Privacy Policy
Last updated 2026-09-23
Effective date: The changes in this version take effect on 23 October 2026, 30 days after we published them. Until then, no photo of yours is sent to Venice, and we collect none of the three new things listed below: how you found us, ad click references, and the record of which planner tools you use. Last updated: 23 September 2026
What changed and why
We promised to tell you at least 30 days before we change who handles your photos. This is that notice. Here's what's different, in plain terms:
- Retouching, and the finishing of Virtual You looks, now use an outside image model, run by a company called Venice. Your photos are sent to it to be retouched when a person on our team works your order. Venice has another company, BytePlus Pte. Ltd., in Singapore, do that processing. We chose Venice deliberately, for its privacy terms, and rather than summarise those terms into something that sounds better, we quote them word for word in Section 8.
- A new way to have your photos retouched is coming: eyes-off retouching. It isn't available yet; this policy describes it now so you know before it launches. No one on our team will open your photos in the normal course of the order. You're the reviewer: you get 4 tries per photo and keep all of them, and if none is right you can hand that photo to a person at no extra cost. That person will then see it. It's a choice, not a recommendation, and the exceptions are spelled out in Section 7.
- Google Cloud and Anthropic are off our list. We don't use either of them for anything involving your data.
- We'll note how you found us. When you create a free account, we save which of our starting points brought you in and the campaign tag on the link you followed, so we can learn which of our guides actually help people. Details in Section 2.
- We'll tell Google or Microsoft when one of their ads led to a sign-up. If you arrive from one of our search ads and then create a free account, we report that ad's click reference back to the company that ran it, and nothing else: no name, no email, nothing you told us. Your browser's Global Privacy Control signal switches it off. Details in Section 2.
- We'll keep a record of which planner tools you use. Things like "finished the quiz" or "opened the planner", filed under a random code instead of your email, kept for 12 months, and never containing your profile answers, your body profile or anything from your photos. Details in Section 2.
If you'd rather your photos weren't handled by Venice, you can delete your data before 23 October 2026 (see Section 11). That window is the reason for the 30 days.
The short version
You're about to hand intimate photos of yourself to a company on the internet. You deserve to know precisely what happens to them. Here it is, in plain terms — and every one of these is spelled out properly further down.
- Your images are encrypted — in transit, and at rest in our storage.
- We never sell them. We never share them. Not with advertisers, not with anyone.
- We never train AI on your photos — with exactly one carve-out, below, which we are not going to bury.
- You own your likeness — plus your photos and your finished images. We make no claim on any of it.
- Everything derived from you gets deleted too — your images, any model trained from you, and any stored descriptions or metadata about you — on schedule, or when you ask. Most of it disappears from the live service straight away, and we confirm it's done in writing within 48 hours.
- They're deleted after 30 days by default — automatically, without you having to remember. You can extend that, shorten it, or ask us to purge everything at any time.
- Only named companies touch your data, and we tell you exactly what binds each one. For the company that retouches your photos, that means its own words, quoted. The full list is in Section 8.
- You can ask for a copy of everything, or ask us to delete all of it, at any time, and we'll do it.
- We only ever process photos of you — which is why we verify your ID before any work starts. Until that check passes your uploads are sealed: our staff tools don't display them, and every access is logged.
The one carve-out, stated up front
If you order Virtual You, we train a private AI model of you. That is the service. New images that genuinely look like you can't be conjured from nothing — something has to learn your face and your body. So we train a small model from your photos and nothing else, use it only to make your pictures, keep it encrypted and isolated, never hand it to a vendor as theirs to use, never let it touch another customer, and delete it when we delete your photos. It's a tool for filling your order, not something we keep.
If you order retouching only, none of that happens — no model of you is trained, full stop.
We could have written "we never train AI on customer data" and quietly done the above anyway. Plenty of companies would. We'd rather tell you the exact shape of it, because a promise you can check is worth more than one you can't.
One other thing we deliberately do not claim: we don't tell you your photos never leave hardware we own. They do. Our own systems run on dedicated hardware that we lease and operate — not shared cloud — with its disks encrypted. But retouching, and the finishing of Virtual You looks, send your photos to an outside image model, Venice's, and Virtual You training runs on GPU capacity we rent. What we can tell you is exactly who those companies are, what binds each of them (for Venice, in its own words), and what we encrypt before anything reaches the GPUs we rent.
1. Who's responsible for your data
Boudoir Central is operated by Clarovi Technologies, LLC ("we," "us," "our"), which is the data controller for the personal information described here.
