Privacy Policy
Last updated: 6 August 2026 · version 1.1
This Privacy Policy explains what personal data Portrevo processes, why, on what legal basis, for how long, who else touches it and what rights you have. It is written to be read together with the Biometric Consent, which covers the photographs of your face separately.
In short: we process the photographs of your face in order to train your personal AI model and generate photographs for you, on the basis of your explicit consent; we do not use them to train our own models; you can delete the model, the photographs and the generated images at any time from within the application.
1. Controller
The controller of your personal data is archBO s.r.o., Korunní 2569/108, 101 00 Prague, Czech Republic, company registration number (IČO) 01944711, registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 285018.
You can reach us in all data protection matters at kontakt@portrevo.com or on +420 725 543 392. We have not appointed a data protection officer; the e-mail address above is the contact point for data subjects.
Where this policy says photographs of your face, it means both the photographs you upload and the personal AI model derived from them.
2. Categories of data we process
Account data: e-mail address, authentication identifiers and, if you provide it, the name you give to a model. Created when you register.
Photographs of your face (input photos): the 10 to 15 images you upload for training. Because they are processed by a specific technical means that produces a mathematical representation of your face, we treat them as biometric data and therefore as a special category of personal data under Art. 9 GDPR.
The trained model: the personal AI model derived from your photographs. It is treated with the same protection as the photographs.
Generated photographs: the images the Service produces from your model. They depict you and are therefore personal data.
Payment and transaction data: the record of whether and when the download from a model was unlocked by payment, the payment reference from the payment service provider, and the payment data processed by Stripe. We never see and never store your card number.
Free trial and unlock records: the fact that your account has used the one free trial available to it and which model it was used for, and the flag showing whether a model has been unlocked. The watermarked previews shown before payment are produced on our server for each request from the stored photograph and are not stored separately.
Consent records: your user identifier, the kind and version of the consent, the time it was given, and a salted hash of the IP address from which it was given. We do not store the IP address itself in the consent record.
Usage and technical data: usage events (training and generation runs, quantities, provider request identifiers), rate-limit counters, and server and error logs generated by our hosting provider, which may contain an IP address.
3. Purposes and legal bases
Providing the Service — creating and running your account, training your model, generating photographs, storing them for you, showing them as watermarked previews, unlocking the download after payment, sending service e-mails such as the notification that a model is ready. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Processing the photographs of your face and the model derived from them. Legal basis: Art. 6(1)(b) GDPR for the contract and, in addition and cumulatively, Art. 9(2)(a) GDPR — your explicit consent to the processing of a special category of data. Without that consent we cannot provide the Service at all, because processing the photographs is its very substance.
Security, abuse prevention and protection of the Service — usage limits, quotas, filtering of prohibited requests, logs, investigation of incidents. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a secure and available service and in preventing misuse of an image-generation tool).
Accounting, tax and record-keeping — the accounting documents for the payment and the records of payments and unlocks. archBO s.r.o. is not registered for value added tax, so we keep no VAT records about you. Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation).
Handling complaints and establishing, exercising or defending legal claims. Legal basis: Art. 6(1)(c) and Art. 6(1)(f) GDPR.
We do not process your data for advertising or profiling, we do not sell it, and we do not use your photographs or generated images for marketing or as references.
4. How long we keep the data
Uploaded photographs: stored in a private bucket for as long as the model trained from them exists. They are deleted when you delete the model, when training fails (the failure is recorded by our processor or detected by us afterwards), or when you ask us to delete them. They are also deleted if a training attempt is aborted before it starts.
The training archive (the ZIP we assemble from your photographs and from which the AI processor trains the model): kept in a private bucket only while the training runs and deleted immediately once the training finishes or fails, and in any case when the model is deleted.
The trained model: kept in private storage for as long as the model exists in your account. Deleting the model deletes it.
Generated photographs: kept in a private bucket for as long as the model they were generated from exists. The application does not currently have a delete button for an individual photograph: you remove generated photographs by deleting the model, which deletes all photographs generated from it, or by withdrawing your consent in the Account section, which deletes all models and all photographs. If you want a single photograph removed, write to kontakt@portrevo.com and we will delete it. Where the download has been unlocked by payment, we keep the photographs available to you for as long as the model exists in your account, and in any event for at least 12 months from the payment. A model that has not been unlocked, together with its previews, is kept for at least 90 days from the completion of training and may be deleted afterwards; we warn you by e-mail before we delete it.
Account data: kept until you delete the account, after which it is removed together with the related storage objects.
Payment records, unlock records and usage events: kept for as long as required by accounting and tax law.
Consent records: kept as evidence that consent was given (Art. 7(1) GDPR) for as long as the processing based on the consent continues, and afterwards for the period in which claims can still be raised.
Technical logs: kept according to the default retention of our hosting provider and used only to operate and secure the Service.
At the AI processor: we instruct fal to retain nothing beyond what is needed to carry out the training and the generation. Generated photographs expire at the processor within about an hour of delivery, and the trained model within seven days; as soon as the model has been copied to us, we additionally instruct the processor to delete the data of that training request. We copy both the generated photographs and the model into our own private storage, so the copies at the processor are only an intermediate step.
5. Who processes the data for us
fal — Features and Labels, Inc., San Francisco, USA. Trains the model and generates the photographs. Acts as a processor under a public data processing addendum which incorporates the EU Standard Contractual Clauses, Module 2 (governed by Irish law), and which is bound by a contractual commitment not to use client content to create, train or develop its own products or services. Processing takes place in the USA.
Supabase (Supabase Pte. Ltd.) — database, authentication and file storage. Our project is hosted in the EU region eu-central-1 (Frankfurt). Data processing addendum with the Standard Contractual Clauses, Modules 2 and 3. Some support functions may be performed from the USA.
