Skip to content
EnhancerPro

Draft for legal review, last updated 11 October 2026. These pages are not legal advice and are not a finished contract. A qualified lawyer must review them for the real operating company, country, tax setup, and payment provider before the site takes customers or processes other people’s photos in production.

Privacy

On-device photos are not uploaded. Cloud photos are deleted on a short timer. This is a draft, not a finished policy.

Who this draft is for

This privacy note describes how the EnhancerPro website is built to handle photos and accounts. The operating company, address, and jurisdiction are not filled in yet. Do not rely on this page as a finished privacy policy.

What stays on your device

The default enhancer runs in your browser. That photo is not uploaded, is not written to our database, and does not appear in your account history. The result lives in the tab until you download it or close the page.

What we process if you choose Cloud

The image file, the tool you chose, the scale, and the fidelity setting. We store the upload and the result only long enough to show you a preview and a download.

Signed-out cloud files are kept for 1 hour. Account files are kept for 24 hours. You can delete a cloud photo sooner from the dashboard. A daily sweep also refuses downloads after the expiry time and removes the file.

We do not use uploads to train models. There is no data-donation programme in this version.

Account and payment data

If you sign in, we store your email, a credit balance, a ledger of grants and spends, and job history without the image bytes after deletion. In demo mode the account lives in a file on the server. With Supabase configured, it lives in Postgres.

Card numbers are not handled by this app. Paddle or Lemon Squeezy is the merchant of record and processes payment, tax, and receipts. We store the credit grant that their webhook reports.

Cookies

An essential anonymous id cookie remembers the free daily cloud try. A session cookie remembers a demo sign-in. If Supabase is configured, Supabase sets its own auth cookies. A consent preference is stored in local storage on this device.

This version does not load analytics. If analytics are added later, they must stay off until you choose Accept, and Reject must work in one click.

Sub-processors you would be trusting

Supabase (auth and Postgres), Cloudflare R2 (image storage), Replicate (GPU inference, only if a token is set), Paddle or Lemon Squeezy (payments), and the host that runs the Next.js app, expected to be Vercel or another Node host behind Cloudflare DNS. Each vendor is used only when its keys are present.

Retention of records that are not photos

Credit and payment ledger rows are kept while the account exists, because they explain the balance. Contact messages are kept so the operator can reply. Server logs are not meant to contain image bytes. This draft does not set a tax-retention period; counsel needs to set one for the real entity.

Your requests

You can delete cloud photos and the whole account from the dashboard. For an export or a question, use the contact page and choose Privacy request. The mailbox support@enhancerpro.ai has to exist before you promise a response time.

Children

The service is not for anyone under 16. Do not upload photos of minors for any sexual, undress, or exploitative purpose. That is prohibited and the account will be closed.

Security

The site is served over HTTPS in production, sets a strict referrer policy, and refuses to be embedded in another site’s frame. Downloads use short-lived signed links. Secrets stay in environment variables. Image bytes are not written to application logs.

EnhancerPro is a product prepared for Nimbuly Apps. The legal entity name, registered address, company number, and governing law are intentionally blank until the owner fills them in. Do not describe a company that has not been formed.