Where your clients’ photos go
You are routing other people’s photographs through us. This page says where they are stored, who touches them, how long they stay, who can see them, and what our checks do and do not tell you.
Storage
Agency photos are stored in a private Amazon S3 bucket in us-east-1 (N. Virginia, United States), used only for business accounts and separate from consumer orders. Case details live in a database in the same region. Photos are served through short-lived signed links, never public addresses.
Who processes them
Face detection and cropping run in our own processing function. Two steps go to outside providers for the time it takes to run them: background removal and the advisory quality assessment. Nobody else receives a photo.
Training
We do not use your clients’ photos to train models, and we do not sell or share them.
| Provider | What it does | What it receives |
|---|---|---|
| Amazon Web Services | Storage, database, processing functions, accounts and email | Photos, case details, account details |
| fal.ai | Background removal | The photo, to remove its background |
| OpenAI | The advisory quality assessment | The processed photo, to assess it |
| Vercel | Hosts the website and its API | Requests in transit |
| Stripe | Payments | Billing details. No photos. |
| Google (Analytics and Ads) | Measuring visits and ad conversions on the business pages | Page views and signup events. No photos, never on client links. |
| PostHog and Sentry | Product analytics and error reports | Usage events and error traces. No photos. |
How long they stay
Uploads are deleted 30 days after the upload, processed outputs 90 days after the attempt that produced them, and the case record 365 days after the last activity on the case. Delete a case and its photos go at once. The full retention policy
Who can see them
Members of your agency, and anything you give your API key to. Owners manage billing and branding; members work cases. Every photo records who added it: a member, your API key, or the client link. A client link opens one case only, works for 14 days and up to 25 photos, and can be revoked at any time.
What the checks are
Each photo is measured against the published specification for its document:
- Head size and position
- Image dimensions, resolution and file size
- Background
- Eyes open, face visible, expression
- Lighting and sharpness
You get what passed, what did not, and an advisory quality score with reasons. The score is our model’s opinion of the photo. It is not a decision by any passport office or consulate, and a passing check does not guarantee acceptance.
Questions
Write to sales@snap2pass.com and a person answers. Our privacy policy covers the rest.