Privacy Policy

Privacy Policy

Last updated July 16, 2026

1. Your photo never leaves your browser

Resizing, cropping, background checks, machine-learning checks, and compression run locally in your browser. The photo itself is not included in requests to ResidencyPhoto or its service providers.

The editor loads its machine-learning models and runtimes from ResidencyPhoto's own origin. Remote model fallback is disabled.

2. What we store

We use Neon to provide account authentication and store account-related information such as your user identifier, email, plan, download count, and Stripe customer identifier when applicable.

Processed-photo history is off by default. If you explicitly enable it, locally generated copies are stored in this browser's local storage. Turning history off deletes those copies. Clearing browser data, using another browser, or switching devices may also remove them.

3. Payment information

Payments are handled by Stripe. We don't see or store your full card number. We retain the Stripe customer reference and plan status needed to provide purchased features.

4. Cookies and analytics

Authentication uses cookies needed to keep you signed in securely. We don't use advertising, session-replay, chat, or third-party analytics scripts in the photo editor.

We collect only allowlisted model-load event names, success or failure status, and bounded loading duration. Telemetry excludes filenames, error text, image data, canvas output, classifications, photo-derived measurements, and browser user-agent information.

5. Sharing your data

We don't sell your data. We use service providers including Neon for authentication and database hosting, Stripe for payments, and Vercel for application hosting and operational logs. We may also disclose information if required by law.

6. Your choices

You can enable, disable, or clear locally stored photo history from Settings. To request deletion of server-side account and billing-related records, email support@residencyphoto.com. Some transaction records may be retained where required for legal, tax, fraud-prevention, or accounting purposes.

7. How to verify local processing

Open your browser's developer tools, select Network, clear the request list, and then choose and process a test photo. Model files should load only from residencyphoto.com, and application requests should not contain image files, blob contents, data URLs, filenames, or canvas output.

ResidencyPhoto publishes these implementation details so users and security reviewers can independently inspect the browser's network activity rather than relying only on a privacy claim.

8. Children's privacy

ResidencyPhoto is intended for medical residency applicants and program staff, not children. We don't knowingly collect data from anyone under 13.

9. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected by an updated "last updated" date below.

10. Contact

Questions about this policy? Email support@residencyphoto.com.

Back to home