Boudoir Central
Menu
← Trust & Privacy

Privacy Policy

Last updated 2026-07-25

Effective date: This policy takes effect when published at boudoircentral.com. Last updated: 25 July 2026


The short version

You're about to hand intimate photos of yourself to a company on the internet. You deserve to know precisely what happens to them. Here it is, in plain terms — and every one of these is spelled out properly further down.

  • Your images are encrypted — in transit and at rest.
  • We never sell them. We never share them. Not with advertisers, not with anyone.
  • We never train AI on your photos — with exactly one carve-out, below, which we are not going to bury.
  • You own your likeness — plus your photos and your finished images. We make no claim on any of it.
  • Everything derived from you gets deleted too — your images, any model trained from you, and any stored descriptions or metadata about you — on schedule, or when you ask. Most of it disappears from the live service straight away, and we confirm it's done in writing within 48 hours.
  • They're deleted after 30 days by default — automatically, without you having to remember. You can extend that, shorten it, or ask us to purge everything at any time.
  • Only named companies touch your data, each under a contract that says they work on our instructions and nothing else. The full list is in Section 8.
  • You can ask for a copy of everything, or ask us to delete all of it, at any time, and we'll do it.
  • We only ever process photos of you — which is why we verify your ID before any work starts. Until that check passes your uploads are sealed: our staff tools don't display them, and every access is logged.

The one carve-out, stated up front

If you order Virtual You, we train a private AI model of you. That is the service. New images that genuinely look like you can't be conjured from nothing — something has to learn your face and your body. So we train a small model from your photos and nothing else, use it only to make your pictures, keep it encrypted and isolated, never hand it to a vendor as theirs to use, never let it touch another customer, and delete it when we delete your photos. It's a tool for filling your order, not something we keep.

If you order retouching only, none of that happens — no model of you is trained, full stop.

We could have written "we never train AI on customer data" and quietly done the above anyway. Plenty of companies would. We'd rather tell you the exact shape of it, because a promise you can check is worth more than one you can't.

One other thing we deliberately do not claim: we don't tell you your photos never leave hardware we own. They don't — we run on a mix of infrastructure we operate ourselves and dedicated cloud and GPU capacity we rent under contract, like nearly everyone, including nearly every professional photographer you might have hired instead. What we can tell you is exactly who those companies are, what they're contractually bound to do, and what we encrypt before it ever reaches them.


1. Who's responsible for your data

Boudoir Central is operated by Clarovi Technologies, LLC ("we," "us," "our"), which is the data controller for the personal information described here.

  • Email: [email protected]
  • Privacy contact: [email protected]
  • Postal address: available on request via [email protected]
  • Where we operate: Boudoir Central is a US service, directed to residents of the United States and the United Kingdom. We do not market to, or offer our services in, the EU or EEA.

If you use Boudoir Central through a photographer's white-label service, the photographer is the controller for their client's data and we act as their processor — see Section 13.

2. What we collect

If you only read the site

Nothing that identifies you personally beyond the basics your browser sends (IP address, browser type) and what our server needs to log to stay secure and rate-limit abuse. For traffic statistics we run our own self-hosted, cookie-free analytics — it sets no cookies, builds no profile, follows you nowhere, and sends nothing to a third party. That is why this site has no cookie consent banner: there is no non-essential cookie to consent to.

If you sign up for the free newsletter or checklist

Your email address, and your name if you give it.

If you create a free account

  • Account basics: email, password (stored hashed, never in readable form), preferences.
  • Equipment and space profile: what camera or phone you have, your tripod and lights, the rooms available to you.
  • Body profile and comfort boundaries: your body type, what you'd like to flatter or conceal, and what coverage levels and pose types you are and aren't comfortable with.
  • What you save, favourite, and plan.

That body profile is genuinely personal, and we treat it that way. It exists to make recommendations fit you instead of a default. It is never shown to other customers and never sold or shared; inside our company, access is limited to the people who need it to help you, and it's logged. You can edit or clear it whenever you like.

If you buy something

  • Your photos — the images you upload for retouching or as Virtual You source material, and the finished images we produce from them.
  • Order details — what you ordered, the options you chose, your instructions to the artist, and our notes about the work.
  • Payment information — handled by our payment processor. We receive a confirmation, the last four digits of the card, and billing details. We never see or store your full card number.
  • Identity verification — a government-ID check and a selfie liveness check, performed by a specialist provider (see Section 6).

