Version 1.1 · Last updated: September 16, 2026
Portraitor ("we", "our", "us") is a service operated by Project Fifty4, which is the data controller for the information described here.
Registered address and company number to be inserted here.
You can reach us at admin@portraitor.ai about anything in this policy.
This policy explains what information we handle when you use portraitor.ai (the "Service"), why, and the choices you have. By using the Service you agree to the practices described here. If you do not agree to them, please do not use the Service.
Before any part of your conversation is transmitted, your browser removes names, email addresses, telephone numbers, postal addresses and credentials and replaces them with anonymous placeholders. This process takes place entirely on your own device. If it does not complete successfully, no data is transmitted and your payment is refunded automatically.
This removes who is speaking. It does not remove what was discussed: if the people in the conversation talked about their health, beliefs, relationships or sexuality, those passages travel to the analysis provider inside the anonymised text, without any name attached.
Chat exports often contain photographs, videos and voice recordings. The Service never opens them and never transmits them. Only the written messages are read, on your device, and only their masked text is sent.
The redacted text is then transmitted to our servers and passed immediately to our artificial-intelligence provider for the generation of your portrait. We do not store the content of your conversation. It is held only for as long as generation requires and is discarded once your portrait has been produced. A very large conversation arrives in parts and is held in a temporary file on our server until the analysis request is assembled, at which point it is consumed and deleted; an upload that is abandoned part-way becomes unreadable after fifteen minutes and is removed by our daily maintenance. Conversation text is never written to our database, our backups or our logs.
The portrait itself is information about a person. The analysis produces inferences about a participant in the conversation: personality traits, attachment and conflict style, emotional regulation, motivations, communication style, patterns of concern such as manipulation or coercive control, and darker personality tendencies, each with an estimate of confidence. It also estimates the language of the conversation and whether messages appear to have been written with the help of an AI tool. These inferences are the product. They are delivered to you alone, on screen, by email and as a copy produced on your device. We do not retain them, no one at Portraitor can read them, and no decision about anyone is ever made from them by us or by any system we operate.
A conversation has more than one participant, and the other participants have not used the Service themselves. Their names, email addresses and telephone numbers are removed on your device by the same process described above, before anything is transmitted, and the list that matches each placeholder back to a real detail never leaves your device. Neither we nor that provider therefore learn who they are. We hold no record of them, the portrait is delivered to you alone, and nothing about them remains anywhere on our systems once your portrait has been produced. Before you pay, you confirm that you have permission to analyse the conversation; the Terms of Service set out what that confirmation requires of you.
The Service does not operate user accounts. You may purchase a single portrait as a guest, or purchase a Pass, which is an anonymous code granting a monthly allowance of portraits. A Pass is not associated with your name or email address, and we are unable to identify the person using one.
When you make a purchase, you give us your email address at checkout so that Stripe can issue your receipt and so that we can deliver your portrait. We pass it to Stripe and keep no copy of it. That address is held by Stripe and is not retained by us. We retrieve it from Stripe only at the point of delivery and do not copy it into our own records.
Payments are processed directly by Stripe. We receive confirmation of payment and a transaction reference only. We do not receive or store your card details at any time.
Your portrait history, comprising the conversations you submit and the results returned to you, together with the email address last used for billing or delivery, is stored within your own browser. While a subscription purchase is being completed, your browser also keeps a short record of it, holding the subscription reference and a single-use confirmation value so that your Pass code can still reach you if the page is reloaded; that record holds no card details, no email address and no Pass code. This information remains on your device and is not transmitted to us unless you choose to share it or enter the address at checkout. Clearing your browsing data for this site removes it permanently.
Our servers record IP addresses, browser type and times of access for security and diagnostic purposes, and we record technical faults in order to correct them. Where an IP address is retained in our fault records, it is stored in an irreversible form that allows us to establish whether a series of failures originates from one visitor or several, but does not enable us to identify that visitor. Retention periods are set out in section 7.
Data protection law requires us to identify a lawful basis for each purpose for which we process your personal data. Those bases are set out below.
| Purpose | Lawful basis |
|---|---|
| Processing your conversation in order to generate and deliver your portrait | Performance of a contract with you |
| Taking payment and maintaining the transaction record | Performance of a contract, and compliance with a legal obligation for the tax retention period |
| Maintaining server and fault records, and limiting abuse of the Service | Our legitimate interests in keeping the Service secure and available |
| Responding to your enquiries and to requests concerning your data | Compliance with a legal obligation |
| Measuring how the site is used | Our legitimate interests in understanding and improving the Service; your consent where your local law requires it, which you may withhold by the means described in section 6 |
We do not use your data for advertising, and we do not take automated decisions producing legal or similarly significant effects concerning you.
