Privacy Policy
Last updated
1. Who we are. KNK Consulting LLC, 8465 W. Sahara Ave., Suite 111, Unit #1441, Las Vegas, NV 89117. Contact: hello@graydrop.com. We are the data controller for the personal data described here.
2. What we collect.
| Category | What | Why | Kept for |
|---|---|---|---|
| Uploaded photographs the photo you give us | Images you submit, including images of identifiable people | To generate your portrait | Deleted within 24 hours of upload. Always, and automatically, whether or not you ask. |
| Purchased portrait the file you buy | The finished image we produce for you | To deliver your order | Downloadable for 30 days, then deleted. It does not disappear with your uploaded photo. |
| Unpurchased portrait a preview never bought | A portrait generated but not paid for | To show you the result before you decide | Deleted within 24 hours, with the photo it came from |
| Email address | Given at checkout, or typed into one of the optional fields described in section 2a | Order delivery and support; sending you a link you asked for; marketing only if you separately ticked the box asking for it | Until you unsubscribe or ask us to delete it |
| Payment data | Handled entirely by Stripe | To take payment | We never receive or store card details |
| Consent record | Timestamp, hashed IP, consent version | To evidence lawful processing | 3 years |
| Technical data | Hashed IP, browser type, timestamps | Security, abuse prevention, rate limiting | 90 days |
| Usage analytics | Aggregate page views via Cloudflare Web Analytics, cookieless | To improve the Service | Aggregate only |
| Creator referral | Which creator’s link you arrived through, if you used one | To pay that creator their share of a sale | 30 days in a cookie; with your order while we keep it |
We do not use cookies for advertising or to follow you around the web. We do not run advertising trackers. We do not sell personal data.
Our analytics sets no cookie and stores nothing on your device, so there is no consent banner to click. It records a page view — the page, the referrer, and general device type — and cannot identify you or follow you to other sites. The cookies we set are strictly necessary ones: a rate-limiting identifier on the preview form; if you buy, a short-lived session for your order; and if we send you a private gift link, a cookie that remembers it until the portrait is made. There is one exception, described next.
Creator links. We work with a small number of creators who share a link to Graydrop with the people who follow them. If you arrive through one of those links — an address with ?ref= and their name on the end — we set one cookie, gd_ref, which holds only that creator’s name. It says nothing about you and cannot be used to identify you. It lasts 30 days, and if you buy a portrait in that time, the creator is paid a share of the sale. You pay the same price either way. We do not set it if you are in the European Economic Area, the United Kingdom or Switzerland, where a cookie like this needs your permission first, or if your browser sends a Global Privacy Control signal. You can delete it in your browser settings at any time, and nothing about the site changes if you do.
2a. Email addresses you give us before buying anything. There are two optional fields on the site that ask for an email address before any purchase: a reminder field on a seasonal style page, and an “email me this portrait” field on the preview screen. Both are optional, neither is required to use the Service, and refusing costs you nothing.
An address given through either field is used only for the one thing it was given for. If you asked to be reminded, you get one reminder. If you asked for a link to your portrait, you get that link. We do not send marketing to these addresses.
Beside each field there is a separate, unticked box offering marketing email. It is not required, ticking it is not a condition of anything, and the field works identically either way. Only if you tick it may we send you anything else — and every such message carries a one-click unsubscribe. Whether you ticked it is stored as its own field on your record, with its own timestamp, and the code that builds a marketing send reads that field and excludes every address without it.
We store, for each address: the address, when it arrived, where on the site it came from, whether marketing consent was given and when, the version of this policy in force at the time, a hashed (never raw) IP, and the order it relates to where there is one. That record is the evidence that the consent was lawfully obtained, which is why we keep it. Unsubscribing deletes the record and leaves only an irreversible hash of the address on a suppression list, so that we can recognise it and refuse to add it again without ever holding it.
Bot protection. We use Cloudflare Turnstile in invisible mode on the portrait form to stop automated abuse. Turnstile collects limited technical signals from your browser to distinguish humans from bots; it does not track you across sites and is not used for advertising. See Cloudflare’s Turnstile Privacy Addendum.
3. Legal bases (GDPR/UK GDPR). Performance of a contract, for processing your images to deliver your order. Explicit consent, for processing images containing biometric or special-category data. Legitimate interests, for security, fraud prevention, and aggregate analytics. Legal obligation, where applicable.
4. Biometric and special category data. Photographs of identifiable people may constitute biometric or special-category personal data in some jurisdictions. We process such data only with your explicit prior consent, only to generate the portraits you request, and never to identify, verify, or recognise any individual.
We do not create, derive, store, or retain facial recognition templates, face embeddings, face geometry scans, or biometric identifiers of any kind. Our processing produces images only.
See our Biometric Data Policy for the full retention and destruction schedule.
5. Sub-processors. To provide the Service we transmit your images to:
| Provider | Purpose | Location |
|---|---|---|
| OpenAI, L.L.C. | Image generation and quality analysis | USA |
| Google LLC | Alternate image generation provider | USA |
| Vercel Inc. | Hosting and temporary image storage | USA/EU |
| Upstash Inc. | Order and rate-limit data | USA/EU |
| Stripe, Inc. | Payment processing | USA |
| Resend Inc. | Transactional email — receipts, download links, and links you asked us to send you | USA |
| Cloudflare, Inc. | Bot protection (Turnstile) on the preview form, and cookieless usage analytics (Cloudflare Web Analytics) | USA |
We have instructed our AI providers that submitted content must not be used for model training, and we use API tiers configured accordingly. International transfers rely on Standard Contractual Clauses or the EU–US Data Privacy Framework where applicable.
6. Retention and deletion. There are two separate clocks and they are not the same. The photograph you upload is automatically and permanently deleted within 24 hours, along with any portrait that was never purchased. The portrait you buy stays downloadable for 30 days and is then deleted. Deletion is automated; it is not dependent on you requesting it.
7. Your rights. Depending on where you live you may have the right to access, correct, delete, port, restrict, or object to processing of your personal data, to withdraw consent at any time, and to lodge a complaint with your data protection authority. California residents additionally have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal data as those terms are defined.
Exercise any right by emailing hello@graydrop.com. We respond within 30 days and do not charge or discriminate for exercising rights.
8. Children. The Service is for adults 18 and over. We do not knowingly collect personal data from anyone under 18. Photographs may contain images of children, uploaded by an adult who has confirmed they are the parent or guardian or have that parent or guardian’s consent. If you believe a child’s data has been submitted improperly, contact hello@graydrop.com and we will delete it promptly.
9. Security. Encryption in transit and at rest, strict access controls, metadata stripping on upload, short-lived signed download links, automated deletion, and rate limiting. No system is perfectly secure, and we cannot guarantee absolute security.
10. Changes. Posted here with a revised date; material changes notified by email where we hold one.
Questions about any of this? Email hello@graydrop.com.