Privacy
Last updated 22 August 2026
Heirloom restores old photos. Those photos are often the most personal files a person owns, so this policy is written to be read, not skimmed. If anything here is unclear, email hello@heirloom.photos and a human will answer.
The short version
- Your photos are never used to train AI — ours or anyone else’s.
- Photos auto-delete after 30 days. You can delete any photo yourself, immediately, at any time.
- We never sell your data, and we don’t run ads.
- We store the minimum needed to run the service: your images, your email address, and basic usage events.
- Payments are handled by Stripe. We never see your card number.
What we store
- Images. The original photo you upload, the restored HD version, and a watermarked 1024px preview. If you create a share link we also render a before/after preview image for that link.
- Account details. Your email address, used to send you a sign-in link and purchase receipts. There are no passwords to store.
- Purchase records. A ledger of credits bought and used, and the Stripe customer and subscription IDs needed to honour what you paid for.
- Usage events. Things like “uploaded a photo”, “restoration finished” or “started checkout”, tied to an anonymous session ID and, if you are signed in, your account. We use these to find where the product is confusing or broken.
- Technical data. A salted hash of your IP address (not the address itself) for rate limiting, plus standard server logs kept briefly for security and debugging.
Before you sign in, your uploads are tied to an anonymous session cookie. When you create an account, photos restored in that session are attached to it so you don’t lose them.
Where it lives
Images and account data are stored in Supabase, in private storage buckets that are not publicly accessible. Images are served only through short-lived signed links (ten minutes or less for your own photos; up to an hour for the watermarked preview on a share link you chose to create). The hosting region is configurable per deployment; the current region is available on request.
How long we keep it
- Photos: deleted automatically 30 days after upload — originals, restored files, previews and share images together. A scheduled job runs daily to do this.
- Delete now: every photo you own has a delete control, and Account has a “delete all my photos” option. Deletion removes the files and the database record immediately; it is not a soft delete.
- Account and purchase records: kept while your account exists, plus as long as tax and accounting law requires for payment records (generally seven years in Australia). Email us to close your account.
- Usage events: kept for up to 24 months, then deleted or aggregated.
AI training
Your photos are never used to train, fine-tune or evaluate AI models — not by us, and not by the providers that run the restoration for us. We use those providers under terms that prohibit training on customer inputs and outputs. Restoration is a one-way process: a photo goes in, a restored photo comes out, and nothing about it is retained by the model.
Who processes it for us
We rely on a small number of service providers. Each receives only what it needs for its job, and none may use your data for its own purposes.
- Supabase
- Database, authentication and private file storage for originals and restored images.
- fal.ai
- Primary AI restoration provider. Receives a short-lived link to the photo being restored; the link expires within minutes.
- Replicate
- Backup AI restoration provider, used only if fal.ai fails. Same short-lived link model.
- Stripe
- Payments. Card details go straight to Stripe and never touch our servers. We store only Stripe's customer and subscription IDs.
- PostHog
- Product analytics (which screens are used, where people get stuck). Receives event names and a session ID, never photos.
- Vercel
- Hosts the website and runs the code that serves it.
- Resend
- Sends transactional email: sign-in links and receipts. Nothing promotional.
Some of these providers operate outside Australia (mainly in the United States). Where they do, we rely on their contractual commitments to protect your data to at least the standard described in this policy.
Selling data
We don’t sell, rent or trade personal information, and we don’t share it with advertisers or data brokers. The only circumstances in which we would disclose it to anyone other than the processors above are: with your explicit direction, to comply with a lawful request we are obliged to honour, or as part of a sale of the business — in which case the buyer would be bound by this policy and you would be told first.
Your rights
Heirloom is operated from Australia and handles personal information in line with the Australian Privacy Act 1988 and the Australian Privacy Principles. If you are in the UK or the European Economic Area, the UK and EU GDPR also apply, and we treat everyone to that standard regardless of where they live. In practice that means you can:
- Access — ask for a copy of the personal information we hold about you.
- Correct — have inaccurate information fixed (your email address, for example).
- Delete — remove your photos yourself at any time, or ask us to erase your account and everything attached to it.
- Export — receive your data in a portable format.
- Object or restrict — tell us to stop processing for a particular purpose, including analytics.
- Complain — to us first, please, and otherwise to the Office of the Australian Information Commissioner (OAIC) or your local data protection authority.
Our legal bases under the GDPR are: performance of a contract (restoring and storing your photos, handling payments), our legitimate interest in keeping the service secure and understanding how it is used, and consent where we ask for it. Email hello@heirloom.photos to exercise any of these rights. We reply within a few business days and complete requests within 30 days; we may need to verify that the request comes from the account holder.
Children
Heirloom is not directed at children under 16, and we don’t knowingly collect their personal information. If you believe a child has created an account, email us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top. If a change meaningfully reduces your rights or expands what we collect, we will email account holders before it takes effect. We will never quietly start training on your photos.
Contact
Privacy questions, data requests and complaints: hello@heirloom.photos. See also our contact page and terms of service.