Privacy Policy

Last Updated: 8/2/2026

At Rembrandt AI, we take your privacy and the security of your biometric data extremely seriously. This Privacy Policy explains how we collect, use, and protect your information, with a specific focus on our AI generation pipeline. We are fully committed to compliance with global data protection laws, including the GDPR (Europe), CCPA (California), and BIPA (Illinois).

1. Collection of Biometric Data

When you upload photographs to our service, you are providing us with access to your facial geometry. Under various privacy frameworks, this is classified as sensitive biometric data. We only collect this data after you have provided explicit, opt-in consent during the registration or upload process.

2. Zero-Training Guarantee

We operate under a strict "Process-Only" architecture. Your uploaded photographs and facial data are used exclusively to generate the specific AI portraits you requested using the Nano Banana framework via Google APIs. We will NEVER use your photographs, biometric data, or generated images to train, fine-tune, or improve our AI models, nor will we sell this data to third parties.

3. Strict Data Retention & Automatic Deletion (7-Day Policy)

To minimize security risks and ensure your privacy, we implement a strict, automated data destruction policy:

  • Original Uploads: All selfies and photographs you upload are permanently and automatically deleted from our servers and cloud storage 7 days after they are uploaded.
  • Generated Portraits: Your final AI-generated portraits are kept in your account for your convenience. However, you maintain the right to delete them permanently from your dashboard at any time.

4. User Rights (GDPR & CCPA)

Depending on your jurisdiction, you have the right to access, correct, or request the complete erasure of your personal data ("Right to be Forgotten"). To exercise these rights, please contact our Data Protection Officer at rembrandt.lens@gmail.com. Upon request, we will permanently delete your account and all associated biometric data within 30 days.