Privacy Policy

PBH — professional headshots. Last updated: July 19, 2026.

The short version

Your photos are used once to generate your headshot and are never stored on our servers. We have no accounts, no ads, and no tracking.

Who we are

PBH is operated by Filip Kilter (Norway) ("we", "us"). We are the data controller for the processing described here. Contact: filip.kilter@icloud.com.

Photos and face data

When you generate a headshot, the selfie you choose is sent over an encrypted connection to our server, forwarded to an AI image-generation provider to produce your portrait, and discarded. Specifically:

— We do not store your photos on our servers. They are processed in memory for the duration of one generation request and are not written to storage by us.
— We do not create, store, or use facial recognition templates, face geometry, or any biometric identifiers. Your photo is used only as the visual reference for generating the portrait you requested.
— We do not use your photos to train any model.
— The generated headshot is returned to your device and saved only there. Deleting the app deletes your generated photos.

You choose which photo to submit; submitting a photo is the instruction to process it for that one generation.

What else we process

To operate the service we process: an anonymous install identifier (a random ID created on first launch, not linked to your name, email, or Apple ID), a device attestation token from Apple's App Attest service (to prevent abuse and fraud), a weekly count of generations tied to the anonymous ID (to enforce usage limits), and your subscription status via RevenueCat and Apple. We do not collect names, email addresses, contacts, or location, and we run no advertising or cross-app tracking.

Legal bases (EEA/UK)

Where the GDPR applies, we process your photo and generate your portrait to perform our contract with you (Art. 6(1)(b)); we process the anonymous identifier, attestation tokens, and usage counts for our legitimate interests in preventing abuse and operating the service securely (Art. 6(1)(f)); and we process subscription state to perform the contract and meet legal obligations.

Service providers

We share data only with the processors needed to run the service, each bound by their own data-processing terms:

Cloudflare (infrastructure hosting; processes requests, including your photo transiently, and stores the anonymous usage counters).
OpenRouter and the underlying image-model provider (receive the submitted photo transiently to generate your portrait; not used for training).
RevenueCat (subscription management; receives the anonymous install identifier and purchase receipts — see RevenueCat's privacy policy).
Apple (payment processing and App Attest device attestation, under Apple's own terms).

We do not sell or rent any data, and we do not share data with advertisers or data brokers.

International transfers

Our providers process data in the United States and other countries. Where data leaves the EEA/UK, the transfer is protected by our providers' standard contractual clauses or equivalent safeguards. Photo data leaves our processing pipeline as soon as your generation completes.

Data retention

Photos: not retained. Anonymous generation counts: kept for weekly quota accounting. Subscription records: kept while your subscription is active and as required for accounting. Standard server logs: retained briefly for security and debugging and contain no photo data.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your data and to object to processing. Because we hold no personal data about you beyond an anonymous ID, there is normally nothing to export or correct. If you want the anonymous usage record deleted, contact us with your install ID (shown in the app under Profile) and we will remove it. If you are in the EEA/UK you may also lodge a complaint with your local data protection authority (in Norway, Datatilsynet).

Children

PBH is not directed at children and is intended for users 13 or older (or the higher minimum age of your country). We do not knowingly process photos of children; if you believe a child has used the service, contact us and we will delete the associated usage record.

Security

All traffic is encrypted in transit (TLS). Access to generation requires a device attestation issued by Apple, which prevents scripted abuse of the service. No system is perfectly secure, but our design minimizes what could ever be exposed: we simply do not keep your photos.

Changes to this policy

If we change this policy, we will update this page and the date above. Material changes that affect how photos are handled will be shown in the app before they apply to you.

Contact

filip.kilter@icloud.com