Privacy policy
Last updated 2026-10-11. In short: your photos are used only to make your pictures, are deleted within 24 hours, and are never used to train AI, sold or shared for marketing.
Who we are
FamilyPhotoLab is run by a small independent team, who decide how the data described here is used. Contact: hi@familyphotolab.com.
Photos you upload
When you upload a photo, our server first re-encodes it: it is turned the right way up, resized to at most 1536 pixels and saved as a new JPEG without any metadata, so location (GPS), camera and time information are removed.
The cleaned photos are stored privately (not publicly reachable) and used only to make the pictures you asked for. They are deleted 24 hours after upload. If a preview cannot be made, or a photo is refused by our safety check, the photos are deleted straight away.
We never use your photos or pictures to train AI models, and we never sell them or share them for advertising.
Who processes them
To draw a picture, the photos are sent over HTTPS to the LaoZhang API, which passes them to the image or video model: Nano Banana 2 Lite, Nano Banana 2.1 (Google), GPT Image 2.5 Flare (OpenAI) or Wan 2.7 (Alibaba). They receive the photos for that request only, under their own API terms, and may keep request logs for abuse monitoring.
Our servers run on Vercel; files and records are stored with Cloudflare (R2 and D1).
Your pictures
Finished pictures and videos are stored privately for 30 days so you can download them again, then deleted. They are shown only through links that expire after an hour.
The watermarked preview can be opened by anyone who has the page link for it (the link contains a long random code). Pictures without a watermark, downloads and the video are shown only to the Google account that bought them.
Children
FamilyPhotoLab is for adults. We do not accept photos of children as uploads on the baby predictor, and we do not knowingly collect personal data from children. The babies and children in our pictures are AI-generated and fictional. See how pictures of children are kept safe in the acceptable use policy.
Google sign-in
Sign-in is optional until you buy. We receive your Google account id, name, email address and profile picture and keep them in a signed session cookie. We store only an identifier derived from your Google account id (not the id itself) with your pictures and orders, and your email with orders. We do not send marketing email.
Purchases
Payments are processed by Waffo.com Limited, our merchant of record. You give your payment details and billing information to Waffo on its checkout page; we never see your card number. Waffo’s privacy policy covers that data.
For each order we keep the account identifier, your email, what you bought, the amount, Waffo’s order id, dates and any refund, for support, refunds and accounting and tax obligations.
Safety checks
Each safety decision on your photos and pictures is logged with its reason and the account identifier — never the photos themselves — so a person can review refusals and reports. Logs are kept for up to 12 months.
Usage data
To stop abuse of the free previews we store a one-way hash of your IP address (not the address itself) with each upload, and we count steps of the funnel (opening the tool, upload, preview, sign-in, opening the payment window, checkout, payment) with your country and the kind of site you came from (for example a search engine or an AI assistant), never the full address of that page. We do not use advertising or analytics cookies; the only cookie is the sign-in session. Google’s sign-in script loads after your preview is shown.
Your choices
You can ask us to delete your pictures, orders data we are not required to keep, and safety logs about you at any time: write to hi@familyphotolab.com from the email of your Google account. We reply within 7 days.