Privacy Policy
Last Updated: June 28, 2026
Our Commitment to Your Family's Privacy
We know that the photos you entrust to Phossil AI aren't just files; they are your most precious memories. Before the legal details, here are our core promises to you in plain English:
- You own your photos. We don't. You can export or delete them at any time.
- We will never sell your photos or personal data to advertisers or third parties.
- Our AI is used solely to organize your private account. We do not use your photos to train public AI models.
This Privacy Policy describes how Phossil AI ("we," "us," or "our") collects, uses, and discloses information, and what choices you have with respect to the information. By using our Services, you agree to the Terms of Service and this Privacy Policy.
1. Information We Collect
A. Information You Provide Directly
- Account Information: When you create an account, we collect your email address, name, and password.
- Payment Information: If you purchase a tier, credit pack, or platform access, our third-party payment processor (Stripe) collects your financial information. We do not store full credit card numbers on our servers.
- User Content (Your Photos): We collect and store the photographs and images you upload to the Service ("User Content"), along with any associated metadata (such as existing filenames).
B. Information Generated by AI Processing (Biometric Data)
To group photos by person and to estimate when a photo was taken, Phossil works with face data. Depending on the feature and your settings, this happens in one or both of the following ways:
- On your device (face grouping): When you turn on face grouping, your device creates a numeric "faceprint" of each face in your photos so it can gather pictures of the same person together for you. A faceprint is biometric information under laws such as the Illinois Biometric Information Privacy Act (BIPA). It is created and stored only on your device, is never uploaded, and never leaves your device. To help organize and date your archive, three things that are not the faceprint are saved to our servers: a rough age estimate for each face, where each face sits in the photo (a bounding box), and the name you give that person. When face grouping is on, faces are also blurred on your device before a photo is sent to our cloud for dating and tagging, so the cloud only ever sees a face-blurred copy. Learn how on-device face grouping protects your family.
- On our servers (facial recognition service, decommissioned): A previous server-side facial recognition service has been fully decommissioned as of June 2026. All server-side facial templates, face indexes, and biometric data from this service have been permanently deleted. No biometric identifiers or faceprints are stored on our servers. Only the on-device approach described above is available.
- Visual Metadata: Our AI analyzes images for visual cues (such as clothing styles, photo texture, or film type) to estimate the date the photo was taken.
2. How We Use Artificial Intelligence
This is crucial: We use AI technologies solely to provide the Phossil AI service to you and your invited family members.
- For face grouping, the work of recognizing a face happens through a faceprint. With on-device face grouping that faceprint is created and used only on your device and is never uploaded to us. A previous server-side facial recognition service has been fully decommissioned; no biometric identifiers or faceprints are stored on our servers (see Section 1).
- We use generative AI models to create "Living Portrait" animations upon your request.
We do NOT use your User Content, faceprints, or facial templates to train general-purpose, public artificial intelligence models. Your data remains isolated within your account's scope.
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the Service.
- Process your transactions.
- Send you technical notices, updates, security alerts, and support messages.
- Respond to your comments and questions and provide customer service.
4. How We Share Your Information
We are not in the business of selling your data. We do not share your personal information or User Content with third parties for marketing or advertising purposes.
We only share information in the following limited circumstances:
- Service Providers: We may share information with third-party vendors who need access to perform services for us. These partners are strictly prohibited from using your data for any purpose other than providing these services to us. Our service providers include:
- Cloud Infrastructure: Industry-standard secure cloud providers for hosting and storage
- Payment Processing: Stripe
- AI Processing: Google Cloud Platform (photo analysis, which receives face-blurred copies when face grouping is on), Replicate (video generation)
Our AI processing partners process your photos solely to provide the Service. Per their enterprise data policies, they do not use your content to train their models and do not retain your data beyond the processing request.
- Legal Requirements: We may disclose information if required to do so by law or in the good faith belief that such action is necessary to comply with legal obligations or protect the safety of any person.
5. Data Retention and Security
We retain your User Content for as long as your account is active. The faceprints created by on-device face grouping are stored only on your device, never on our servers, and you can delete them at any time (see below). Any server-side facial templates and the data tied to your face grouping are retained as described below. We employ industry-standard security measures designed to protect your information from unauthorized access, including:
- Encryption: All data is encrypted at rest and in transit using TLS 1.2+ and AES-256 encryption standards.
- Access Controls: Biometric data access is restricted to automated systems; human access requires explicit authorization and is logged.
- Secure Infrastructure: We use enterprise-grade cloud providers with SOC 2 Type II compliance.
However, no internet transmission or electronic storage method is 100% secure, and we cannot guarantee absolute security.
Biometric Data Retention Policy
The faceprints created by on-device face grouping live only on your device, never on our servers, so your device is what deletes them. For those faceprints, for the age, location, and name data tied to face grouping, our retention and destruction schedule is:
- When you turn off face grouping, switch to a different account, or delete your face data: Your device clears its local faceprints right away.
- When you forget a person: We remove the affected face groupings.
- When you delete a photo: Any face data associated with that photo is removed.
- When you delete your account: Your User Content, face groupings, the age, location, and name data tied to face grouping, and any server-side facial templates are permanently deleted from our active servers.
- Inactivity backstop: If you go three years without using face grouping, your device deletes its faceprints the next time you open it. Any server-side facial templates and the data tied to face grouping are deleted within 3 years of your last activity, or once their purpose is satisfied, whichever comes first.
We do not sell, lease, trade, or otherwise profit from your biometric data. Your face data is used solely to provide the face grouping feature within your private account and is never shared with third parties for commercial purposes.
6. Your Rights and Choices
- Access and Export: You may access and download your User Content at any time through the Service interface. You may also request a complete copy of your personal data, including the metadata and face groupings associated with your account, by contacting us.
- Data Portability: Upon request, we will provide your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) to facilitate transfer to another service.
- Deletion: You may use Forget or turn off People in Settings to remove your face data, delete photos individually, or delete your entire account via your account settings. When you delete your account, your User Content, face groupings, and any server-side facial templates are permanently deleted from our active servers within 30 days. You may also request deletion by contacting us directly.
- Withdraw Consent: You may withdraw your consent to biometric data processing at any time by deleting your photos or account. This does not affect the lawfulness of processing based on consent before its withdrawal.
7. Children
Our Service is intended for use by adults to archive family history. We do not knowingly collect personal information directly from children under 13. If you become aware that a child has provided us with personal information without parental consent, please contact us.
8. Changes to This Policy
We may change this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service to provide you the opportunity to review the changes before they become effective.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us.