If you contact us

Your name, email, and whatever you write to us, so we can reply and keep track of the conversation.

3. What we do with it, and why

What we doWhat it usesOur lawful basis
Run your account and the free toolsAccount basics, profilesPerforming our contract with you
Personalise looks, poses, and your walkthroughEquipment + body profilePerforming our contract with you
Deliver retouching and Virtual YouYour photos, order detailsPerforming our contract, plus your explicit consent for the intimate images themselves
Train your private Virtual You modelYour photos onlyPerforming our contract, plus your explicit consent
Verify you're 18 and that it's youID document, selfie, resultLegal obligation and our legitimate interest in preventing serious abuse; explicit consent where biometric matching is used
Take payment, keep tax recordsPayment and order dataPerforming our contract; legal obligation
Answer your messagesContact details, your messageLegitimate interest in supporting customers
Send the newsletter you asked forEmail addressYour consent — unsubscribe any time
Keep the service secure and stop abuseLogs, limited account dataLegitimate interest in security

Two things that row four and row five do not mean. Retouching never trains a model of you — that row applies only to Virtual You orders. And no photo of yours ever trains anything shared — the only model your images touch is the private one that exists to make your pictures.

We do not do behavioural advertising, we do not build advertising profiles, and we do not sell data to anyone. There is no version of this business where that becomes a good idea.

About "special category" data

Intimate photographs of an identifiable person, and the private likeness model we train from them, are treated by us as special category / sensitive personal information — the most protected tier under the privacy laws that apply to us: US state privacy law, and UK data-protection law for our UK customers. Our basis for handling them is your explicit consent, given when you place an order, and you can withdraw it at any time (see Section 11).

4. What actually happens to your photos

Most privacy policies stop at "we process your images." Here's the real sequence, because you should be able to picture it.

  1. Upload. Your photos travel over an encrypted connection (TLS) and land in our storage encrypted at rest. They're tied to your account and your order, and nothing else. Two kinds of image go to two different places: photos of you are the sealed kind described next, while reference images you send purely for inspiration — a look you like, a corner of a room — are visible to the team by design, because their whole job is to be looked at.

  2. Sealed. From the moment they land until your identity check passes, the photos of you are sealed: our staff tools do not display them, nobody picks up the order, and every access to them is written to an audit log. We'll be exact about what that is — a control we operate and record, not a lock we couldn't open. What we can promise is that access is restricted and recorded, and we'd rather say that than something grander that isn't true.

  3. Identity check. You verify that you're 18 or over and that you are who you say you are (see Section 6). Nothing happens to your photos before this passes — no artist opens them, no model is trained, no image is generated. If it never passes, your order is refunded and the photos are deleted.

  4. A human opens your order. With verification behind us, a digital artist opens your order. This is the point where we check the photos are of you — the check means something now that we know who "you" is — that they're within our content standards, and that they're something we can actually deliver well on.

  5. Retouching orders are worked by that artist using professional tools — including AI-assisted tools inside their own manual workflow — to do exactly what you selected on the order form. Nothing else gets "fixed," and no model of you is trained.

  6. Virtual You orders additionally involve training a small, private model on your photos. In practice: the source photos you supplied are normalised into a consistent reference set and expanded into a training set — different angles, lighting, and clothing — whose job is to teach the model your face and your proportions accurately. Those are captioned for pose, clothing, and lighting, and used to train a LoRA: a small adapter file that teaches an image model what you look like. The artist then uses that adapter to produce your finished looks.

    All of that — building the reference and training set, training the adapter, and generating your finished looks — runs on image models we run ourselves, on GPU infrastructure we operate and dedicated GPU capacity we rent under contract (see Section 8). The line we hold is simple and absolute: nothing of yours is ever sent to a public AI service or a general-purpose image API — not the photos you gave us, and not the images we make from them.

  7. GPU compute. Training a model and generating images need a powerful GPU, and some of that capacity is rented (see the RunPod row in Section 8). Before your photos go anywhere near it, they are encrypted with our own keys. On the compute machine they are decrypted into isolated memory only — never written to that machine's disk — the trained adapter is re-encrypted before it comes back, and the whole compute environment is destroyed when the job ends. We keep an internal audit record of each job so we can prove that happened.

  8. Human QA. A person reviews every image before it's released to you.

  9. Proofs, then approval, then delivery. You review watermarked proofs first, in your own time. Ask for changes, or approve them — and on approval the full-resolution images appear in your account and we email you.

