it is simply to stop uploading — we hold no photograph of yours between requests, so withdrawal takes effect the moment you stop (Section 7.1, Section 9). If you have paid for a download, the file from that purchase is the one thing of yours left on our side: tell us and we will delete it, and in any case it is due for deletion 30 days after it was made. Withdrawing does not make our earlier processing unlawful, and it does not undo images already delivered to you.
4.11 State-specific note. If you live in a state with a specific biometric-privacy law — including Illinois, Texas, and Washington — that law may give you rights in addition to those described elsewhere in this policy. We have built the controls in this Section 4 to meet the substance of those laws: a written notice of what we collect and why, a published retention term and destruction schedule — the photograph you upload is not retained at all, and a file you have paid for is kept for up to 30 days and then destroyed (Section 7.1, which is also honest about which part of that deletion is automatic today) — your affirmative consent before collection, a prohibition on selling or profiting from face data, a prohibition on disclosing it without your consent, and a reasonable standard of care in storing and transmitting it. Whether any particular statute applies to us is a legal question we do not decide in this document. Nothing here is a waiver of your rights or an admission of anything.
5. The AI provider
5.1 Who. Image generation is performed by Google LLC through the Google Gemini API. Your photo and the text instruction built from your style choices are transmitted to Google for processing, and the generated image is returned to us.
5.2 What tier we use, and why it matters. We use Google's paid Gemini API tier. Google's published terms for the paid tier state that Google does not use prompts or responses to improve its products, and Google acts as our data processor under a Data Processing Addendum. Google's free tier does not carry those commitments — content sent through it may be used to improve Google's products and may be reviewed by humans. We do not send your photo through a free tier.
5.3 What Google may do. Google may retain content briefly for abuse monitoring and to comply with law, as described in its own terms. We do not control that retention. Google's terms for the Gemini API are published at ai.google.dev/gemini-api/terms, and Google's privacy policy at policies.google.com/privacy.
5.4 If we change providers, we will update this section and this policy before your data goes anywhere new.
6. Who else touches your information
We share personal information only with service providers who work for us, on our instructions, under contract. We do not sell it and we do not share it for cross-context behavioural advertising.
| Provider | What it does | What it can see |
|---|---|---|
| Google LLC (Gemini API) | Generates the image | Your photo and the text instruction. See Section 5 |
| Stripe, Inc. | Processes payments | Your payment details, email, and purchase amount. We never see your full card number |
| Vercel Inc. | Runs the website and the servers | Traffic and request data, including IP address |
| Cloudflare, Inc. (R2) | Holds the files people have paid to download, and waitlist sign-ups | The finished high-resolution image you bought, for up to 30 days (Section 7.1). It never receives the photograph you uploaded, and never receives a free preview — neither of those is written to storage at all. Where sign-ups are switched on it also holds waitlist sign-ups: one small file per sign-up containing an email address, a random identifier, and a timestamp (Sections 2 and 7.2) |
| Neon, Inc. (managed Postgres) | Runs the database behind purchases and credits | Your checkout email, what you bought and when, your credit balance, and the pointer to the file you bought. It also holds our consent records: for each consent, an opaque session identifier, the consent version, a fingerprint of the consent wording, a salted hash of your IP address, and the time (Section 7.2). No photographs, no generated images, no prompt text, and no IP addresses in the clear — where a record refers to something sensitive, it carries a one-way fingerprint, not the thing itself |
Waitlist sign-ups are collected on our own site. If we ever move that form to one hosted by someone else, we will name that company in this table before we switch it on. The database row above is the one we promised to fill in before the first sale; if we end up using a different database provider, we will change that row before it holds anything of yours.
We keep this list current, and the table in this section is that list — there is no separate page. If we add a provider that touches your personal information, we add a row here before it starts work.
We may also disclose information (a) to comply with law or a valid legal request, (b) to protect our rights, safety, or property or those of others, or (c) to a buyer as part of a merger, acquisition, or sale of assets — in which case face data remains subject to this policy, or we obtain fresh consent.
