Skip to content
Baby AI Photoshoot Logo
BabyAIPhotoshoot
Back to Home
Family privacy

Privacy Policy

Paper Street Labs LLC · Last updated September 30, 2026 · Version 2026-09-30

Baby AI Photoshoot is operated by Paper Street Labs LLC ("we", "us"). This policy explains what personal data we collect when you use babyaiphotoshoot.com, our iOS app and our free AI tools, why we use it, who processes it for us, how long we keep it and how you control it. Photos of children deserve extra care, so we explain that part in detail.

Private models only

Your baby's photos train a private model used only for your account — never for other models.

Delete any time

Delete photos, models, a baby or your whole account yourself in Account & privacy.

Never sold

We don't sell or share personal data for advertising, and we don't use it to identify people.

1. Who we are and who this covers

Paper Street Labs LLC is the controller of the personal data described here. The service is meant for adults (18+) — parents, legal guardians and parents-to-be. We do not knowingly collect personal data directly from children. Photos of a child are provided by their parent or guardian, who decides how they are used (see section 4).

2. What we collect

  • Account data: your name, email address and password (stored only as a secure hash), or the basic profile Google or Apple shares when you sign in with them.
  • Baby profiles: the name, birth date and (optional) gender you enter for each child.
  • Training photos and private models: the photos you upload for each age range and the AI model (a small file of learned settings) we train from them to reproduce your child's appearance.
  • Portraits and requests: the portraits we create, the themes you pick and any scene description you write.
  • AI tool inputs and results: photos you upload to a tool (for example a baby photo, a child's drawing, an ultrasound image or photos of the two parents) and the images we create from them.
  • Billing data: your plan, credit balance and credit history. Card details are handled by our payment processor; we never see or store full card numbers.
  • Consent records: which version of our terms and consents you agreed to and when.
  • Technical data: cookies needed to keep you signed in, a random browser ID and a hashed (scrambled) IP address used to limit free tool tries, basic logs and, where allowed, analytics (see our Cookie Policy).
  • Messages: what you send us when you contact support.

3. How we use it and our legal bases

  • To provide the service — your account, training your baby's private models, creating portraits and tool results, emails about your account (contract).
  • To train a private model of your child — only after you give explicit consent for that child (consent; see section 4).
  • To bill you and keep records — plans, credits, refunds and tax records (contract and legal obligation).
  • To keep the service safe and fair — preventing abuse of free tries and welcome credits, fraud prevention, security logs (legitimate interests).
  • To improve the website — aggregated analytics about page use (legitimate interests or consent where the law requires it).

We do not use your or your child's photos, models or results to train general or public AI models, to build face recognition, to identify anyone, or for advertising.

4. Children's photos and private AI models

A photo of a face can be sensitive data. Before we train a model of a child, the parent or guardian must confirm they have the right to do so and agree to our Child Photo & AI Model Consent. We record that consent with its version and date, per child.

  • Each model belongs to one child and one age range, and is only used to create portraits for your account.
  • Training photos and models are stored privately. They are only reachable through short-lived signed links issued to you or to the providers doing the work.
  • You can withdraw consent at any time in Account & privacy. We then delete that child's training photos and models; portraits you already have stay until you delete them.
  • Tools such as Our Baby Match and Ultrasound Baby create artistic images for fun. They are not medical or genetic predictions. Only upload photos of people who have agreed to it.

5. Who processes data for us

We don't sell or rent personal data. We share it only with service providers that process it on our instructions, under contracts that require them to protect it:

  • fal.ai — trains private models and runs the AI tools.
  • RunPod — GPU servers that create studio portraits.
  • Microsoft Azure — private file storage and cloud infrastructure.
  • Anthropic — turns a scene description you write into a structured scene plan (text only, no photos).
  • Stripe — payments and billing records.
  • Google and Apple — sign-in, if you choose them; Google Analytics — website statistics.
  • Microsoft Clarity — heatmaps and session replays of website visits, only if you accept analytics cookies. Photos, baby details and account pages are hidden from it.
  • Hotjar — heatmaps, session replays and feedback questions, on the same terms as Clarity: only if you accept analytics cookies, with photos, baby details and account pages hidden.
  • Cloudflare — bot protection for free tool tries.
  • Our email provider — account and password-reset emails.

Providers may keep processing logs for a short period under their own policies. We may also disclose data if the law requires it, to protect the safety of a child or others, or as part of a merger or acquisition (in which case this policy continues to apply). Illegal content involving the exploitation of children is reported to the authorities.

6. How long we keep data

  • Account, baby profiles, portraits and tool results in your account: until you delete them or your account.
  • Training photos and models: until you delete them, the baby profile or your account, or withdraw consent.
  • Photos uploaded to an AI tool: deleted as soon as the result is made (or the run fails).
  • At our AI providers: fal.ai deletes the files it creates for us within 1 hour (AI tools) or 24 hours (model training), and we delete each job's record there as soon as we've saved the result.
  • Free tries without an account: results are deleted after 24 hours. A record of the try (a random browser ID and a hashed IP address, no photos) is kept to enforce the one-free-try limit.
  • Error reports: technical error reports (no photos) are kept on our own error-tracking server for up to 90 days to fix problems.
  • Billing and tax records: as long as the law requires, typically up to 7 years, held by our payment processor.
  • After you delete your account: we keep only a keyed hash of your email address (we can't read the email from it) and anonymous usage counts, so free welcome credits can't be claimed twice. This record is deleted after 3 years.

7. Deleting your data

You can delete individual photos, a baby profile (with its photos, models and portraits) or your whole account yourself in Account & privacy, on the web or in the app. Account deletion is immediate and permanent: your account, babies, photos, models, portraits, tool results, credits and consent records are removed from our live systems right away, and from backups within 30 days.

8. Your rights

Depending on where you live (for example under the GDPR, UK GDPR or US state laws such as the CCPA), you can ask to access, download, correct or delete your data, object to or restrict some uses, and withdraw consent at any time. You can download a copy of your data in Account & privacy. For anything else, email [email protected]; we answer within 30 days. We won't treat you differently for using these rights. You can also complain to your local data protection authority.

We do not sell personal information or share it for cross-context behavioural advertising.

9. Security

Data travels over encrypted connections (HTTPS) and files are encrypted at rest by our storage provider. Photos and results are never public: we check ownership before issuing short-lived signed links. Access inside our team is limited to what is needed to run and support the service. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.

10. International transfers

We are based in the United States and our providers may process data in the US and other countries. Where the law requires it, we rely on safeguards such as the EU Standard Contractual Clauses.

11. Changes to this policy

We'll post any update here with a new date and version. If a change is significant — especially about children's photos — we'll tell you by email or in the app before it applies, and ask for consent again where needed.

Contact

[email protected]

Paper Street Labs LLC, 131 Continental Dr Suite 305, Newark, DE 19713, USA