MULTIPASSBack to photo maker

PRIVACY POLICY

Your photos stay yours.

Effective 6 October 2026

The short version: Standard formatting and cleanup run on your device. Optional website clothing previews send your selected photo and clothing mask through MULTIPASS to OpenAI only after you agree. MULTIPASS does not save photos or generated previews to its database or file storage. OpenAI’s separate data policies apply to cloud processing.

1. Who we are

MULTIPASS is an independent public-beta document-photo preparation service operated from the Kingdom of Bahrain. Questions or privacy requests can be sent to MULTIPASS.doc@gmail.com.

2. Photos and camera images

  • Standard formatting and cleanup of selected or captured photos run locally in your browser or the MULTIPASS mobile app.
  • Standard processing does not transmit photo pixels. If you request a clothing preview, our server receives the image and mask temporarily, forwards them to OpenAI for editing, and returns the result. We do not write those images to our database, file storage or application logs.
  • We do not create facial-recognition profiles, identify people, extract identity numbers or retain biometric templates.
  • Saved, shared and original files remain under your control on your device. Your browser, operating system, cloud-backup provider, photo library, email app or another sharing destination you choose may keep copies independently of MULTIPASS.

3. Child and baby photos

The child and baby tools are for use by a parent, legal guardian or other adult who has authority to use the photograph. MULTIPASS is not directed to children; the tools are intended for adults preparing photographs they are authorised to use. Standard processing keeps the photo on the adult user’s device. A guardian who chooses optional cloud clothing editing must agree to the upload before a preview starts.

4. Anonymous beta analytics

We collect limited technical events to understand whether the beta works: page or app opens, photo-selection events, processing success or failure, downloads or shares, print-sheet use, selected country/document, contact or country-request clicks, checkout-preview interest, referring domain, campaign tags and time of the event.

Analytics do not include your photo, filename, name, email address, exact location or document contents. A random session identifier connects actions during one open page or app session; it is not saved on your device and is not reused after the service restarts. Analytics older than 12 months are deleted when the next accepted event is recorded.

5. Device storage

The website uses local storage to remember light/dark appearance and the optional demo-credit balance. The mobile app uses device preferences to remember the last document preset you selected. These values stay on your device and are not advertising identifiers. We do not use third-party advertising cookies or cross-site tracking.

6. When you contact us

If you email us, we receive the information you choose to include, such as your email address, requested country and message. We use it to respond, improve the service and handle legal or privacy requests. Email records are retained only as reasonably needed for those purposes or to meet legal obligations. You may ask us to delete them, subject to any lawful retention requirement.

7. Hosting, app stores and service providers

The website and anonymous analytics database use hosting infrastructure that processes ordinary network and security information needed to deliver and protect the service. Apple or Google may process app-download, purchase-account, crash or device information under their own policies when you obtain the mobile app from their stores. Such infrastructure may operate in more than one country. Optional clothing editing uses OpenAI. Review its API data policies for provider retention and processing practices. We cannot delete provider-held records by clearing the browser. No clothing photo is uploaded unless you select that feature and agree.

8. Legal grounds and your rights

Where data-protection law applies, limited beta analytics are processed for our legitimate interest in operating, securing and improving MULTIPASS. Contact information is processed to answer your request and, where relevant, take steps you request. Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, or complain to a regulator. Email us to exercise a right.

9. Security and limits

We minimise data collection and keep standard processing on-device. Cloud clothing previews are optional. To limit abuse and processing costs, the server stores daily request counters and a daily hash derived from the network address for analytics and cloud previews; it does not store the address in those counters. Counters from earlier days are deleted when another request is accepted. No internet service can guarantee absolute security.

10. Changes

We may update this policy as the beta develops. The effective date above will change when material revisions are published.

This policy describes the current beta’s actual data handling. It is not a promise that third-party browsers, devices or services selected by a user will follow the same practices.