For DPOs, bursars and heads
Data protection and security
What happens to a pupil's photo from the moment it's added to the moment it's deleted: where it's stored, who handles it, how long we keep it and what we keep afterwards. Everything you need for a DPIA, in plain English.
At a glance
- Stored in the EU. Photos are kept in private storage in Ireland, and the app runs in London.
- Deleted after 48 hours (or 7 days if you choose), automatically.
- Never used to train AI.
- Location data removed before upload.
- You stay in control. You're the controller and we're your processor, under a data processing agreement.
What happens to a photo
- You add a photo. Your browser looks for faces on your device and redraws the photo, which removes hidden information such as its GPS location and camera details. If your browser can't find faces itself, the photo is sent to a face-finding model run by Replicate instead.
- It uploads to private storage. The photo uploads as soon as you add it, so it's ready when you press anonymise. Storage is private: nobody can reach a file without a link we create for your account, and those links expire within minutes.
- It's checked. Before anything is anonymised, OpenAI's moderation service checks the photo for explicit or graphic content. Photos that fail are refused, and you aren't charged.
- The faces you chose are replaced. Only the area around each face you chose is sent to Google's Gemini image model, run by Replicate, which draws a new face. We put only those faces back into your photo, so the rest of it is untouched.
- You download it. Nothing is published or shared. You decide where the finished photo goes.
- Everything is deleted. Each file we stored is deleted 48 hours after it was stored, or 7 days if you chose that in History. The clean-up runs every hour, so a file can last up to an hour longer.
Who handles the data
These are the only companies that handle personal data for us. We'll update this list before adding a provider that handles your photos.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, sign-in and photo storage | Ireland (EU) |
| Vercel | Hosts the website and app (functions run in London) | UK, with global edge network |
| Replicate (running Google's Gemini 2.5 Flash Image model, “nano-banana”) | Anonymises the faces you choose, and finds faces when your browser can’t | USA |
| OpenAI | Automatic content checks on uploads | USA |
| Stripe | Payments and receipts | UK/EU and USA |
| Resend | Sign-in and account emails | USA |
| Google Analytics | Website usage statistics, only if you accept analytics cookies | USA |
| Measuring our LinkedIn adverts, only if you accept analytics cookies | Ireland and USA |
For providers in the USA we rely on the UK–US data bridge where they're certified under it, or on the UK International Data Transfer Addendum to the EU standard contractual clauses. Our AI and moderation providers may keep what they receive for a limited period for security and abuse monitoring under their own terms (OpenAI: up to 30 days).
What we keep, and for how long
- Photos: 48 hours after each file is stored, or 7 days. This covers originals, anonymised photos and everything in between.
- A record of each job: the date, file name, how many faces were found and changed, the face positions as box coordinates, and the result. There are no images in it. It's kept while your account is open, so you can show what was done.
- Who confirmed the right to upload: when someone at your organisation agrees to our upload checklist, we record the wording, the time, their IP address and browser.
- Purchases: 6 years, as UK tax law requires.
- When an account is deleted, its photos go at the next hourly clean-up and its job records go with it.
How the photos are protected
- Photos are sent over HTTPS and stored in private storage that's encrypted at rest.
- The storage can't be read directly from the website. Every file is reached through a link we create for the account that owns it, and the link expires within minutes.
- Every request checks that the photo belongs to the account asking for it.
- Everyone who works on Safeguard Vision is bound by confidentiality, and we'll tell you without undue delay if we become aware of a breach affecting your photos.
For your DPIA
Anonymising photos before you publish them reduces risk: the published photo no longer shows a real child's face. A DPIA for Safeguard Vision usually covers:
- Roles: your organisation is the controller for the photos and we're the processor (terms, section 6).
- Lawful basis: yours to choose. Our GDPR for schools guide explains the state and independent school differences.
- Data minimisation: location data is removed before upload, and only the area around each chosen face goes to the image model.
- Retention: 48 hours or 7 days, set by you.
- Transfers: the USA, for content checks and anonymising, under the UK–US data bridge or the IDTA.
- Your rights requests: we'll help you answer requests from the people in your photos.
Our privacy policy has the full detail. For a signed data processing agreement or anything else your DPIA needs, email hello@safeguard-vision.com.
Common questions
Data protection: quick answers.
Where are the photos stored?
How long do you keep pupils' photos?
Are the photos used to train AI?
Do you have a data processing agreement?
Who is the data controller?
Do parents need to consent to the photos being anonymised?
Share school life, not pupils' identities.
Try it on two of your own photos now. If it doesn't earn a place in your week, you've lost nothing.
Anonymise 2 photos free →- ✓ 2 photos free
- ✓ No card
- ✓ About ~20 seconds