- Email: [email protected]
- Privacy contact: [email protected]
- Postal address: available on request via [email protected]
- Where we operate: Boudoir Central is a US service, directed to residents of the United States and the United Kingdom. We do not market to, or offer our services in, the EU or EEA.
If you use Boudoir Central through a photographer's white-label service, the photographer is the controller for their client's data and we act as their processor — see Section 13.
2. What we collect
If you only read the site
Nothing that identifies you personally beyond the basics your browser sends (IP address, browser type) and what our server needs to log to stay secure and rate-limit abuse. For traffic statistics we run our own self-hosted, cookie-free analytics — it sets no cookies, builds no profile, follows you nowhere, and sends nothing to a third party. That is why this site has no cookie consent banner: there is no non-essential cookie to consent to.
If you sign up for the free newsletter or checklist
Your email address, and your name if you give it.
If you create a free account
- Account basics: your email address and your preferences. There is no password — you sign in with a single-use link we email you, so there is no password for us to store and none for you to have reused somewhere else.
- Equipment and space profile: what camera or phone you have, your tripod and lights, the rooms available to you.
- Body profile and comfort boundaries: your body type, what you'd like to flatter or conceal, and what coverage levels and pose types you are and aren't comfortable with.
- What you save, favourite, and plan.
- How you found us: which of our starting points brought you in (doing it yourself at home, doing it on a budget, or feeling nervous about it), and, if you followed one of our links or ads, the campaign tag on it (for example "search ad" or "spring guide"). It's saved with your account when you create it, and deleted with your account. It never includes an ad click reference, and never the words you typed into a search engine.
- Which planner tools you use — see the next part.
That body profile is genuinely personal, and we treat it that way. It exists to make recommendations fit you instead of a default. It is never shown to other customers and never sold or shared; inside our company, access is limited to the people who need it to help you, and it's logged. You can edit or clear it whenever you like.
The record of which planner tools you use
Once you have an account, we keep a simple log of the steps you take in the planner, so we can see which parts help and which ones people give up on. Each entry is one thing from a short, fixed list, like "finished the quiz", "opened the planner", "marked a step done" or "started an order", and the hour it happened.
- What's never in it: your profile answers, your body profile, your comfort boundaries, anything you typed, your photos, and anything worked out from your photos. The list of things it can record is fixed in our code, and none of those are on it.
- How it's filed: under a random code that stands in for your account, not your email or your name. That code still connects to your account inside our own systems, which is what lets us include it when you ask for a copy of your data and delete it when you ask us to.
- Where it lives: on our own systems. It isn't sent to any outside company, including our analytics and the ad companies described next.
- How long: 12 months. After that we keep only totals, like "how many people finished the quiz that week", which identify no one.
If you arrived from one of our search ads
When you click one of our ads on Google or Microsoft Bing, that company adds a click reference to the link: a code that identifies that one click. If you then create a free account, we tell the company that ran the ad that this click led to a sign-up, and when. That's all it receives.
- We never send your name, your email (not even a scrambled "hashed" version of it), or anything you told us. The click reference never goes near your photos, your profiles or your orders.
- Until you sign up, the click reference is held in your browser (not in a cookie), and if you never sign up it never reaches us.
- If your browser sends a Global Privacy Control signal, we don't keep the click reference at all, and nothing is reported.
- How long: we delete the click reference once it's been reported, or after 90 days, whichever comes first. It's also deleted with your account.
There are no ad pixels or ad-company code on this site. The report is sent by our server, and the click reference it carries is one Google or Microsoft created in the first place.
If you buy something
- Your photos — the images you upload for retouching or as Virtual You source material, and the finished images we produce from them.
- Order details — what you ordered, the options you chose, your instructions to the artist, and our notes about the work.
- Payment information — handled by our payment processor. We receive a confirmation, the last four digits of the card, and billing details. We never see or store your full card number.
- Identity verification — a government-ID check and a selfie liveness check, run on our own self-hosted service rather than by an outside vendor (see Section 6).
If you contact us
Your name, email, and whatever you write to us, so we can reply and keep track of the conversation.