7. How long we keep things
7.1 Face data. We do not keep your photograph. Not on any lane, and not for a moment longer than the single request that makes your images. There is exactly one piece of face data we do keep — the file you pay to download — and it is written out below in the same size type as everything else, because a retention period a reader has to hunt for is not a published one.
Your photograph: never stored, whatever you do.
Your photo is held in memory only, for the duration of the single request that makes your images. It is not written to a database, a bucket, a disk, or a backup of ours. It goes to the AI provider that renders your image (Section 5), and nowhere else. When the response ends, nothing of it remains on our side.
So for the photograph there is no retention period, because there is nothing retained, and no destruction schedule, because there is nothing to destroy on a schedule. "We store your photo for thirty days and then delete it" would be a weaker promise than the one we are actually making about it, and we are not going to make the weaker one.
Free previews: never stored either.
The free preview — 640 pixels on its longest edge, and with no watermark on it — comes back inside the same HTTP response that carried your photo in. It is not written to storage, and nothing of it survives the response. Someone who only ever uses the free preview leaves nothing behind at all — which is the whole design, not a temporary state of it.
The file you pay for: stored, for up to 30 days.
A high-resolution download has to exist as a file before we can give it to you, and it has to still be there when you click the link. So when you pay for a render, we write that one finished image — not your photograph, not any preview — to our object storage at Cloudflare R2, and we stamp it to be deleted 30 days after it is made. Thirty days is the number our software actually uses, not a number chosen to look good on this page.
Stored beside it, in our database, is the record of the order: the style, the size, when it was made, what it cost, and the pointer to the file. That record contains no photograph and no prompt text — only a one-way fingerprint of the instruction, which cannot be turned back into it.
How far the 30 days goes today, exactly.
Two parts of it are already real. The 30-day mark is written onto the file itself at the moment we store it. And once that mark passes, the file can no longer be downloaded: our system refuses the request, tells you the photo has expired, and takes no credit for the attempt.
The third part is the sweep, and it now exists: a job runs once a day, finds the files whose 30 days are up, and deletes them. It is written to refuse rather than guess — it will only ever delete the three kinds of image file, it leaves anything else in our storage alone, and where our records still say a file is live it keeps the file and skips it. If it cannot read those records, it deletes nothing at all and waits for the next day.
Two honest qualifications. It runs daily, so a file goes in the day after its 30 days end rather than on the stroke of the hour. And a delete that fails is left for the following run instead of being retried immediately. If you want your file gone sooner, or gone for certain, email privacy@kheadshot.com and we will delete it by hand (Section 9).
This is a statement about our systems, not about our AI provider's. Google may hold content briefly for abuse monitoring and legal compliance under its own terms — Section 5.3 — and we do not control that.
If we ever store face data for longer than this, or store something we do not store today, we will publish what it is and how long it lives in this section before that feature is turned on, and we will not apply it retroactively to any photograph given to us under this version of the policy.
7.2 Everything else.
Two rows in this table describe things that are brand new. Credits, purchases, and paid files did not exist before this version of the policy: nothing of that kind was collected before it, and those periods start running from a customer's first purchase, not before. The rows that have been describing live behaviour for longer are generation logs, rate-limit counters, support messages, and — with an important qualification in its own row — the waitlist email. Consent records changed on September 2, 2026: what used to be a fragile line in a server log is now a durable database record, and the row below describes the record, not the line.
