Legal
Last updated 19 September 2026
This policy explains what WeddingPicture AI collects, why, who we share it with, and how long we keep it. We are the data controller for the information described here. Contact us at weddingpictureai@protonmail.com.
The short version
The photograph you upload for the demo is sent to our AI provider to generate your picture and is never stored on our servers. We keep the description you typed, the resulting picture, your device identifier and a hash of your IP address, so we can enforce the one-try limit.
Paddle handles the payment. We receive a transaction id, what you bought, the amount and currency. We never see or store your card number or billing address.
| Google (Gemini API) | Your photograph and every guest description, in order to screen the description and generate the picture. |
| Vercel | Hosting, and the blob storage that holds your pictures. |
| Neon | The database holding your account and wedding records. |
| Paddle | Payment processing. Paddle is the merchant of record and is a separate controller for the payment data you give them. |
| Resend | Sending verification, password reset and purchase emails. |
These providers process data on our instructions under data processing agreements, except Paddle, which acts as its own controller for payments. Some are outside the EEA; transfers rely on Standard Contractual Clauses or an adequacy decision.
We do not sell your data, and we do not use it for advertising. We run no third-party analytics or advertising trackers.
Generating a picture requires sending your photograph and the guest's description to Google's Gemini API. Google processes this to return the image. Under Google's terms for the paid Gemini API, this data is not used to train their models. We have no separate agreement allowing anyone to train on your photographs, and we do not do so ourselves.
We do not perform facial recognition, build face templates, or attempt to identify anyone from a photograph. The AI is used to redraw a likeness, not to recognise a person. We never match faces across accounts or against any external database.
We use two, both strictly necessary, and neither used for advertising or analytics:
Because both are strictly necessary for a service you asked for, no consent banner is required.
If you are in the EU, EEA or UK you have the right to access, correct, delete, restrict or object to our processing of your data, and to receive a copy in a portable format. Email weddingpictureai@protonmail.com and we will respond within 30 days. You can also complain to your national data protection authority.
Guests who want a picture of themselves removed can ask the couple, or email us directly.
The service is not for anyone under 18. We do not knowingly collect data from children, and we automatically refuse photographs that appear to show a minor. If you believe a child's data has reached us, email weddingpictureai@protonmail.com and we will delete it.
Data is encrypted in transit. Passwords are hashed with bcrypt. Access to production data is limited to what is needed to operate the service. No system is perfectly secure, but if a breach affects your data we will tell you and the relevant authority as the law requires.
We will update this page when our practices change, and email account holders about anything material. See our Terms of Service for the rest of the agreement.
weddingpictureai@protonmail.com