What we process
Only the records needed to run, recover, support, and audit the preview flow.
We process the photo you choose, preview selections, generation metadata, session identifiers, purchase records, referral attribution, share-page data, and deletion requests. Image bytes are stored in object storage; Postgres stores metadata and object references.
- Uploaded and generated image objects for the active preview.
- Session, checkout, referral, and account-link metadata.
- Account name, normalized email, email-verification state, secure password hash, and linked authentication-provider identifiers. LookPrep never stores plaintext passwords.
- Partner profile and promotional identity, signed attribution, aggregate performance, financial ledgers, payout country, and normalized Stripe Connect status.
- Privacy-filtered product events and error-monitoring records used to understand the flow and diagnose reliability. LookPrep sends explicit PostHog events with autocapture and session recording disabled. Sentry default PII is disabled; error replay masks text and inputs and blocks media.
- Deletion request records needed for support follow-up.
Consent and age gate
Photo generation stays blocked until the user confirms age and processing consent.
You must confirm that you are 18 or older and consent to photo processing before any model generation request can run. The server records this consent event with version, session, timestamp, user agent, and hashed network signal.
Authentication and model providers
Provider processing is bounded to account access and authorized preview execution.
Google may process the minimum profile and verified-email data needed when you choose Google sign-in. Google is an authentication provider, not a payout provider. LookPrep stores the linked provider account record required to preserve one account across sign-in methods and does not expose provider tokens to product features or browser code.
LookPrep sends authorized object references to its private media worker for model execution. The worker uses the configured generation provider, while the website enforces consent, entitlement, quota, and result access. We do not use uploaded faces to train LookPrep models.
Retention and deletion
Retention exists for recovery, support, share pages, purchase proof, and abuse prevention.
Uploaded and generated images are retained only for product recovery, share pages, purchase support, and abuse prevention. You can request deletion of account data, session data, stored image objects, and public share pages through the deletion workflow.
Public share pages
A public URL is an explicit user action, not a default result state.
Share pages are private until you explicitly publish them. Published pages expose the selected before/after preview to anyone with the URL. A deletion request can include unpublishing or deleting share pages.
Partner program privacy
Partners receive aggregate performance and their own financial records, not buyer identities or photos.
We process the partner profile, code and vanity slug, signed attribution records, checkout outcomes, commission snapshots, payout country, current payout-terms acceptance, and payout history. Attribution may be retained in a signed, time-limited browser cookie. Stripe supplies provider references and normalized readiness status; bank, card, tax, requirements payloads, and identity-verification credentials remain with Stripe.
Partner reporting does not expose buyer names, email addresses, payment credentials, uploaded photos, or generated previews. Financial and attribution records may be retained for refunds, disputes, fraud prevention, accounting, tax, audit, and other legal obligations.
Contact and deletion
The data deletion form is the canonical support path for removal requests.
Use the deletion form if you want your data removed or if you need operator follow-up for a guest session.