Privacy policy
Last updated .
What we collect
- The portrait photo you upload is biometric data — special-category personal data under GDPR Article 9. It is sent to Google's Gemini API for the sole purpose of generating your document photo and is not stored on Anfas.Pro servers after the response is returned to your browser.
- The email address you provide at checkout is used to deliver the download link and to issue VAT receipts where required.
- Payment metadata (card last 4, country, currency) is received from our payment provider — we never see the full card number.
- Basic analytics (page visits, country, browser) is collected by Plausible in aggregate, cookieless, and is not linked to your photo or email.
- Error reports are captured by Sentry without your photo, email, or payment data — only stack traces and request metadata.
Legal basis (GDPR)
Processing of your portrait photo is special-category biometric data under GDPR Article 9. The lawful basis is your explicit consent under Art. 9(2)(a), given by the act of uploading the photo after reading this notice, combined with performance of a contract under Art. 6(1)(b). You may withdraw consent at any time by closing the page before payment, or by emailing privacy@anfas.pro after purchase — your download record will be deleted within 30 days.
What we do not do
- We do not sell, rent or share your photo with anyone other than the sub-processors listed below.
- We do not retain your photo on our servers after the generation response is delivered to your browser.
- We do not use your photo to train any model — Google's Gemini API on a paid tier with abuse-review opt-out is configured to not train on your input.
- We do not send marketing emails unless you opt in explicitly.
Sub-processors
The following companies process your data on our behalf as GDPR data processors. Each has its own privacy policy, listed:
- Google LLC / Google Ireland Ltd (Gemini API, United States) — runs the AI model that generates your document photo from the portrait you upload. Cross-border transfer is governed by EU Standard Contractual Clauses.
- Vercel Inc. (United States) — application hosting and serverless functions.
- WayForPay (Ukraine) — payment processing for the €4.99 download fee.
- Plausible Analytics (Germany / EU) — cookieless aggregate page analytics.
- Sentry (United States) — server-side error reporting.
International data transfer
Your portrait photo is transmitted to Google's Gemini API in the United States to generate the document photo. The transfer is covered by the EU Standard Contractual Clauses (SCCs) approved by the European Commission. The image is processed in memory and not retained by Google on a paid-tier API project with abuse-review opt-out enabled.
Your rights
Under GDPR you can request a copy of any personal data we hold about you (Art. 15), correction (Art. 16), deletion (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and you may withdraw consent or object to processing (Art. 21) at any time. To exercise any of these rights, write to privacy@anfas.pro — we respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Data controller
The data controller is the Anfas.Pro operator (ФОП Кравченко Євген Євгенович, Ukrainian sole proprietorship). Contact: privacy@anfas.pro for all privacy questions, or support@anfas.pro for everything else.