Photocheck Tool

Privacy Policy Addendum

Last updated: April 3, 2026

This Supplemental Privacy Notice applies specifically to the Homebase Photo Check Tool (“Photo Check”) and supplements the Homebase Privacy Policy. In the event of conflict between this Supplemental Notice and the general Homebase Privacy Policy, this Supplemental Notice governs with respect to Photo Check.

§1. Who this notice applies to

This Notice applies to all individuals who use the Homebase Photo Check Tool, whether or not they are registered Homebase users. This includes international students, scholars, and any other individuals who upload a photograph for compliance verification purposes.

The Photo Check Tool is restricted to users aged 18 and older. We do not knowingly collect biometric or personal data from individuals under the age of 18. If we become aware that a user is under 18, we will delete all associated data immediately.

§2. What data we collect and why

a. Photograph and facial analysis data

When you upload a photograph, that image is submitted to automated analysis that detects facial attributes including face presence, head position and orientation, eye status, expression, and image quality attributes. This analysis is performed for the sole purpose of evaluating whether your photograph meets published U.S. Department of State and USCIS photo compliance requirements.

The facial analysis performed returns attribute flags and confidence indicators used for compliance evaluation. It does not generate or store a persistent biometric template or facial geometry record. To the extent the data processed during analysis constitutes biometric data under applicable law in your jurisdiction, all protections described in this Notice apply.

Data type
Sensitivity
Purpose
Retention
Photograph
High — Biometric
Photo compliance checking only
Deleted within 1 hour of processing
Processed output photo
High — Biometric
Delivery of compliant photo to user
Deleted within 48 hours of generation or download
Email address
Medium
Output delivery and receipt
Retained 2 years from transaction date
Payment data
High
Handled exclusively by Stripe
Not stored by Homebase
Transaction metadata
Low
Support and dispute resolution
Retained 2 years, then deleted
Deletion logs
Low
Compliance recordkeeping
Retained for applicable statute of limitations period
Server logs / IP
Low
Technical operations
Retained maximum 90 days

Your original uploaded photograph is deleted from our systems within 1 hour of processing completion, regardless of whether you proceed to purchase. Processed output photographs are deleted within 48 hours of generation or upon your download, whichever occurs first. Deletion is enforced via automated storage lifecycle policies and is not dependent on manual action. A deletion log confirming completion of each deletion is retained for the applicable statute of limitations period for compliance recordkeeping purposes.

We do not use your photograph or facial analysis data for any purpose other than photo compliance checking. We do not build profiles, train models, or retain facial data beyond the processing windows described above.

b. Email address

Collected at the point of purchase to deliver your processed photograph and transaction receipt. Retained for 2 years from the date of transaction for support, dispute resolution, and refund processing purposes, then securely deleted.

c. Payment data

Payment processing is handled exclusively by Stripe, Inc. We do not collect, store, or have access to your full credit card number, CVV, or bank account details. Stripe’s privacy policy is available at stripe.com/privacy. We retain a Stripe transaction ID and timestamp for our records only.

d. Transaction metadata

We retain a non-biometric record of your transaction including: transaction ID, timestamp, pass/fail result summary (without facial analysis data), and email address. This record is retained for 2 years on the basis of our legitimate interest in support and dispute resolution, then securely deleted.

e. Technical data

Standard server logs including IP address, browser type, and request metadata are collected automatically on the basis of our legitimate interest in technical operations and security. These logs are retained for a maximum of 90 days and are not correlated to your photograph or facial analysis data.

§3. Consent mechanism

Before uploading a photograph, you will be presented with a consent disclosure summarizing how your photograph and associated data will be collected, processed, and deleted. Consent is obtained through an affirmative, unchecked-by-default checkbox that must be actively selected before upload is permitted. Pre-checked boxes are not used. Consent is specific to the purpose described at the time of collection and is not bundled with acceptance of other terms.

This written consent mechanism satisfies the affirmative authorization requirements of applicable biometric privacy laws. This Notice, which constitutes our publicly available biometric data retention and destruction policy, is accessible prior to and independent of the point of collection.

§4. Third-party processors — Disclosure of data transfers

All photo processing for the Photo Check Tool is performed exclusively within Amazon Web Services (AWS) infrastructure. Your photograph does not leave the AWS environment at any stage of processing. The following processors are used:

a. Amazon Web Services (AWS) — AWS Rekognition

Your uploaded photograph is analyzed by AWS Rekognition, a facial analysis service operated by Amazon Web Services, Inc., for the purpose of detecting facial attributes required for compliance checking. AWS infrastructure used for this service is located in the United States. AWS Rekognition does not retain facial data submitted via API calls beyond the duration of the API transaction. AWS’s privacy policy is available at aws.amazon.com/privacy.

b. Amazon Web Services (AWS) — Amazon Titan Image Generator (Bedrock)

For paid processing, background removal is performed by Amazon Titan Image Generator v2, accessed through Amazon Bedrock, operated by Amazon Web Services, Inc. This processing occurs entirely within AWS infrastructure and does not involve transmission of your photograph to any external service or third party. The processed image is subject to the same deletion schedule described in §2(a). AWS’s privacy policy is available at aws.amazon.com/privacy.

c. Stripe, Inc.

