Privacy Policy
PhotoToSpec has two ways of processing a photo, and they are meaningfully different for your privacy. Checking and fixing a photo happens entirely inside your browser — the image is never sent to us. AI generation uploads your image to us and to a third-party AI provider, and we keep a copy for 30 days. You can start AI generation yourself, and for a photo you upload on a requirement that supports it, it also starts automatically when your browser alone cannot make the photo pass. A photo taken with the camera on this site is never sent unless you press the button — §2.2 sets out exactly when each applies. This page explains both, plus the small amount of other data we collect.
This page is only about data. The terms between you and us — what we ask of you, what we do not promise, whether an authority will accept your photo, the limit of what we are liable for, and which law applies — are on a separate page: Terms and Conditions.Choosing a photo to check, taking one with the camera on this site, sending one for AI generation, or sending us a rule — any one of those means you accept them. There is no box to tick and no account to close, because we never asked you for one.
This policy is published in English only. The rest of the site is available in several languages, but we would rather not risk a translation error in a legal document.
1. Who we are
PhotoToSpec is the name this site trades under. It is operated by NEXALIFY LIMITED, a company registered in Hong Kong SAR China at Rm D07, 8/F, Kai Tak Fty Bldg, No. 99 King Fuk St, San Po Kong, Hong Kong. That company is what “we”, “us” and “our” mean everywhere on this page, and it is the data controller for the processing described here. You can reach us at support@phototospec.com for any privacy question or request.
We do not offer accounts. There is no sign-up, no password and no profile, so we hold no account records about you at all.
2. Your photos
2.1 Checking and fixing a photo (the default)
When you select a photo to check against a requirement, the file is read and processed by code running in your browser. Every measurement — dimensions, file size, background uniformity, head size, face position — and every automatic fix, such as cropping, resizing or recompressing, happens on your own device. The photo itself is not uploaded to us. When you download the result, that file is produced locally too.
Face detection uses a model that runs on your device. Your browser downloads that model and its runtime from jsDelivr and Google storage, which means those two services see your IP address — but the model comes to your photo, not the other way around. Your photo is not sent anywhere.
Nothing about the photo is stored after you close or reload the page. We keep no copy, no thumbnail and no derived measurements.
2.2 AI photo generation
Some requirements offer an AI-generated photo when cropping, resizing and colour adjustment in your browser cannot make the photo meet the rule. This path is different, and we want to be blunt about it:
- Your photo is uploaded to our endpoint running on Cloudflare.
- It is then forwarded, together with a generated text prompt, to a third-party AI image provider. What that provider does with the image is governed by their own terms, which we do not control. They may in turn rely on upstream model providers.
- We store the photo we send for generation and the generated result for 30 days, after which they are deleted automatically by a storage lifecycle rule. To be exact about what the first of those is: it is the version your browser already cropped and resized, not the original file off your camera — except in the one case described below where the browser-side fix could not finish at all, and so no such version exists; there we send a copy of your photo reduced to at most 1200 pixels along its longest side. If generation fails, the copy we uploaded is still stored for those 30 days. We use these copies to investigate failed or disputed generations, to prevent abuse, and to re-send you a result if you ask for it.
There are two ways this starts, and only one of them involves you pressing a button:
- You start it. We show you the browser-side result and offer AI generation next to it as a button. Nothing is uploaded unless you press it. The button is there on every outcome — whether that result met the requirement or failed it, including the two failures below where we deliberately stop the automatic route, and including a generated photo that itself did not meet the requirement. Generation is not deterministic, so trying again can land differently, and whether that is worth your time is your call rather than ours. For a photo taken with the camera on this site this is the only route: we never upload a photo you just took without a press.
- It starts automatically — but only for a photo you upload. If a photo you chose from your device still fails the requirement after the browser-side fix — framing, head size, tilt, exposure, background, resolution below the requirement's minimum, file size, and so on — we run generation for you rather than telling you to find another photo. Your photo is uploaded at that point without a further click. Warnings alone never trigger this; only outright failures do. This also now covers the case where the browser-side fix cannot finish at all: some photos are large enough that your browser fails to re-encode them, and some cannot be compressed down to a size limit the requirement sets. That used to be a dead end — we showed you an error and nothing else — and we now send the photo for generation instead. Because there is no browser-fixed version to send in that case, what leaves your browser is a reduced copy of your photo, as described above.
