Privacy
Last updated August 20, 2026 · Plain language on purpose. If anything here is unclear, write and ask.
Who is responsible
HENRI is operated by Seth Goldstein (the data controller for anything you send here). Contact for anything on this page, including deletion and complaints: seth@spiritprotocol.io.
What is collected, and why
If you request a read or pilot: your name, email, an optional link to your work, and what you write about it — used only to reply and to run the engagement you asked for.
If you send photographs: the image files and the analysis produced from them — used only to deliver your read. Reads are private by default. Nothing you send is published, ever, without your recorded per-image consent — and your consent does not cover other recognizable people in the frame; publication involving them needs their permission too.
Operational data: the service keeps ordinary server records — IP addresses used for rate-limiting, request logs, and copies of inquiry emails — for operations and abuse prevention only, deleted or rotated within 90 days.
What is not collected: no analytics trackers, no ad pixels, no sale or sharing of your data for anyone's marketing, ever.
Where photographs go
Analysis runs on Anthropic's Claude models, which makes Anthropic a processor of images you submit. Per Anthropic's commercial terms, API inputs and outputs are not used to train their models and are ordinarily retained by them for up to 30 days (longer only where their safety or legal policies require). Anthropic runs on cloud infrastructure providers and may process across its regions (US, Europe, Asia, Australia). No third party receives your images for its own purposes.
This service itself operates from the United States. If you are in the EU/UK, sending photographs here transfers them to the US; the legal bases relied on are contract (delivering the read or engagement you asked for), consent (any publication — always explicit, per image, revocable), and legitimate interest (basic operational records like the request email itself).
How long things are kept
- Unpublished reads (you sent a photo, never chose to share it): deleted automatically after 30 days.
- Delivered engagement work (your edit, collections, essays): originals and working files deleted 30 days after delivery unless we agree in writing to keep them. What we deliver to you is yours to keep, always.
- Published reads (you recorded consent): kept while published; unpublished and deleted on your request — consent is revocable. Deletion removes the files from live systems immediately; cached copies and operational logs referencing the file clear within 30 days.
- Request emails: ordinary correspondence, deleted on request.
What HENRI refuses, as policy
- No facial identification or recognition of people in your photographs.
- No inference of age, gender, ethnicity, health, or any sensitive characteristic of people in your photographs.
- No training of any model on your images.
- No publication of any image, name, or location without recorded consent.
Who can use this service
Uploaders must be 18 or older. During the pilot period, do not send photographs of minors or intimate images of third parties — HENRI does not screen for them (it refuses age inference as a matter of policy), so this rests on your promise; any such image HENRI becomes aware of is deleted immediately.
Your rights
Ask at any time for a copy of what is held about you, correction, or deletion — one email, honored promptly, no process to survive. If you are in the EU/UK, the GDPR rights of access, rectification, erasure, restriction, portability, and objection apply and are honored the same way.
Takedowns and mistakes
If something appears here that should not — a mistaken publication, a copyrighted work, an image of you shared without your authority — email seth@spiritprotocol.io with the URL. Removal first, questions after.