  10. Deletion. 30 days after delivery, by default, your source photos, your finished images, and your private model are deleted automatically — unless you've chosen to keep them longer.

5. Your Virtual You model, specifically

This is the carve-out we flagged at the top — the one place we do train AI on your data — so we'll be exact about it.

The model we train from your photos:

  • is trained only on photos you submitted, and on nothing else;
  • is never combined with another customer's photos, and never contributes to any shared, public, general-purpose, or cross-customer model;
  • is used only to produce images for you, on your order;
  • is stored encrypted and isolated, keyed to your account;
  • is never handed to anyone else for their own use — it isn't uploaded to a model hub, it isn't sold, licensed, or shared, and it stays encrypted wherever it sits. When a rented GPU has to load it to make your images, it travels there encrypted and exists only in that machine's memory for the length of the job;
  • is treated as sensitive data in its own right — it's derived from your likeness, so it gets the same protection your photos do;
  • is deleted whenever you ask — always, no conditions — along with any stored descriptions or metadata derived from you. It leaves the live service straight away, and we confirm the deletion to you in writing within 48 hours;
  • is deleted with your photos by default. If you'd like to order more looks later without redoing the guided photo set, you can choose to keep your model on file instead. That is entirely optional and free, and you can still delete your source photos while keeping it — the model stays encrypted and isolated, keyed to your account, exactly as it is during an order;
  • if kept, is deleted automatically after 90 days without a login, and whenever you close your account. Nothing built from your face sits here indefinitely.

Your likeness stays yours. We don't claim it, we don't keep a model of you as a company asset, and there is no version of this where something built from your face outlives your account.

Your photos are never used to improve our products for anyone else. The look library on our site is generated from fictional characters we invented, never from customers. There is no scenario in which a customer's photo, or a model derived from it, produces an image for someone else.

And to close the loop on the honest version of the promise: if you never order Virtual You, no model of you is ever trained. Retouching is editing, not learning.

6. ID verification

Before any work starts on your photos, we verify that you are 18 or over and that you are who you say you are, using a government-ID document check and a selfie liveness check run by a specialist verification provider (see Section 8). You can order and upload straight away — verification is the gate on work starting, not on ordering. Until it passes, your uploaded photos are sealed: our staff tools do not display them, and every access to them is written to an audit log. That is a control we operate and record rather than a lock we couldn't open, and we'd rather say so plainly. Once verification passes, the artist opens your order — and that is where we check the photos are of you.

How it works:

  • You submit your ID and selfie directly to the provider, not to us.
  • The provider performs the biometric comparison under its own terms and retention schedule.
  • We receive the result — pass or fail, your verified name, your date of birth or an over-18 flag, and a reference number — and we keep the minimum record needed to show we ran the check.
  • We do not keep a copy of your ID document, and we do not keep the biometric template.

Selfie liveness matching is biometric processing, so we ask for your explicit consent before it happens — and there is always a way through without it. If the automated check fails, or if you'd simply rather a person did it, ask us and a member of our team will review the same documents by hand and decide. You never have to accept an automated decision about whether you are who you say you are. We offer this partly because it's your right, and partly because automated face matching is measurably worse at recognising some people than others, and that should never be your problem.

7. Who can see your photos inside our company

A very small number of people: the digital artist working your order, and whoever is handling support if you've written in about it. Access is limited to the people who need it to do the job, and it's logged.

Being straight about what "working on your photos" means: there is no way to retouch an image without seeing it, so the artist on your order downloads decrypted working copies onto a work computer to do the editing. Those downloads are logged, and the working copies are deleted along with the rest of your data.

Browsing customer photos is not a thing anyone here is allowed to do, and the tools are built so it isn't a thing anyone falls into: there is no internal gallery and no "look at this one" channel, access is scoped to the order a person is actually working, and every open is logged and reviewable. We won't tell you it's impossible — an administrator with the right access could reach a file, the same as at any company that holds your data. What we will tell you is that doing it would be a policy breach, that it would leave a record with a name on it, and that we treat that record as the point. And there is no marketing use of your images unless you specifically opt in and can opt out again.

8. The companies that help us run this (subprocessors)

We don't run every piece of this ourselves — nobody does. Here's every company that processes data on our behalf, what they do, and whether your photos are involved.