| What | How long | Why |
|---|---|---|
| Purchase and tax records | In use from your first purchase. 7 years from the date of that purchase. It runs longer only where a tax rule, an audit, or a legal hold requires it (Section 7.3), and where that happens we keep only the records the requirement reaches, for only as long as it lasts. One honest qualification: nothing in our systems erases a purchase record when its 7 years are up, so read 7 years as the period we hold them for and the point after which they are due for deletion, not as something that happens by itself. These records carry no photograph and no prompt text — Section 7.1 | Tax, accounting, and anti-fraud recordkeeping |
| The file you paid to download | In use from your first purchase. Up to 30 days, then due for deletion — Section 7.1 says exactly how automatic that is today | So that we can deliver the file you bought |
| Waitlist email | In use — and this promise is weaker than it sounds. Read the paragraph below it. Marked for deletion two years after you sign up. Nothing in our systems carries that deletion out yet, so treat two years as the longest we intend to hold it, not as something that happens by itself | To send you the single notice you asked for when credits open |
| Generation logs (no photo, no prompt text) | In use. 12 months | Debugging, cost control, and abuse investigation |
| Rate-limit counters (IP-based) | In use. Same day only, in memory | Rate limiting. Not written to disk |
| Support messages | In use. 24 months | To handle follow-ups and disputes |
| Consent records | In use. One row per consent, written to our database the moment you tick the box — the next paragraph says exactly what is in it. Kept for as long as we may need to prove that consent was asked for and given; we have not set an automatic deletion date, and the table is deliberately built so rows can be added and read but never edited or deleted | To prove that we asked before collecting, and exactly which words were on screen when you agreed |
On consent records, precisely. The consent text you agree to is consent version 5, and the exact wording appears in section 4.4 above. When you tick the consent box we write one row to our database, and that row contains exactly five things: an opaque session identifier, the consent version, a fingerprint (SHA-256 hash) of the exact words you agreed to, a salted hash of your IP address, and the time. Never your photograph, never the consent text itself, and never your IP address in the clear — and that is not a practice we ask you to trust, it is how the table is built: the database refuses any row that carries readable consent text or a readable IP address where a fingerprint belongs, and refuses any attempt to edit or delete a row once it is written. Rows can be added and read. Nothing else. We keep these records because a consent we could not prove we asked for would be little better than one we never asked for: the record exists to show that we asked, which words were on screen, and when. We have not set an automatic deletion date for them — a record that proves consent has to outlive any argument about that consent — so we do not promise one here. One honest limit: sessions are anonymous by design, so if you ask us to produce your record and your session identifier is gone, we may have no way to tell which row is yours. That is a consequence of our not identifying you, not a loophole. A copy of the same fields also appears briefly in our ordinary server logs, which our host rotates on its own schedule — the database row, not the log line, is the record.
On the waitlist email, precisely. If you join the waitlist, your address ends up in two places. First, one line in our server log, written the moment it arrives and before we try to save it, so that an address is not lost if the save fails. That line contains your address in readable form, and it lives for as long as our hosting provider keeps its logs — a period we do not set, cannot query, and will not overstate. Second, one small file in our object storage, holding your address, a randomly generated identifier, and the moment you signed up. That file is stamped with a marker saying it may be deleted two years after sign-up.
Here is the part most policies would leave out. We have written that two-year mark onto the file, but we have not yet built the scheduled job that reads those marks and deletes what has expired. So "two years" is the limit we have set for ourselves and the point after which the file is fair game for deletion — it is not an automatic erasure that happens on its own today, and we are not going to describe it as one. When the deletion job exists, this paragraph will say so plainly, and not before.
What is not in either copy: no photograph, no session identifier, no detail of anything you generated, and no IP address. Your IP is checked against a rate limit held in memory and is never written down beside your address — an address and a face must never meet on one line of a log whose retention we do not control. And where sign-ups are not switched on, nothing is kept at all: the form refuses and tells you so, instead of accepting an address it would quietly drop.
Getting off the list. Email privacy@kheadshot.com and we will delete your address from the waitlist. The single notice we send, when it goes out, will also carry a one-click unsubscribe link.
7.3 We may keep information longer where a law, a tax rule, or a legal hold requires it. If we do, we keep only what is required, and only for as long as required.
8. Security
8.1 We use reasonable technical and organisational measures appropriate to the sensitivity of face data, including transport encryption (HTTPS/TLS) for everything sent between your browser, our servers, and our providers, access restricted to the people who need it, and security headers on our web responses. The one face-derived file we store — the download you paid for (Section 7.1) — has no public address: the only way to fetch it is through a link we sign for you, and that link expires within minutes.
8.2 We handle face data with at least the same care as our own confidential and sensitive business information.
8.3 No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. If a breach affects your personal information, we will notify you and any regulator as required by the law of your state.
