Build Notes
What AI photo restoration can fix — and what it can get wrong
What AI restoration repaired reliably on our own damaged family photos, where it altered identity or invented detail, and the limits we accepted before releasing a public beta.
That difference decides how a restored photo should be used. Damage repair is usually safe to accept and share. Reconstructed identity detail should be treated as an interpretation: keep the original file, compare the two side by side at full size, and check the face before printing, framing or sending a result to family. If a photograph is the only surviving record of someone, prefer a conservative result over a sharper one.
The rest of this article is the first-party evidence behind that conclusion. Memory Haus is our own public-beta restoration product, so every ACCEPT, CAUTION and REJECT example below comes from photographs we tested ourselves, alongside the privacy, payment and capability limits we chose to publish rather than hide.
1. A simple first attempt at family-photo repair
Fading, scratches and creases can make family photos difficult to view and share. Memory Haus tests a narrow consumer workflow: upload, generate, compare and download. The original photograph must remain the source of truth because a generative result can reconstruct historically incorrect detail.
Talk To Ah Ma explores heritage-language connection through a generated virtual-grandmother conversation with Singapore Hokkien, Mandarin translation and pronunciation help. It generates new persona-style replies; it does not retrieve a real relative's voice, memories or identity.
2. Bound the restoration flow
- Accept only supported JPEG, PNG and WebP uploads within the current size limit.
- Reject arbitrary external image URLs and reserve a free use or paid credit before the model call.
- Ask the third-party model to repair damage without modernising, beautifying or changing identity-related details.
- Return the generated result for browser comparison and download.
- Confirm the reservation on success and attempt a refund after a failed run.
3. Accountless does not mean stateless
The browser holds an opaque wallet identifier and a one-time recovery code until it is acknowledged. Server state tracks balance, recovery-code hash, daily usage, orders and credit transactions. Losing both browser state and the recovery code can make cross-device recovery impractical, and the recovery code should be treated as a secret.
4. Payment verification is manual
A purchase creates a pending internal order and sends the user to a hosted PayPal payment link. The user then submits a transaction ID; credits remain pending until an operator verifies and approves it. This is not webhook-confirmed automatic fulfilment, and operator delay or error is possible. This article intentionally omits exact pack prices because product surfaces must remain the current source of truth.
5. Explain uploaded-photo processing precisely
The reviewed wallet data does not store originals or results, but the restoration request passes through the Memory Haus server and uploads the photo to a third-party processor before the result returns. That is not proof of instant deletion, zero retention or no infrastructure metadata. Users should avoid highly sensitive material and keep the original file.
6. Real-photo evidence: three difficult before/after pairs
These are Founder-approved original files and their supplied Memory Haus outputs, published without beautifying, manual retouching, cropping-away damage or substitution. This deliberately difficult qualitative sample is not a benchmark, accuracy rate or success-rate claim. Generated or inferred detail is not verified historical detail.
| Review criterion | Visible disposition |
|---|---|
| Damage removal; structure and identity preservation; invented-detail risk; artifacts | ACCEPT, CAUTION or REJECT — with failures as visible as successful outputs |
MH-E1 — ACCEPT, with a generative-restoration caveat


MH-E2 — CAUTION


MH-E3 — REJECT


7. Keep Talk To Ah Ma's fictional boundary visible
- Replies can be inaccurate or culturally imperfect and may include invented conversational memories.
- Recent chat context is sent to the server-side AI gateway; visible history remains in the current browser.
- Daily limits and best-effort abuse controls involve server-side usage metadata.
- Voice output is configuration-dependent and is not a dependable baseline feature.
- The feature is not grief therapy, mental-health support, language certification or oral history.
8. Known limitations and operational risks
- Restoration quality varies and identity or missing detail can change.
- There is no verified gallery or completed broad real-photo evidence set.
- Photos are sent to a third-party processor; effective retention and deletion timing are not established here.
- Supported formats and upload size are bounded by the current route.
- Wallet recovery depends on local state and a secret recovery code.
- Payment confirmation is manual and may remain pending.
- Talk To Ah Ma is generated fiction with usage and capability limits.
- No paying-customer, revenue, retention or stable unit-economics evidence is claimed.
9. What we learned
The hard restoration requirement is not make it sharper; it is improve damage without rewriting identity. The accountless wallet also shows why no signup is not a complete privacy description: durable credits, recovery, orders and external processing still need explanation.
