CherishVowCherishVow

Privacy Policy

Last updated: August 25, 2026

Who We Are

CherishVow (“we”, “us”, or “our”) is the data controller for the personal data processed through this website and service. If you have questions about this policy or how we handle your data — including if you are located in the European Economic Area, the United Kingdom, or Switzerland — contact us at support@cherishvow.com.

What Data We Collect

We collect the photos you upload (bride and/or groom reference photos), your email address, and session metadata such as scene selections, generation preferences, and payment history. We also store AI-generated portraits and quality-control metrics associated with your account. Payment card details are collected and processed directly by Stripe; we never see or store your card number.

Sensitive and Biometric Data

The reference photos you upload contain facial images. Depending on your jurisdiction, facial images and the face measurements (“face embeddings”) we derive from them may be classified as biometric data, biometric identifiers, or a special category of personal data. Before you can upload photos, we ask for your explicit consent via a checkbox in the upload flow, and we record the date and time of that consent; you may withdraw that consent at any time by deleting your uploads or your account. We process this data only to validate your uploads, generate the portraits you request, and perform automated quality checks. We do not use your photos or facial data to train AI models, create facial recognition databases, or build profiles for any purpose other than delivering your portraits, and we never sell biometric data.

Retention schedule for biometric data: face embeddings are deleted together with the reference photos they were derived from — 48 hours after a session ends (or within 72 hours for sessions you never complete). Embeddings linked to a saved character are retained until you remove that character or delete your account, and in all cases are permanently destroyed at account deletion. If you are an Illinois resident, this schedule constitutes our retention schedule and destruction guidelines under the Illinois Biometric Information Privacy Act; you may withdraw consent and request early deletion at any time via Account Settings or by contacting us.

How Photos Are Stored

Uploaded and generated photos are stored in a private Cloudflare R2 bucket located in Western North America (United States) and served only through short-lived presigned URLs. All database records (including metadata and embeddings) are hosted on Railway PostgreSQL over a private network and encrypted at rest. Generated photos expire after 7 days and are automatically removed from storage.

Third-Party Processors

We work with a small set of processors to operate the service. Each processor handles data only as needed to provide its function:

  • Clerk — authentication and user identity.
  • Stripe — payment processing and fraud prevention.
  • Cloudflare R2 — photo storage and CDN.
  • Railway — database hosting.
  • Vercel — website hosting and delivery.
  • Atlas Cloud — AI image generation. Your uploaded photos are transmitted to this provider solely to generate your portraits.
  • SiliconFlow — AI vision and language analysis used to prepare your generation prompts. Images derived from your reference photos are transmitted to this provider solely to prepare your portraits.
  • Replicate — image upscaling. Your generated portraits are transmitted to this provider solely to produce high-resolution downloads.
  • Microsoft Azure — face detection on uploaded photos, used to validate that your uploads can be used for generation.
  • Amazon Web Services — automated content moderation of uploaded photos.
  • Resend — transactional email.
  • Sentry — error monitoring.

AI Training

We never use your uploaded photos, face data, or generated portraits to train AI models. Your images are processed only to create the portraits you request.

Data Retention

  • Generated portraits expire after 7 days and are automatically deleted.
  • Reference photos from a completed session are automatically deleted 48 hours after the session ends, and uploads from sessions you never complete are deleted within 72 hours.
  • Your most recent photos for each person are kept as your saved characters, so you can generate new portraits without re-uploading. They are retained until you remove the character or delete your account.
  • Face embeddings extracted during photo validation share the lifecycle of the reference photos they were derived from: session photos’ embeddings are deleted with those photos, and saved-character embeddings are retained until you remove the character or delete your account.
  • Session metadata (no photos) is retained until you delete your account.
  • Payment and tax records are retained for 7 years after a transaction to comply with legal and accounting obligations.

Security

We use industry-standard safeguards to protect your data, including encryption in transit (TLS), encryption at rest for database records, access controls for our infrastructure, and private object storage with presigned URLs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Data Breaches

In the unlikely event of a personal data breach, we will notify affected users and relevant regulators as required by applicable law, including without undue delay under GDPR where feasible.

Cookies & Similar Technologies

We use a small number of essential cookies required for authentication, security, and payment fraud prevention. With your consent, we also collect optional, first-party analytics events to understand how the service is used. We do not use advertising or cross-site tracking cookies, and our optional analytics does not involve any third-party cookies.

NameProviderPurposeDuration
__sessionClerkAuthentication session (essential)Session
__client_uatClerkSign-in state synchronization (essential)Session
__stripe_midStripePayment fraud prevention (essential)1 year
__stripe_sidStripePayment fraud prevention (essential)30 minutes
ai_portrait_cookie_consentCherishVowRemembers your cookie choice (browser storage, not a cookie)Until cleared

Optional analytics events are sent only after you choose “Accept All” in the consent banner, and are stored on our own systems. You can change your choice at any time via “Cookie settings” in the site footer. Because we do not sell or share personal data for advertising, we do not respond to “Do Not Track” browser signals; where the Global Privacy Control (GPC) signal is legally required to be honored as an opt-out, we treat it as declining optional analytics.

Automated Processing of Your Photos

Uploaded photos are validated automatically (face detection, quality checks, and content moderation), and automated checks may reject a photo that cannot be used for generation. These decisions are made solely to deliver the service you requested and have no legal or similarly significant effect on you. If you believe a photo was rejected in error, contact us at support@cherishvow.com and we will review it manually.

Legal Basis & International Transfers

If you are in the EU/EEA or UK, we process your data on the following legal bases: performance of a contract (creating and delivering your portraits), your consent (biometric processing of uploaded photos, optional analytics, and any marketing), legitimate interests (service security and improvement), and legal obligations (payment and tax records). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Your data may be processed in the United States and other countries where our processors operate. For transfers from the EU/EEA and UK, we rely on the European Commission’s Standard Contractual Clauses supplemented by appropriate technical safeguards, including encryption.

Your Rights

You have the right to access, export (data portability), correct, and delete your personal data, to withdraw consent, and to request restriction of or object to certain processing. Use the Export and Delete options in your Account Settings, or contact us at support@cherishvow.com. If you are in the EU/EEA, you have the right to lodge a complaint with your local data protection authority; if you are in the UK, you may complain to the Information Commissioner’s Office (ICO).

US State Privacy Rights

If you are a resident of California or another US state with a consumer privacy law, you have the right to know what personal data we collect, to request deletion of your data, to opt out of the sale or sharing of your personal data, and to non-discriminatory treatment for exercising your privacy rights. We do not sell or share personal data for cross-context behavioral advertising, so there is no sale or sharing to opt out of; where applicable law requires it, we honor Global Privacy Control signals as an opt-out request. To exercise your rights, contact us at support@cherishvow.com.

Children's Privacy

CherishVow accounts are intended for users aged 18 and over, and we do not knowingly collect personal data directly from children. Photos in which minors appear may only be uploaded by a parent or legal guardian who has the authority to provide consent on behalf of the minor. If you believe we have collected data from a child without appropriate consent, please contact us so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact

If you have any questions about this Privacy Policy, please reach out to support@cherishvow.com.