3. What we do with it, and why
| What we do | What it uses | Our lawful basis |
|---|---|---|
| Run your account and the free tools | Account basics, profiles | Performing our contract with you |
| Personalise looks, poses, and your walkthrough | Equipment + body profile | Performing our contract with you |
| Deliver retouching and Virtual You | Your photos, order details | Performing our contract, plus your explicit consent for the intimate images themselves |
| Train your private Virtual You model | Your photos only | Performing our contract, plus your explicit consent |
| Verify you're 18 and that it's you | ID document, selfie, result | Legal obligation and our legitimate interest in preventing serious abuse; explicit consent where biometric matching is used |
| Take payment, keep tax records | Payment and order data | Performing our contract; legal obligation |
| Answer your messages | Contact details, your message | Legitimate interest in supporting customers |
| Send the newsletter you asked for | Email address | Your consent — unsubscribe any time |
| Keep the service secure and stop abuse | Logs, limited account data | Legitimate interest in security |
| Learn which of our guides and campaigns help people | How you found us (starting point and campaign tag) | Legitimate interest in improving what we publish |
| Understand which parts of the planner help, so we can improve them | Which planner tools you used, and when. Never your profile answers, body profile or photos | Legitimate interest in improving the product |
| Find out whether our search ads work | Ad click reference, and the date you signed up | Legitimate interest in measuring our advertising. Your browser's Global Privacy Control signal turns it off |
Two things that row four and row five do not mean. Retouching never trains a model of you — that row applies only to Virtual You orders. And no photo of yours ever trains anything shared — the only model your images touch is the private one that exists to make your pictures.
We do not do behavioural advertising, we do not build advertising profiles, and we do not sell data to anyone. There is no version of this business where that becomes a good idea.
About "special category" data
Intimate photographs of an identifiable person, and the private likeness model we train from them, are treated by us as special category / sensitive personal information — the most protected tier under the privacy laws that apply to us: US state privacy law, and UK data-protection law for our UK customers. Our basis for handling them is your explicit consent, given when you place an order, and you can withdraw it at any time (see Section 11).
4. What actually happens to your photos
Most privacy policies stop at "we process your images." Here's the real sequence, because you should be able to picture it.
-
Upload. Your photos travel over an encrypted connection (TLS) and land in our storage encrypted at rest. They're tied to your account and your order, and nothing else. Two kinds of image go to two different places: photos of you are the sealed kind described next, while reference images you send purely for inspiration — a look you like, a corner of a room — are visible to the team by design, because their whole job is to be looked at.
-
Sealed. From the moment they land until your identity check passes, the photos of you are sealed: our staff tools do not display them, nobody picks up the order, and every access to them is written to an audit log. We'll be exact about what that is — a control we operate and record, not a lock we couldn't open. What we can promise is that access is restricted and recorded, and we'd rather say that than something grander that isn't true.
-
Identity check. You verify that you're 18 or over and that you are who you say you are (see Section 6). Nothing happens to your photos before this passes — no artist opens them, no model is trained, no image is generated. If it never passes, your order is refunded and the photos are deleted.
-
Who opens your order. For person-led retouching and Virtual You, with verification behind us, a digital artist opens your order. This is the point where we check the photos are of you — the check means something now that we know who "you" is — that they're within our content standards, and that they're something we can actually deliver well on. When eyes-off retouching launches, no one on our team will open those orders. Instead, you'll confirm at upload that the photos are of you, or that everyone pictured has explicitly agreed, and an automated safety check will run on each photo. It looks for two things: signs that the person pictured may be under 18, and content that appears illegal or non-consensual. The exceptions, including when a person may still see a photo, are in Section 7.
-
Retouching orders are person-led, and will come two ways, at the same price, once eyes-off retouching launches.
- Person-led retouching (the default) is worked by that artist using professional tools — including AI-assisted tools inside their own manual workflow, one of which is Venice's image model (see Section 8) — to do exactly what you selected on the order form. Nothing else gets "fixed," your body is never altered — the finish works on colour, light, background and polish, never on your shape — and a person checks every image against that before you see it.
- Eyes-off retouching (coming) will retouch your photo automatically, without a person on our team opening it. We're still choosing and testing how it will work: which software, where it runs, and which finish levels it can honestly offer. Before it launches we'll update this policy with exactly that, and if it involves any company not already on the list in Section 8, you'll get the same 30 days' notice. What's already decided: you'll get up to 4 tries per photo (the first, plus 3 redos), you keep all of them, and you can hand that photo to a person at no extra cost.
Either way, no model of you is trained.