Two failures stop the automatic route, and neither one uploads your photo on its own. The first is when we cannot find exactly one face — either none at all, or more than one, in which case we cannot know which person is you. The second is dark lenses, on requirements that ask for the eyes to be visible. We stop on these two because generation would have to invent the part of the photo that identifies you: a face where we found none, a choice of person we have no basis to make, or a pair of eyes behind the lenses. An invented face looks entirely natural in the preview, which is exactly why we will not hand you one without saying so. Both have a clear fix at your end — crop the other person out, or take the sunglasses off — and that is what we ask for first. The button is still there, with that warning printed next to it: we will not upload your photo for a result we expect to be invented, but neither will we decide on your behalf that you may not try. Pressing it uploads your photo exactly as any other generation does. And we never start generation automatically on the camera path at all: retaking a photo costs you seconds, whereas the photo you uploaded may be the only one you have.
Resolution is on that list for a reason worth spelling out, because it cuts against what you might expect. We never enlarge your photo to reach a minimum — that invents detail rather than recovering it. Generation is different: it produces a new image at a fixed size of its own, so for most requirements a photo that is too small can still be met that way, and a photo you upload may be sent for generation precisely because it was too small. Where even a generated photo would come out below the minimum, we ask you to retake and upload nothing.
We tell you this before you choose a photo: on almost every requirement on this site, the notice at the foot of the checker says that generation can start automatically for a photo you upload, that a photo taken here is only sent if you start it yourself, and that your photo is uploaded whenever generation runs. There is one kind of exception, and it is narrow: a requirement that sets a minimum resolution higher than anything our generator can produce, because generation could never satisfy it. On those, the foot of the checker says instead that everything stays in your browser, and it does — no photo of yours ever leaves it. Among the requirements published here, today that is one: the Canadian passport. The same test applies to a requirement you enter yourself on the custom page (§3.4); if the minimum resolution you type is above what our generator produces, that page offers no generation either, on the same single comparison.
Whenever an upload does happen, the result screen shows a job reference. Quote it in an email to us and we can find that stored copy and delete it before the 30 days are up. We show it even when the generation fails, because by that point the upload has already happened.
We do not use your photos to train any model of our own, and we do not sell them or share them with anyone beyond the provider described above. We cannot make that promise on the AI provider's behalf, which is why the option is clearly labelled before you use it.
3. Other data we process
3.1 Rate-limit counters
AI generation costs money to run, so we cap it per visitor per day. To count without identifying you, we combine your IP address with the first part of your browser's user-agent string and store only a one-way SHA-256 hash of that combination, alongside the date and a request count. We cannot read your IP address back out of it. These rows are deleted after 90 days. Sending us a rule (§3.4) is capped the same way, on its own separate count, so the two never draw down each other's allowance.
We are being precise rather than reassuring here: a hash of an IP address is still personal data under the GDPR, because the input space is small enough that it is not truly anonymous. We treat it as personal data accordingly.
3.2 Analytics
We use Google Analytics 4 to understand which photo requirements people actually need, so we know what to add next. Google Analytics 4 uses your IP address to work out roughly where you are and then discards it, rather than storing it against your events. We record:
- Pages viewed, and the site language you are using.
- Which requirement you selected, and how you got to it.
- Button and funnel interactions — starting a check, switching language, filtering by market, requesting AI generation.
- Search terms typed into the requirement search, lower-cased and truncated to 40 characters, together with how many results they returned. We look at searches that return nothing, because that tells us which requirement to add. Please do not type anything personal into that box.
We do not run advertising, ad retargeting or cross-site tracking, and we do not sell any data.
3.3 Server logs
Cloudflare processes standard request data — IP address, user agent, requested URL, timestamp — in order to serve the site and absorb attacks.
We also keep a short-lived diagnostic log of each AI generation call, so we can trace failures and investigate abuse. These entries expire automatically within days.
3.4 Rules you send us
If you cannot find your requirement, the custom page lets you paste the wording you were given — an email from a school, a page from an official site — and we read the sizes out of it into a form you can see and correct. That reading happens in your browser. Pasting text and checking a photo against it sends us nothing at all.
Underneath the result there is a separate button that sends the rule to us, so we can verify it and publish it for other people who need the same requirement. It is a second, deliberate action: nothing about checking your photo triggers it. If you press it, we receive and store the text you pasted (truncated at 4,000 characters) and the values in the form, plus which language you were using. Your photo is not part of that — it never leaves your browser on this path. The text is read by a person when we review the rule; it never goes to any AI model.
