Headshot Generator - Privacy
Privacy Policy
Last updated: 4 August 2026
This Privacy Policy explains how Furkan Kaya ("we", "us", "our") collects, uses, shares and retains information when you use the Headshot mobile application for iOS (the "App"). It is written to be read in full - there is nothing important hidden further down.
In short: the App works without an account, we do not sell your personal data, we do not use your photos or your face to train AI models, and we do not track you across other companies' apps or websites.
1. Who we are and how to reach us
The App is developed and operated by Furkan Kaya, an independent developer established in the Republic of Turkiye, acting as the data controller for the processing described here.
You can reach us about any privacy matter at support@furkankaya.com.tr. We answer data-protection requests within 30 days.
2. Summary of what we process
- Photographs you choose, including the face they contain - to generate the result you asked for.
- Purchase and subscription status - to unlock and restore the features you paid for.
- An anonymous installation identifier, app version, OS version, device model and language - to keep entitlements in sync, enforce fair use and diagnose faults.
- Anonymous in-app events, such as which screen opened - to improve the App.
- Preferences and your generated gallery - stored only on your device.
We never ask for your name, email address, postal address, phone number or date of birth. We do not access your contacts, precise location, health data, calendar, microphone or your wider photo library - the system photo picker hands us only the single image you select.
3. Face data
Because the App works with portraits, this section sets out exactly how face data is handled. It is the controlling section for anything face-related in this policy.
- What we collect. Two things. First, an on-device face detection signal: before a photo is sent anywhere, Apple's Vision framework checks locally whether the image contains a face and how large it is in the frame, so we can warn you if the photo will not produce a good result. This check produces only a yes/no answer and a size measurement, and it never leaves your iPhone. Second, the photograph itself, which of course contains your facial image, is transmitted for AI generation as described below.
- What we do NOT collect. We do not create, derive, store or compare faceprints, face templates, face embeddings, face geometry maps or any other biometric identifier. We cannot and do not use face data to recognise, identify, authenticate, verify or match a person, nor to infer age, ethnicity, emotion, health or any other characteristic. There is no face database, and no face is ever matched against another.
- All planned uses. The facial image in your photograph is used for exactly one purpose: producing the stylised portrait, outfit change or edit that you explicitly requested in that session. It is used for no other purpose - not advertising, not profiling, not analytics, not model training, not research, not product improvement.
- Who it is shared with, and where it is stored. The photograph is transmitted over TLS to our own processing service, which runs on dedicated servers we control at a European hosting provider. That service passes the image to the Google Gemini API (Google Ireland Limited / Google LLC), which performs the generation and returns the result. No other party receives it. It is never sold, licensed, published, or disclosed to advertisers, data brokers or any third party for their own purposes.
- How long it is retained. The photograph you send is not written to permanent storage at any point: it exists only in memory for the seconds the request takes, and is discarded as soon as the result is produced. The generated result is held, encrypted, for a maximum of 24 hours so that it can be delivered to your device or re-sent if the connection failed, and is then deleted automatically. Google retains API inputs and outputs only as permitted by the paid Gemini API terms, under which submitted content is not used to train Google's models. Nothing about the face persists on our systems after that 24-hour window.
- Your control. Face data is only ever processed after you give explicit, separate in-app consent, which is requested before the very first photo leaves your device and can be withdrawn at any time under Profile > Settings > AI photo processing. Withdrawing consent stops all future transmission immediately; the on-device tools keep working.
4. How your photos are handled, step by step
On-device only. Face detection and every editing tool in the App - background removal, portrait blur, auto enhance, manual adjustments and filters - run entirely on your iPhone using Apple frameworks. Photos used with those features are never uploaded, and they work in flight mode.
Sent for AI generation. AI headshot generation and the AI outfit change need more computing power than a phone provides. For these two features only, and only after you have consented, the selected photo (resized and JPEG-compressed) is sent over an encrypted TLS connection to our processing service, which relays it to the Google Gemini API together with a fixed instruction describing wardrobe, background and lighting. The instruction is defined by us on the server; it is never composed from free text you type.