8.4 We do not currently hold a SOC 2 or ISO 27001 certification, and we do not claim one.
9. Deleting your data and withdrawing consent
9.0 Read this before the rest of the section. For your photograph, you do not need to send us a request and you do not need to wait for us to act. We do not keep it (Section 7.1), so withdrawal is immediate and self-executing: stop uploading, and your photo is not on our side to begin with. The request machinery below is for everything else — the other categories in Section 7.2, and the file you paid to download, which is the one piece of face data we hold and the one thing a deletion request can usefully reach.
9.1 You can withdraw your consent at any time, for any reason, and at no cost. Withdrawing consent to face-data processing requires nothing of you but to stop.
9.2 How. Email privacy@kheadshot.com and tell us what you would like us to do. If your request is about something we hold under a particular email address — a waitlist sign-up, or a purchase — write to us from that address, or tell us what it is, so we can find it.
9.3 When. We will act within forty-five (45) days of your request and confirm to you in writing when it is done — and because the list of what we actually hold is short (Section 9.4), it is usually much sooner than that. Where the law allows, we may extend once by another 45 days, and if we ever need to, we will tell you why before the first 45 days are up. This is the same clock as Section 11.6, on purpose: one promise, not two.
9.4 What happens. Your photo is not part of this, because we never stored it in the first place (Section 7.1). What we can and do erase on request is anything we actually hold that is connected to you: the file from a paid download, if it is still inside its 30 days; a waitlist email address if you gave us one; and a support message you sent us. Each is erased or anonymised unless Section 7.2 requires us to keep it. Images you already downloaded stay on your own device — we cannot reach those. Purchase and tax records are kept as Section 7.2 requires, because the law requires them; they do not contain your photo. One more thing stays: the consent record from Section 7.2. It is the evidence that we asked before collecting — a session identifier, a version, two fingerprints, and a time, with no photograph and no readable IP address in it — and our database is built to refuse its deletion. Keeping the proof that you consented is not the same as keeping what you consented to give us.
9.5 What you lose. Withdrawing consent means we can no longer generate images for you. Unused credits are not forfeited by a deletion request — see the Refund and Credits Policy.
10. Children
10.1 The Service is for adults. You must be 18 or older to use it, and every person shown in any uploaded photo must be 18 or older.
10.2 We do not knowingly collect, keep, or use personal information from anyone under 18, and no part of the Service is directed to children.
10.3 We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under 13. Under the California Consumer Privacy Act, if we determine a user is under 16, we treat their personal information as Sensitive Personal Information with heightened protection. We do not sell or share the personal information of anyone under 16 — and in fact we do not sell or share anyone's.
10.4 If you believe a child has given us personal information, or that a photo of a minor has been uploaded, email abuse@kheadshot.com immediately. In every case we restrict access to the material and suspend the account responsible straight away. Where a report involves apparent child sexual abuse material, U.S. federal law (18 U.S.C. Section 2258A) requires us to report it to the CyberTipline operated by the National Center for Missing & Exploited Children and to preserve the reported material for the period the law specifies, rather than delete it immediately — we do both, as the law requires, instead of promising you a deletion the law would not let us keep. For a report that does not involve apparent child sexual abuse material, we delete the material and take action on the account responsible.
10.5 We do not run automated age estimation, and we do not analyse faces to guess anyone's age. Doing so would require processing more biometric information about more people, which is the opposite of what this policy is for. Our controls are the contractual ban in the Terms, the confirmation you give before uploading, and the reporting channel above.
11. Your rights
11.1 Rights everyone gets from us. Regardless of where you live in the United States, you can ask us to:
- tell you what personal information we hold about you;
- give you a copy of it;
- correct anything that is wrong;
- delete it (Section 9); and
- withdraw your consent to face-data processing (Section 9).
We will not treat you differently, charge you more, or give you a worse service for exercising any of these.
11.2 California (CCPA/CPRA). If you are a California resident, you also have the right to know the categories of personal information we collect, the purposes, and the categories of third parties we disclose to (all in Sections 2, 3, and 6); the right to opt out of sale or sharing for cross-context behavioural advertising (we do neither, so there is nothing to opt out of); the right to limit our use of Sensitive Personal Information (we already limit face data to the single purpose in Section 4.3); and the right to appeal a decision on your request.
