Perso

Privacy Policy

AI Model operates Perso at tryperso.com and is the controller of the personal data described here. This page says what we collect, why we are allowed to, who else sees it, how long we keep it, and how to get it deleted. Contact for anything on this page: hello@tryperso.com. Last updated 2 August 2026.

What we collect

A session identifier
When you first open the app we set a signed cookie (ps_sid) containing a random account id. It is how your model and your credits are yours, and it is required for the service to work at all. It contains no personal information and is not shared with anyone.
An analytics identifier
Our analytics provider sets a cookie containing a random id, so that repeat visits are counted as one person rather than several - that is how we tell which parts of the product people actually use. It contains no personal information, and you can refuse it with your browser’s tracking protection without affecting the service.
Your choices in the builder
The attributes you pick for your AI model, and which of the generated faces you kept. These describe a person who does not exist.
The instructions you type
Where you write your own prompt instead of picking a preset (up to 300 characters), we store that text against the generation it paid for, and we send it to our generation provider as part of the request. We keep it so that we can answer a support message, respond to a payment dispute, and establish what a specific image was asked to be - none of which is possible from the image alone. Please do not type personal information about yourself or anyone else into it; nothing about the product needs it.
Name, email and profile picture, if you sign in with Google
Only those, plus Google’s stable identifier for your account. We do not request or receive access to anything else in your Google account.
That you accepted these policies, and which version
When you continue past the agreement notice at sign-in we record the date and the version of the terms and this policy that were published at the time. It is stored against your account whether or not the sign-in then completes.
Billing email and payment status, if you subscribe
Stripe collects your payment details on its own hosted page. We never see or store your card number. We store the email you gave Stripe, the amount, whether it was paid, and the Stripe customer and subscription identifiers needed to renew or cancel it.
Usage and generated output
What you generated, when, what it cost in credits, and the resulting file. Plus ordinary technical data - approximate location derived from your IP address, browser and device type, and pages visited.

Why we are allowed to (legal bases)

  • Performing our contract with you - your account, your model, generating and storing your images and clips, taking payment, and answering support.
  • Our legitimate interests - keeping the service secure, preventing fraud and abuse of free usage, enforcing the daily spending limits that keep it available, understanding how the product is used, and measuring which advertising works.
  • Complying with a legal obligation - keeping records of payments for tax and accounting.
  • Your consent, where the law requires it for optional cookies and similar technologies. See “Advertising and analytics” below for how to refuse them.

We do not make automated decisions that produce legal effects for you or similarly significantly affect you.

Who else processes it

  • Stripe - payments. Receives your billing details directly.
  • MuAPI, and the AI providers behind it (ByteDance, Google) - generation. Receives the prompt, including anything you typed yourself, and the reference image, in order to produce the output. It receives no account or billing information.
  • Vercel - hosting and image storage.
  • Railway - the database.
  • Google - sign-in, if you use it.
  • PostHog (EU region) - product analytics. Session recording, heatmaps and automatic click capture are turned off; we send a fixed list of named events and nothing else.
  • Meta - advertising measurement, so we can tell which ads work. Where we send your email or account id, they are SHA-256 hashed before they leave our server. Meta also sets its own cookies (_fbp, _fbc) via its pixel.

We do not sell your data, and we do not use your generated output or your prompts to train AI models. What a generation provider does with a request once we have passed it on is governed by that provider’s own terms, which we do not control and cannot vary on your behalf - so do not put anything into a prompt that you would not send to a third party.

Where your output is stored

Images: our storage, on unlisted public URLs
Each image is copied to our own storage and served from a URL containing a random, unguessable path. It is not listed or indexed anywhere and the gallery is visible only to your session - but anyone holding the exact URL can open it, which is what makes it shareable. Treat the link as the secret.
⚠️ Video: our provider’s storage, deleted after about 30 days
Clips are never copied to our storage. They are served from the generation provider and are removed on their schedule. Download anything you want to keep.

How long we keep it

Your account, model and images
For as long as your account exists. Images carry no expiry of their own.
Video clips
About 30 days, on the provider’s schedule. Not ours to extend.
Generation and credit records, including the prompts you typed
For as long as your account exists. These are the record of what was charged and what was delivered, and they are what a support request or a payment dispute is answered from.
Payment records
Up to seven years after your account closes, where tax or accounting law requires us to keep a record of a payment. This is the one category that survives a deletion request.
Analytics events
On our providers’ standard retention schedules.

Advertising and analytics

When you use the service we load Meta’s advertising pixel and PostHog product analytics. The events we send are a fixed, named list rather than everything you do: automatic click capture is switched off, and so is session recording - we do not record your screen.

Alongside those named events PostHog measures how a page is used rather than what you write: how far down a page you scroll, how long you stay on it, where on the screen you tap, and taps that did not hit anything. We use this to find pages that are broken or confusing. It is not tied to anything you type, and we do not record video of your session.

To refuse them, use your browser’s tracking protection or block third-party cookies - the service works without them, though the ps_sid session cookie is required for it to function at all. You can also email hello@tryperso.com and ask us to stop processing your data for advertising measurement, and we will.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. Email hello@tryperso.com and we will act within 30 days. Deletion removes your account, your model and your generated output, and cannot be undone; we keep the minimum payment record the law requires. If you are in the UK or EU, you also have the right to complain to your data protection authority.

Security

The session cookie is signed and is not readable by scripts in your browser. Card details never reach us. No service is perfectly secure, and the unlisted image URLs described above are shareable by design - anyone you give a link to can open it.

Children

The service is for adults. We do not knowingly collect data from anyone under 18. If you believe we have, email us and we will delete it.

International transfers

Our processors operate in the United States and the EU, so your data may be transferred outside your country under the standard contractual clauses those providers offer.

Changes

We may update this page. The date at the top is when it last changed substantively, and we keep a record of which version of our policies each account accepted.

Contact

hello@tryperso.com.