-
Virtual You orders additionally involve training a small, private model on your photos. In practice: the source photos you supplied are normalised into a consistent reference set and expanded into a training set — different angles, lighting, and clothing — whose job is to teach the model your face and your proportions accurately. Those are captioned for pose, clothing, and lighting, and used to train a LoRA: a small adapter file that teaches an image model what you look like. The artist then uses that adapter to produce your looks, and finishes them.
Building the reference and training set, training the adapter, and generating your looks from it run on image models we run ourselves, on dedicated GPU capacity we rent under contract (see Section 8). The artist's finishing of your looks uses Venice's image model, so those images are sent to Venice. Your adapter itself is never sent to Venice or to any other outside company.
What's changed about where your photos go. We used to say, simply and absolutely, that nothing of yours was ever sent to a general-purpose image API. That's no longer true, and we'd rather retire the sentence than stretch it: your photos are sent to Venice to be retouched, and your Virtual You looks are sent to it to be finished. Venice is named, with its own words about what it does with them, in Section 8. No other outside AI service receives your photos or the images we make from them.
-
GPU compute. For Virtual You, training a model and generating images need a powerful GPU, and some of that capacity is rented (see the RunPod row in Section 8). Before your photos go anywhere near it, they are encrypted with our own keys. On the compute machine they are decrypted into isolated memory only — never written to that machine's disk — the trained adapter is re-encrypted before it comes back, and the whole compute environment is destroyed when the job ends. We keep an internal audit record of each job so we can prove that happened.
-
Human QA, for person-led orders. In person-led retouching and Virtual You, a person reviews every image before it's released to you. Eyes-off retouching, when it launches, will have no human QA: you are the reviewer. You'll get up to 4 tries per photo and keep all of them. If none is right, you can hand that photo to a person, at no extra cost. That handover is per photo, you confirm it, and the person it goes to will see that photo.
-
Proofs, then approval, then delivery. You review watermarked proofs first, in your own time. Ask for changes, or approve them — and on approval the full-resolution images appear in your account and we email you. In eyes-off retouching, your tries are the proofs: each try is a watermarked proof, and picking one approves it and releases it at full resolution. Either way, your order stays fully refundable until you approve.
-
Deletion. 30 days after delivery, by default, your source photos, your finished images, and your private model are deleted automatically — unless you've chosen to keep them longer.
5. Your Virtual You model, specifically
This is the carve-out we flagged at the top — the one place we do train AI on your data — so we'll be exact about it.
The model we train from your photos:
- is trained only on photos you submitted, and on nothing else;
- is never combined with another customer's photos, and never contributes to any shared, public, general-purpose, or cross-customer model;
- is used only to produce images for you, on your order;
- is stored encrypted and isolated, keyed to your account;
- is never handed to anyone else for their own use — it isn't uploaded to a model hub, it isn't sold, licensed, or shared, and it stays encrypted wherever it sits. When a rented GPU has to load it to make your images, it travels there encrypted and exists only in that machine's memory for the length of the job. The model itself never goes to Venice; the looks made with it do, when the artist finishes them (see Section 4);
- is treated as sensitive data in its own right — it's derived from your likeness, so it gets the same protection your photos do;
- is deleted whenever you ask — always, no conditions — along with any stored descriptions or metadata derived from you. It leaves the live service straight away, and we confirm the deletion to you in writing within 48 hours;
- is deleted with your photos by default. If you'd like to order more looks later without redoing the guided photo set, you can choose to keep your model on file instead. That is entirely optional and free, and you can still delete your source photos while keeping it — the model stays encrypted and isolated, keyed to your account, exactly as it is during an order;
- if kept, is deleted automatically after 90 days without a login, and whenever you close your account. Nothing built from your face sits here indefinitely.
Your likeness stays yours. We don't claim it, we don't keep a model of you as a company asset, and there is no version of this where something built from your face outlives your account.
Your photos are never used to improve our products for anyone else. The look library on our site is generated from fictional characters we invented, never from customers. There is no scenario in which a customer's photo, or a model derived from it, produces an image for someone else.
And to close the loop on the honest version of the promise: if you never order Virtual You, no model of you is ever trained. Retouching is editing, not learning.
6. ID verification
Before any work starts on your photos, we verify that you are 18 or over and that you are who you say you are, using a government-ID document check and a selfie liveness check that runs on our own self-hosted verification service, on infrastructure we operate. This is the one part of the service with no subprocessor at all — which is why you will not find an identity-verification vendor in Section 8. We chose it that way deliberately: a government ID and a face scan are the most sensitive things this service will ever hold, and the safest number of outside companies to hand them to is none. You can order and upload straight away — verification is the gate on work starting, not on ordering. Until it passes, your uploaded photos are sealed: our staff tools do not display them, and every access to them is written to an audit log. That is a control we operate and record rather than a lock we couldn't open, and we'd rather say so plainly. Once verification passes, the artist opens your order — and that is where we check the photos are of you. In eyes-off retouching no artist opens it, so that check rests on your confirmation at upload and on automated checks instead (see Section 4).
