Home › Privacy Policy
Privacy Policy
Last updated: 14 September 2026
This policy describes what Passport Room does with your photos and your data. It was written against the actual behaviour of the code that runs this site, not from a template.
1. Your photos are processed on your device
Every image operation in Passport Room — background removal, face detection, face enhance, cropping to a passport or visa size, colour and exposure adjustments, the outfit overlay, print-sheet layout and export — runs inside your web browser on the device you are using. The app has no photo upload endpoint. We never receive, see, store, transmit or back up the photo you open in the tool, and no human at Passport Room can look at it. If you close the tab without downloading, the image is simply gone.
2. Network requests the app does make
The AI features need model files, and those are downloaded to your browser the first time you use each feature, then cached on your device for later visits. Your photo is not part of these requests; they are ordinary file downloads. The files are fetched from:
- huggingface.co — the MODNet background-segmentation model, the YOLOFace face-detection model and the GPEN-BFR-256 face-restoration model.
- cdn.jsdelivr.net — the onnxruntime-web runtime and WebAssembly binaries that execute those models, and the three.js library used by the decorative animation.
- fonts.googleapis.com / fonts.gstatic.com — the site's web fonts.
As with any web request, those third parties can see your IP address and browser user agent when a file is fetched. They receive no image data. Their own privacy terms apply to those requests.
3. Data stored in your browser
Passport Room stores a few things locally so the app is usable across visits: your profile name and avatar if you set one, your editor preferences and last-used adjustment settings, whether you opted in to saving photo history, and — if you did opt in — the recent photos themselves. This is kept in your browser's localStorage and IndexedDB on that device only. It is not an account on our servers, it is not synchronised between devices, and we cannot read it. Clearing your browser's site data for passport-room.com permanently deletes all of it, and saved photo history can be switched off or emptied inside the app at any time.
4. Cookies and analytics
Passport Room sets no tracking cookies of its own. We do record anonymous usage statistics in a Firebase Realtime Database: a randomly generated visitor number, device type, browser, operating system, screen size, country, number of visits, time spent and number of photos made. These records contain no name, email, phone number or image data and are not used to identify you. The browser storage described in section 3 is functional, not analytical.
5. Advertising
We display advertising on this site through Adsterra. Adsterra and its advertising partners may use cookies or device identifiers to serve and measure ads, and may personalise them based on your prior visits to this and other sites. You can read how Adsterra handles this in the Adsterra privacy policy, and manage interest-based advertising generally at YourAdChoices. Advertising never has access to your photo, because your photo never leaves your browser.
6. Payments and Passport Room Pro
Passport Room Pro is an optional one-off purchase of US$0.99 for 30 days of unlimited, ad-free exports. Our order process is conducted by our online reseller Paddle.com, which is the Merchant of Record for all our orders and handles payment, tax, invoicing and billing support. Your card details are entered into Paddle's own secure checkout and are never seen, received or stored by Passport Room.
When a payment succeeds, Paddle sends us a notification containing your purchase email address, a transaction identifier and the purchase date. We store only those three items, plus the expiry date of your pass, in our Firebase Realtime Database, so the app can confirm your Pro access and let you restore it on another device using that email. We do not store your name, address, card number or any part of it. These records are kept for as long as you may need to restore a pass, and are deleted on request to support@passport-room.com. Paddle's own handling of your data is described in the Paddle privacy policy. Refund terms are set out in our refund policy.
7. Children
Passport Room is a general-purpose utility and is not directed at children under 13. Because we collect no personal data on our servers other than the purchase record described in section 6, we hold no children's data. A parent or guardian is welcome to use the tool to produce a child's passport photo, and that photo is handled exactly as described in section 1.
8. Your rights and how to exercise them
You may ask for access to, correction of, deletion of, or a copy of any data we hold about you. In practice the only data we hold is the purchase record in section 6; there is no user database, no photo storage and no server-side profile. Everything else the app creates lives on your device, so you can delete it yourself by clearing site data in your browser. For any request, including deletion of your purchase record, write to support@passport-room.com and we will answer within 30 days. Billing records held by Paddle as Merchant of Record are requested from Paddle directly.
9. Security
The site is served over HTTPS. Because processing is local, the usual risk of a server breach exposing customer photos does not exist here. The practical security boundary is your own device and browser, so keep them updated and be careful on shared computers where saved photo history would remain in that browser profile.
10. Changes to this policy
If the app's data behaviour changes — for example if a future feature needs a server — this page will be updated with a new "last updated" date and the change will be described plainly rather than buried.
11. Contact
Passport Room, Dhaka, Bangladesh. Email support@passport-room.com for any privacy question or data request.