Iniciar sesiónEmpezar

Privacy policy

5 October 2026

Legal text in English for convenience. The German version is binding: Deutsch.

This explains which personal data we process when you use InterviewShot, why, on what legal basis and for how long. Most importantly: to create your photos we process your selfies and calculate facial features (biometric data). We only do this with your express consent. The German version is legally binding.

1. Controller

Dimitri Frank (Einzelunternehmer) Detmolder Weg 30, 32657 Lemgo, Deutschland Email: [email protected]

We have not appointed a data protection officer because this is not required by law. For data protection questions you can reach us at the email address above.

2. Overview

  • Visiting the website: technical access data (server log files).
  • Account and login: email address and password (stored as a check value).
  • Creating photos: your selfies, selection of style and options, calculated facial features, the generated photos.
  • Phone upload via QR code: photos you upload with your phone.
  • Payment and purchase record: payment status, amount, currency, country, card country, credits.
  • Contact and cancellation: your details in the form or the email.

3. Visiting the website and server log files

When you visit the website, the server processes technically necessary data: IP address, date and time, requested address, amount of data transferred, browser and operating system. The purpose is secure and stable operation and defence against abuse. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure operation). Log files are deleted after 14 days at the latest.

The website is hosted by Hetzner Online GmbH in Germany. A data processing agreement is in place. For delivery and protection we use Cloudflare (DNS, protection against attacks). Your IP address may pass through Cloudflare servers, also outside the EU. Standard contractual clauses apply.

4. Account and login

To buy and use the service you create an account with an email address and password. The password is not stored in plain text but only as a check value. We send you a confirmation email. The purpose is performance of the contract (Art. 6 (1) (b) GDPR). Account and login data are stored with the provider Supabase (data centre in Frankfurt am Main, Germany). We delete the account at your request unless statutory retention obligations (see section 7) prevent this.

5. Creating photos: selfies, AI and biometric data

What happens. You upload at least three and at most eight selfies and choose a style and options (for example hair, beard, make-up, expression, glasses). We reduce the size of the images, select the most suitable selfies and pass them to an AI image model that creates the requested portrait photos. We check each generated photo automatically before it is shown to you: it must show exactly one face, resemble the selfies, the eyes should be open, and there must be no other persons, no text and no recognisable image errors. You only receive the best photos.

Biometric data (Art. 9 GDPR). For this check, faces are detected on our server and a mathematical face profile (numerical values) of the selfies and the generated photos is calculated and compared. The approximate age is also estimated so that photos on which you look clearly older can be filtered out. These face profiles are processed only in memory for the duration of the order and are not stored. The legal basis is your express consent (Art. 9 (2) (a) and Art. 6 (1) (a) GDPR), which we obtain with a checkbox before every order. Without this consent we cannot create the photos. You can withdraw the consent at any time with effect for the future, for example by email. The lawfulness of processing carried out until then remains unaffected.

Recipients. To generate the photos we transmit your selfies to fal.ai Inc. (USA), which provides the AI model. For the automatic quality check, the selfie and the generated photo are also transmitted to an AI image-understanding model (Google Gemini, provided via fal.ai). Data processing agreements are in place with the providers. Transfer to the USA is based on standard contractual clauses under Art. 46 GDPR. We do not use your selfies to train AI models. At fal.ai the storage of request data (and therefore of your selfies) is switched off, and generated images are deleted there after one hour at the latest.

Retention. Your selfies are deleted as soon as the order is complete. The generated photos are available to view and download for 30 days and are then deleted automatically, earlier on your request. Downloaded photos are with you and are no longer managed by us.

Note on AI. The photos are artificially generated images. We make no decision that has legal effect on you. The automatic selection of the best photos is part of the service only.

6. Phone upload via QR code

When you upload selfies with your phone, we create a personal link that is valid for 30 minutes. The photos are stored temporarily until they are retrieved on the computer and are then deleted immediately. Photos not retrieved are deleted after 24 hours at the latest. The link contains a signature and only works for your order. For use we need the consent described in section 5 before you start the order.

7. Payment, purchase record and guarantee

Payment is handled by Stripe Payments Europe, Ltd. (Ireland), with Stripe, Inc. (USA) as an affiliated company. We receive details of the purchase from Stripe (amount, currency, payment status, card country, payment reference) but no full card data. Payment data is entered directly with Stripe. The legal basis is performance of the contract (Art. 6 (1) (b) GDPR).

In a purchase record we store date, package, amount, currency, price tier, country, card country and credits added. We use the card country only to assign the price paid to the right country (legitimate interest, Art. 6 (1) (f) GDPR, protection against misuse of country prices). For the satisfaction guarantee we also store whether and when a photo was downloaded.

We keep invoice and booking data because of statutory retention obligations (commercial and tax law, generally up to ten years). The legal basis is Art. 6 (1) (c) GDPR.

8. Contact form, email and cancellation

If you write to us through the contact form or by email, or cancel through "Cancel contracts here", we process your details (name, email address, message) to handle your request (Art. 6 (1) (b) or (f) GDPR). We delete the details when the matter is settled and no retention obligations exist. We send system emails (confirmation, cancellation) through the provider Resend (USA) based on standard contractual clauses. Emails to our support address are forwarded to our mailbox via Cloudflare Email Routing.

9. Retention overview

  • Server log files: 14 days at most.
  • Selfies: until the end of the order, phone uploads 24 hours at most.
  • Face profiles: only in memory, not stored.
  • Generated photos: 30 days or until you delete them earlier.
  • Account: until the account is deleted.
  • Purchase record and invoices: statutory retention periods, generally up to ten years.

10. Cookies and local storage

We only use technically necessary cookies and similar storage: login (session), selected language and selected currency. They are required for the functions you request (§ 25 (2) TDDDG). We use no cookies for advertising or audience measurement and do not embed tracking services, so no consent banner is needed.

11. Recipients and processors

  • Hetzner Online GmbH (Germany): hosting.
  • Supabase (data centre Frankfurt): account, database, storage for photos.
  • Stripe Payments Europe, Ltd. (Ireland), Stripe, Inc. (USA): payment processing.
  • fal.ai (USA): AI image generation and image understanding (Google Gemini) for the quality check.
  • Resend (USA): sending system emails.
  • Cloudflare (USA): DNS, protection against attacks, email forwarding.

Where providers transfer data to countries outside the EU and EEA, this is based on standard contractual clauses (Art. 46 GDPR) or an adequacy decision.

12. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw a consent given at any time with effect for the future (Art. 7 (3)). Contact the email address above.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany. You can also contact the authority at your place of residence.

13. Minors

The service is aimed at persons aged 18 and over. We do not knowingly process selfies of children.

14. Changes

We update this privacy policy when the service or the legal situation changes. The version currently published applies.

Volver al inicio