How it works:
- You submit your ID and selfie to our own verification service, running on infrastructure we operate. No outside company sees your document or your selfie.
- The biometric comparison happens there, on infrastructure we operate.
- One other face comparison, for eyes-off Editorial retouching (once it launches): to make sure every retouched version still looks like you, our software compares the face in your photo with the face in each result. It runs on infrastructure we operate or rent under contract (never an outside AI service), the face measurements exist only in memory for that comparison, and they are never stored. Only the pass or fail is kept, with the order.
- Your account record holds the result — pass or fail, your verified name, your date of birth or an over-18 flag, and a reference number — which is the minimum record needed to show we ran the check.
- We do not keep a copy of your ID document, and we do not keep the biometric template. The document and the selfie are deleted from that service automatically within 48 hours of the check.
Selfie liveness matching is biometric processing, so we ask for your explicit consent before it happens — and there is always a way through without it. If the automated check fails, or if you'd simply rather a person did it, ask us and a member of our team will review the same documents by hand and decide. You never have to accept an automated decision about whether you are who you say you are. We offer this partly because it's your right, and partly because automated face matching is measurably worse at recognising some people than others, and that should never be your problem.
7. Who can see your photos inside our company
A very small number of people: the digital artist working your order, and whoever is handling support if you've written in about it. Access is limited to the people who need it to do the job, and it's logged.
Eyes-off retouching is coming, and this is how it will work. If you choose it, nobody on our team will open your photos in the normal course of the order, and no artist will be assigned to it. Exactly where the automated retouching runs is still being decided, and we'll say so here before launch (see Section 8). A person inside our company could see an eyes-off photo in three situations, and we'd rather list them than bury them:
- You hand it to a person. If you switch a photo to person-led retouching, the artist who takes it will see that photo. Nobody makes that switch but you.
- The safety check flags it. Every eyes-off photo goes through an automated safety check that looks for signs the person pictured may be under 18, and for content that appears illegal or non-consensual. If it flags a photo, a trained person on our team may need to look at that photo to decide what happens next.
- An administrator reaches it. Our tools won't show eyes-off photos to staff, and any access will be logged, but we won't tell you it's impossible: what we say below about administrator access applies to eyes-off photos too.
Being straight about what "working on your photos" means: there is no way to retouch an image without seeing it, so the artist on your order downloads decrypted working copies onto a work computer to do the editing. Those downloads are logged, and the working copies are deleted along with the rest of your data.
Browsing customer photos is not a thing anyone here is allowed to do, and the tools are built so it isn't a thing anyone falls into: there is no internal gallery and no "look at this one" channel, access is scoped to the order a person is actually working, and every open is logged and reviewable. We won't tell you it's impossible — an administrator with the right access could reach a file, the same as at any company that holds your data. What we will tell you is that doing it would be a policy breach, that it would leave a record with a name on it, and that we treat that record as the point. And there is no marketing use of your images unless you specifically opt in and can opt out again.
8. The companies that help us run this (subprocessors)
We don't run every piece of this ourselves — nobody does. Here's every company that processes data on our behalf, what they do, and whether your photos are involved.
| Subprocessor | What they do for us | Does it involve your photos? | Where |
|---|---|---|---|
| RunPod, Inc. | Dedicated secure-cloud GPU compute, where your Virtual You model is trained and your images are generated | Yes — for Virtual You. Your source photos and the images we generate reach it only in encrypted form, are decrypted solely into isolated memory for as long as the job runs, and are deleted when the compute instance is destroyed at the end of the job | USA |
| Venice.ai, with BytePlus Pte. Ltd. doing the processing on Venice's instructions | Runs the image model that retouches your photos and finishes your Virtual You looks: as one of the tools our artists use | Yes — your photos and your Virtual You looks are sent to it to be retouched or finished. What Venice says it keeps, and when it deletes, is quoted in full below | BytePlus: Singapore. Venice is a US company: its terms say it operates its service from offices in Wyoming |
| Stripe, Inc. | Taking payment, storing card details, handling refunds | No | USA |
| Amazon Web Services (Amazon SES) | Sending account, order, and support email — sign-in links, receipts, and the notes you ask for. Message content passes through it in transit | No — email only, never an image | USA |
One thing is deliberately missing from that table: identity verification. There is no row for it because there is no company to name — the ID and liveness check runs on our own self-hosted service, on infrastructure we operate (see Section 6). It is the only part of this service with no subprocessor at all, and it is the part that most deserved one fewer company.
