Legal

Privacy Policy

How we collect, use, and protect your data — including your selfies and generated portraits. Last updated: June 2025.

Who is responsible for your data

SyntheticPic is operated by OMU SAS, 2 rue Jacquard, 93100 Montreuil, France (SIREN 103147971, TVA FR54103147971). OMU SAS is the data controller for all personal data processed through the SyntheticPic service. Contact us at hello@ohmyunicorn.com for any privacy-related requests.

What data we collect

We collect only what is necessary to provide the service:

  • Account data — name, email address, and profile picture from your Google account (collected via Google OAuth at sign-in).
  • Training photos — the selfies you upload to train your personal AI face model (JPEG, PNG, or WebP images).
  • Generated portraits — images produced by your personal model, stored so you can access and download them.
  • Usage data — pages visited, features used, error logs, and performance metrics (collected in aggregate; no cross-site tracking).
  • Billing data — payment method details are handled exclusively by Stripe. We store only a Stripe customer ID and subscription status — never full card numbers.

How we use your data

  • Training photos are used solely to train your personal AI face model. They are not shared with other users, not used to train any shared or third-party model, and not used for advertising.
  • Generated portraits are stored so you can re-download them at any time. We do not use them for any purpose other than serving them back to you.
  • Account data is used to authenticate you and send transactional emails (order confirmations, model-ready notifications, password resets).
  • Usage data is used in aggregate to improve the service and diagnose issues.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

Data retention

  • Training photos — retained for as long as you have an active account and model. Deleted within 30 days of model deletion or account closure.
  • Generated portraits — retained for as long as your account is active. Deleted within 30 days of account closure.
  • Account data — retained for the duration of your account, plus 12 months after closure (to handle disputes or legal obligations).
  • Billing records — retained for 10 years as required by French commercial law (Code de commerce, art. L123-22).

Your rights

Under GDPR and French law you have the right to:

  • Access — request a copy of all personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — ask us to limit how we process your data in certain circumstances.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — revoke consent for biometric processing at any time.

To exercise any of these rights, email hello@ohmyunicorn.com. We respond within 30 days. You may also lodge a complaint with the French data-protection authority: CNIL (cnil.fr).

Data security

All data is stored on servers in the European Union. Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted using AES-256. Access to personal data is restricted to authorised personnel on a need-to-know basis. We conduct regular security reviews and notify affected users within 72 hours of a confirmed personal data breach, as required by GDPR Art. 33–34.

Third-party processors

We use a small number of sub-processors to operate the service. All are bound by Data Processing Agreements and handle your data only on our documented instructions:

  • Stripe — payment processing (USA; EU Standard Contractual Clauses apply).
  • Google — authentication via Google OAuth.
  • Cloud infrastructure provider — server hosting within the EU.

We do not use third-party advertising networks or sell data to data brokers.

Cookies

SyntheticPic uses strictly necessary cookies to keep you signed in and remember your session. We do not set advertising or third-party tracking cookies. You can disable cookies in your browser settings, but doing so will prevent sign-in from working.

Children

SyntheticPic is not directed at anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page will change. For material changes we will notify you by email at least 14 days before the new policy takes effect.