Photo2Report is operated by NorthKit Labs. NorthKit Labs does not sell your personal information or make your project content public. By default, photos and generated files are available only in your signed-in workspace. We and the service providers below process them only to operate the features you use.
Information we handle
Photo2Report may store the following information:
- Your verified sign-in email, display name, password hash, selected industry, plan, and account settings. We do not store your readable password.
- Project titles, customer names, service dates, work types, areas, captions, summaries, and private notes.
- Photos you upload, their visibility choices, and PDFs or ZIP archives you generate.
- Stripe customer and subscription identifiers, plan status, renewal date, and limited card details such as brand and last four digits. Photo2Report does not receive your full card number.
- Limited product and first-touch attribution records used to operate, secure, and improve the service. These can include an anonymous browser-session identifier, landing page, referring website hostname, and campaign tags you arrived with. If you create an account, Photo2Report can associate that original source with the account so we can measure whether a visit led to useful product activity. These records do not include photo contents, report text, complete payment details, or IP addresses.
- Feedback you choose to submit, including its topic, message, page, account email, and submission time.
Uploaded images are resized for report quality, converted to JPEG, and stripped of location metadata before storage.
Photos added to the pre-registration private preview are processed only in your browser. If you choose to continue with those photos, an expiring copy stays in that browser for up to 24 hours while you sign in or verify your email. Photo2Report uploads them only after sign-in, into a project owned by your account. If you continue without the photos, they are not transferred to Photo2Report.
After you sign in, Photo2Report may keep an optimized copy of a photo upload in this browser for up to 24 hours when the upload is interrupted. The recovery copy is scoped to the signed-in account and is removed after a confirmed upload, when you discard it, or when it expires. It is not stored in the public offline cache.
How information is used
We use this information to authenticate your workspace, organize projects, create the files you request, apply account limits, operate billing, prevent abuse, provide support, troubleshoot the service, and understand which workflows need improvement.
Service providers
Photo2Report uses Cloudflare for the application, database, and private file storage; Stripe for subscription billing; Resend for account verification and support email delivery; and OpenAI for optional AI-assisted drafts. Cloudflare may process technical request data such as IP address, device, and security information to deliver and protect the service. Stripe, Resend, and OpenAI receive only the information needed for the feature you choose. Each provider handles data under its own privacy, security, fraud-prevention, and legal-retention policies.
AI-assisted drafts
AI generation is optional and starts only when you select Generate with AI. The request can include project metadata, captions, and up to twenty relevant photos. Customer reports use customer-visible photos; marketing reports use marketing-approved photos; internal reports may use the project's internal photos.
OpenAI states that API inputs and outputs are not used to train its models by default. Its API service may retain limited abuse monitoring logs under its applicable policy. Always review and edit AI-generated text before creating or sharing a file.
Retention and deletion
We retain workspace data while your account remains active so you can reopen projects and download saved files. You can permanently delete a single photo from its settings or delete your entire account from the Account page.
Account deletion first cancels an active Stripe subscription, then removes the Photo2Report account, projects, stored photos, generated files, linked feedback, account-linked attribution, and product events. It cannot recall copies you already downloaded, emailed, or shared. Stripe payment records and provider security or delivery logs may remain under the provider's required retention period.
Browser-local preview and failed-upload recovery copies expire within 24 hours. You can also remove them from the relevant prompt; clearing this site's browser data removes them immediately.
Your choices and responsibilities
You control each photo's area, stage, customer visibility, and marketing approval. Customer visibility controls eligibility for customer-facing reports; marketing approval is a separate choice for promotional output. Internal reports can include private project content. Upload only material you are authorized to use. Avoid faces, identification, licence plates, confidential documents, or other sensitive information unless it is necessary for the job and you have permission to process it.
To review or delete stored information, open your Account page. For privacy questions, use our private support form.