On the GPU row specifically, because it's the row where your images are actively worked on rather than merely stored. Making new images that look like you takes a powerful GPU, and we rent that capacity on dedicated, non-shared secure-cloud instances rather than buying a data centre. What that means for your photos in practice: they leave our storage already encrypted with keys we hold, they are decrypted only into memory on the compute instance — never onto its disk, and never onto shared or network storage — the trained model file is re-encrypted before it comes back, and the instance itself is destroyed when the job finishes, which is the deletion event. We keep an audit record of every job. Retouching orders don't involve this step: they use Venice, below.
On the Venice row specifically, because it's the one place a company outside ours actually edits your photo. We chose Venice on purpose, and the reason is its privacy terms: what they say about keeping your photo, deleting it, and not training on it. Those are Venice's promises, not ours, so we won't restate them in our own words and risk making them sound stronger than they are. Here they are verbatim, from Venice's Privacy Policy (effective 2 June 2026) and Terms of Service (last updated 8 June 2026), as they read on 23 September 2026. Where Venice says "you" and "your account", it means us: we're the one uploading your photo, so we're Venice's customer.
On who processes a photo of a person, and what they may use it for:
"We do not store your likeness images, videos, or biometric feature data on our servers. Processing and short-term storage of the image and video is carried out by BytePlus Pte. Ltd. (Singapore), acting solely on our instructions for the specific generation you requested. BytePlus does not use your likeness data for any unrelated purpose, and we do not use your likeness data for any of our own business purposes."
On deletion, and what Venice keeps afterwards:
"For compliance and audit purposes, we will retain minimal anonymized metadata in the form of a cryptographic hash of the uploaded image or video, the timestamp, your consent record, and an internal asset identifier, linked to your account. This metadata is not biometric data and cannot be used to reconstruct your likeness or biometric identity. We will delete any image or video from our temporary upload storage within 1 hour. BytePlus is instructed to delete any such image or video immediately after your generation completes."
On the model providers behind Venice:
"We operate a zero data retention policy with our model providers in which our model providers are prohibited from storing, retaining, or using any of your Prompts or Outputs beyond the time strictly necessary to process and return a response."
On training, from Venice's Terms of Service:
"Notwithstanding anything to the contrary, Venice.ai agrees that it shall not use, and shall require that third-party large language model providers ("Third-Party LLM Providers") do not use, any User Content to train any machine learning, deep learning, or statistical learning algorithms, LLMs, neural networks, or models."
And on the connection itself, from Venice's API documentation: "requests pass through the Venice proxy over encrypted connections."
Plainly, so nothing is hidden in the quotes: Venice keeps a hash of each image, a timestamp, a consent record and an asset ID, linked to our account with Venice. Venice's policy says that record can't be used to rebuild your likeness. The consent record is there because Venice asks, every time a photo of a person is uploaded, for confirmation that the photos are of the uploader or that the person pictured has explicitly agreed. That's why we ask you the same thing when you upload (see our Terms of Service). One more thing you should know: Venice's policy says a revised version "will be effective when it is posted," so the quotes above are accurate as of the date we give, not forever.
So we watch it, and this part is our promise. We automatically check Venice's Privacy Policy and Terms of Service against the sentences we quote above. If any quoted promise is weakened or removed, we treat that as a change to this list, with the same 30 days' notice to account holders that we give for any other change to it (see "Changes to the list," below).
What we promise about this list, precisely. RunPod, Stripe and Amazon SES are each bound by a written contract to process your data only on our instructions, to keep it confidential and secure, and never to use it for their own purposes, including never using it to train their own models.
Venice is different, and we'd rather say so than blur it. We use Venice on its standard published terms. We have no separate contract with it. What binds Venice is its own Privacy Policy and Terms of Service, the words quoted above, and we won't promise you anything about Venice beyond what they say. What we control is what we send it and when: your photo goes to Venice only after your identity check has passed (see Section 4), and only to be retouched.