Vercel Inc. — hosting and delivery of the application. Certified under the EU-US Data Privacy Framework. Primary processing takes place in the USA.
Resend — sending transactional e-mails (for example the notification that your model is ready). We never send photographs by e-mail; e-mails contain only your address, your name if you gave one, and a link into the application behind login.
Stripe — payment processing. For part of the processing (fraud prevention, anti-money-laundering and legal compliance) Stripe acts as an independent controller, not as our processor.
Each processor is bound by a contract under Art. 28 GDPR. The list of processors in force at any time is available on request at kontakt@portrevo.com.
6. Transfers outside the European Economic Area
Training and generation take place at fal in the United States, and parts of the hosting and e-mail infrastructure are also operated from the United States. Your photographs therefore leave the European Economic Area.
fal is not certified under the EU-US Data Privacy Framework. The transfer is based on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module 2 (controller to processor). The same applies to Supabase. Vercel and Stripe are certified under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), which provides an adequacy decision for those transfers.
Where a transfer relies on the Standard Contractual Clauses, we prepare and keep under review a transfer impact assessment in line with the recommendations of the European Data Protection Board, and we apply the additional measures available to us: private storage, access only through short-lived links, instructions to the processor to retain nothing beyond what the service requires, and the contractual prohibition on training.
We are honest about the limit of these measures: photographs must reach the AI processor in a readable form in order to train a model, so encryption cannot be used to make them inaccessible to the provider. If this residual risk is unacceptable to you, please do not use the Service.
You can request a copy of the Standard Contractual Clauses at kontakt@portrevo.com.
7. Your rights
You have the right of access to your data and to a copy of it; the right to rectification; the right to erasure; the right to restriction of processing; the right to data portability; and the right to object to processing based on our legitimate interest.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
You can exercise most of these rights yourself: the application lets you delete a model together with its training photographs and all photographs generated from it, and the Account section lets you withdraw all your consents and delete everything at once. For anything else, or to delete your entire account, write to kontakt@portrevo.com. We reply within one month; in complex cases we may extend this by two further months and we will tell you if we do.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, uoou.gov.cz. If you live in Poland you may instead complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl, or to the supervisory authority of your habitual residence.
8. Withdrawing consent and deleting your data
Withdrawing the consent to the processing of the photographs of your face means that we can no longer train or run your personal model. Withdrawal therefore leads to the deletion of the model, of the photographs used to train it and of the photographs generated from it.
You can do this yourself in the application: the Account section contains a single button, Withdraw consent and delete everything, which marks your consent to the processing of the photographs of your face (and any statement you made about the start of delivery before the withdrawal period expired) as withdrawn and deletes every model on your account together with the uploaded photographs and the generated photographs. Deleting a single model has the same effect for that model, and when it is your last model your consent to the processing of the photographs of your face is marked as withdrawn as well. You can also write to kontakt@portrevo.com. Withdrawing consent is as easy as giving it and costs nothing.
Once a consent is marked as withdrawn, it no longer counts: no training can start until you give the consent again, which the application asks for before the next training.
Withdrawing consent does not close your account. Your acceptance of the Terms of Service and your declaration that you are over 18 are not consents under the GDPR but contractual declarations, so they are not withdrawn by this button and the record of them stays: without them the account would have no contractual basis. If you have paid to unlock the download of photographs from a model, withdrawing this consent deletes those photographs as well — download them first. To have the account itself deleted, write to kontakt@portrevo.com.
Data that we must keep for accounting or tax reasons, and the record that a consent was given and later withdrawn, is retained even after deletion, because a legal obligation applies to it.
9. Automated decision-making
The Service generates images automatically, but it does not take decisions about you that produce legal effects or similarly significantly affect you within the meaning of Art. 22 GDPR.
Automated checks that we do run are: quality checks on uploaded photographs in your browser, a filter on the free-text field, safety filtering at the AI processor, and usage limits. Their only consequence is that a specific request is rejected or a photograph is excluded from training; you can always contact us and have this reviewed by a person.
We do not profile you and we do not set prices individually based on automated processing.
10. Security
Your photographs, your model and the generated photographs are stored in private storage that has no public addresses. They are made accessible to you only through short-lived signed links.
Database access is restricted by row-level security so that a logged-in user can read only their own rows. Writes that affect credits or models are performed only by our server using a service-role key that is never exposed to the browser.
Transport is encrypted with TLS and storage providers encrypt data at rest.
We do not claim any certification. We describe here only the measures that are actually implemented in the Service.
11. Children
The Service is intended solely for adults. We do not knowingly process the data of persons under 18 and we do not permit the uploading of photographs of children under any circumstances.
If you believe that a child's photograph has been uploaded to Portrevo, write to kontakt@portrevo.com and we will delete it without undue delay.
12. Cookies, local storage and analytics
We use cookies that are strictly necessary to keep you logged in. We do not use advertising or tracking cookies.
The application stores your language preference in the local storage of your browser.
We use Vercel Analytics to measure aggregate traffic. According to the provider it does not use cookies and does not track individual visitors across sites.
13. Changes to this policy
We may update this policy when the Service, the processors or the law change. Every version carries a version number and an effective date.
If a change materially affects how we process your data, we will inform you by e-mail before it takes effect, and where the change concerns processing based on consent, we will ask for your consent again.
14. Effective date
This version 1.1 of the Privacy Policy applies from 6 August 2026.
archBO s.r.o., IČO 01944711, Korunní 2569/108, 101 00 Prague, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 285018. Telephone +420 725 543 392, e-mail kontakt@portrevo.com.