What happens to your child's photos

August 16, 2026 · 6 min read

Exact deletion dates, who sees the files, what we strip on arrival, and the three things we honestly cannot promise you. No marketing language.

Your photos are deleted two days after your book ships, or 14 days after upload if you never order. Metadata and GPS are stripped on arrival. Every company that sees the files is named further down this page. No faceprint is created, no face matching is run, and no customer photo appears anywhere on this website.

Ask Google whether it is safe to upload your child's photo to an AI app and it answers, in its own voice, before any search result: generally, no.

That is a fair answer to a badly-behaved industry, and we are not going to argue with it in the abstract. What we can do is tell you exactly what happens to your files here — the dates, the companies, the deletions — so you can judge this one case on facts rather than on a reassuring tone.

Three things we cannot promise you

Everyone in this category leads with reassurance. Here is the other half first, because a promise is only worth as much as the things its author is willing to rule out.

We cannot un-send a file. Uploading a photo of your child to any company, ours included, is a real decision. If you are not comfortable making it, the honest answer is not to — and we would rather write that sentence than have you talked out of an instinct that is basically sound.

We cannot audit our suppliers' servers. Two outside companies see your photos, and we name both of them below. We can tell you who they are and what their terms commit them to. We cannot stand inside their data centers, and neither can any company that implies otherwise.

We cannot promise that no human ever sees them. A person does, on purpose. That is the quality check described in how a book gets made, and it is the reason blurry photos come back to you as an email instead of as page fourteen. A company promising that no human ever looks at your upload is also, quietly, promising that nobody is checking.

What we do control, with dates

  • Two days after your book ships, the photos and everything derived from them are deleted.
  • Two days after we send your PDF, for a digital-only order — same rule, same job.
  • 14 days after upload, if payment never arrives and the book never starts.
  • On arrival, all embedded metadata is stripped, including the GPS coordinates your phone wrote into the file.

The deletions are not a policy someone remembers to follow. A job runs every day, removes the files, and writes a line recording that it did. We built it that way in August 2026 precisely because the previous version depended on somebody clicking a button, and a promise that depends on somebody remembering is not a promise.

What stays behind is the order record — names, email, what you bought — because tax law requires us to keep transaction records for years. Your children's faces are not a transaction record, and they do not stay.

Your photo's journey, end to end

  • Upload. The file travels over an encrypted connection and lands outside the public web root, where no web-server misconfiguration can serve it to a stranger.
  • Strip. Embedded metadata, including location, is removed before the file is stored.
  • Consent. Your parental consent is recorded with a timestamp and the version of the policy you agreed to — its own checkbox at upload, never bundled into a general "I agree".
  • Review. A person checks the photo is usable.
  • Reference. We draw a character reference from it: your hero, in our illustration style.
  • Pages. The illustrations are made from that reference.
  • Delete. Two days after the book leaves us, the photo and the reference are gone.

Who sees them, by name

Most privacy policies in this category say "trusted partners". Here are the actual names.

  • Higgsfield AI — the illustration system. It receives the photos to build the character references and draw the artwork, and no other use is permitted.
  • Anthropic — our team runs the human photo check inside Claude, so your photos pass through Anthropic for that step. Their published commercial terms state they do not train their models on what customers send through them.
  • Stripe — payment, and the shipping address. Never sees your photos.
  • Our US print partner — receives the finished book file and your shipping address. Never sees your photos.

That is the complete list. If it ever changes, the Privacy Policy changes with it on the same day.

What is not on this website at all

No advertising pixels. No retargeting. No Meta pixel, no Google Ads tag, no TikTok pixel, no Pinterest tag. We do not sell personal information and we do not share it for cross-context behavioral advertising — and because there is genuinely nothing to switch off, there is no "Do Not Sell" link here to click.

Analytics run only if you say yes to the cookie banner, and if your browser sends the Global Privacy Control signal we treat that as your answer and do not ask again. We never receive your IP address alongside an order.

No faceprint

This is the question worth asking any company that turns a photo into a picture, so we will answer it plainly.

What our pipeline produces from your photo is a drawing. We do not build, store or use a mathematical face template of the kind that could match your child against another photograph somewhere else, and we do not run face recognition or face matching on anything you send. The illustrated hero is a stylized likeness — recognizably your child in a storybook, not a measurement of your child's face.

If you want it gone sooner

Email [email protected] and we will delete the photos. No form, no retention team, no three-step flow designed to change your mind. A person reads it and it gets done.

The full timetable, including how long the order record itself lives, is written out in our Retention Schedule.

Frequently asked questions

How long do you keep my child's photos?

Two days after your book ships, or two days after we email your PDF for a digital order. A job runs every day and deletes them, and it writes a line recording that it did. If you never pay, the photos are deleted 14 days after upload without anyone having to remember.

Do you use our photos to train AI?

No. We never train a model on them, and we never license them to anyone else to do so. Every company that touches them receives them under instructions covering your book and nothing further.

Does a human being look at our photos?

Yes, deliberately. Before any illustration starts, a person checks that each face is sharp, large enough, and identifiable. Companies that promise no human ever sees your files are usually promising that nobody is checking the quality either.

Do you make a faceprint of my child?

No. What our pipeline produces is a drawing — a character reference in our illustration style. We do not build, store or use a mathematical face template of the kind that could match your child against another photograph, and we do not run face recognition on anything you send.

Can I have the photos deleted sooner?

Yes. Email [email protected] and we will delete them. If the book has not been made yet, that also means we cannot make it.

What about the location data in a phone photo?

Stripped the moment the file arrives, before it is stored — GPS coordinates and all other embedded metadata. Phone photos usually carry the location where they were taken, and that has no business being on our server.

Was this article helpful?

More from the workshop