Written by the BetterPic team. Disclosure: BetterPic is one of these vendors, so read this with that in mind. Everything below is checkable in each company's own published policy, which is the point — the answer is never in the marketing copy.
You are about to hand fifteen selfies to an AI headshot generator run by a company you had not heard of last week. It is a reasonable thing to feel uneasy about, and the uneasiness is usually vague. Here is the specific version, and the four questions that resolve it.
These tools work by fine-tuning a model on your face. Your selfies are not stored and retrieved; they are used to train a small personalised model, which then generates new images. That distinction matters for two of the questions below.
So there are three artefacts, not one: the selfies you uploaded, the trained model derived from them, and the images it produced. A policy that only talks about the first is incomplete, and most do.
How long are the uploads kept, and is deletion automatic or on request? "Deleted after processing" and "deleted on request" are very different commitments. Look for a stated period in days.
Is the trained model deleted too? This is the one almost nobody asks. The model is derived from your face and can generate more images of you indefinitely. A policy that deletes the uploads and keeps the model has not really deleted anything.
Are your portraits used to train anything general? Distinct from the personalised model. Some vendors reserve the right to use customer data to improve their base models; some explicitly do not. It is usually one sentence in the terms, and it is worth finding.
Where is the processing done, and by whom? Most of these companies use third-party GPU infrastructure. That means the selfies behind your headshot are processed by at least one company you did not choose. The good ones publish a sub-processor list; you should be able to find it.
They are worth something and they are not what most people assume.
SOC 2 Type II is an audit of whether a company follows its own stated security controls over a period. ISO 27001 certifies an information security management system. Both say the company has processes and follows them. Neither says anything about what the company is allowed to do with your selfies or with the headshots it made from them. That lives in the privacy policy and the terms, not in the certification.
So a vendor with both certifications and a permissive data-use clause is worse for you than an uncertified one with a strict clause. Read the clause.
Rolling out generated headshots across a company means uploading employee faces, which is a data-protection decision rather than a purchasing one, and someone will eventually ask you to justify it. Before rolling anything out you want: a lawful basis under GDPR if you have European staff, a sub-processor list, a retention period you can state, and — this is the one that gets missed — an opt-out that does not disadvantage the person who takes it.
Facial images can be biometric data depending on how they are processed and where you are, which raises the bar considerably. That is a question for whoever handles data protection at your organisation, not for a vendor's FAQ. The compliance side of a company rollout is worth reading before you commit a budget, and the team pricing is the easy part by comparison.
Open the privacy policy and search it for four words: retention, delete, train, sub-processor. If all four produce a clear answer, the vendor has thought about this. If any of them produce nothing, that is information too.
It takes about four minutes and it is the highest-value four minutes in choosing a headshot generator — considerably more useful than comparing style counts or turnaround times. Ours is here; do the same exercise on whoever else is on your shortlist.