SubprocessorWhat they do for usDoes it involve your photos?Where
RunPod, Inc.Dedicated secure-cloud GPU compute, where your Virtual You model is trained and your images are generatedYes — for Virtual You. Your source photos and the images we generate reach it only in encrypted form, are decrypted solely into isolated memory for as long as the job runs, and are deleted when the compute instance is destroyed at the end of the jobUSA
Google Cloud Platform (Google LLC)Cloud hosting, storage, and databases — infrastructure only. Our production systems currently run on infrastructure we operate ourselves; we use Google Cloud as we scaleYes, for anything hosted there — your images are stored encrypted. They are never sent to Google's Gemini or any other Google AI serviceUSA
Anthropic PBCThe Claude API, which generates the personalised guidance in your shoot walkthrough and helps us draft site contentNo — text only. Your equipment and body profile may be included in a prompt so the guidance fits youUSA
Stripe, Inc.Taking payment, storing card details, handling refundsNoUSA
Our identity-verification provider — a specialist regulated vendor; this row is updated with the vendor's name before your first verificationGovernment-ID document check and selfie liveness matchNo — your ID and your selfie only, never your boudoir photosUSA
Our email delivery provider — a specialist vendor; this row is updated with the vendor's name before it sends you anythingSending account, order, and support emailNoUSA

On the GPU row specifically, because it's the row where your images are actively worked on rather than merely stored. Making new images that look like you takes a powerful GPU, and we rent that capacity on dedicated, non-shared secure-cloud instances rather than buying a data centre. What that means for your photos in practice: they leave our storage already encrypted with keys we hold, they are decrypted only into memory on the compute instance — never onto its disk, and never onto shared or network storage — the trained model file is re-encrypted before it comes back, and the instance itself is destroyed when the job finishes, which is the deletion event. We keep an audit record of every job. Retouching orders don't involve this step at all.

What we promise about this list, precisely. Every company on it is bound by a written contract to process your data only on our instructions, to keep it confidential and secure, and never to use it for their own purposes — including never using it to train their own models. We select vendors on the security controls they actually provide, and where your images are involved we add our own protections on top: encryption with keys we hold, decryption into memory only, destruction of the compute environment, and an audit record of every job.

We're not going to tell you more than that. In particular, we're not going to claim that every vendor's standard terms were written with intimate photography specifically in mind — that would be a nice sentence and not a true one.

In plain language: using named cloud vendors under contract puts your photos in roughly the same position as photos kept in ordinary cloud storage — which is where virtually every working photographer already keeps their clients' images, including the studio you might have booked instead. It isn't a magic shield and we won't pretend it is. What we add on top is the part most people don't get: encryption with our own keys before your images go anywhere, automatic deletion on a 30-day clock, a published list of exactly who is involved, and a promise that none of it is ever sold, shared, or fed into anyone else's model.

Changes to the list. When we add or replace a subprocessor that handles your images, we'll update this page and email account holders at least 30 days before the change takes effect — not after. If you'd rather not have your images handled by the new company, you can delete your data first, and that window exists precisely so that choice is a real one.

We may also disclose data if the law genuinely requires it (a valid legal process), or to protect someone from serious harm. We will tell you if that happens unless we're legally barred from doing so.

If our business is ever sold or reorganised, your data may transfer to the successor — and your privacy settings, retention choices, and deletion rights travel with it.

9. How long we keep things

WhatHow long
Your uploaded photos and finished images30 days after delivery by default. You can extend it, shorten it, or purge on request — completed and confirmed within 48 hours
Your Virtual You model, and any captions or metadata derived from youDeleted with the photos it was trained from — unless you choose to keep it on file for future orders (free, optional). If kept: deleted after 90 days without a login, when you close your account, or on request — completed and confirmed within 48 hours
Private gallery (if you opt in)For as long as you keep it, until you delete it or close your account
Account and profile dataUntil you close your account
Order and payment records7 years, as US tax and accounting law requires
ID verification resultThe minimum period required to demonstrate compliance with age-verification law, and then deleted. We keep the outcome and a reference number — never your ID document or the biometric template
Support emails24 months
Newsletter subscriptionUntil you unsubscribe
Security logs90 days

About backups and timing, honestly. When you delete something, most of it leaves the live service straight away. We commit to completing the deletion and confirming it to you in writing within 48 hours — the gap is deliberate, because it covers the pieces that live in more than one system and it means the confirmation you get is a real one rather than an optimistic one. Encrypted backups roll over on a schedule, so a deleted file can persist inside an encrypted backup for up to 35 days after that. Backups are encrypted, are never used to restore individual deleted content, and anything restored from one is re-purged.