The following is a complete list of the third parties that receive your data, the data each receives, and the purpose for which it is disclosed. Each processes data under its own privacy policy.
| Who | What they receive | Why |
|---|---|---|
| Artificial-intelligence provider United States Privacy Policy |
Your masked conversation text | Generates your portrait |
| Stripe Privacy Policy |
Your email address, card details, billing country | Takes payment, sends receipts, and holds the only copy of your email address |
| Google Analytics Privacy Policy |
Pages visited, referring site, device and browser type, approximate location. Never your conversation. | Shows us how the site is used so we can improve it |
| Hostinger Privacy Policy |
Everything that passes through the Service, plus your portrait and email address when we send it | Hosts the Service and sends your portrait by email |
| Google Fonts Privacy Policy |
Your IP address, when a page loads | Serves the typefaces the site is set in |
| Cloudflare Privacy Policy |
Your IP address, when a page loads. When you make a purchase, your email address and the details of that purchase, which pass through the payment gateway we run on Cloudflare. Your card details never pass through it, and never reach our servers either: they go from your browser directly to Stripe. | Serves one JavaScript library used to read chat export files, and routes payment requests to Stripe so that no payment credentials are held on our own servers |
Our payment processor's script is loaded on all pages of the site rather than on payment pages alone, and collects device information for the purpose of fraud prevention.
We use Google Analytics to understand how the site is used: which pages are visited, where visitors arrive from, and what kind of device and browser they use, together with an approximate location derived from the network address. Analytics measures your use of the site itself; it never receives your conversation, which is protected by the separate mechanisms described above. If you prefer not to be counted, Google's browser opt-out add-on prevents the analytics code from running, blocking cookies for this site in your browser has the same effect, and turning on Global Privacy Control or Do Not Track in your browser stops the analytics cookies being set at all, because we honour both signals. We use no advertising pixel and no session recording software.
We set the cookies that are strictly necessary for the Service to function, and Google Analytics sets cookies to measure how the site is used. We do not use cookies to advertise to you, whether on this site or elsewhere. You can prevent the analytics cookies through your browser's cookie settings or with Google's browser opt-out add-on.
| Purpose | Set by | Duration |
|---|---|---|
| Keeping your Pass active Allows your Pass to remain active as you move between pages, so that it need not be re-entered each time. |
Portraitor | Up to 30 days |
| Fraud prevention on payments Used by our payment processor to detect fraudulent activity. See Stripe's cookie policy. |
Stripe | Up to 1 year |
| Usage analytics Google Analytics cookies ( _ga and variants) distinguish visitors and sessions so we can see how the site is used. You can block them in your browser or with Google's opt-out add-on, as described above. |
Google Analytics | Up to 2 years |
Your portrait history is held in your browser's own storage rather than in a cookie, and is not transmitted to us. For completeness, the Service also keeps the following on your device and nowhere else: an identifier that distinguishes your browser's own saved conversations from those of another browser; a snapshot of the placeholder list that allows an interrupted portrait to resume after the page is refreshed; the short record of a subscription purchase in progress described in section 2; and a cached copy of the privacy filtering model, so that it is downloaded once rather than on every visit. None of these is transmitted to us, and all of them are removed when you clear your browsing data for this site.
We honour the Global Privacy Control and Do Not Track signals. If your browser sends either of them, the analytics cookies are not set at all.
| Data | Kept for | Reason |
|---|---|---|
| Conversation content | Not retained | Processed only for the duration of generation, then discarded |
| Your email address | Not retained by us | Held by Stripe. We access it to deliver your portrait and keep no copy |
| Your Pass | Retained indefinitely | Required to operate your monthly allowance and to permit a cancelled Pass to be reinstated. Contains no information identifying you |
| Payment records | 7 years | Required by tax law. No name, email address or card details |
| Technical fault records | 90 days | Diagnosing and correcting faults. IP addresses held in irreversible form |
| Server access logs | 30 days | Security and prevention of abuse |
| Payment confirmations | 30 days | Verifying that each payment is applied once and once only |
| Data-rights request record | Until the verification link expires | An irreversible code derived from the requesting email address, used only to limit repeat requests. Deletion links expire after 30 minutes and access and export links after 24 hours; the record is then cleared by daily maintenance |
| Receipt delivery outcome | With the payment record | Whether the receipt email was accepted, and when. Held with no address |
| Portraits held in your browser | Until you clear them | Stored on your device and under your control |
Our hosting provider takes a copy of our database roughly daily and keeps each copy for about one month. A record deleted from the live database can therefore persist in those copies for up to a month before they expire. The copies contain the same records as the live database and nothing more: no conversation text and no portrait is ever in them.
