Privacy Policy
This policy explains how PortraitDesk processes personal data when you visit the website, sign in, generate an image, buy credits, or contact us.
1. Controller
DI Lukas Steinbrecher
Goldschlagstraße 82/28
1150 Vienna, Austria
Email: support@portraitdesk.app
No data protection officer has been appointed. You can send privacy requests to the email address above.
2. Who may use PortraitDesk
PortraitDesk is intended only for people aged 18 or older. You may upload your own portrait or an image for which you have verifiable permission to use and process.
3. Website delivery, hosting, and security
Cloudflare delivers and operates the website. It processes request data such as your IP address, requested URL, date and time, browser and device information, error details, and security events. We use this data to deliver the service, diagnose errors, secure the application, and prevent abuse. The legal basis is our legitimate interest in providing a stable and secure service under Article 6(1)(f) GDPR.
The production Cloudflare D1 database is restricted to the EU jurisdiction. D1 database instances and replicas run and store data inside the European Union. Other Cloudflare services may process data outside the EU and EEA under Cloudflare's Data Processing Addendum and applicable transfer safeguards.
Cloudflare Workers logs and traces are retained for no longer than seven days. Aggregated Worker metrics are retained for no longer than three months. We do not forward logs or traces to another logging provider.
4. Account and Google sign-in
When you sign in with Google, we receive your Google account ID, name, email address, email verification status, and profile image. We also process the identity provider, access and identity tokens, session token, session dates, IP address, and user agent. Google provides this data after you approve the sign-in request. Google and PortraitDesk each act as a separate controller for their respective processing.
We use the data to create and manage your account, authenticate you, protect your session, assign credits, and provide the service. The legal basis is performance of the contract and steps taken at your request before entering into a contract under Article 6(1)(b) GDPR. Security records are also processed under Article 6(1)(f) GDPR.
Sessions expire after seven days. OAuth state data used to protect the sign-in flow expires after ten minutes. Account data is stored until you request account deletion.
5. Image generation
To generate an image, we process your uploaded portrait, the PortraitDesk reference image you select, generation instructions, the generated image, job identifiers, status information, and technical error data. Providing the required image is necessary to generate the requested result. Without it, we cannot provide image generation. The legal basis is Article 6(1)(b) GDPR.
Depending on the selected model, we send this data to one of the following processors:
- FASHN LTD, United Kingdom
- Recraft, Inc., United States
- Replicate, LLC, United States
The provider used for a generation is shown when more than one provider is available. Providers may process images only to deliver and secure the requested service and to perform necessary content and abuse checks. PortraitDesk images are not used to train or improve their models or products.
Uploaded and generated images are deleted no later than 30 days after upload or generation. The usual periods are shorter: FASHN schedules standard API output deletion after three days, Replicate removes API prediction inputs, outputs, files, and logs after one hour by default, and PortraitDesk currently makes generated images available for about 24 hours.
Generation metadata, including the user ID, model, provider job ID, status, output URL, expiry time, error code, timestamps, and credits used, is deleted 90 days after the generation completes or fails.
PortraitDesk changes images to provide the service. It does not use portraits to identify or authenticate people or compare faces against a person database.
6. Payments
Stripe processes payments. We send Stripe your email address, internal user ID, the selected product, amount, currency, and checkout metadata. Stripe also processes payment method, device, fraud prevention, and transaction data. Stripe acts as our processor for some activities and as a separate controller for regulated payment, fraud prevention, and compliance activities.
The legal bases are performance of the contract under Article 6(1)(b) GDPR and compliance with accounting and tax obligations under Article 6(1)(c) GDPR. Accounting records are retained for seven years from the end of the calendar year to which they relate, and longer while a court or authority proceeding remains pending.
7. Cookies
PortraitDesk does not set tracking, analytics, or advertising cookies. It uses only cookies required for Google sign-in, session management, and security. These cookies are HttpOnly, use SameSite=Lax, apply to the path /, and are sent over HTTPS with the Secure attribute.
__Secure-better-auth.session_token: identifies the authenticated session; expires after seven days.__Secure-better-auth.state: protects the Google OAuth flow; expires after five minutes.
These cookies are strictly necessary to provide the service you request and do not require consent under Section 165(3) of the Austrian Telecommunications Act 2021. Google and Stripe may set their own cookies on their websites when you choose to visit or use their services. Their policies govern those cookies.
8. Support and privacy requests
When you contact us, we process your contact details, message, related evidence, and handling notes to answer your request and document compliance. The legal bases are Article 6(1)(c) GDPR for privacy requests and Article 6(1)(f) GDPR for support and the defence of legal claims. Records are deleted three years after the request closes, unless they are needed for a pending proceeding.
9. Recipients and international transfers
Recipients include Cloudflare, Google, Stripe, and the image provider used for your generation. We may also disclose data to professional advisers and public authorities where required by law or necessary to establish, exercise, or defend legal claims.
Some recipients and their subprocessors are located outside the EU and EEA. Transfers are protected, as applicable, by an adequacy decision, participation in the EU-U.S. Data Privacy Framework, or the European Commission's Standard Contractual Clauses. You may request information about the safeguard used for a transfer and a copy of the relevant clauses at support@portraitdesk.app.
10. Your rights
Subject to the legal requirements, you have the right to access, correct, erase, or restrict the processing of your personal data, object to processing based on legitimate interests, and receive data you provided in a structured, commonly used, machine-readable format. Where processing is based on consent, you may withdraw it at any time for the future. Withdrawal does not affect processing that took place before withdrawal.
Send requests to support@portraitdesk.app. When you request account deletion, sessions and Google tokens are deleted without delay. The account and generation metadata are deleted within 30 days. Payment records required by law remain restricted until their retention period ends.
You may lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, Austria, email dsb@dsb.gv.at. You may also contact another competent supervisory authority in the EU or EEA.
11. Automated decisions
PortraitDesk does not make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. Image generation is a service you request, not a decision about you under Article 22 GDPR.
12. Changes to this policy
We update this policy when our processing changes. If we intend to use personal data for a new purpose, we will provide the required information before that processing begins.
Last updated: August 29, 2026
