AI Safety & Privacy
We process photographs of your face. That’s the most personal data most people will ever hand a company, so this page explains exactly what happens to it — in plain language, with no hedging.
What we do with your photos
We train a private model that belongs only to you. Your uploaded selfies are used to train an individual AI model that generates your headshots and nothing else. It is never public, never shared, and never used to generate images of anyone else.
We never use your photos to train general-purpose AI. Your images do not feed any foundation model, ours or anyone else’s.
We delete everything automatically. Your photos, your trained model and your generated headshots are deleted 90 days after your last purchase. We email you 7 days beforehand so nothing disappears unexpectedly, and you can extend for three more months if you want longer.
You can ask us to delete sooner, at any time. Email support@themultiverse.ai and we’ll action it within a month. Photos and generated images usually go within days; the trained model is removed in our next deletion cycle.
You own everything we make for you. Full rights to every image, for any use, forever.
Every image we produce is marked as AI-generated
We think being able to verify how an image was made is part of doing this responsibly.
Every headshot and every edit we deliver carries machine-readable metadata identifying it as AI-generated, using the IPTC standard property DigitalSourceType with the value trainedAlgorithmicMedia — the recognised vocabulary term for content produced by a generative AI model. It’s invisible: it changes no pixels, affects no image quality, and adds under a kilobyte.
This satisfies the marking requirement in Article 50(2) of the EU AI Act, which requires providers of AI systems generating synthetic images to ensure outputs are marked in a machine-readable format and detectable as artificially generated.
How to tell if an image is AI-generated
There are two ways, and they work on any image, not just ours.
1. Check the metadata. Most AI-generated images from responsible providers carry a provenance field. On our images, the IPTC DigitalSourceType property reads trainedAlgorithmicMedia. The reliable way to check is ExifTool, the original command-line tool — run exiftool -XMP:all yourimage.webp. Be aware that many browser-based “EXIF viewer” websites cannot read metadata inside WebP files and will report that nothing was found; that is a limitation of those tools, not of the file.
2. Check for an invisible watermark. Some AI models embed a watermark in the pixels themselves, which survives cropping and compression. Google’s SynthID is the best-known. Unlike metadata, these can’t be stripped by uploading to a website.
An important limitation, which applies to everyone: most social platforms and websites strip metadata from images when you upload them. So an image with no provenance data is not necessarily human-made — it may simply have passed through a platform that removed it. Metadata proves what an image is; its absence proves nothing.
Are AI headshots safe to use?
Yes, and we’d argue they’re more transparent than heavily retouched photography, which carries no disclosure at all.
Our headshots are a faithful representation of the actual person. They preserve your real facial geometry, your features and your expression. We are not creating a different-looking person — we are photographing the real one without a studio. What changes is lighting, background and clothing, which is exactly what a photographer and a retoucher change too.
If you’re publishing team photos in the European Union in a professional capacity, we suggest a short line on your About Us page or in your footer noting that some imagery was created or enhanced using AI. That’s a proportionate way to be transparent with your audience without labelling every individual image.
Only upload photos you have the right to upload
Before you upload anything, we ask you to confirm two things, and we record your answer:
- The photos are of you, or you have explicit permission from the person in them
- You agree to us processing your facial images to create your headshots
For teams, every person agrees for themselves, at their own upload. An admin cannot accept on a colleague’s behalf. It’s their face, so it’s their decision.
If you believe a photograph of you has been uploaded by someone else, contact us and we’ll remove it.
Who we share data with
We share personal data only with the companies below, only for the purpose stated, and only as far as necessary. We do not sell your personal data.
| Company | What they receive | Why |
|---|---|---|
| Replicate | Your photos, your trained model, your generated images | Running the AI models |
| Supabase | Account details, photos, generated images | Database and file storage |
| Stripe | Name, email, payment details | Processing payments |
| Amazon Web Services | Name and email for service emails | Sending email |
| Lovable | Hosts our application, so data the app processes passes through their servers; support chat messages and related account details (your credits, trainings and orders) are processed by their AI service | Application hosting; powering our AI support assistant |
| Support chat messages and related account details (via the AI model behind our chat assistant); separately, advertising identifiers and purchase events | Answering your support questions; advertising measurement | |
| Zoho | Contents of emails you send us | Receiving support email |
| Meta, LinkedIn | Advertising identifiers and purchase events | Advertising measurement |
| Rewardful | Referral identifier and purchase value | Crediting affiliate partners |
Your photographs go only to Replicate and Supabase. They are never sent to any advertising platform.
How we protect your data
- TLS encryption on all traffic between our servers and your device
- Your trained model is private and never publicly accessible
- Access controls limiting which of our staff can reach personal data, on a need-to-know basis
- Automatic deletion on the schedule above, so we hold your most sensitive data no longer than necessary
- DKIM, SPF and DMARC protecting our email against spoofing and phishing
No system is perfectly secure. If a breach affecting your personal data occurs, we’ll notify you and the relevant authority as the law requires.
Where your data is processed
Stored in the European Union, processed in the United States and the European Union. Transfers out of the EEA and UK rely on the European Commission’s Standard Contractual Clauses. You can request a copy of the safeguards for any particular transfer.
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, send it elsewhere, or object to how we’re using it. You can withdraw consent at any time, and you can complain to your data protection authority.
Email support@themultiverse.ai and we’ll respond within one month. Because we hold photographs of your face, we may ask you to confirm your identity first — that protects you from someone else obtaining your images.
Questions we get asked
Do you keep my photos forever? No. Everything is deleted 90 days after your last purchase, automatically, whether or not you ask.
Could someone else generate images of me? No. Your trained model is private to your account and cannot be used by anyone else.
Will my photos train your AI? No. We never use customer photos to train general-purpose models.
Can I get everything deleted right now? Yes. Email support@themultiverse.ai. We’ll confirm when it’s done.
Is this GDPR compliant? Yes. See our Privacy Policy for the full detail, including legal bases, retention periods and your rights.
Full detail: Privacy Policy · Terms of Use · Questions: support@themultiverse.ai