Privacy Policy

Last Updated: August 25, 2026


1. Introduction

TeamShotsPro and Portreya are services operated under the Carpe Diem Ventures trade name. In this policy, “we,” “our,” and “us” refer to that operator. We operate teamshotspro.com and portreya.com (collectively, the “Services”).

This policy explains what personal information the Services handle, why we handle it, which providers may receive it, how long it may remain, and how to contact us about it.


2. Information We Collect

A. Account & Team Data

Identity: Name, email address, and language preference. If you choose to set a password, it is stored in hashed form. Most accounts use passwordless authentication (one-time codes or magic links) and do not store a password.

Team Data: For teamshotspro.com users, we store team names, roles, and member email addresses managed by Team Admins.

B. Face & Image Data

Important:A new selfie is uploaded and analyzed only after you select “Approve & Save” on the review screen.

Input Data: We collect the photos (“Selfies”) you upload for the purpose of generating professional headshots.

Process Data: Our systems and third-party AI providers analyze facial and visual features in your uploads to perform safety checks and create the requested result. We do not train a custom face model for your account. Provider handling, including any retention or model-improvement setting, is governed by the provider and configuration used for the request.

Output Data: We store the resulting AI-generated images. All generated images are AI-created and are not real photographs.

Image Controls: You can delete individual selfies and generated images. Direct individual users can delete all their images in account settings. For an invited team member, the Team Admin controls bulk deletion and handles requests to remove all of that member's images.

Content Moderation: Uploaded photos may be automatically scanned to detect and reject prohibited content. A rejected image may already have been uploaded or temporarily retained before the check completes.

C. Outfit Capture Browser Extension

Explicit capture: Image capture happens only when you right-click an image and choose the Portreya outfit-capture command. The extension retrieves those image bytes and sends them over HTTPS to our Service so you can continue in the Virtual try-on pack in the web app.

Source URL: The source image URL is kept only in trusted browser session storage for retry for up to ten minutes. It is not sent to our backend, logged, or used for analytics, and is removed after a successful handoff, expiry, browser restart, extension update, or disable.

Local extension data: A limited upload credential, its expiry, and a random installation identifier remain in trusted local extension storage. Web pages and content scripts cannot read this credential. We use this data only to connect the extension and upload an explicitly selected outfit image, consistent with Chrome Web Store Limited Use requirements.

Outfit retention and deletion: A captured outfit is stored by our hosting and storage provider as a person-owned account Asset for as long as the account exists. It is sent to Google Cloud for AI processing only after you start a generation in the web app. You can request deletion through account erasure or by contacting support under Sections 5, 7, and 9.

D. Financial Data

We use Stripe for payment processing. We do not store your credit card details. We only retain a transaction ID and customer reference number to manage your purchases.


3. Infrastructure & Data Transfer

We use the providers below to operate the Services. Processing location can vary by product configuration, provider, model, network route, and selected upstream provider.

Data TypeProviderLocationPurpose
Hosting & StorageHetzner Online GmbHGermany (EU)Application hosting, database, and image storage.
AI ProcessingGoogle Cloud (Vertex AI)Configured European region or global endpoint, depending on modelImage analysis and generation.
AI ProcessingGoogle Gemini APIGoogle infrastructure; location may varyImage analysis and generation.
AI ProcessingOpenRouter and selected upstream model providersLocation varies by selected providerImage analysis and generation when that route is selected.
AI ProcessingWaveSpeedAIProvider infrastructure; location may varyImage generation when that route is selected.
Network & SecurityCloudflareGlobal networkDNS, routing, security, and delivery.
AuthenticationGoogle OAuth (when selected)Google infrastructure; location may varyAccount sign-in.
PaymentsStripeUSA/GlobalPayment processing.
EmailsResendUSATransactional and marketing emails.
Product AnalyticsPostHogEU/USAUsage analytics.
Web AnalyticsGoogle Analytics (GA4)USAWebsite traffic and conversion measurement.
Error MonitoringSentryUSAApplication error tracking and performance monitoring.

Some providers process data outside your country. The transfer protections and contractual terms that apply depend on the provider, service configuration, and applicable law. Contact us before purchasing if your organization requires a particular processing region or contractual arrangement.


4. Cookies & Tracking

We use the following cookies and tracking technologies:

Essential Cookies: Session and authentication cookies required for the Service to function (Auth.js).

Product Analytics: We use PostHog to understand how users interact with our Service and improve the user experience.

Web Analytics: We use Google Analytics (GA4) to measure website traffic and conversion performance.

Error Monitoring: We use Sentry to receive application error and performance reports.

Payment: Stripe may use cookies or similar technologies during secure payment processing.


5. Data Retention Policy

Uploaded selfies, captured outfits, generated photos, and related account records may remain while your account exists. AI providers may also retain request or output data under their own service terms and the configuration used for a request. You may request deletion using the contact details in Section 9. We will confirm the scope and status of the request; some operational, security, transaction, backup, or legally required records may remain for longer.


6. Marketing Communications

When you create an account, complete checkout, or sign in for the first time, we may enroll you in tenant-specific marketing email preferences for the brand you are using. Marketing emails may include practical tips, examples, product updates, and occasional offers related to our services.

Opt-Out: You can object to and unsubscribe from direct marketing at any time by clicking the unsubscribe link included in every marketing email, changing your email preferences in your account profile, or contacting us using the details in Section 9. Once you object or unsubscribe, we will stop processing your personal data for direct marketing for that brand.

Service Emails: Transactional and service-related emails (such as one-time login codes, purchase receipts, team invite notifications, onboarding reminders for an active invite, and account security messages) are separate from marketing emails and may continue as needed to provide the Service.

Legal Basis: We rely on legitimate interests for service communications and, where permitted, for marketing about our related products and services. Where local law requires consent for marketing, we will use consent as the legal basis.


7. Your Rights

Depending on where you live and the law that applies, you may have the following rights regarding your personal data:

  • Access & Export: Request a copy of your photos and personal data we hold about you.
  • Rectification: Update or correct inaccurate account information.
  • Erasure (“Right to be Forgotten”): Request deletion of your account and all associated data.
  • Restriction: Request that we limit how we process your data in certain circumstances.
  • Data Portability: Receive your data in a structured, commonly used, machine-readable format.
  • Objection: Object to processing of your personal data in certain circumstances.
  • Direct Marketing Objection: Object to direct marketing at any time. This right is unconditional, and we will stop processing your personal data for direct marketing after you object.
  • Withdraw Consent: Where processing is based on consent, withdraw it for future processing.

How to Exercise Your Rights: Contact us using the details in Section 9. We will respond within the period required by applicable law and may ask you to verify your identity before processing a request.


8. Security

We use technical and organizational safeguards intended to reduce unauthorized access, loss, or misuse, including:

  • Encryption in Transit: All data transmitted to and from our servers is protected using SSL/TLS encryption.
  • Access Controls: Application roles and service credentials limit access to systems and account data.
  • Provider Controls: We use the security features made available by our hosting, storage, payment, and AI providers.

While we strive for maximum security, no internet transmission is completely invulnerable. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by law.


9. Contact

TeamShotsPro and Portreya are services operated under the Carpe Diem Ventures trade name. For privacy concerns, please contact us at: