Privacy Policy

Last UpdatedFebruary 28, 2026

Welcome to HeadShooter AI (hereinafter referred to as "the Service" or "We"). The Service is operated by the HeadShooter Operations Team. We take your personal privacy and data security extremely seriously and have formulated this Privacy Policy (hereinafter referred to as "this Policy") in accordance with relevant data protection laws and international privacy standards.

Chapter 1: General Provisions and Definitions

1.1 Scope of Application

This Policy applies to the collection, processing, and utilization of personal data generated when you use the HeadShooter website (headshooter.co), mobile applications, API services, and all related functions provided through this platform (collectively referred to as "the Service"). This Policy does not apply to external websites or products operated by third parties that are linked to our Service.

1.2 Term Definitions

  • Personal Data: Refers to data that identifies a natural person, including but not limited to name, date of birth, identity identifiers, characteristics, contact information, financial status, and other data that can directly or indirectly identify that individual (such as email, IP address, image data, etc.).
  • Image Data: Refers to photos and pictures uploaded by users to the platform, as well as generated images resulting from AI computation.
  • Subject: Refers to the person whose personal data is being processed (i.e., you, the user of the Service).
  • Special Categories of Data: Refers to medical records, genetic data, sexual orientation, health checks, and criminal records. As a principle, the Service does not collect special categories of data; please do not provide them proactively.

Chapter 2: Purpose of Personal Data Collection

We collect your personal data based on the following specific purposes:

2.1 Core Service Provision

  • Marketing: Used to recommend style combinations (Composes) that match your interests.
  • Legal Compliance: Used to fulfill legal and regulatory obligations.
  • Contractual Obligations: Fulfilling registration terms and service contracts between you and us.
  • Customer Management and Service: Handling account creation, identity verification, and providing customer support.
  • Information and Communication Services: Providing AI generated images, cloud storage, and network traffic analysis.
  • E-commerce Services: Processing subscriptions, credit purchases, and transaction records.

2.2 Operational and Optimization Purposes

  • Product Improvement: Analyzing user behavior to optimize the accuracy of AI models and algorithms.
  • Communication and Liaison: Sending important update notifications, system maintenance announcements, and security alerts.
  • Security Detection: Preventing fraud, phishing attacks, inappropriate image generation (e.g., distributing pornographic or violent content), and other information security threats.

Chapter 3: Categories and Methods of Collection

We collect the following categories of personal data as required by the Service:

3.1 Data Provided Proactively by You

  • Registration Identifiers: When you register for an account or log in (including via Google, Github, or Apple authorization), we obtain your email address, name, and avatar.
  • Original Image Data: Original portrait photos you upload to the platform. These photos may contain highly identifiable facial features; we use them solely for the specified generation purposes.
  • Payment Assistance Data: When you conduct a transaction, our third-party payment processors (such as Stripe) collect necessary information. For security, we do not directly store your full credit card number or CVC code.

3.2 Technical Data Recorded Automatically

  • Device Information: Including browser type, operating system, mobile device model, and unique device identifier (UDID).
  • Traffic Data: IP address, access time, web browsing history, referral source URL, and clickstream data.
  • Geographic Location: Approximate geographic area (country or city level) estimated via IP address.

3.3 Data Collected via Cookies and Tracking Technologies

We use Cookies and similar technologies (such as Web Beacons, Pixel tags) to analyze trends, manage the website, and track user activities on the site. Please refer to Chapter 7 for detailed information.

Chapter 4: Period, Region, Recipients, and Methods of Utilization

4.1 Utilization Period

  • Account Operation Period: We will retain relevant data as long as your account is in an active state.
  • Statutory Retention Period: For example, accounting regulations or tax laws may require transaction records to be kept for 5 to 10 years.
  • Contract Duration: The time required for the execution of rights and obligations under the service contract.
  • Image Deletion Period: Photos and model data you proactively delete will be completely removed from our backup servers within 14 days.

4.2 Utilization Region

The locations where we utilize personal data include HeadShooter's current or future operational sites and the host locations of our contracted service providers (currently mainly: Taiwan, Japan, US, Singapore).

4.3 Utilization Recipients

We will not provide your personal data to third parties except in the following circumstances:

  1. Sub-processors: To provide stable services, we commission professional technical teams to process data, such as:
    • Cloud Storage: Cloudflare Inc., Amazon Web Services (AWS), Google Cloud Platform (GCP).
    • Payment Processing: Stripe, Inc.
    • Accounting and Customer Support: Related operational auxiliary system providers.
  2. Prior Written Consent: For example, if you authorize us to share your generated stories on social media.
  3. Legal Requirements: Requests from law enforcement agencies, courts, or government authorities according to legal procedures.
  4. Public Interest or Prevention of Harm: To investigate illegal activities or protect the lives and property of others.

4.4 Utilization Methods

We process images through digital automated computations. We guarantee: All image training and generation processes are conducted under strict access controls, and no personnel will arbitrarily view your original images.

Chapter 5: Rights of the User (Data Subject)

You enjoy the following statutory rights regarding the personal data we hold about you:

5.1 Inquiry, Access, or Request for Copies

You can view your data at any time through the account settings interface. If you require a complete data copy (Data Portability), you can apply to us, and we will provide it in a commonly used electronic format. Note: We may charge necessary cost fees according to regulatory standards.

5.2 Supplement or Correct Data

If your personal data is inaccurate or incomplete, you can modify it at any time in the profile settings page or contact customer service for assistance.

5.3 Request to Stop Collection, Processing, Utilization, or Deletion

  • If you no longer need our Service: You can apply to close and delete your account (Account Deletion). Once confirmed, all identifying data associated with you will be thoroughly erased, except where retention is required by law.
  • How to Exercise Your Rights: You can submit a request by sending an email to the address provided at the end of this Policy. We will process your request within 15 days of receipt (extensible to 30 days if necessary).

Chapter 6: Data Security Management and Technical Specifications

We implement security levels consistent with industry standards to protect your personal data:

6.1 Encryption and Transmission Security

  • SSL/TLS Encryption: The platform uses secure communication protocols (HTTPS) throughout. Any information transmitted between your device and our servers is highly encrypted.
  • Data Tiered Storage: Sensitive image data and basic personal data are stored in separated, isolated databases.

6.2 Access Control and Management

  • Principle of Least Privilege: Staff access to data is strictly managed in layers. Only authorized developers can perform necessary operations for fixing system bugs, and detailed access logs are maintained.
  • Isolation Mechanism: During the AI training process, photos enter an encrypted expiration zone immediately after processing to prevent massive leakage in the event of an external attack.

6.3 Incident Response Mechanism

In the event of a security incident, we will immediately initiate emergency procedures. If a major privacy leak is involved, we will notify affected users and report to regulatory authorities according to relevant laws.

Chapter 7: Cookie Policy and Analytics

7.1 Types of Cookies

In this Service, we use the following types of Cookies:

  1. Essential: Used for maintaining login status, cross-page navigation, and transaction security.
  2. Analytical: Such as Google Analytics, helping us understand where users come from and which features are most popular.
  3. Functional: Recording your language settings (Traditional Chinese, Simplified Chinese, English, Japanese) and personalized interface preferences.

7.2 How to Disable

You can refuse Cookies through your browser's settings menu (such as "Privacy and Security" in Chrome). Please note that if you refuse Cookies, some core functions (such as login and checkout) may not work properly.

Chapter 8: AI Model Training and De-identification

8.1 Photo Usage Principles

The core value of HeadShooter is generating professional headshots for you via AI. To this end:

  • Photos you upload (Source Images) are used solely for training specific fine-tuned weights for you personally.
  • Unless you proactively check "Agree to use as official promotion case", your photos will never be used in anyone else's AI generation, nor will they be used to train public large-scale foundation models.

8.2 De-identification Processing

When conducting internal performance testing or algorithm optimization, we will process relevant data for "De-identification" (Anonymization), removing all names and IDs that can be linked to a specific individual, so that the data no longer constitutes personal data.

Chapter 9: Protection of Minors

Our Service is primarily intended for adults with full behavioral capacity. If you are under the age of 18 (or the age of majority in your jurisdiction), please read this Policy with your legal guardian (such as parents) and use the Service only after obtaining their explicit consent.

If we discover personal data of a minor collected without guardian consent, we will proactively delete relevant records and terminate account services.

Chapter 10: Changes to and Effectiveness of this Policy

10.1 Modification and Effectiveness

This Policy will be updated periodically. When there are significant changes to the content, we will notify you through one of the following methods:

  • Pop-up announcement on the official website.
  • In-app message notification.
  • Sending an email to your registered address.

All modifications take effect 14 days after the date of announcement. If you continue to use the Service after the effective date, you are deemed to have agreed to the modified Policy content.

Chapter 11: Miscellaneous Provisions and Dispute Resolution

11.1 Third-Party Links

The Service may contain links to other third-party websites not controlled by us. We are not responsible for the privacy policies of such websites and suggest you review their statements before providing personal data.

11.2 Governing Law and Jurisdiction

The interpretation and application of this Privacy Policy are governed by relevant laws. Any disputes arising from this Policy shall be submitted to the court of competent jurisdiction.

Chapter 12: Contact Us

If you have any questions regarding this Privacy Policy, your data rights, or our security practices, please feel free to contact:

  • Brand and Service: HeadShooter AI
  • Privacy Compliance Center: HeadShooter Operations Team
  • Email: support@headshooter.co
  • Contact Address: Taipei, Taiwan (Contact support for details)

Thank you for trusting HeadShooter AI. We will do our utmost to protect your privacy assets.

Privacy Policy|HeadShooter Docs