SelectTakeEffective date: 23 August 2026
AJ GmbH, Danziger Str. 80, 65191 Wiesbaden, Germany, represented by Dr. Andreas Jahnke, is the controller for the processing described in this policy. You can contact us at privacy@selecttake.com or +49 155 61229658. No data-protection officer has been designated at this time. The contact details in the Legal Notice also apply.
This policy explains how SelectTake processes personal data when you visit the service, create an account, upload or organise images, use optional known-people matching, contact us, or purchase a subscription. It also explains important limits: SelectTake is a private image-organisation service, not a public search, surveillance, identity-verification, or social-networking service.
When you sign in, we process your email address, authentication events, account identifiers, and technical security information necessary to deliver one-time passcodes and protect access. We do not operate a fixed-password system. When you create an account, we record the version and time of your acknowledgement of the Terms of Service and Privacy Policy. Your browser may store the authentication session either until the browser is closed or, if you choose “Remember this browser”, beyond that session. This storage is exclusively used for login continuity and no other purposes, including cross-site advertising.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interests in account security, abuse prevention, and reliable service operation (Art. 6(1)(f) GDPR).
We process the image files, filenames, file type and size, collection names, selected filters, image metadata (which may include date, camera information, and location data if present), generated thumbnails, analysis results, duplicate indicators, and your export or deletion requests. The service uses this information to store your private collection, create previews, organise images, run the requested analysis, and make the resulting filters and exports available to you.
For new uploads, SelectTake temporarily processes the source file to extract available capture metadata and create a verified, optimised JPEG derivative with a maximum dimension of 2048 pixels. Once that derivative is safely stored and verified, the source file is discarded. The retained image and its ZIP download are therefore the optimised JPEG, not necessarily the original HEIC, PNG, Live Photo motion component, original encoding, transparency, or all original metadata. Existing stored images are not changed by this upload process.
Your images are private: they are not public or searchable by other users. We use private storage and short-lived signed links that are issued only after the relevant account and collection ownership checks. The service functions that create previews, analyse images, prepare exports, and delete content require privileged technical access to the relevant stored objects. A strictly limited number of authorised platform administrators may also technically access private storage only when necessary to operate, secure, repair, or meet a legal obligation for the service; this is not a user-facing image-browsing feature, is not used for advertising, and is not ordinary manual review of customer collections.
For a requested image analysis, SelectTake sends the prepared analysis image or derivative to OpenAI. Where needed to return the result to your private collection, the request may also include the original filename and any locally selected Known People labels. We do not send images to OpenAI for unrelated advertising, public-face-search, or general-model-training purposes. Image analysis is assistive: it can be incomplete or wrong, including duplicate, quality, subject, and keep/review suggestions. It does not make decisions that produce legal or similarly significant effects about you. You remain in control and must review selections before deleting, sharing, printing, or otherwise using images.
Where shown, upload and analysis time remaining is a convenience estimate based on current batch progress and recent operational measurements. It is not a promise or service-level commitment and can change with file size, connection quality, device performance, provider availability, queueing, and other factors.
You may upload, organise, and export ordinary family photographs through SelectTake. The additional safeguards in this section apply only if you choose to create a known-person reference. This optional feature is not needed for uploading, ordinary analysis, or organisation. If you deliberately add a known person, face-matching software runs in your browser on the reference photo and creates a numerical face descriptor. We store the descriptor, the label you supply, the reference filename, and a private compressed reference-image copy so that you can review or replace that reference. During an upload, matching likewise runs locally in the browser against your saved descriptors and only the selected label match is stored with the image. Plan limits are Free 2, Starter 5, Pro 10, and Scale 20 saved references.
We treat a face descriptor used to recognise a person as sensitive biometric processing. Before saving one, we obtain a separate confirmation and require you to confirm that you are the person shown or have the authority and permission required for this narrow private-account purpose. Do not use the feature for surveillance, public identification, employment, eligibility, law-enforcement, or other high-impact decisions. For a child’s known-person reference, only proceed if you are their parent or legal guardian, or otherwise have the specific authority and consent required by applicable law. You can withdraw your confirmation by deleting the known-person profile; SelectTake removes the associated stored descriptor and reference image and stops future matching. Withdrawal does not affect processing already carried out before it.
The legal basis is your explicit consent (Art. 6(1)(a) and, where applicable, Art. 9(2)(a) GDPR). Where you add another person, you remain responsible for having the lawful authority and permissions required to do so.
You can optionally turn on personalisation for an individual collection. If enabled, SelectTake stores only your explicit Keep, Review, and Delete choices for images in that collection to help you review that same collection. After at least three choices, a small explainable scoring rule may refine that collection's suggestions for images without an explicit choice, using already available blur, duplicate, and screenshot results. It does not submit a new image-analysis request or train a model. It does not use face data, known-people data, sensitive traits, or a cross-collection/account-wide behavioural profile; it never automatically deletes an image. You can reset the collection's saved choices at any time. The legal basis is your consent (Art. 6(1)(a) GDPR).