We select vendors on the protections they actually provide, and where your images are involved we add our own on top where we can. For the GPUs we rent, that's encryption with keys we hold, decryption into memory only, destruction of the compute environment, and an audit record of every job. We're not going to tell you more than that. In particular, we're not going to claim that every vendor's standard terms were written with intimate photography specifically in mind — that would be a nice sentence and not a true one.
In plain language: using named vendors puts your photos in roughly the same position as photos a working photographer sends to the software and services they edit with, which is what the studio you might have booked instead does too. It isn't a magic shield and we won't pretend it is. What we add on top is the part most people don't get: encryption with our own keys before your images go to any GPU we rent, automatic deletion on a 30-day clock, a published list of exactly who is involved, the exact words of the company that retouches your photos, and our promise that we never sell your images, never share them, and never use them to train anyone else's model.
Changes to the list. When we add or replace a subprocessor that handles your images, we'll update this page and email account holders at least 30 days before the change takes effect — not after. If you'd rather not have your images handled by the new company, you can delete your data first, and that window exists precisely so that choice is a real one.
Two companies that receive something from us but aren't on that list: Google and Microsoft. If you arrive from one of our search ads and create a free account, we tell the company that ran the ad that its click led to a sign-up (see Section 2). What they receive is the click reference they created themselves, the fact that it led to a sign-up, and when. They don't do any work for us with it: they use it in their own ad systems, under their own terms, to report on and run our ads, so we don't list them as companies acting on our instructions, and we won't pretend our contract promises above bind them. It never involves your photos, your name, your email or anything you told us, and your browser's Global Privacy Control signal stops it entirely.
We may also disclose data if the law genuinely requires it (a valid legal process), or to protect someone from serious harm. We will tell you if that happens unless we're legally barred from doing so.
If our business is ever sold or reorganised, your data may transfer to the successor — and your privacy settings, retention choices, and deletion rights travel with it.
9. How long we keep things
| What | How long |
|---|---|
| Your uploaded photos and finished images | 30 days after delivery by default. You can extend it, shorten it, or purge on request — completed and confirmed within 48 hours |
| Your Virtual You model, and any captions or metadata derived from you | Deleted with the photos it was trained from — unless you choose to keep it on file for future orders (free, optional). If kept: deleted after 90 days without a login, when you close your account, or on request — completed and confirmed within 48 hours |
| Private gallery (if you opt in) | For as long as you keep it, until you delete it or close your account |
| Account and profile data, including how you found us | Until you close your account |
| Record of which planner tools you use | 12 months, then kept only as totals that identify no one. Deleted with your account |
| Ad click reference | Until it's been reported to the ad company, and at most 90 days. Deleted with your account |
| Order and payment records | 7 years, as US tax and accounting law requires |
| ID verification result | The minimum period required to demonstrate compliance with age-verification law, and then deleted. We keep the outcome and a reference number — never your ID document or the biometric template |
| Support emails | 24 months |
| Newsletter subscription | Until you unsubscribe |
| Security logs | 90 days |
About backups and timing, honestly. When you delete something, most of it leaves the live service straight away. We commit to completing the deletion and confirming it to you in writing within 48 hours — the gap is deliberate, because it covers the pieces that live in more than one system and it means the confirmation you get is a real one rather than an optimistic one. Encrypted backups roll over on a schedule, so a deleted file can persist inside an encrypted backup for up to 35 days after that. Backups are encrypted, are never used to restore individual deleted content, and anything restored from one is re-purged.
10. How we protect it
- Encryption in transit (TLS) and at rest for everything, including your images.
- Envelope encryption with our own keys for any image that goes to rented GPU compute, with plaintext decrypted into volatile memory only, never to disk, and the compute environment destroyed at the end of the job.
- An encrypted connection to Venice for any photo or look sent to be retouched or finished. What happens to it there is governed by Venice's own terms, quoted in Section 8.
- Isolation: your Virtual You model is stored separately, keyed to your account, and never pooled.
- Least-privilege access for staff, with logging.
- Automatic deletion as the default, so privacy doesn't depend on you remembering.
No system is perfectly secure, and we're not going to pretend otherwise. What we will do is tell you quickly and plainly if something happens to your data, and tell regulators within the deadlines the law sets.
11. Your rights, and how to use them
Wherever you live, you can ask us to:
- Show you what we hold about you.
- Give you a copy of your data in a portable format.
- Correct anything wrong.