10. How we protect it

  • Encryption in transit (TLS) and at rest for everything, including your images.
  • Envelope encryption with our own keys for any image that goes to rented GPU compute, with plaintext decrypted into volatile memory only, never to disk, and the compute environment destroyed at the end of the job.
  • Isolation: your Virtual You model is stored separately, keyed to your account, and never pooled.
  • Least-privilege access for staff, with logging.
  • Automatic deletion as the default, so privacy doesn't depend on you remembering.

No system is perfectly secure, and we're not going to pretend otherwise. What we will do is tell you quickly and plainly if something happens to your data, and tell regulators within the deadlines the law sets.

11. Your rights, and how to use them

Wherever you live, you can ask us to:

  • Show you what we hold about you.
  • Give you a copy of your data in a portable format.
  • Correct anything wrong.
  • Delete everything — your photos, your finished images, your Virtual You model, any captions or metadata derived from you, your profiles, your account. You don't have to negotiate for it, and nobody will try to talk you out of it. Most of it is removed from the live service straight away; we finish the job and confirm it in writing within 48 hours.
  • Stop or limit a particular use.
  • Object to processing based on our legitimate interests.
  • Withdraw consent you gave earlier, including consent to process your images. Withdrawing doesn't undo what was lawful before, but it stops everything going forward.

How: email [email protected], or use the controls in your account. We'll respond within 30 days (extendable where the law allows, and we'll tell you if we need longer). We may need to verify it's really you before we act on a request about photos — for obvious reasons.

It's free, and we will never treat you differently for asking. No worse price, no worse service.

If you're in the UK, these are your rights under UK data-protection law, and you can also complain to the Information Commissioner's Office. We'd like the chance to fix it first.

On where we operate, plainly. Boudoir Central is a US service, operated under US and Tennessee law and directed to residents of the United States and the United Kingdom. We do not market to the EU or EEA, we do not target our services there, and we make no claims about EU law. Our free articles and guides are readable by anyone anywhere — that's reading a web page — and the rights listed above are offered to everyone who asks, wherever they live.

If you're in California (or another US state with a privacy law), you have the rights to know, delete, correct, and to opt out of "sale" or "sharing" of your personal information — though there's nothing to opt out of, because we do not sell or share personal information, and we have not in the preceding 12 months. You may also limit our use of sensitive personal information; we already limit it to delivering what you ordered. You can use an authorised agent. Some states let you appeal a refused request: email [email protected] with the word "appeal" and a different member of our team will review the refusal. If we still say no, we'll tell you why in writing and point you to your state regulator.

If you're anywhere else, ask anyway. We apply the same standard to everyone.

12. Cookies and tracking

We use the cookies needed to keep you logged in and keep the site secure. We do not use advertising cookies, and we do not let third parties track you across the web from our site.

Our analytics are self-hosted and cookie-free, so there is no non-essential cookie on this site and therefore no consent banner to click through. The only cookies we set are the ones that keep you signed in and keep the site secure — without them the site cannot work, so they have no opt-out, and they are never used to track you.

13. If you came through a photographer

When a photographer uses our white-label service, they decide what happens to their clients' images and we act on their instructions as their processor, under a data processing agreement. Everything in this policy about encryption, no sale, no sharing, no shared or cross-customer model training, per-client models, and deletion still applies to those images. If you're that photographer's client and want your data deleted, ask them — or ask us and we'll point you to them and support the request.

14. Where your data lives

We're a US company, and your data is processed in the United States. Our services are directed to residents of the United States and the United Kingdom.

If you're in the UK, your data is transferred to the US to deliver the service. We put international data-transfer terms — the UK International Data Transfer Addendum — in place with the subprocessors that process UK customers' data, and we assess the transfer risk before routing that data to them.

15. Children

Boudoir Central is strictly for adults, 18 and over. We don't knowingly collect information from anyone under 18. If we find that we have, we delete it straight away and close the account. If you believe a minor has used our service, please tell us at [email protected].

16. Changes to this policy

Privacy policies change as products do. When we make a material change — especially one about how your photos are handled, or who processes them — we'll post the new version here with a new date and email account holders at least 30 days before it takes effect. If you don't want to continue under the new version, delete your data and close your account, and we'll be sorry to see you go.

17. Talking to us

If any part of this policy is unclear, tell us. A privacy promise you can't understand isn't much of a promise.