Coming back. The generated image is returned to your device and saved into the App's own storage. Your gallery lives on your iPhone. Deleting an image in the App, or deleting the App, removes it permanently - we hold no copy to restore.
Not linked to you. Requests carry only a random installation identifier, never a name or email, so the images cannot be tied to your identity by us or by our providers.
5. Service providers and international transfers
We share data only with the following providers, each acting on our behalf under a data-processing agreement, and each required to protect your data to at least the standard described in this policy:
- Apple Inc. - processes your payment, manages your subscription and provides the App Store. We receive only the subscription status, never your payment details.
- Adapty Tech Inc. - subscription infrastructure. Stores an anonymous profile identifier and your purchase history so that a subscription can be restored on any device signed in with your Apple ID.
- Google Ireland Limited / Google LLC (Gemini API) - performs AI image generation on the photo you submit. We use the paid Gemini API tier, under which submitted content is not used to train Google's models.
- Our own processing service, operated by us on dedicated servers at a European hosting provider, which authenticates the request and relays it to the model provider.
We do not share your data with advertising networks, analytics brokers, data brokers or social networks. Where a provider processes data outside your country, the transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.
6. We do not track you
The App contains no advertising SDK, no attribution SDK and no social-media SDK. We do not collect the Advertising Identifier (IDFA), we do not link any data collected in the App with third-party data for advertising purposes, and we do not share data with data brokers.
Because none of that happens, the App does not need to - and does not - present the App Tracking Transparency prompt. Our App Store privacy labels declare that no data is used to track you.
7. Why we may process your data (legal bases)
- To produce the result you asked for - performance of a contract (Art. 6(1)(b) GDPR).
- To process the facial image contained in your photo - your explicit consent (Art. 9(2)(a) GDPR), obtained in-app before the first transmission and withdrawable at any time.
- To manage subscriptions, entitlements and restores - performance of a contract.
- To secure our processing service and prevent abuse and fraud - our legitimate interests (Art. 6(1)(f) GDPR).
- To send you a notification when your result is ready - your consent, withdrawable in iOS Settings.
- To meet accounting, tax and other legal obligations - legal obligation (Art. 6(1)(c) GDPR).
8. Retention periods
- Photographs you submit: never written to storage; discarded from memory as soon as the result is produced.
- Generated results on our side: encrypted, maximum 24 hours, then deleted automatically.
- Generated results on your side: kept in the App until you delete them or delete the App.
- Subscription records: for the life of the subscription, then for as long as tax and accounting law requires.
- Anonymous diagnostic and usage data: no longer than 24 months.
9. Your rights and how to exercise them
Depending on where you live, you have the right to access your personal data, to have it corrected or deleted, to receive a copy in a portable format, to restrict or object to processing, to withdraw consent at any time without affecting processing already carried out, and to lodge a complaint with your supervisory authority. Residents of Turkiye have equivalent rights under Art. 11 KVKK; residents of California have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
You can act on the two most important ones yourself, immediately and inside the App: withdraw consent for AI photo processing under Profile > Settings > AI photo processing, and delete every generated image from your gallery.
For anything else, email support@furkankaya.com.tr from the device you use with the App. Because the App is anonymous, we may ask you for the Adapty profile identifier or an Apple transaction identifier so that we can locate the only records that exist.
10. Children
The App is not directed to children under 13, or under the higher minimum age that applies in your country, and we do not knowingly process their data. Uploading a photograph of someone else without their permission is prohibited by our Terms of Use. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Security
All network traffic is encrypted with TLS. Every request to our processing service is verified with Apple App Attest, so only genuine, unmodified installations of the App can reach it. Stored data on our side is encrypted at rest, and access is limited to the people who need it to operate the service.
No method of transmission or storage is perfectly secure, but we apply technical and organisational measures appropriate to the sensitivity of the data, and we will notify affected users and the competent authority of a personal-data breach where the law requires it.
12. Changes to this policy
We may update this policy as the App evolves. The "last updated" date above always reflects the version in force. If a change materially affects how we handle your photos or your face data, we will tell you in the App and, where the law requires it, ask for your consent again before the change takes effect.
13. Contact
Furkan Kaya
Email: furkan18688@gmail.com
Yorumlar
Yorum Gönder