- Delete everything — your photos, your finished images, your Virtual You model, any captions or metadata derived from you, your profiles, your account. You don't have to negotiate for it, and nobody will try to talk you out of it. If you use the delete control in your account it runs immediately and issues you a dated deletion certificate on the spot, listing what was removed. If you ask us by email instead, most of it is removed from the live service straight away and we finish the job and confirm it in writing within 48 hours — the 48 hours is our outside limit, not our target.
- Stop or limit a particular use.
- Object to processing based on our legitimate interests.
- Withdraw consent you gave earlier, including consent to process your images. Withdrawing doesn't undo what was lawful before, but it stops everything going forward.
How: email [email protected], or use the controls in your account. We'll respond within 30 days (extendable where the law allows, and we'll tell you if we need longer). We may need to verify it's really you before we act on a request about photos — for obvious reasons.
It's free, and we will never treat you differently for asking. No worse price, no worse service.
If you're in the UK, these are your rights under UK data-protection law, and you can also complain to the Information Commissioner's Office. We'd like the chance to fix it first.
On where we operate, plainly. Boudoir Central is a US service, operated under US and Tennessee law and directed to residents of the United States and the United Kingdom. We do not market to the EU or EEA, we do not target our services there, and we make no claims about EU law. Our free articles and guides are readable by anyone anywhere — that's reading a web page — and the rights listed above are offered to everyone who asks, wherever they live.
If you're in California (or another US state with a privacy law), you have the rights to know, delete, correct, and to opt out of "sale" or "sharing" of your personal information. We never sell personal information, and we have not in the preceding 12 months. There's one thing some privacy laws may call "sharing", and we'd rather name it than argue about the label: when you arrive from one of our search ads, we tell the ad company that ran it, by click reference only, whether that click led to a sign-up (see Section 2). It never includes your name, your email or anything about your photos. Your browser's Global Privacy Control signal turns it off, you can opt out by asking us, and you can ask us to delete it. We don't share anything else. You may also limit our use of sensitive personal information; we already limit it to delivering what you ordered. You can use an authorised agent. Some states let you appeal a refused request: email [email protected] with the word "appeal" and a different member of our team will review the refusal. If we still say no, we'll tell you why in writing and point you to your state regulator.
If you're anywhere else, ask anyway. We apply the same standard to everyone.
12. Cookies and tracking
We use the cookies needed to keep you logged in and keep the site secure. We do not use advertising cookies, and we do not let third parties track you across the web from our site. We don't use ad pixels either. The one thing we report to an ad company is described in Section 2: until you sign up, its click reference is held in your browser rather than in a cookie, and your browser's Global Privacy Control signal turns it off.
Our analytics are self-hosted and cookie-free, so there is no non-essential cookie on this site and therefore no consent banner to click through. The only cookies we set are the ones that keep you signed in and keep the site secure — without them the site cannot work, so they have no opt-out, and they are never used to track you.
13. If you came through a photographer
When a photographer uses our white-label service, they decide what happens to their clients' images and we act on their instructions as their processor, under a data processing agreement. Everything in this policy about encryption, no sale, no sharing, no shared or cross-customer model training, per-client models, and deletion still applies to those images. If you're that photographer's client and want your data deleted, ask them — or ask us and we'll point you to them and support the request.
14. Where your data lives
We're a US company, operating under US law only. We process your data in the United States, and so do RunPod, Stripe and Amazon SES. Venice is a US company too. But the photos and Virtual You looks sent to Venice are processed, and briefly stored, by BytePlus Pte. Ltd. in Singapore, on Venice's instructions (see Section 8). So for those images, the honest answer is: the United States and Singapore.
We don't operate outside the United States. If you live elsewhere and choose to use Boudoir Central, your data is handled exactly as this policy describes, in the places this section names.
15. Children
Boudoir Central is strictly for adults, 18 and over. We don't knowingly collect information from anyone under 18. If we find that we have, we delete it straight away and close the account. If you believe a minor has used our service, please tell us at [email protected].
16. Changes to this policy
Privacy policies change as products do. When we make a material change — especially one about how your photos are handled, or who processes them — we'll post the new version here with a new date and email account holders at least 30 days before it takes effect. If you don't want to continue under the new version, delete your data and close your account, and we'll be sorry to see you go.
17. Talking to us
- Privacy questions, access and deletion requests: [email protected]
- Contact form: boudoircentral.com/contact
- Postal: Clarovi Technologies, LLC — address available on request via [email protected]
If any part of this policy is unclear, tell us. A privacy promise you can't understand isn't much of a promise.