Allow Google Analytics to receive limited product interaction events so we can understand and improve the service. Photos, prompts, account details and payment identifiers are never included in our custom events.
How FamilyPortrait AI handles account, reference photo, generated image, payment, and diagnostic data
August 30, 2026
Privacy Policy
Last updated: 30 August 2026
This Privacy Policy explains how FamilyPortrait AI processes personal information when you use our website and AI family portrait service (the “Services”). It should be read with our Terms of Service.
Depending on how you use the Services, we may process:
We do not ask for your date of birth and do not use AI to infer your real age. Issue reports do not include a copy of your reference photos or your full prompt by default.
We use this information to:
Where regional consent is required and you accept, or where Analytics loads normally without a notice, we use limited product interaction events to understand the service funnel, technical outcomes, result use, purchase completion, and aggregate 7/30-day repeat use. Analytics is never the authoritative source for authentication, Credits, payment, generation, deletion, security, or recovery decisions.
FamilyPortrait AI uses the paid Google Gemini Developer API to create images. The deployed integration sends the business prompt and reference images needed for the requested generation with store: false.
The current product path does not use Google Grounding or the Gemini File API. store: false is a request configuration, not a promise that no provider security, abuse-prevention, billing, or legally required records can ever exist. Provider handling remains subject to the applicable paid-service terms and deployed configuration.
Each completed AI-generated image has no visible FamilyPortrait AI brand watermark and includes Google’s invisible SynthID. SynthID is provenance information; it does not make an output accurate or suitable as evidence.
Google Analytics 4 (GA4) is the Analytics provider. In the EEA, United Kingdom, and Switzerland, the GA4 tag loads only after you select Accept; selecting Reject prevents it from loading. In other countries, GA4 loads normally without a banner. Rejecting does not prevent login, purchase, generation, download, deletion, or other core functions.
Our custom Analytics events use only allowlisted product states, fixed categories, counts, price and currency for the three Credit packs, and duration or session-gap buckets. We do not include reference or result images, prompts or instructions, filenames or MIME types, names, email addresses, account or OAuth identifiers, generation/image/payment/provider identifiers, hashes, object paths, URLs, free text, raw errors, tokens, or secrets, and we do not set a GA4 user_id.
“Limited” or “anonymous” custom events do not mean that Google receives no technical data. When GA4 loads, Google may process standard browser, device, network, page URL/referrer, Cookie, and similar service data under its terms. We disable Google advertising signals and do not enable Microsoft Clarity, Google Ads, advertising or targeting cookies, or cross-product identity stitching in this product scope.
The product keeps the consent preference and limited first-party deduplication/return-use state needed to honour your choice and avoid duplicate custom events. GA4 data is retained according to the configured Google Analytics property settings and applicable Google terms; it is not combined with private application IDs by FamilyPortrait AI.
Reference photos are private and are not added to My Creations. If asynchronous processing requires a temporary private reference object, only the task owner and authorised worker can access it. The Service attempts to delete temporary references when a generation completes, fails, or is cancelled; a 24-hour time-to-live is the fallback for interrupted cleanup.
Generated results are private, owner-only assets. A successful result is available for 30 × 24 hours from its creation time and is then no longer available through the product. The cleanup process uses the same expiry time to remove the stored object and its non-required metadata.
Financial records, Credit ledgers, security records, and records needed to resolve disputes or comply with law may follow a different, limited retention period. They are kept separate from reference and result images where the product design permits.
We disclose information only as needed to operate the Services, including to:
Providers may change with the deployed configuration. We do not describe a provider as receiving information that the active product path does not send.
You can delete an individual image or generation through available product controls. The Service first removes the private object; if that operation fails, access remains restricted and deletion can be retried.
When account deletion starts, the account enters deletion_pending. Product-asset access is disabled while generation records, outputs, and temporary reference objects are removed. Automatic retries are bounded; unresolved cleanup may require manual handling. Necessary payment, fraud-prevention, dispute, or legal records may be retained without retaining your reference or result images.
We use reasonable administrative, technical, and organisational safeguards, including authenticated owner checks and private, no-store delivery for user images. No Internet transmission or storage system is completely secure, so we do not promise absolute security or use “zero logging” language.
Depending on applicable law, you may request access, correction, or deletion of personal information, or ask questions about its processing. Product deletion controls are the fastest way to remove an available image or begin account deletion.
Where the Analytics banner is shown, selecting Reject prevents Analytics from loading. You can clear the saved choice and applicable Analytics cookies through your browser settings. This does not delete necessary Auth, Security, or preference storage unless you also remove that storage.
We may update this Policy when the product, providers, or legal requirements change. The date above will identify the latest version.
For privacy questions or requests, use the Contact page linked in the site footer.