11.3 Other states. If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, or another state with a comprehensive privacy law, you have similar rights — including access, correction, deletion, portability, opting out of targeted advertising, profiling, and sale (we do none of those), and the right to appeal.
11.4 How to exercise a right. Email privacy@kheadshot.com. Tell us what you want and which email address or order you are asking about.
11.5 Verification. We will take reasonable steps to confirm it is really you before we act, usually by replying to the email address the request came from and asking you to confirm details only you would know, such as the date and amount of a purchase. We will not ask you for a photo of your ID or a selfie to verify a request — that would mean collecting more sensitive information to protect your sensitive information.
11.6 Timing. We respond within 45 days, and may extend once by another 45 days where the law allows, telling you why.
11.7 Appeals. If we refuse, we will tell you why and how to appeal. Send appeals to privacy@kheadshot.com with "Appeal" in the subject. We respond to appeals within 45 days. If we deny your appeal, you may contact your state Attorney General.
11.8 Authorized agents. You may use an authorized agent, with written proof of authority. We may still contact you directly to confirm.
12. Washington and Nevada — consumer health data
12.1 If you live in Washington or Nevada, your state's consumer health data law may treat biometric data as consumer health data. Whether any such law applies to us is a legal question this policy does not decide, and nothing in this section is an admission that it does.
12.2 We collect one thing that could fall in that category: the photograph of your face and the images generated from it. We collect it only with your consent, only to generate the images you requested, and we keep it only for the periods in Section 7.1 — which is to say, we do not keep the photograph at all, and we keep a file you have paid for for up to 30 days so that we can deliver it.
12.3 We do not sell consumer health data. We have never sold it and we do not intend to. If that ever changed, we would first obtain a separate, signed authorization from you as the law requires — a checkbox would not be enough.
12.4 We share it only with the processors listed in Section 6, who act on our instructions and may not use it for their own purposes.
12.5 You can ask us to confirm what we hold, to delete it, and to withdraw your consent, using Section 9. You may appeal a refusal under Section 11.7.
13. Cookies and tracking
13.1 As of the effective date of this policy, the Service uses no advertising cookies, no third-party analytics, no tracking pixels, and no cross-site trackers. We do not fingerprint your device.
13.2 We use only what is strictly necessary to make the site work and to keep it secure. Today that means one cookie of ours, and two small notes your own browser keeps for you:
kh_sid, a session cookie. Set the first time you generate an image or start a checkout — you do not need an account and there is nothing to sign in to. It carries a random identifier and a signature, and nothing about you: no name, no email address, no photograph. We use it to count your free previews, to apply limits fairly, and to connect a purchase to the previews made in the same session. It is HttpOnly, SameSite=Lax, sent only over HTTPS, and expires after 30 days.- Two values kept in your browser's own local storage. One remembers that you ticked the consent box, and which version of it; the other remembers that you already joined the waitlist, so the page does not ask you twice. These stay on your device, are not transmitted to us, and clearing your browser data removes both.
13.3 If we ever add analytics, we will update this section before turning it on, and we will not send face data to any analytics provider.
13.4 We honour Global Privacy Control signals as an opt-out of sale and sharing. Since we do neither, the signal changes nothing about how we handle your data — we say it here so you know we are not ignoring it.
14. Automated decisions
We do not use your personal information to make automated decisions that produce legal or similarly significant effects about you. The AI generates a picture. It does not decide anything about you.
15. Changes to this policy
15.1 We may update this policy. The "Last updated" date at the top will change and the new version will be posted here.
15.2 If we make a material change to how we handle face data, we will notify you and ask for your consent again before applying it to data we already hold. A change to this document alone will never expand what we may do with a photo you already gave us.
16. Contact us
| Legal entity | Epikohub LLC (a California limited liability company) |
| Business address | 12100 Wilshire Blvd, 8th Floor, Los Angeles, CA 90025 |
| Privacy and data requests | privacy@kheadshot.com |
| Abuse, minors, and likeness reports | abuse@kheadshot.com |
| General support | support@kheadshot.com |
If you are not satisfied with our response, you may contact your state Attorney General.
We wrote this because almost nobody in this category does. If any part of it is unclear, email us and we will explain it — and if the explanation is better than the text, we will change the text.