For paid plans, Stripe processes payment-method, billing, transaction, invoice, and subscription information. SelectTake receives the subscription status and limited billing identifiers needed to provide the plan and handle support. We do not receive or store full payment-card numbers. The legal basis is contract performance, legal recordkeeping obligations, and fraud prevention. Stripe may act as a processor and, for some payment or regulatory processing, as an independent controller under its own terms and privacy information.
We use Supabase for authentication, database, and private storage; Vercel for hosting and server execution; OpenAI for requested image analysis; Stripe for payment services; and Cloudflare for security challenges and abuse prevention. Access is limited to what is needed for the relevant service. Our Supabase project is hosted in Central EU (Frankfurt, Germany). Processors and subprocessors may nevertheless process data outside the EEA. Where a restricted transfer occurs, we rely on an applicable adequacy decision, Standard Contractual Clauses, or other lawful transfer mechanism as appropriate.
We select and manage processors through contractual and technical safeguards appropriate to the service. Processors and their subprocessors also have their own legal duties and terms; this does not remove our responsibility to handle personal data lawfully as controller.
If you submit in-app feedback, we process the text and submission time so SelectTake administrators can review it. We use account authentication to protect the feedback channel from abuse, but do not store your name, account identifier, or account email with the feedback. A separate, access-controlled abuse-prevention record stores the authenticated account identifier and latest submission time; it contains no feedback content. You may voluntarily add a separate reply email address; if you do, we store it with that feedback only to respond to you. Leaving the field blank keeps the submission anonymous. Anonymous feedback may be retained as operational research after account deletion; feedback with a reply email is deleted or anonymised when it is no longer needed for that reply. Do not include other personal information in the feedback text. The legal basis is our legitimate interest in improving and supporting the service (Art. 6(1)(f) GDPR).
Product-update emails are optional. If you opt in in Settings, we process the email address you provide, your opt-in and withdrawal times, the related account identifier, and a unique unsubscribe token to send SelectTake product and feature news. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time in Settings or through the unsubscribe link in a message; this does not affect processing before withdrawal. We do not use this list for behavioural advertising or sell it to third parties.
We use access controls, private storage, signed access links, one-time-code authentication, rate limits, CAPTCHA where enabled, and security logging designed to protect the service. No system is perfectly secure. We process IP-address and request/security information, error messages, and service logs to diagnose failures, prevent abuse, and investigate security incidents. We do not sell personal data or use it for behavioural advertising.
We retain account, collection, image, descriptor, and analysis data while your account remains open, unless earlier deletion is requested or required. When you delete an image or collection, we remove the associated stored files and mark or remove associated application data as part of the deletion workflow. When you delete your account, we delete account-linked images, collections, analysis data, saved face descriptors, and product-update preferences, and cancel an active subscription as described in the service. Anonymous feedback is not account-linked and may be retained as operational research. We retain only anonymised daily operational totals that cannot be linked back to an account.
When the Free-image retention feature is activated, each image successfully uploaded while an account is on the Free plan is scheduled for deletion 60 days later. If an account returns to the Free plan after a paid period, images that remain stored in that account and are covered by the then-current Free-image policy are scheduled from that return to Free, even if they were originally uploaded during the paid period. The account itself is never deleted by this rule. An active paid plan pauses an already scheduled image’s timer. If fewer than 15 days remained when the paid plan began, we add 15 days to the paused time; when the account later returns to Free, the schedule resumes with that remaining time. We will not silently apply this rule to an existing account before the feature’s activation, required notice, and active acceptance of the updated Terms and Privacy Policy. We will verify the notice-delivery and deletion process before enforcement.
For German tax and accounting purposes, payment, refund, and invoice evidence is generally retained for eight years; accounting books and annual financial statements, where created, for ten years; and relevant business correspondence for six years. We retain only the records required for the applicable category.
Provider backups and deletion propagation have retention windows of their own. Their actual settings must be verified and recorded before launch; backups are not used to restore deleted customer content except where necessary for security, legal, or disaster-recovery purposes.
Subject to the conditions in applicable law, you may request access, correction, deletion, restriction, portability, or objection to processing. Where we rely on consent, you may withdraw it at any time with future effect. You may also lodge a complaint with a competent supervisory authority. For Germany, the BfDI contact finder can help identify the appropriate authority. Send requests to privacy@selecttake.com. To protect your information, we may ask for reasonable proof that the request comes from you before acting on it.
SelectTake is intended for users aged 16 and over. We do not knowingly offer the service to younger children without the permission required by applicable law. If you upload images of other people, you are responsible for having the rights, notices, and permissions needed to do so. That responsibility does not remove our own legal obligations or your statutory rights.
We may update this policy when the service, processors, or legal requirements change. We will publish the new version with an updated effective date. Material changes affecting existing processing will be communicated where required by law.