The rights described in this section are those set out in the UK General Data Protection Regulation and the EU General Data Protection Regulation. We make them available to every user of the Service, wherever you live, and we apply the same procedure and the same 30-day response period to everyone.
You have the right to obtain access to your personal data, to have it corrected or erased, to receive it in a portable form, to object to certain processing, and to withdraw any consent you have given. The procedure for exercising each of these rights is set out on the Your Data Rights page. You may also write to us at admin@portraitor.ai, and we will respond within 30 days.
Because we operate no accounts and retain no email address, the scope of most requests is limited. The personal data associated with you is held by our payment processor and can be erased there on request. Your portraits reside on your own device and are not accessible to us.
You also have the right to lodge a complaint with a data protection supervisory authority. In the United Kingdom this is the Information Commissioner's Office. In the European Union it is the supervisory authority of your country of residence. We would encourage you to raise the matter with us first, but you are not obliged to do so.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so at any time, and no part of the Service is built to do so, so there is no sale or sharing to opt out of. The categories of personal information we handle, the purposes, and every third party that receives any of it are listed in full in sections 2, 4 and 5 of this policy. As described in section 6, we honour the Global Privacy Control and Do Not Track signals: if your browser sends either, the analytics cookies are not set. The rights described above, including access, deletion and correction, are available to you on the same terms as to everyone else, and we will not treat you differently for exercising them.
All data in transit is encrypted using HTTPS. Pass codes and session tokens are stored only in an irreversible form, so neither can be recovered from our records. Card details are collected by our payment processor's own form and never reach our servers. Every request concerning a Pass is tied to the session that made it, so one customer cannot reach another's records by altering a request. No administrative function can read a conversation or a portrait. No permanent copy of your conversation is retained on our servers. We review our analytics settings, our AI provider's terms, security advisories for the software we use, and our stated retention periods every quarter. No method of transmission over the internet is entirely secure, however, and we are therefore unable to guarantee absolute security.
The redacted text is analysed by a third-party artificial-intelligence provider, on that provider's paid service tier. What reaches it carries no names, email addresses or telephone numbers, because those were replaced on your own device before anything was transmitted. Three limits apply to what the provider may do with it, and we state them expressly rather than leaving the matter to inference.
Under the terms applicable to that tier, the provider does not use your conversation to train or improve its models, and it is not reviewed by the provider's personnel for that purpose. The provider does retain submitted content for a limited period in order to monitor misuse of its own service, and we are unable to disable that retention. A long conversation is analysed in sections, each sent separately in anonymised form, and the results are combined into one portrait. The provider's own privacy policy is linked in the register at section 5, and the service terms these limits rest on are available here.
Your data may be processed outside your country, including in the United States where our artificial-intelligence provider and Stripe operate. These transfers are protected by appropriate safeguards, including Standard Contractual Clauses.
The Service is not intended for anyone under 16. We do not knowingly collect data from children. If you believe that a child has provided us with personal data, please contact us and we will remove it.
If we are required by law or by a court to disclose information, the most we are able to produce is what section 7 describes: payment records identifying no one, Pass records containing nothing identifying, and fault records with network addresses in irreversible form. We hold no conversation, no portrait and no email address, so none can be disclosed by us.
If the business is sold or transferred, the records described in section 7 would pass to the new owner under the same commitments made in this policy. Nothing else exists to transfer: conversations and portraits are not held by us, and your email address is held only by our payment processor.
This policy applies to portraitor.ai only. Where we link to other sites, including our service providers' own policies, those sites are governed by their own terms.
We may update this policy from time to time. Each version carries its own number and date, shown at the top of this page, and every previous version remains readable from the version history at the end of this page. Continuing to use the Service after a change means you accept it.
Project Fifty4
Email: admin@portraitor.ai
Each version of this document is listed below, together with the date it took effect and what changed. Superseded versions remain readable so that you can see the exact wording that applied when you used the Service.
| Version | In effect from | What changed |
|---|---|---|
| 1.1 | September 16, 2026 | Named the laws your rights come from and confirmed they apply to everyone. Added a section for residents of California and other US states. Described what happens to the other people in a conversation. Listed everything the Service keeps on your device. Stated that Do Not Track and Global Privacy Control signals are honoured. Described what the analysis infers about a person, that masking removes identifiers but not subject matter, that attachments are never opened, and how a very large conversation is handled. Added backups, the data-rights request record and the receipt delivery record to the retention section, a lawful basis for usage measurement, and new sections on disclosure required by law, change of ownership and links to other sites. Replaced the general security statement with the specific measures in place. The analysis provider is now described by category rather than by name, with its privacy policy and service terms still linked at section 5; Google Analytics and Google Fonts remain named because they are named products. |
| 1.0 (archived copy) | September 13, 2026 | First published version of this policy. |