So please do not paste anything you would not want us to read. If the email you were sent has your name or case number in it, delete those lines first, or just fill in the form by hand. We keep submissions until we have reviewed them and, if the rule is a real one, indefinitely afterwards as the record of where a published requirement came from. We store no identifier alongside them — not your IP address, not a hash of it, nothing that ties a submission to you — which cuts both ways: we cannot work out who sent a rule, and we cannot find yours to delete it unless you tell us roughly what you pasted and when.
4. Cookies and local storage
We set no cookies of our own, and we store nothing in your browser's local storage — no saved preferences, no cached photos, no identifiers. Google Analytics sets its own cookies to tell repeat visits from new ones. Blocking them, or using any tracker blocker, does not affect the photo checker in any way — all of the actual functionality runs without analytics.
5. Who receives your data
| Recipient | What they receive | Purpose |
|---|---|---|
| Cloudflare | Hosts the site and runs the AI endpoint. Sees your IP address and request metadata for every page you load. | Hosting, delivery and abuse prevention |
| Third-party AI image provider | Receives your photo and a text prompt whenever AI generation runs — whether you started it yourself or it started automatically (see §2.2). | AI photo generation |
| Google Analytics 4 | Receives usage events (see “Analytics” below). It uses your IP address to derive a coarse location, then discards it rather than storing it. | Understanding which requirements people need |
| Google Fonts | Serves the Inter typeface. Sees your IP address when the font loads. | Page rendering |
| jsDelivr and Google storage | Serve the face-detection runtime and model file to your browser. They see your IP address, never your photo. | Delivering the on-device face detector |
We may also disclose data if we are legally required to. We will not hand over your photos to anyone else voluntarily.
6. How long we keep things
| Data | Retention |
|---|---|
| Photos checked or fixed in the browser, with no AI generation | Never leaves your browser; discarded when you close the tab |
| Photos you send for AI generation, and the generated result | 30 days, then deleted automatically |
| Rate-limit counters (hashed) | 90 days |
| A rule you choose to send us, and the text you pasted | Until reviewed, then kept as the source of a published requirement |
| Analytics events | 2 months (event data); 14 months for user-level data |
| Server and diagnostic logs | Days, then deleted automatically |
7. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Contract / your request — uploading and processing your photo for AI generation. You ask us to make a photo meet a specific requirement; generation is how that request gets completed when your browser cannot do it alone, whether you trigger it yourself or it runs automatically as described in §2.2. Either way we disclose it before you choose a photo, and we could not perform the request otherwise.
- Legitimate interests — rate-limit counters, server logs and security measures, to keep a free service from being drained by abuse.
- Legitimate interests — aggregate analytics, to decide which requirements to support next. You can opt out at any time with a tracker blocker, and nothing breaks.
- Legitimate interests — a rule you send us (§3.4), to build out the requirement library. Nothing asks you to send one; the photo check works fully without it.
8. International transfers
We serve users worldwide. Cloudflare, Google and our AI provider operate globally, so your data may be processed outside your own country, including in the United States. Where required, these transfers rely on the standard contractual clauses or equivalent safeguards published by those providers.
We are ourselves established in Hong Kong SAR China (§1). The data described on this page sits with the providers in §5 rather than on any machine of ours, but when we read a piece of it — a rule you sent us, or a request you make under §9 — that reading happens from Hong Kong.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a copy of it in a portable form, and to lodge a complaint with your data protection authority. If you are in California, you additionally have the right to know what we collect, to delete it, and to opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of.
Email support@phototospec.com and we will respond within 30 days. Because we have no accounts, we may need details to locate your data — for AI generation, the job reference shown on the result screen is the fastest way for us to find it, and we show it on failed generations too. For a rule you sent us, we need roughly what you pasted and when, because we store nothing that identifies the sender (§3.4). If you have never run AI generation and never sent us a rule, there is most likely nothing of yours for us to look up, which is rather the point of the local-only design.
10. Children
This service is not directed at children. Adults do legitimately use it to prepare passport and visa photos of their children — if you do, you are providing that photo as the parent or guardian, and the same rules on this page apply to it.
11. Security
The site is served over HTTPS. Stored photos are written to object storage that our server reaches through a private binding: the application has no code path that reads them back out and publishes no URL for them, so there is nothing for a browser to guess at. The AI provider's API key is held as a server-side secret that never reaches your browser. No system is perfectly secure, so the strongest protection remains the design itself: if AI generation never runs for your photo, we hold no photo of yours to lose.
12. Changes
If we change how we handle your data we will update this page and the date at the top. Earlier versions of this policy are available on request: write to us at the address in §13, tell us roughly when you used the site, and we will send you the version that was published then.
13. Contact
Questions, requests or complaints: support@phototospec.com.