Payment processing is conducted by Stripe, Inc., headquartered in San Francisco, California, USA. Stripe’s privacy policy is available at stripe.com/privacy. No payment data passes through our servers.

d. International data transfers

All photo and biometric data processing occurs within AWS infrastructure located in the United States. For users in the European Economic Area, United Kingdom, or Switzerland, the transfer of personal data to the United States is governed by Standard Contractual Clauses (SCCs) as maintained by AWS and incorporated into our data processing agreements. We do not transmit your photograph or facial analysis data outside of AWS infrastructure for any purpose.

§5. Legal basis for processing

For users in the European Economic Area (EEA), United Kingdom, and Switzerland

We process your photograph and facial analysis data on the basis of your explicit consent (GDPR Article 6(1)(a) and Article 9(2)(a)), provided through the consent mechanism described in §3. Transaction metadata and server logs are processed on the basis of our legitimate interests (GDPR Article 6(1)(f)) in operating, supporting, and securing the service.

You may withdraw your consent at any time by contacting us at privacy@myhomebase.org. Withdrawal does not affect the lawfulness of processing completed prior to withdrawal. Given the short processing and deletion window, practical withdrawal applies to any unprocessed data only. Withdrawal of consent does not affect our ability to retain transaction metadata and server logs on the basis of legitimate interests.

We have assessed that a Data Protection Officer is not required for our current processing activities. This assessment will be reviewed as our processing activities evolve. You have the right to lodge a complaint with the data protection supervisory authority in your country of residence.

For users in Illinois (BIPA — 740 ILCS 14/15)

By providing explicit affirmative consent through the mechanism described in §3, you authorize Homebase to collect, use, and process your biometric identifiers and biometric information as described in this Notice. This constitutes the written release required under 740 ILCS 14/15(b). Our biometric data retention and destruction schedule is as stated in §2(a) above. We do not sell, lease, trade, or profit from biometric data. We do not disclose biometric data except to the processors identified in §4 for the specific purposes described.

For users in California (CCPA/CPRA)

Your photograph constitutes sensitive personal information under California law. We collect and use it solely for the purpose of providing the Photo Check service you have requested. We do not sell or share your sensitive personal information for cross-context behavioral advertising or any other purpose. You have the right to limit our use of your sensitive personal information to the purpose for which it was collected. To exercise this right, contact privacy@myhomebase.org. Requests to limit use of sensitive personal information will be acknowledged within 15 business days.

For users in other U.S. states with applicable privacy laws

Several U.S. states have enacted privacy laws governing the collection and processing of biometric or sensitive personal data. Where such laws apply to your use of the Photo Check Tool, we process your data only on the basis of your explicit consent as described in §3, and we honor the rights described in §6 regardless of your state of residence.

For all other users

We process your data on the basis of your explicit consent provided at the point of upload and as necessary to perform the service you have requested.

§6. Your rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right to access the personal data we hold about you
  • Right to deletion of your personal data
  • Right to restriction of processing
  • Right to withdraw consent at any time
  • Right to data portability
  • Right to object to processing based on legitimate interests
  • Right to information about automated decision-making that significantly affects you
  • Right to lodge a complaint with a supervisory authority

Regarding automated decision-making: the Photo Check Tool produces a compliance result based on automated analysis of your photograph. This result determines whether your photo meets published government requirements. You may contact us to request human review of any result you believe is incorrect.

Given that photographs and biometric data are deleted within 1–48 hours of processing, deletion requests received after the processing window has elapsed will be fulfilled with respect to any remaining transaction metadata we hold.

To exercise any of these rights, contact us at privacy@myhomebase.org. We will respond within 30 days of receipt. California residents seeking to limit use of sensitive personal information will receive a response within 15 business days.

§7. Data security

Your photograph is transmitted to our systems over encrypted HTTPS connections. All processing occurs entirely within AWS infrastructure. No photograph is transmitted outside of AWS at any point. Storage is secured with role-based access controls and automated lifecycle deletion policies. No photograph is stored in browser cache, hidden fields, or any publicly accessible location.

§8. Changes to this notice

We will update this Notice as needed to reflect changes in our data practices or applicable law. Material changes will be communicated via email notification and/or website notice prior to taking effect. Continued use of the Photo Check Tool after the effective date of any update constitutes acceptance of the revised Notice.

§9. Contact

Privacy inquiries: privacy@myhomebase.org

Refund and support inquiries: support@myhomebase.org